Hardware-based certificate installation method, system, control device and storage medium
By generating public and private keys through a hardware-based security unit and verifying device and root certificates, the system addresses the security deficiencies in the digital certificate installation process, achieving higher security and reliability.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- NIO TECH ANHUI CO LTD
- Filing Date
- 2024-08-28
- Publication Date
- 2026-05-15
AI Technical Summary
The security of digital certificate installation in existing technologies is insufficient, and it is vulnerable to problems such as private key leakage, forgery, and man-in-the-middle attacks.
A hardware-based security unit is used to generate public and private keys. The security unit is used to verify device certificates and root certificates to ensure the legality and integrity of certificates. Physical isolation features prevent unauthorized access and tampering.
This improves the security and reliability of the certificate installation process, prevents private key leakage and forgery, and ensures the validity and integrity of the certificate.
Smart Images

Figure CN118972071B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, specifically providing a hardware-based certificate installation method, system, control device, and storage medium. Background Technology
[0002] Digital certificates play a crucial role in devices such as smart cars, smartphones, and wearable devices. They are generally used for device identity verification, communication encryption and authentication, access control, firmware and software update verification, as well as user identity verification and data privacy protection. These measures collectively build the trust framework of smart device systems, ensuring their stable operation and user trust.
[0003] The main security problems currently faced in the installation and use of digital certificates include private key leakage, forgery, man-in-the-middle attacks, and expiration attacks. The root cause is the low level of security in the installation environment during the installation process.
[0004] Accordingly, there is a need in the art for a new hardware-based certificate installation method, system, control device, and storage medium to solve the above problems. Summary of the Invention
[0005] In order to overcome the above-mentioned deficiencies, this application is made to provide a hardware-based certificate installation method, system, control device, and storage medium that solves or at least partially solves the technical problem of low security in digital certificate installation environments in the prior art.
[0006] In a first aspect, this application provides a hardware-based certificate installation method, wherein the hardware on which the method is based includes at least a security element, and the method includes:
[0007] The first module requests to obtain device information and public key;
[0008] The second module sends the current device information and the public key generated based on the security unit to the first module;
[0009] The first module generates a device certificate based on the received device information and the public key, and sends the device certificate to the second module;
[0010] The security unit verifies the device certificate received and installed by the second module. If the verification is successful, the device certificate is determined to be installed successfully.
[0011] The above technical solution utilizes a security unit with physical isolation to generate a public key, ensuring the security of the certificate installation process. Furthermore, by using the security unit to verify the device certificate, it can be ensured that the certificate is valid and legitimate, thus guaranteeing the reliability of the installed certificate.
[0012] In one technical solution of the above method, the security unit further generates a private key that matches the public key, the device certificate includes at least the public key, and the security unit verifies the device certificate by:
[0013] The security unit determines whether the private key and the public key in the device certificate match. If they do, the verification is successful.
[0014] The above technical solution utilizes a secure unit to generate a private key that matches the public key. The key generated based on the physical hardware of the secure unit can be physically protected, thereby preventing unauthorized access and attacks. Furthermore, the key generated based on the secure unit has higher quality randomness.
[0015] In one technical solution of the above method, before the first module requests to obtain device information and public key, the method further includes:
[0016] The third module responds to the received preset instruction, obtains the root certificate information and sends the root certificate information to the second module, wherein the root certificate information includes at least the root certificate;
[0017] The second module receives and installs the root certificate;
[0018] The security unit verifies the root certificate installed in the second module. If the verification passes, the verification result is sent to the third module.
[0019] The third module sends the verification result to the first module, so that the first module triggers the request.
[0020] The above technical solution enables the second module to install the root certificate to establish a chain of trust, thereby ensuring that the certificate used by the device can be trusted. Utilizing the security unit to verify the root certificate, and fully leveraging its resistance to side-channel attacks and high verification efficiency, the verification process achieves higher security and the verification results have higher credibility.
