Key management method and vehicle

By using a random number key seed generated by the key management master node in the key management system and performing security verification, and periodically updating the key seed, the problem of keys being easily cracked due to imperfect key management schemes is solved, thereby improving key security and protection capabilities.

CN119519959BActive Publication Date: 2026-04-07Z-ONE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing key management schemes are imperfect, which makes keys vulnerable to cracking and acquisition, especially since fixed keys in vehicles are easily obtained by attackers.

Method used

The key management master node generates a key seed based on a key random number, and distributes it to the key management slave nodes after security verification. The key slave nodes generate keys based on the key seed and periodically update the key seed to reduce the risk of cracking.

Benefits of technology

It effectively reduces the risk of key cracking, improves key security, and prevents attackers from obtaining key seeds and affecting the normal operation of electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119519959B_ABST
    Figure CN119519959B_ABST
Patent Text Reader

Abstract

The application discloses a key management method and a vehicle. The key management method comprises the following steps: a key management master node responds to key seed acquisition request information sent by a key management slave node, and performs security verification on the key management slave node; if the security verification is passed, the key management master node sends key seed acquisition response information including a key seed to the key management slave node, and the key seed is generated based on a key random number. The key management slave node responds to the received key seed acquisition response information, and obtains the key seed. If there is a key use requirement, the key management slave node generates a key based on the key seed, so that the risk of key cracking can be effectively reduced, and the key security is improved. Further, the key seed is generated by the key management master node based on the key random number, so that the key seed information generated by the key management master node cannot be predicted, the risk of key cracking is further reduced, and the key security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of key management, and in particular to a key management method and a vehicle. BACKGROUND

[0002] In order to prevent and alleviate network attacks, more and more information security measures are applied in network protection. At present, security measures are usually implemented based on cryptography, and most of the cryptographic techniques rely on keys. The use scenarios of keys are various, but there is no perfect and unified key management scheme at present. The keys are pre-configured, and the pre-configured keys are fixed, which leads to a high risk of key cracking. Therefore, how to implement perfect and unified key security management and reduce the risk of key cracking and acquisition is a problem to be solved at present. SUMMARY

[0003] The purpose of the present application is to solve the problem of key cracking and acquisition. To solve the above technical problems, the embodiments of the present application disclose a key management method and a vehicle.

[0004] In a first aspect, the embodiments of the present application provide a key management method applied to a key management system, the key management system comprising a key management master node and a plurality of key management slave nodes; the key management method comprising:

[0005] The key management master node responds to the key seed acquisition request information sent by the key management slave node, performs security verification on the key management slave node, and in the case that the security verification is passed, sends key seed acquisition response information to the key management slave node, the key seed acquisition response information comprising key seed information, the key seed information comprising a key seed, the key seed being generated by the key management master node based on a key random number;

[0006] The key management slave node responds to the key seed acquisition response information, obtains the key seed according to the key seed acquisition response information, and in the case that there is a key use demand, generates a key according to the key seed for business encryption processing.

[0007] When the key management method is used to manage the key, the key management master node generates the key seed based on the received key seed obtaining request information and sends the key seed to the key management slave node. In the case where there is a key usage requirement, the key management slave node generates the key based on the key seed. In the key management method, the key is generated based on the key seed, so that the risk of the key stored in the firmware being cracked can be effectively reduced, and the key security is improved. Further, the key seed is generated by the key management master node based on the key random number, so that the key seed information generated by the key management master node cannot be predicted, and the risk of the key being cracked is further reduced, and the key security is improved.

[0008] In a possible implementation of the key management method of the present application, the key management method further comprises:

[0009] In the case where the key management slave node receives the key seed distribution notification information sent by the key management master node, the key management slave node sends the key seed obtaining request information to the key management master node.

[0010] When the key management method is used to manage the key, the key management slave node generates the key seed obtaining request information based on the received key seed distribution notification information sent by the key management master node. The key seed obtaining request information obtained based on the method corresponds to the key seed obtaining request information generated by the key management slave node, so that the key seed obtaining request information has a corresponding relationship with the key management slave node, and the accuracy of the security verification of the key management slave node based on the key seed obtaining request information can be effectively guaranteed.

[0011] In a possible implementation of the key management method of the present application, the key management method further comprises:

[0012] The key management master node generates the key seed distribution notification information in response to receiving the key seed distribution instruction information sent by the diagnostic tool; or,

[0013] The key management master node generates the key seed distribution notification information according to a preset key seed distribution period.

[0014] When the key management method is used to manage the key, the key management master node generates the key seed obtaining request information when the diagnostic tool sends the key seed distribution instruction information to the key management master node. That is, the user can update the key seed based on the diagnostic requirement, so that the key seed can be regenerated after the old key seed is obtained by the attacker, thereby effectively avoiding the risk that the operation of the electronic device involved in the key management system is affected after the key seed is obtained by the attacker.

[0015] Further, the key management master node can generate the key seed acquisition request information according to the preset key seed distribution period. Based on this method, the key seed distribution notification information can be updated periodically based on the key seed distribution period, that is, the key seed can be generated and updated periodically. Periodic update of the key seed can regenerate a new key seed after the old key seed is obtained by an attacker, effectively avoiding the risk that the key seed obtained by the attacker affects the operation of the electronic device involved in the key management system.

[0016] In a possible implementation of the key management method of the present application, the key seed distribution period is determined according to the power-on period of the electronic device involved in the key management system.

[0017] When the key management method is used to manage the key, the key seed distribution period can be determined based on the power-on period of the electronic device corresponding to the key management system. Based on this method, the power-on period and the key seed distribution period are set in a certain relationship, so as to facilitate the subsequent management of the currently generated key seed and the key seed currently used to generate the key.

[0018] In a possible implementation of the key management method of the present application, the key seed acquisition request information includes identification information and identity token information of the key management slave node, and the key management master node performs security verification on the key management slave node, including:

[0019] The key management master node parses the identification information and identity token information of the key management slave node from the key seed acquisition request information, and performs security verification on the key management slave node based on the identification information and identity token information of the key management slave node and the key management slave node registration information. The key management slave node registration information includes the identification information, the identity token information and the validity information of the identity token information of the key management slave node registered in the key management master node. If the identification information and the identity token information of the key management slave node exist in the key management slave node registration information and the identity token information is valid, the security verification result of the key management slave node is that the security verification is passed. If the identification information and the identity token information of the key management slave node do not exist in the key management slave node registration information or the identity token information is invalid, the security verification result of the key management slave node is that the security verification is not passed.