[0021] In one technical solution of the above method, the root certificate information further includes at least first verification information corresponding to the root certificate in the third module, and the security unit verifies the root certificate installed in the second module by:
[0022] The second module generates second verification information corresponding to the installed root certificate based on the installed root certificate;
[0023] The security unit determines whether the second verification information matches the first verification information; if so, it determines that the verification is successful.
[0024] The above technical solution can verify whether the received root certificate is consistent with the sent root certificate, thereby determining whether the root certificate has been tampered with during transmission or whether the received root certificate is complete, ensuring the integrity and trustworthiness of the root certificate. Using a secure unit for verification, based on its physically secure protection, leverages its higher performance as physical hardware to execute the verification process, improving the efficiency of the verification process and the trustworthiness of the verification results.
[0025] In one technical solution of the above method, the security unit verifies the device certificate by including:
[0026] The security unit uses the root certificate to determine whether the device certificate is valid; if so, the verification is successful.
[0027] The above technical solution utilizes root certificates to determine whether device certificates are issued by legitimate certificate authorities, thereby ensuring the security and reliability of the certificate installation process. Employing a secure unit to perform certificate verification improves verification security and efficiency, preventing certificate tampering and forgery.
[0028] In one technical solution of the above method, the second module sending the current device information and the public key generated based on the security unit to the first module includes:
[0029] The second module sends the device information and the public key to the third module;
[0030] The third module sends the received device information and the public key to the first module.
[0031] In one technical solution of the above method, sending the device certificate to the second module includes:
[0032] The first module sends the device certificate to the third module;
[0033] The third module sends the received device certificate to the second module.
[0034] In a second aspect, this application provides a certificate installation system, the system comprising at least a security unit, a first module, a second module, and a third module, the certificate installation system being used to perform the method described in any of the above technical solutions.
[0035] In a third aspect, a control device is provided, comprising one or more memories and one or more processors, characterized in that the memories are used to store computer programs; and the processors are used to invoke the computer programs, causing the control device to execute the method described in any of the above-described hardware-based certificate installation methods.
[0036] In a fourth aspect, a computer-readable storage medium is provided, including computer instructions; when the computer instructions are executed on an electronic device, the electronic device is caused to perform the method described in any of the above-described hardware-based certificate installation methods. Attached Figure Description
[0037] The disclosure of this application will become more readily understood with reference to the accompanying drawings. It will be readily understood by those skilled in the art that these drawings are for illustrative purposes only and are not intended to limit the scope of protection of this application. Furthermore, similar numbers in the drawings are used to denote similar components, wherein:
[0038] Figure 1 This is a schematic flowchart of the main steps of a hardware-based certificate installation method according to an embodiment of this application;
[0039] Figure 2 This is a schematic flowchart of the main steps of a hardware-based certificate installation method according to an embodiment of this application;
[0040] Figure 3 This is a schematic diagram illustrating an application scenario of a hardware-based certificate installation method according to an embodiment of this application;
[0041] Figure 4 This is a schematic diagram of data interaction timing in an application scenario of a hardware-based certificate installation method according to an embodiment of this application;
[0042] Figure 5 This is a schematic diagram of the main structural framework of a certificate installation system according to an embodiment of this application.
[0043] List of reference numerals :
[0044] 110: Module 1; 120: Module 3; 130: Module 2; 140: Security Unit Detailed Implementation
[0045] Some embodiments of this application are described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of this application and are not intended to limit the scope of protection of this application.
[0046] In the description of this application, "module" and "processor" can include hardware, software, or a combination of both. A module can include hardware circuitry, various suitable sensors, communication ports, memory, and can also include software components, such as program code, or a combination of software and hardware. A processor can be a central processing unit, microprocessor, image processor, digital signal processor, or any other suitable processor. The processor has data and / or signal processing capabilities. The processor can be implemented in software, in hardware, or a combination of both. Non-transitory computer-readable storage media includes any suitable medium capable of storing program code, such as magnetic disks, hard disks, optical disks, flash memory, read-only memory, random access memory, etc. The term "A and / or B" means all possible combinations of A and B, such as only A, only B, or A and B. The terms "at least one A or B" or "at least one of A and B" have a similar meaning to "A and / or B" and can include only A, only B, or A and B. The singular terms "a" or "this" can also include plural forms.