[0020] When the key management method is used to manage the key, before sending the key seed obtaining response information to the key management slave node, the key management master node verifies the identity of the key management slave node, and when the identity verification of the key management slave node is passed, the key management master node sends the key seed obtaining response information to the key management slave node. In the key management method, the identity verification of the key management slave node is set, which can effectively ensure the accuracy of the identity of each node and further prevent the risk of the key seed being obtained by an attacker.

[0021] In a possible implementation of the key management method of the application, the key management slave node registration information is generated in the following manner:

[0022] The key management master node sends the node identity registration notification information to the key management slave node;

[0023] The key management slave node sends the identity registration request information to the key management master node in response to receiving the node identity registration notification information, and the identity registration request information includes the identification information of the key management slave node;

[0024] The key management master node generates the identity token information and the identity key information of the key management slave node in response to receiving the identity registration request information, obtains the key management slave node registration information, and generates the identity registration response information and sends it to the key management slave node, the identity registration response information includes the identity token information and the identity key information of the key management slave node, and the identity key information is used for encryption and decryption processing of the identity token information and the key seed information;

[0025] The key management slave node stores the identity token information and the identity key information of the key management slave node parsed from the identity registration response information in response to receiving the identity registration response information, and sends the identity registration response parsing result information to the key management master node;

[0026] The key management master node obtains the identity registration response parsing result in response to receiving the identity registration response parsing result information.

[0027] When the key management method is used to manage the key, before the key management master node generates the key seed distribution information, the identity registration of the key management slave node is completed, the accuracy of the identity of the key management slave node can be determined based on the registered identity information of the key management slave node in the subsequent key seed distribution process, so that the accuracy of the key seed distribution can be ensured, and the risk of the key seed being obtained by an attacker can be prevented, and when the key management slave node performs the identity registration, the identity key corresponding to the key management slave node is generated, so that the key seed can be encrypted based on the identity key when the key seed is generated subsequently, thereby effectively preventing the key seed from being obtained by an attacker.

[0028] In a possible implementation of the key management method, the key management master node sends node identity registration notification information to the key management slave node, including:

[0029] The key management master node sends node identity registration notification information to the key management slave node in response to receiving the node identity registration instruction information sent by the diagnostic tool.

[0030] The method further includes:

[0031] The key management master node generates identity registration result response information based on the identity registration response analysis result, and sends the identity registration result response information to the diagnostic tool.

[0032] The diagnostic tool obtains the identity registration result in response to receiving the identity registration result response information.

[0033] When the key is managed by using the key management method, the diagnostic tool sends node identity registration information, so that the key management master node generates identity information of the key management slave node, and the key management master node sends identity registration result response information to the diagnostic tool, so that the diagnostic tool determines that the identity registration of the key management slave node is completed, to facilitate subsequent triggering of generation of key seed acquisition information and generation of a key seed.

[0034] In a possible implementation of the key management method, the node identity registration instruction information includes node identity token validity period information, and the key management method further includes:

[0035] The key management master node manages the validity period of the identity token of the key management slave node based on the node identity token validity period information.

[0036] When the key is managed by using the key management method, the node identity token validity period information is set in the node identity registration instruction information. Based on the node identity token validity period, the validity of the current node identity token can be determined, and based on the validity, it can be determined whether the received identity token is correct, thereby ensuring the security of the distributed key seed and effectively preventing the risk of obtaining the key seed.

[0037] In a possible implementation of the key management method, the node identity registration instruction information includes key seed distribution period information, and the key management method further includes:

[0038] The key management master node manages the key seed distribution time based on the key seed distribution period information.

[0039] When the key is managed by using the key management method, the key management master node distributes the key to the key management slave node based on the key seed distribution period, which can manage the key distribution and ensure the orderliness of the key distribution.

[0040] In a possible implementation of the key management method, the identification information is name and / or serial number information of the electronic device to which the key management slave node is related.

[0041] When the key is managed by using the key management method, the name and / or serial number information of the electronic device to which the key management slave node is related is set in the identification information, the identity information of the key management slave node can be determined based on the name and / or serial number of the electronic device, and the security of the key seed transmission is effectively ensured.

[0042] In a possible implementation of the key management method, the key management slave node generates a key according to the key seed in the case where there is a key usage requirement, and the method comprises:

[0043] The key management slave node generates a key according to the key seed generated by the electronic device to which the key management system is related in the last power-on cycle in the case where there is a key usage requirement.

[0044] When the key is managed by using the key management method, the key is generated based on the key seed generated in the last power-on cycle, and the risk that the key management slave node cannot generate a key due to the absence of a key seed in the key management slave node when the key needs to be used in the key seed generation process can be effectively prevented.

[0045] In a possible implementation of the key management method, the key management method further comprises:

[0046] The key management slave node stores the generated key in the memory of the key management slave node.

[0047] When the key is managed by using the key management method, the key is stored in the memory of the key management slave node, that is, the key is not stored in firmware, and the risk that the key is acquired by an attacker can be effectively prevented.

[0048] In a possible implementation of the key management method, the key management method further comprises:

[0049] The key management slave node decrypts the target data based on an old key generated by an old key seed, generates a new key based on a new key seed, encrypts the target data based on the new key, and deletes the old key seed and the old key.

[0050] When the key is managed by using the key management method, the old key seed is deleted after the new key seed is generated, and the problem of calling errors caused by too many key seeds when the key seed is called can be effectively prevented.

[0051] In a possible implementation of the key management method, the key management method further includes that the key management slave node destroys the key seed in any of the following cases:

[0052] a new key seed is obtained;

[0053] the key seed is used up;

[0054] a key seed destruction instruction predefined by the system is received.

[0055] When the key management method is used to manage the key, the old key seed is destroyed when a new key seed is obtained, the key seed is used up, and a key seed destruction instruction is received, thereby effectively preventing the problem of key seed calling error when the key seed is called.

[0056] In a possible implementation of the key management method, the key management system further includes a hardware security module, and the hardware security module includes a random number generator. The key random number is generated by the random number generator and sent to the key management master node.

[0057] When the key management method is used to manage the key, the hardware security module is arranged in the key management master node, the random number generator is arranged in the hardware security module, the key random number is generated based on the random number generator, and the key seed is generated based on the key random number, thereby effectively ensuring that the key seed information generated by the key management master node cannot be predicted, and further reducing the risk of key cracking.

[0058] In a possible implementation of the key management method, the key management method further includes:

[0059] The information transmitted between the key management master node and the key management slave node is encrypted and transmitted based on a preset key.

[0060] When the key management method is used to manage the key, the information transmitted between the key management master node and the key management slave node is encrypted and transmitted based on a preset key, thereby effectively ensuring the security of information transmission and further ensuring the security of the key seed generation and transmission process.

[0061] In a possible implementation of the key management method, the electronic device related to the key management master node and the key management slave node is an electronic control unit.

[0062] In a second aspect, another embodiment of the application discloses a vehicle, the vehicle including a key management system, the key management system including a key management master node and a plurality of key management slave nodes. The key management master node and the key management slave nodes interact to implement the key management method of any of the above embodiments.

[0063] Another embodiment of the present application provides a vehicle with a key management system, and the key management system can interact with information, and the key management method of any one of the above embodiments is used to generate and manage the key, so as to effectively prevent the risk of the key in the vehicle being obtained by an attacker, and effectively guarantee the safe use of the vehicle. BRIEF DESCRIPTION OF DRAWINGS

[0064] Figure 1 A flowchart of a key management method provided by an embodiment of the present application;

[0065] Figure 2 A flowchart of another key management method provided by an embodiment of the present application;

[0066] Figure 3 A flowchart of another key management method provided by an embodiment of the present application;

[0067] Figure 4 A flowchart of generating key management slave node registration information in the key management method provided by an embodiment of the present application;

[0068] Figure 5 A flowchart of generating key management slave node registration information in the key management method provided by an embodiment of the present application;

[0069] Figure 6 A structure diagram of a key management system provided by another embodiment of the present application;

[0070] Figure 7 A structure diagram of a vehicle provided by another embodiment of the present application. DETAILED DESCRIPTION

[0071] In the existing network security protection, in order to prevent and alleviate network attacks, the information in the network can be protected based on the password technology. However, the implementation of the password technology depends on the key. The key has many use scenarios, but there is no perfect management method for the management of the key, resulting in a high risk of key cracking.

[0072] For example, the risk of the key in the vehicle being cracked is taken as an example for illustration.

[0073] In the vehicle, when the vehicle is on the production line, the key management system in the vehicle generates the key used in the operation of the vehicle after the diagnosis tool is diagnosed. In addition, the key used in the operation of the vehicle is fixed and unchangeable in the whole life cycle of the vehicle, that is, the key is not supported to be updated. Therefore, it is easy to cause a high risk of the key being cracked in the use process of the vehicle.

[0074] Further, the key generated in the key management system is stored in the hard disk, and even the key can be stored in the hard disk in plaintext, further increasing the risk of the key being obtained by an attacker.

[0075] Based on the above problems, the application provides a key management method and a vehicle. In the key management method, a key management slave node generates a key based on a key seed, and the key seed is generated by a key management master node based on a key random number, thereby effectively reducing the risk of the key being cracked. In addition, the key seed is stored in the key management master node and the key management slave node, and the key seed is periodically updated, further reducing the risk of the key being cracked.

[0076] Reference Figure 1 , Figure 1 A flowchart of a key management method provided by an embodiment of the application is shown. In a first aspect, the embodiment of the application provides a key management method applied to a key management system, the key management system including a key management master node and a plurality of key management slave nodes; the key management method including:

[0077] Step S1: The key management master node performs security verification on the key management slave node in response to receiving key seed acquisition request information sent by the key management slave node.

[0078] Step S2: In the case where the security verification is passed, the key management master node sends key seed acquisition response information to the key management slave node, the key seed acquisition response information including key seed information, the key seed information including a key seed, the key seed being generated by the key management master node based on a key random number.

[0079] Step S3: The key management slave node obtains the key seed according to the key seed acquisition response information in response to receiving the key seed acquisition response information.

[0080] Step S4: In the case where there is a key usage requirement, the key management slave node generates a key based on the key seed for business encryption processing.

[0081] When the key is generated and managed by using the above key management method, the key management master node generates a key seed based on the received key seed acquisition request and sends the key seed to the key management slave node. In the case where there is a key usage requirement, the key management slave node generates a key based on the key seed. In the key management method, the key management slave node generates a key based on the key seed, thereby effectively reducing the risk of the key being cracked. Further, the key seed is generated by the key management master node based on a key random number, which can effectively ensure that the key seed information generated by the key management master node cannot be predicted, further reducing the risk of the key being cracked.

[0082] Reference Figure 1 In a possible implementation of the key management method, the specific method of step S1 includes: the key management master node receiving key seed acquisition request information sent by the key management slave node; and the key management master node verifying the security of the key management slave node based on the key seed acquisition request information. If the security of the key management slave node is verified, step S2 is performed; if the security of the key management slave node is not verified, subsequent steps are stopped.

[0083] The specific method of step S2 includes: the key management master node generating key seed acquisition response information, and sending the key seed acquisition response information to the key management slave node after the key seed acquisition response information is encrypted based on the pre-stored identity key of the key management slave node.

[0084] Further, the key seed acquisition response information includes key seed information, and the key seed information includes a key seed and a key seed batch number. The key seed batch number is set in the key seed information, the corresponding key seed can be determined based on the key seed batch number, and the target key seed can be quickly determined based on the key seed batch number.

[0085] The specific method of step S3 includes: the key management slave node receiving the key seed acquisition response information; and the key management slave node decrypting the key seed acquisition response information based on the pre-stored identity key of the key management slave node to obtain the key seed.

[0086] The specific method of step S4 includes: the key management slave node generating a corresponding key based on the key seed and a key generation rule in response to the received key acquisition information, and performing encryption processing on the service based on the key. The key is a key used for password operation of service function data.

[0087] Further, in the key management method, the key seed is generated based on a key random number, which can ensure that each generated key seed is different and unpredictable, thereby effectively ensuring that the information of the key seed cannot be predicted by an attacker, and reducing the risk of cracking the key seed.