[0047] Please see the appendix Figure 1 , Figure 1 This is a schematic flowchart illustrating the main steps of a hardware-based certificate installation method according to an embodiment of this application. Figure 1 As shown, the hardware-based certificate installation method of this application mainly includes steps S1-S4:
[0048] Step S1: The first module requests to obtain device information and public key;
[0049] In this embodiment, the first module can be a hardware module or a software program; the device information can be the device identification code or other data information that can uniquely represent the device identity, such as the vehicle information of a car can be the Vehicle Identification Number (VIN), or the chassis number, engine number, etc.; the public key is a key used for encryption in the encryption algorithm, which can be used for encrypted communication, digital signature, authentication, etc.
[0050] Step S2: The second module sends the current device information and the public key generated based on the security element to the first module;
[0051] In this embodiment, the second module can be a hardware module or a software program; the security unit is physical hardware, which can be integrated into the processor, chip or other hardware device as a hardware security engine (HSE) to provide functions such as encryption, random number generation, secure storage, and key management. In this embodiment, the security unit generates the public key in the form of a random number.
[0052] Step S3: The first module generates a device certificate based on the received device information and public key, and sends the device certificate to the second module;
[0053] In this embodiment, the first module can be a Public Key Infrastructure (PKI), which can be used to establish, manage and use digital certificates to support secure communication and authentication. The first module can generate a device certificate using device information and encrypt or sign it with a public key. Therefore, the first module in this embodiment can have both PKI function and information request function. The execution entity when requesting to obtain device information and public key can be a sub-module in the first module.
[0054] Step S4: The security unit verifies the device certificate received and installed by the second module. If the verification is successful, the device certificate is confirmed to be installed successfully.
[0055] In this embodiment, the security unit and the second module establish a connection through a dedicated communication method. The second module first performs the installation of the device certificate, so that the device certificate itself or related information can be transmitted to the security unit. Only after the security unit verifies and passes the device certificate can it be confirmed that the installation of the device certificate is successful and valid.
[0056] In one implementation, the security unit also generates a private key that matches the public key. The key generation process can be simultaneous; that is, the security unit randomly generates a key pair containing the public and private keys. The public key is sent to the recipient, and the private key is securely stored for use in subsequent verification processes. Therefore, in step S4, the process of the security unit verifying the device certificate can at least include: the security unit using the stored private key to determine whether the private key matches the public key in the device certificate; if so, the verification is successful.
[0057] Based on the above steps S1-S4, it can be seen that this application uses a security unit with physical isolation characteristics to generate a public key, which ensures the security of the certificate installation process. Furthermore, by using the security unit to verify the device certificate, it can ensure that the certificate is a valid and legitimate certificate, thus guaranteeing the reliability of the installed certificate.
[0058] In the above Figure 1 Based on the embodiments shown, please continue to refer to the appendix. Figure 2 , Figure 2 This is a schematic flowchart illustrating the main steps of a hardware-based certificate installation method according to an embodiment of this application. Figure 2 As shown, prior to step S1 above, the hardware-based certificate installation method of this application may further include steps S01-S04:
[0059] Step S01: The third module responds to the received preset instruction, obtains the root certificate information, and sends the root certificate information to the second module;
[0060] In this embodiment, the third module can be a hardware module or a software program; the preset instruction can be a preset instruction for a button to be pressed, or preset instruction data containing specific codes. In general application scenarios, the preset instruction is a certificate installation instruction input by the user; the root certificate information includes at least the root certificate body. The root certificate can be stored in a local storage device or a cloud server, or the root certificate can be issued by the first module (i.e., PKI) and sent to the third module; the third module establishes a connection with the second module through a dedicated communication method, and the third module forwards the root certificate information to the second module.
[0061] Step S02: The second module receives and installs the root certificate;
[0062] In this embodiment, the second module receives the root certificate information and installs the root certificate body.