[0088] In addition, in the key management method, the number of key management slave nodes in the key management system can be multiple, and the multiple key management slave nodes can simultaneously generate corresponding key seeds.

[0089] Reference Figure 2 , Figure 2 Another flowchart of a key management method provided for an embodiment of the application is shown. In a possible implementation of the key management method, the key management method further includes:

[0090] Step S0: The key management slave node sends key seed acquisition request information to the key management master node in the case of receiving the key seed distribution notification information sent by the key management master node.

[0091] Reference Figure 2 In a possible implementation of the key management method, the key management master node performs security verification on the key management slave node based on the received key seed acquisition request information. The specific method of the key management slave node generating and sending the key seed acquisition request information to the key management master node includes that the key management slave node receives the key seed distribution notification information sent by the key management master node. The key management slave node calls the pre-stored identification of the key management slave node and the identity token of the key management slave node based on the key seed distribution notification information. The key management slave node generates the key seed acquisition request information based on the pre-stored identity key encrypting the identification of the key management slave node and the identity token of the key management slave node, and sends the key seed acquisition request information to the key management master node.

[0092] In a possible implementation of the key management method, the key seed acquisition request information includes the identification information and the identity token information of the key management slave node, and the security verification of the key management master node on the key management slave node includes:

[0093] The key management master node parses the identification information and the identity token information of the key management slave node from the key seed acquisition request information, performs security verification on the key management slave node based on the identification information and the identity token information of the key management slave node and the key management slave node registration information, and the key management slave node registration information includes the identification information, the identity token information and the validity information of the identity token information of the key management slave node registered in the key management master node. If the identification information and the identity token information of the key management slave node exist in the key management slave node registration information and the identity token information is valid, the security verification result of the key management slave node is that the security verification is passed. If the identification information and the identity token information of the key management slave node do not exist in the key management slave node registration information or the identity token information is invalid, the security verification result of the key management slave node is that the security verification is not passed.

[0094] In the above key management method, the key management master node needs to perform security verification on the key management slave node before sending the key seed acquisition response information to the key management slave node. In a possible implementation of the key management method, the key management master node performs security verification on the key management slave node based on the identification information and the identity token information of the key management slave node existing in the key seed acquisition request information and the pre-stored key management slave node registration information in the key management master node.

[0095] Further, the specific method of the key management master node for security verification of the key management slave node comprises: the key management master node decrypts the received key seed acquisition request information based on the pre-stored identity key of the key management slave node upon receiving the key seed acquisition request information. The key management master node decrypts the identification information and the identity token information of the key management slave node, and compares the decrypted identification information and identity token information of the key management slave node with the identification information and identity token information of the key management slave node in the pre-stored key management slave node registration information.

[0096] Further, if the identification information and the identity token information of the key management slave node are in the registration list in the key management master node, it is proved that the key management slave node is the key management slave node for information interaction with the key management master node, and if the identity token is valid, it is proved that the current key management master node and the corresponding key management slave node are for information interaction. The key management master node generates the key seed corresponding to the key management slave node and delivers the key seed to the key management slave node.

[0097] Further, if the identification information and the identity token information of the key management slave node are not in the registration list in the key management master node, it is proved that the key management slave node is not the key management slave node for information interaction with the key management master node, and the key management master node will not generate the key seed corresponding to the key management slave node. If the identification information and the identity token information of the key management slave node are in the registration list in the key management master node, but the identity token of the key management slave node is invalid, the key management master node sends the identity registration information notification to the key management slave node, and the key management slave node re-registers the identity information.

[0098] Reference Figure 3 , Figure 3 Another flowchart of a key management method provided for an embodiment of the application is provided. In a possible embodiment of the key management method of the application, the key management method further comprises:

[0099] Step S01: the key management master node generates key seed distribution notification information in response to receiving the key seed distribution instruction information sent by the diagnostic tool; or,

[0100] Step S02: the key management master node generates key seed distribution notification information according to a preset key seed distribution period.

[0101] Reference Figure 3In a possible implementation of the key management method, the key management master node generates the key seed distribution notification information based on the received key seed distribution instruction information sent by the diagnostic tool or based on a preset key seed distribution period.

[0102] Further, when the key management master node generates the key seed distribution notification information based on the preset key seed distribution period, the key management master node generates the corresponding key seed distribution notification information at the node of the key seed distribution period based on the preset key seed distribution period. Based on the key seed distribution notification information, the key management master node performs the subsequent steps to generate the key seed corresponding to the key seed distribution period, thereby updating the key seed.

[0103] Further, the key management master node based on the received key seed distribution instruction information sent by the diagnostic tool can be prepared when the key management system involves the electronic device, based on the diagnostic tool triggering the generation of the key seed distribution instruction or based on the demand of the administrator corresponding to the electronic device involved in the key management system, the diagnostic tool triggers the generation of the key seed distribution instruction. Wherein, the administrator can remotely trigger the generation of the key seed distribution instruction based on the actual need through the diagnostic tool, and the administrator can remotely trigger the generation of the key seed distribution instruction multiple times based on the actual need to update the key seed.

[0104] Reference Figure 3 Further, in a possible implementation of the key management method, before step S4, the key management method further comprises: step S31, the key management slave node sends the key seed acquisition result information to the key management master node; step S32, the key management master node obtains the key seed acquisition result in response to receiving the key seed acquisition result information; step S33, the key management master node generates the key seed acquisition situation information based on the key seed acquisition result in response to receiving the key seed acquisition situation determination information sent by the diagnostic tool, and sends the key seed acquisition situation information to the diagnostic tool; step S34, the diagnostic tool obtains the key seed acquisition situation in response to receiving the key seed acquisition situation information. Based on the above steps, the diagnostic tool determines that the key management slave node obtains the key seed to determine that the key management system can generate the key, so that the electronic device involved in the key management system can run.

[0105] Based on the above, in the key management method, the key seed can be automatically updated periodically based on the preset key seed distribution period, which can effectively reduce the risk of key seed cracking, thereby reducing the risk of key cracking.

[0106] In a possible implementation of the key management method, the key management slave node generates a key according to a key seed in the case that there is a key usage requirement, including:

[0107] The key management slave node generates a key according to a key seed generated by the key management system in a last power-on cycle of an electronic device to which the key management system is applied in the case that there is a key usage requirement.

[0108] In a possible implementation of the key management method, the key seed distribution period is determined according to a power-on cycle of an electronic device to which the key management system is applied.

[0109] In a possible implementation of the key management method, the key seed used for generating a key in a current power-on cycle is a key seed generated in a last power-on cycle. In the key management system, the generation of the key seed is based on the key seed distribution period or a diagnostic tool to generate a key seed distribution notification information so as to trigger the subsequent steps of generation, and since the key seed distribution period is fixed, the power-on cycle of the electronic device corresponding to the key management system is uncertain. In order to prevent the update of the key seed at the power-on cycle, there is no key seed that can generate a key, and therefore in the key management method, a key seed generated in a last power-on cycle of an electronic device to which the key management system is applied is used to generate a current required key.

[0110] Further, in a possible implementation of the key management method, the distribution period of the key seed is set to correspond to the power-on cycle of the electronic device, so that the distribution period of the key seed can be determined based on the power-on cycle of the electronic device to which the key management system is applied, thereby facilitating the determination of the key seed used in the power-on cycle of the electronic device.

[0111] Further, the key seed distribution period can be set to one key seed distribution period corresponding to one power-on cycle or to one week or one month according to the actual use scene. The specific key seed distribution period can be set by an administrator based on the specific use scene of the electronic device to which the key management system is applied.

[0112] Reference Figure 4 , Figure 4 A flowchart for generating key management slave node registration information is provided in the key management method of the embodiments of the present application. In a possible implementation of the key management method, the key management slave node registration information is generated by the following method:

[0113] Step S11: The key management master node sends node identity registration notification information to the key management slave node.

[0114] Step S12: The key management slave node sends identity registration request information to the key management master node in response to receiving the node identity registration notification information, the identity registration request information including identification information of the key management slave node.

[0115] Step S13: The key management master node generates identity token information and identity key information of the key management slave node in response to receiving the identity registration request information, obtaining key management slave node registration information.

[0116] Step S14: The key management master node generates identity registration response information and sends it to the key management slave node, the identity registration response information including the identity token information and the identity key information of the key management slave node, the identity key information being used for encryption and decryption processing of the identity token information and the key seed information.

[0117] Step S15: The key management slave node stores the identity token information and the identity key information of the key management slave node parsed from the identity registration response information in response to receiving the identity registration response information.

[0118] Step S16: The key management slave node sends identity registration response parsing result information to the key management master node.

[0119] Step S17: The key management master node obtains identity registration response parsing results in response to receiving the identity registration response parsing result information.

[0120] Reference Figure 4 In the above key management method, the security of the key management slave node is verified based on the key management slave node registration information pre-existing in the key management master node and the identification information and the identity token information of the key management slave node obtained by decrypting the key seed acquisition request information, and the security of the key management slave node is determined. The key management slave node registration information pre-existing in the key management master node is obtained by registration when the electronic device involved in the key management system is prepared. In the possible implementation manner of the key management method of the present application, the key management method includes an identity registration process of the key management slave node. Based on the identity registration process of the key management slave node, the key management slave node registration information is generated and saved in the key management master node.

[0121] Reference Figure 4In detail, the specific steps of generating and storing the registration information of the key management slave node in the key management master node include: the key management master node sends the node identity registration notification information to the key management slave node. The key management slave node generates the corresponding identity registration request information based on the received node identity registration notification information, and encrypts the identity registration request. The key management slave node sends the encrypted identity registration request information to the key management master node. The identity registration request information generated by the key management slave node includes the identification information of the key management slave node. Further, the identification information of the key management slave node can be the name and serial number information.

[0122] The key management master node decrypts the name and serial number information of the key management slave node based on the received identity registration request of the key management slave node. The key management master node generates the identity token and identity key corresponding to the key management slave node based on the name and serial number of the key management slave node, and stores the identification information, identity token and identity key of the key management slave node in the key management master node. The key management master node encrypts the identification information, identity token and identity key of the key management slave node into identity registration response information, and sends the identity registration response information to the corresponding key management slave node. The key management slave node receives the corresponding identity registration response information. The key management slave node decrypts the received identity registration response information to obtain the identification information, identity token and identity key of the key management slave node, and stores the decrypted identification information, identity token and identity key of the key management slave node in the key management slave node. The key management slave node generates the identity registration response analysis result and sends it to the key management master node. The key management master node determines the identification information, identity token and identity key of the key management slave node based on the received identity registration response analysis result.

[0123] The identity key is used for encryption and / or decryption key when the key management master node and the key management slave node corresponding to the identity key interact to generate a key seed.

[0124] Reference Figure 5 , Figure 5 Another flowchart for generating the registration information of the key management slave node in the key management method provided by the embodiments of the present application is provided.

[0125] In a possible embodiment of the key management method of the present application, the key management master node sends the node identity registration notification information to the key management slave node, including: step S10: the key management master node generates the node identity registration notification information in response to receiving the node identity registration instruction information sent by the diagnostic tool.

[0126] In detail, reference is made to Figure 5, the identity registration step of the key management slave node further comprises: before the key management master node sends the node identity registration notification information to the key management slave node, the key management master node receives the node identity registration instruction information triggered by the external diagnosis device. The key management master node generates the node identity registration notification information based on the received node identity registration instruction information and sends it to the key management slave node to execute the subsequent steps S11, S12, S13, S14, S15, S16 and S17.

[0127] With reference to Figure 5 , further, the key management method further comprises the following steps:

[0128] Step S18: the diagnosis tool sends identity registration result determination information.

[0129] Step S19: the key management master node receives the identity registration result determination information sent by the diagnosis tool. Step S20: the key management master node generates identity registration result response information based on the identity registration response analysis result and sends the identity registration result response information to the diagnosis tool.

[0130] Step S21: the diagnosis tool obtains the identity registration result in response to receiving the identity registration result response information.

[0131] In particular, with reference to Figure 5 , after the key management master node obtains the identity registration response analysis result, the key management master node responds to the identity registration result determination information sent by the external diagnosis tool. After receiving the identity registration result determination information, the key management master node generates the identity registration result response information based on the identity registration response analysis result and sends the identity registration result response information to the external diagnosis tool. The external diagnosis tool obtains the identity registration result based on the received identity registration result response information, thereby determining that the identity registration of the key management slave node is completed. After the diagnosis tool determines that the identity registration of the key management slave node is completed, the diagnosis tool sends the key seed distribution instruction information to the key management master node to execute the subsequent steps S01, S0, S1, S2, S3, S31, S32, S33, S34 and S4.