[0063] Step S03: The security unit verifies the root certificate installed in the second module. If the verification is successful, the verification result is sent to the third module.
[0064] In this embodiment, the second module first performs the installation of the root certificate, thereby enabling the root certificate itself or related information to be transmitted to the security unit. Only after the security unit verifies and passes the root certificate can the installation of the root certificate be confirmed as successful and valid; if the verification fails, all subsequent steps are terminated.
[0065] In one implementation, the root certificate information further includes at least first verification information corresponding to the root certificate sent previously. The security unit's verification of the root certificate installed by the second module may further include at least: the second module generating second verification information corresponding to the installed root certificate based on the installed root certificate; and the security unit determining whether the second verification information matches the first verification information. If so, the verification is deemed successful. In typical application scenarios, the verification information can be a hash value. Therefore, the verification process in this implementation can be summarized as "generating a first hash value based on the sent version of the root certificate, generating a second hash value based on the received version of the root certificate, and verifying the integrity of the received root certificate by comparing the first and second hash values," ensuring that the root certificate is not damaged or tampered with during transmission.
[0066] Step S04: The third module sends the verification result to the first module so that the first module triggers a request;
[0067] In this embodiment, after receiving the root certificate verification result, the first module triggers a request to "request device information and public key". It should be understood that although the second module responds to the request, it does not mean that the request was directly sent to the second module by the first module. For example, in one embodiment, the first module triggers the request and sends the request to the third module. The third module forwards the request to the second module. The second module responds to the request and sends the relevant information to the third module. Finally, the third module forwards the relevant information to the first module. In this embodiment, the third module has the functions of responding to preset instructions and forwarding information.
[0068] exist Figure 2 Based on the illustrated embodiment, step S4 may further include: the security unit uses the root certificate to determine whether the device certificate is valid; if so, the verification is deemed successful. The root certificate is used to verify the issuer's identity information of the device certificate. In one embodiment, the public key of the CA obtained from the root certificate is used to verify the digital signature in the device certificate, to verify whether the signature was generated by the CA that issued the device certificate using its private key. In another embodiment, the security unit may also verify whether the current time is within the validity period of the device certificate, thereby determining the validity of the device certificate's validity period.
[0069] exist Figure 2 Based on the illustrated embodiment, step S2 may further include: the second module sending device information and public key to the third module; and the third module sending the received device information and public key to the first module. Similarly, step S3 may further include: the first module sending device certificate to the third module; and the third module sending the received device certificate to the second module. In both embodiments, the third module acts as an information forwarding module, undertaking the data interaction between the first and second modules.
[0070] Please refer to the attached document. Figure 3 and attached Figure 4 , Figure 3 This is a schematic diagram illustrating an application scenario of a hardware-based certificate installation method according to an embodiment of this application. Figure 4This is a schematic diagram of the data interaction timing in an application scenario of a hardware-based certificate installation method according to an embodiment of this application. In this application scenario, the first module is PKI, the second module is ServerAPP, the third module is ClientAPP, and the security unit is HSE security engine. The ECU is the vehicle controller. The ServerAPP responsible for certificate installation runs in an insecure space and can interact with the HSE security engine through a specific inter-core communication method. The HSE security engine runs in a physically isolated secure space and has functions such as key generation, key storage, encryption, decryption, and authentication. The vehicle diagnostic tool (DT) is the ClientAPP responsible for handling user requests, interacting with the ECU via Ethernet, and interacting with the cloud PKI server via HTTPS. The main function of Public Key Infrastructure (PKI) is to bind the identity of the certificate holder and related key pairs (by issuing digital certificates for public keys and related user identity information), providing users with convenient services such as certificate application, certificate revocation, certificate acquisition, and certificate status query. In this application scenario, the data interaction timing of each module can be described as follows:
[0071] 1. The user initiates a certificate installation request;
[0072] 2-3. The Client App responds to the certificate installation request, obtains the root certificate from the cloud server, and transmits the root certificate and the first hash value to the Server App;
[0073] 4-5. The Server App installs the root certificate and generates a second hash value based on the installed root certificate. Then, it transmits the first hash value and the second hash value to the HSE.