[0132] In a possible implementation of the key management method of the present application, the node identity registration instruction information includes node identity token validity period information, and the key management method further comprises: the key management master node manages the validity period of the identity token of the key management slave node based on the node identity token validity period information.

[0133] In the key management method, when the security of the key management slave node is verified, if the validity period of the identity token of the key management slave node is invalid, the key management slave node needs to re-register the identity information. The setting of the validity period of the identity token of the key management slave node can be based on the use scenario of the electronic device designed by the key management system and set in the key management master node, or set in the node identity instruction information sent by the diagnostic tool.

[0134] Further, in a possible implementation of the key management method, the node identity instruction information sent by the diagnostic tool can include node identity token validity period information. Setting the node identity token validity period information in the node identity instruction information can determine the corresponding node identity token validity period information based on the use scenario of the key management system, so that different node identity token validity period information can be set in different use scenarios, thereby facilitating the key management of the electronic device involved in the key management system.

[0135] In addition, the electronic device involved in the key management system can generate node identity instruction information based on the current application scenario triggered by the diagnostic tool, thereby modifying the node identity token validity period information.

[0136] In a possible implementation of the key management method, the node identity registration instruction information includes key seed distribution period information, and the key management method further includes:

[0137] The key management master node manages the key seed distribution time based on the key seed distribution period information.

[0138] In the key management method, the key management master node sends node identity registration notification information to the key management slave node based on the node identity registration instruction information sent by the diagnostic tool. Further, in a possible implementation of the key management method, the node identity registration instruction information sent by the diagnostic tool can include key seed distribution period information. The key management master node can periodically generate key seed distribution notification information based on the key seed distribution period information, thereby periodically generating key seeds.

[0139] Further, setting the key seed distribution period information in the node identity registration instruction information can determine the corresponding key seed distribution period information based on the use scenario of the key management system, so that different key seed distribution period information can be set in different use scenarios, thereby facilitating the key management of the electronic device involved in the key management system.

[0140] In a possible implementation of the key management method, the identification information is the name and / or serial number information of the electronic device involved in the key management slave node.

[0141] In a possible implementation of the key management method, the identification information of the key management slave node can be the name of the electronic device corresponding to the key management slave node and / or the serial number information of the electronic device. Based on the name of the electronic device corresponding to the key management slave node and / or the serial number information of the electronic device, the key management master node can more accurately and conveniently compare the identification information and the identity token information of the key management slave node decrypted to the key management slave node with the identification information and the identity token information of the key management slave node in the pre-stored key management slave node registration information.

[0142] In a possible implementation of the key management method, the key management method further includes: storing, by the key management slave node, the generated key into the memory of the key management slave node.

[0143] In the above key management method, the generated key seed, the key, and the identification information and the identity token information of the key management slave node are stored in the key management master node and the key management slave node. Further, in a possible implementation of the key management method, the generated key seed, the key, and the identification information and the identity token information of the key management slave node are stored in the memory of the key management master node and the key management slave node. Storing the generated key seed, the key, and the identification information and the identity token information of the key management slave node in the memory of the key management master node and the key management slave node increases the difficulty of directly extracting the firmware to obtain the key by an attacker, thereby ensuring the security of the key seed, the key, and the identification information and the identity token information of the key management slave node.

[0144] In a possible implementation of the key management method, the key management method further includes: decrypting, by the key management slave node, the target data based on the old key generated based on the old key seed, encrypting the target data based on the key generated based on the new key seed, and deleting the old key seed and the old key.

[0145] In the above key management method, the key seed generated based on the last power-on cycle of the electronic device to which the key management system is applied is used to generate the current required key, and the key seed can be updated periodically based on the key seed distribution period, so that the key management master node and the key management slave node have the old key seed and the new key seed.

[0146] Further, in a possible implementation of the key management method, after the key management slave node decrypts the target data based on the old key generated based on the old key seed, the key management slave node deletes the old key and the old key seed.

[0147] Further, when the key management slave node deletes the old key seed, the key management slave node sends the key management master node with the old key seed deletion information, and the key management master node deletes the old key seed in response to the received old key seed deletion information.

[0148] In a possible implementation of the key management method, the key management method further includes that the key management slave node destroys the key seed in any of the following cases: obtaining a new key seed; using up the key seed; receiving a key seed destruction instruction predefined by the system.

[0149] In a possible implementation of the key management method, the key management method further includes destroying the key seed. The key management master node and the key management slave node destroy the key seed in the following cases: in a first case, when a new key seed is obtained and the electronic device involved in the key management system starts a new power-on cycle, the old key seed is destroyed at this time, and a new key is generated based on the new key seed, wherein the old key seed can be an unused key seed; in a second case, when the current key seed is used up and a new key seed is generated in the key management master node at this time, the old key seed is destroyed when the electronic device involved in the key management system starts a new power-on cycle; and in a third case, the key seed is destroyed when the key management master node and the key management slave node receive a key seed destruction instruction predefined by the system, wherein the key management master node and the key management slave node receiving the key seed destruction instruction predefined by the system includes that the system triggers the generation of the key seed destruction instruction when the vehicle is resold or the vehicle is scrapped.

[0150] In a possible implementation of the key management method, the key management system further includes a hardware security module, and the hardware security module includes a random number generator, and the key random number is generated by the random number generator.

[0151] In a possible implementation of the key management method, the key management system further includes a hardware security module. The key management master node interacts with the hardware security module. The hardware security module is provided with a random number generator, and the key seed is generated based on the random number generator of the hardware security module. The key generated based on the random number generator can effectively ensure that the key seed information generated in each batch cannot be predicted by the outside, thereby guaranteeing the security of the key seed.

[0152] In a possible implementation of the key management method, the key management method further includes that information transmitted between the key management master node and the key management slave node is encrypted and transmitted based on a preset key.

[0153] In a possible implementation of the key management method, in the identity registration process of the key management slave node, the identity registration request information generated by the key management slave node and the key management slave node registration information generated by the key management master node are encrypted or decrypted based on a preset key. The preset key is an encryption key pre-set in the key management master node and the key management slave node. In addition, the preset key can be protected based on a memory or a white box.