[0074] 6-7. HSE checks whether the first and second hash values are the same. If they are, the verification passes and the result is returned to the Client APP (or the result can be transmitted to the Server APP first, and the Server APP can forward the result to the Client APP).
[0075] 8-10. The Client APP sends the result to the PKI. After receiving the verified result, the PKI triggers a request to obtain the vehicle number and public key.
[0076] 11-13. HSE sends the generated public key to Server APP, which then sends the public key and vehicle number to PKI (or the vehicle number and public key can be sent to Client APP first, and then forwarded to PKI by Client APP).
[0077] 14-17. PKI generates vehicle certificates based on public keys and vehicle numbers, and sends the vehicle certificates to the server app through the client app, so that the server app can receive and install the vehicle certificates;
[0078] S18-20. The Server App requests the HSE to check the legality and validity of the vehicle certificate (using the private key stored in the HSE and the already installed root certificate), and the HSE sends the result to the Server App.
[0079] The S21-S22 Server APP sends the vehicle certificate verification result to the PKI via the Client APP;
[0080] S23-S24.PKI associates the vehicle number and vehicle certificate and sets them to valid, then sends the operation result to the Client APP so that the user knows that the certificate has been successfully installed.
[0081] It should be understood that the above application scenarios are only one of the actual application scenarios of this application, and their main purpose is only to simply describe the technical solution of this application, and they should not be used to limit the technical solution of this application.
[0082] It should be noted that although the steps in the above embodiments are described in a specific order, those skilled in the art will understand that in order to achieve the effect of this application, different steps do not necessarily have to be executed in such an order. They can be executed simultaneously (in parallel) or in other orders, and these variations are all within the scope of protection of this application.
[0083] Furthermore, this application also provides a certificate installation system.
[0084] See appendix Figure 5 , Figure 5 This is a main structural block diagram of a certificate installation system according to an embodiment of this application. Figure 5As shown, the certificate installation system in this embodiment mainly includes a first module 110, a third module 120, a second module 130, and a security unit 140. In some embodiments, one or more of the first module 110, the third module 120, the second module 130, and the security unit 140 can be combined into a single module. In some embodiments, the first module 110 can be configured to request device information and a public key, generate a device certificate based on the received device information and public key, and send the device certificate to the second module 130. The second module 130 can be configured to send the device information of the current device and the public key generated based on the security unit 140 to the first module 110. The security unit 140 can be configured to verify the device certificate received and installed by the second module 130; if the verification is successful, the device certificate installation is determined to be successful. The third module 120 can be configured to, in response to a received preset instruction, obtain root certificate information and send the root certificate information to the second module 130, and send the verification result to the first module 110, so that the first module 110 triggers a request.
[0085] The above certificate installation system is used for execution Figure 1 The hardware-based certificate installation method embodiments shown are similar in technical principle, the technical problems they solve, and the technical effects they produce. Those skilled in the art can clearly understand that, for the sake of convenience and brevity, the specific working process and related descriptions of the certificate installation system can be found in the embodiments of the hardware-based certificate installation method, which will not be repeated here.
[0086] Those skilled in the art will understand that all or part of the processes in the method of the above-described embodiment can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable storage medium can include any entity or device capable of carrying the computer program code, a medium, a USB flash drive, a portable hard drive, a magnetic disk, an optical disk, a computer memory, a read-only memory, a random access memory, an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc. It should be noted that the content included in the computer-readable storage medium can be appropriately added or removed according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable storage medium does not include electrical carrier signals and telecommunication signals.
[0087] Furthermore, this application also provides a control device. In one embodiment of the control device according to this application, the control device includes a processor and a storage device. The storage device can be configured to store a program for executing the hardware-based certificate installation method of the above-described method embodiments. The processor can be configured to execute the program in the storage device, which includes, but is not limited to, the program for executing the hardware-based certificate installation method of the above-described method embodiments. For ease of explanation, only the parts related to the embodiments of this application are shown. For specific technical details not disclosed, please refer to the method section of the embodiments of this application. The control device can be a control device device formed by various electronic devices.
[0088] Furthermore, this application also provides a computer-readable storage medium. In one embodiment of the computer-readable storage medium according to this application, the computer-readable storage medium can be configured to store a program that performs the hardware-based certificate installation method of the above-described method embodiments. This program can be loaded and run by a processor to implement the above-described hardware-based certificate installation method. For ease of explanation, only the parts related to the embodiments of this application are shown; for specific technical details not disclosed, please refer to the method section of the embodiments of this application. The computer-readable storage medium can be a storage device comprising various electronic devices. Optionally, in the embodiments of this application, the computer-readable storage medium is a non-transitory computer-readable storage medium.
[0089] Furthermore, it should be understood that since the various modules are only provided to illustrate the functional units of the device described in this application, the physical devices corresponding to these modules may be the processor itself, or a part of the processor's software, hardware, or a combination of both. Therefore, the number of modules shown in the figures is merely illustrative.
[0090] Those skilled in the art will understand that the various modules in the device can be adaptively split or combined. Such splitting or combining of specific modules will not cause the technical solution to deviate from the principles of this application; therefore, the technical solutions after splitting or combining will fall within the protection scope of this application.
[0091] The technical solutions of this application have been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of this application is obviously not limited to these specific embodiments. Without departing from the principles of this application, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of this application.
Claims
1. A hardware-based certificate installation method, characterized in that, The hardware upon which the method is based includes at least a security element, which is integrated into the hardware device as a hardware security engine. The method includes: The third module sends root certificate information to the second module, the root certificate information including at least a root certificate; the second module receives and installs the root certificate; the security unit verifies the root certificate installed by the second module, and if the verification is successful, sends the verification result to the third module, and the third module sends the verification result to the first module; After receiving the verification result, the first module requests to obtain device information and public key; The second module sends the current device information and the public key generated based on the security unit to the first module; The first module generates a device certificate based on the received device information and the public key, and sends the device certificate to the second module; The security unit verifies the device certificate received and installed by the second module. If the verification is successful, the device certificate is determined to be installed successfully.
2. The method according to claim 1, characterized in that, The security unit also generates a private key that matches the public key, the device certificate includes at least the public key, and the security unit verifies the device certificate by: The security unit determines whether the private key and the public key in the device certificate match. If they do, the verification is successful.
3. The method according to claim 1, characterized in that, The third module sends the root certificate information to the second module, including: The third module responds to the received preset instruction by obtaining the root certificate information and sending the root certificate information to the second module.
4. The method according to claim 3, characterized in that, The root certificate information further includes at least first verification information corresponding to the root certificate in the third module, and the security unit verifies the root certificate installed in the second module by: The second module generates second verification information corresponding to the installed root certificate based on the installed root certificate; The security unit determines whether the second verification information matches the first verification information; if so, it determines that the verification is successful.
5. The method according to claim 3, characterized in that, The security unit verifies the device certificate by including: The security unit uses the root certificate to determine whether the device certificate is valid; if so, the verification is successful.
6. The method according to any one of claims 3 to 5, characterized in that, The second module sends the current device information and the public key generated based on the security unit to the first module, including: The second module sends the device information and the public key to the third module; The third module sends the received device information and the public key to the first module.
7. The method according to any one of claims 3 to 5, characterized in that, Sending the device certificate to the second module includes: The first module sends the device certificate to the third module; The third module sends the received device certificate to the second module.
8. A certificate installation system, characterized in that, The system includes at least a security unit, a first module, a second module, and a third module, and the certificate installation system is used to perform the method of any one of claims 1-7.
9. A control device comprising one or more memories and one or more processors, characterized in that, The memory is used to store a computer program; the processor is used to invoke the computer program, causing the control device to perform the method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, Includes computer instructions; when the computer instructions are executed on an electronic device, the electronic device causes the electronic device to perform the method of any one of claims 1-7.