[0154] In a possible implementation of the key management method, the electronic device related to the key management master node and the key management slave node is an electronic control unit.

[0155] In a possible implementation of the key management method, the key management master node and the key management slave node are respectively arranged in different electronic control units. Further, the electronic control unit corresponding to the key management master node is different from the electronic control unit corresponding to the key management slave node. A hardware security module is arranged in the electronic control unit corresponding to the key management master node.

[0156] Reference Figure 6 , Figure 6 The structure schematic diagram of the key management system provided by another embodiment of the present application is shown.

[0157] Reference Figure 6 The key management system provided by another embodiment of the present application includes a first electronic control unit and a second electronic control unit. The first electronic control unit includes a key management master node. The second electronic control unit includes a key management slave node. The key management master node includes a hardware security module, a key seed distribution module, a node information saving module, a key information saving module and a node identity registration module, and the hardware security module includes a random number generator. The key management slave node includes a key seed management module, a key seed saving module, a node identity information management module and a node identity information saving module.

[0158] Reference Figure 6 Further, in the key management system, the node information saving module is configured to save the identification information and the identity token information of each key management slave node which performs information interaction with the key management master node. The key information saving module is configured to save each key seed and the key seed batch number, the identity key and the preset key generated by the hardware security module. The node identity information saving module is configured to save the identification information and the identity token information of the key management slave node. The key seed saving module is configured to save the key seed received by the key management slave node and the key seed batch number, the identity key and the preset key corresponding to the key seed.

[0159] Reference Figure 6Further, in the key management system, the node identity information management module is configured to call the node identity information storage module to generate identity registration request information, and send the identity registration request information to the node identity registration module after encryption based on the preset key; the node identity registration module is configured to receive the identity registration request information, decrypt the identity registration request information based on the preset key, and send the identity token information and the identity key of the key management slave node to the key management slave node based on the identity registration request information, and send the identity token information and the identity key of the key management slave node to the node information storage module for storage.

[0160] With reference to Figure 6 Further, in the key management system, the key seed management module is configured to send key seed acquisition request information to the key seed distribution module; the key seed distribution module is configured to receive the key seed acquisition request information, decrypt the key seed acquisition request information based on the identity key, and send the key seed acquisition request information to the hardware security module; the random number generator in the hardware security module is configured to generate a key seed and a key seed batch number based on the received key seed distribution information, and send the key seed and the key seed batch number to the key seed distribution module after encryption based on the identity key; the key seed distribution module is configured to receive and decrypt the key seed and the key seed batch number based on the identity key, send the key seed and the key seed batch number to the key seed management module, and send the key seed and the key seed batch number to the key information storage module for storage. The key seed management module is configured to receive the key seed and the key seed batch number, and send the key seed and the key seed batch number to the key seed storage module for storage.

[0161] The node identity registration module is further configured to receive node identity registration instruction information sent by the diagnostic tool.

[0162] In the key management based on the above key management system, the diagnostic tool triggers the key management slave node identity registration information; the key management master node generates node identity registration notification information in response to receiving the node identity registration instruction information sent by the diagnostic tool, and sends the node identity registration notification information to the key management slave node; the key management slave node generates and sends the identity registration request information to the key management master node in response to receiving the node identity registration notification information; the key management master node generates the identity token information and the identity key information of the key management slave node to obtain the key management slave node registration information in response to receiving the identity registration request information; the key management master node generates the identity registration response information based on the key management slave node registration information and sends it to the key management slave node; the key management slave node stores the identity token information and the identity key information of the key management slave node parsed from the identity registration response information in response to receiving the identity registration response information, and sends the identity registration response analysis result information to the key management master node; the key management master node obtains the identity registration response analysis result in response to receiving the identity registration response analysis result information; the diagnostic tool sends the identity registration result determination information to the key management master node; the key management master node receives the identity registration result determination information sent by the diagnostic tool, and generates the identity registration result response information based on the identity registration response analysis result, and sends the identity registration result response information to the diagnostic tool; the diagnostic tool obtains the identity registration result in response to receiving the identity registration result response information.

[0163] The diagnostic tool determines that the key management slave node identity registration is completed. The diagnostic tool sends a key seed distribution instruction to the key management master node. The key management master node generates a key seed distribution notification information in response to receiving the key seed distribution instruction information sent by the diagnostic tool. The key management slave node sends a key seed acquisition request information to the key management master node in response to receiving the key seed distribution notification information sent by the key management master node. The key management master node performs security verification on the key management slave node in response to receiving the key seed acquisition request information sent by the key management slave node. The key management master node sends a key seed acquisition response information to the key management slave node in response to passing the security verification. The key management slave node obtains a key seed according to the key seed acquisition response information in response to receiving the key seed acquisition response information. The key management slave node sends a key seed acquisition result information to the key management master node. The key management master node obtains a key seed acquisition result in response to receiving the key seed acquisition result information. The key management master node generates a key seed acquisition situation information based on the key seed acquisition result in response to receiving the key seed acquisition situation determination information sent by the diagnostic tool, and sends the key seed acquisition situation information to the diagnostic tool. The diagnostic tool obtains a key seed acquisition situation in response to receiving the key seed acquisition situation information. The key management slave node generates a key according to the key seed in response to the existence of a key usage requirement.

[0164] Based on the above process, the key seed can be periodically generated to generate the key required for service encryption.

[0165] Figure 7 A structural diagram of a vehicle is provided for another embodiment of the present application. In a second aspect, another embodiment of the present application discloses a vehicle, as shown in the figure, which comprises a key management system, the key management system comprising a key management master node and a plurality of key management slave nodes, the key management master node and the plurality of key management slave nodes interacting to implement the key management method of any one of the above embodiments. Figure 7

[0166] ​It is to be understood that the above description is intended to be illustrative and not restrictive. Many other embodiments will be apparent to those of skill in the art upon reading and understanding the above description. Although the application has been described with reference to the preferred embodiment, persons skilled in the art will recognize that changes can be made in form and detail without departing from the spirit and the scope of the application. Those skilled in the art will recognize or be able to ascertain using no more than routine experimentation, many equivalents to the specific embodiments described herein. It is the following claims, including any amendments thereto, that define the scope of the application.

[0167] In the description of the present embodiments, it should be noted that the terms "upper", "lower", "inner", "bottom" and the like are intended to indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings, or the orientation or positional relationship in which the product of the present application is usually placed, and are merely for the convenience of describing the present application and simplifying the description, and therefore cannot be understood as indicating or implying that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as limiting the present application.

[0168] In the description of the present embodiments, it should be noted that, unless otherwise explicitly specified and limited, the term "provided" can be understood by those of ordinary skill in the art in the light of the specific meaning of the term in the present embodiments.

[0169] While the application has been illustrated and described in detail in the drawings and foregoing description, such illustration and description are to be considered illustrative or exemplary and not restrictive; the application is not limited to the disclosed embodiments.

Claims

1. A key management method, characterized in that, The key management system is applied to a key management system, which includes a key management master node and multiple key management slave nodes; the key management method includes: The key management master node generates key seed distribution notification information in response to receiving key seed distribution instruction information sent by the diagnostic tool, or generates key seed distribution notification information according to a preset key seed distribution period, and sends the key seed distribution notification information to the key management slave node. The key seed distribution period is determined according to the power-on cycle of the electronic equipment involved in the key management system. When the key management slave node receives the key seed distribution notification information sent by the key management master node, it calls the identification information and identity token information of the key management slave node, encrypts the identification information and identity token information based on the pre-stored identity key to generate key seed acquisition request information, and sends the key seed acquisition request information to the key management master node. The master node of the key management system responds to receiving the key seed acquisition request information sent by the slave node of the key management system. Based on the pre-stored identity key corresponding to the slave node of the key management system, it decrypts the received key seed acquisition request information to obtain the identification information and identity token information of the slave node of the key management system. According to the decrypted identification information, identity token information and pre-stored registration information of the slave node of the key management system, it performs security verification on the slave node of the key management system. If the security verification is successful, it generates key seed acquisition response information and sends the key seed acquisition response information to the slave node after encrypting it based on the identity key of the slave node of the key management system. The key seed acquisition response information includes key seed information, and the key seed information includes the key seed. The key seed is generated by the master node based on a key random number. The key management slave node responds to receiving the key seed acquisition response information, decrypts the key seed acquisition response information based on the identity key to obtain the key seed, and generates a key based on the key seed when there is a key usage requirement, for use in business encryption processing.

2. The key management method according to claim 1, characterized in that, The key management slave node registration information includes the identification information, identity token information, and validity information of the identity token information of the key management slave node registered with the key management master node. The key management master node performs security verification on the key management slave node based on the decrypted identification information, identity token information, and key management slave node registration information, including: If the identification information and identity token information of the key management slave node exist in the registration information of the key management slave node, and the identity token information is valid, then the security verification result of the key management slave node is security verification passed. If the identification information and identity token information of the key management slave node do not exist in the registration information of the key management slave node, or the identity token information is invalid, then the security verification result of the key management slave node is security verification failed.

3. The key management method according to claim 2, characterized in that, The key management slave node registration information is generated in the following way: The key management master node sends node identity registration notification information to the key management slave node; In response to receiving the node identity registration notification information, the key management slave node sends an identity registration request information to the key management master node, the identity registration request information including the identification information of the key management slave node; In response to receiving the identity registration request information, the key management master node generates the identity token information and the identity key information of the key management slave node, obtains the registration information of the key management slave node, and generates identity registration response information and sends it to the key management slave node. The identity registration response information includes the identity token information and the identity key information of the key management slave node, and the identity key information is used to encrypt and decrypt the identity token information and the key seed information. In response to receiving the identity registration response information, the key management slave node parses the identity token information and the identity key information of the key management slave node from the identity registration response information, stores them, and sends the identity registration response parsing result information to the key management master node; The key management master node receives the identity registration response parsing result information and obtains the identity registration response parsing result.

4. The key management method according to claim 3, characterized in that, The key management master node sends node identity registration notification information to the key management slave node, including: In response to receiving the node identity registration instruction information sent by the diagnostic tool, the key management master node sends node identity registration notification information to the key management slave node; The method further includes: The key management master node generates identity registration result response information based on the identity registration response parsing result and sends the identity registration result response information to the diagnostic tool; The diagnostic tool receives the identity registration result response information and obtains the identity registration result.

5. The key management method according to claim 4, characterized in that, The node identity registration instruction information includes node identity token validity information, and the key management method further includes: The key management master node manages the validity period of the identity tokens of the key management slave nodes based on the validity period information of the node identity tokens.

6. The key management method according to claim 4 or 5, characterized in that, The node identity registration instruction information includes key seed distribution cycle information, and the key management method further includes: The key management master node manages the key seed distribution time based on the key seed distribution cycle information.

7. The key management method according to claim 6, characterized in that, The identification information is the name and / or serial number information of the electronic device involved in the key management slave node.

8. The key management method according to claim 7, characterized in that, When a key usage requirement exists, the key management slave node generates a key based on the key seed, including: When there is a need for key usage, the key management slave node generates the key based on the key seed generated in the previous power-on cycle of the electronic device involved in the key management system.

9. The key management method according to claim 8, characterized in that, The key management method further includes: The key management slave node stores the generated key in the memory of the key management slave node.

10. The key management method according to claim 9, characterized in that, The key management method further includes: The key management slave node decrypts the target data using an old key generated based on the old key seed, encrypts the target data using a new key generated based on the new key seed, and deletes the old key seed and the old key.

11. The key management method according to claim 10, characterized in that, The key management method further includes the key management slave node destroying the key seed under any of the following circumstances: The new key seed is obtained; Use up the key seed; Received a predefined key seed destruction command from the system.

12. The key management method according to claim 11, characterized in that, The key management system also includes a hardware security module, which includes a random number generator. The key random number is generated by the random number generator and sent to the key management master node.

13. The key management method according to claim 12, characterized in that, The key management method further includes: The information transmitted between the key management master node and the key management slave node is encrypted based on a preset key.

14. The key management method according to claim 13, characterized in that, The electronic devices involved in the key management master node and the key management slave node are electronic control units.

15. A vehicle, characterized in that, The vehicle includes a key management system, which includes a key management master node and multiple key management slave nodes. The key management master node and the key management slave nodes interact to implement the key management method as described in any one of claims 1-14.

Citation Information

Patent Citations

  • Private key management method, system and device and storage medium

    CN112910654A