Vehicle-mounted component, debugging method and vehicle
By adding a debugging module outside the control module of the vehicle-mounted component, the connection status of the debugging interface is detected and power is cut off, thus solving the problem of attackers physically accessing the debugging interface and achieving higher security and practicality.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BYD CO LTD
- Filing Date
- 2024-04-10
- Publication Date
- 2026-05-01
AI Technical Summary
Existing vehicle component debugging solutions cannot prevent attackers from physically accessing the debugging device for debugging, resulting in insufficient security.
A debugging module is added outside the control module. The debugging module detects whether a debugging device is connected to the debugging interface, and stops supplying power to the control module when debugging is not allowed and a debugging device is detected.
It improves the safety of debugging on-board components, reduces the cost of control modules, and enhances the practicality of debugging.
Smart Images

Figure CN119758791B_ABST
Abstract
Description
A vehicle-mounted component, debugging method, and vehicle Technical Field
[0001] This application relates to the field of debugging technology, and in particular to an on-board component, debugging method and vehicle. Background Technology
[0002] With the rapid development of the Internet of Vehicles (IoV), the requirements for the cybersecurity of vehicle-mounted components are becoming increasingly stringent. For vehicles on the market, their onboard components may be disassembled by attackers who can then use emulators to extract the software. Attackers could then conduct further research to uncover potential vulnerabilities and create malicious software to infiltrate other vehicles. Therefore, to ensure that only authorized personnel can directly access and debug onboard components through debugging interfaces, secure debugging has become an indispensable technology in vehicle cybersecurity.
[0003] Existing secure debugging solutions primarily rely on purely software-based interaction to debug automotive components. However, this method cannot prevent attackers from directly debugging chips through physical access to the debugging device. Therefore, improving the security of debugging automotive components has become a current research hotspot. Summary of the Invention
[0004] This application provides an on-board component, a debugging method, and a vehicle, which improves the safety of debugging the on-board component.
[0005] In a first aspect, embodiments of this application provide a vehicle-mounted component. The vehicle-mounted component includes at least a control module, a debugging module, and a debugging interface, with the debugging module connected to both the control module and the debugging interface. The control module provides a first signal to the debugging module, wherein the first signal indicates whether debugging of the vehicle-mounted component is permitted. The debugging module stops supplying power to the control module when it determines, based on the first signal, that debugging of the vehicle-mounted component is not permitted, and detects that a debugging device is connected to the debugging interface.
[0006] In this embodiment, by adding a debugging module outside the control module, the vehicle-mounted component can stop supplying power to the control module when it is determined that debugging of the vehicle-mounted component is not allowed and a debugging device is detected connected to the debugging interface. This effectively prevents attackers from directly debugging the vehicle-mounted component through physical access of the debugging device, thereby improving the security of debugging the vehicle-mounted component. Furthermore, placing the debugging module outside the control module improves its practicality and reduces the cost of the control module.
[0007] In conjunction with the first aspect, in one feasible implementation, the debugging module includes a debugging circuit and a power supply circuit. The debugging circuit is connected to the power supply circuit, the control module, and the debugging interface, respectively. The power supply circuit is also connected to the control module. The debugging circuit is used to determine whether debugging of the vehicle-mounted component is permitted based on the first signal. The debugging circuit is also used to detect whether the debugging interface is connected to the debugging device. Furthermore, the debugging circuit is used to control the power supply circuit to stop supplying power to the control module when it is determined that debugging of the vehicle-mounted component is not permitted and the debugging interface is detected to be connected to the debugging device.
[0008] In conjunction with the first aspect, in one feasible implementation, the debugging circuit includes at least a control circuit and a switching circuit. The control circuit is connected to the switching circuit, the control module, and the power supply circuit, respectively. The switching circuit is also connected to the control module and the debugging interface, respectively. The switching circuit is used to establish a connection between the control module and the debugging interface if it is determined, based on the first signal, that debugging of the vehicle component is permitted. The switching circuit is also used to disconnect the connection between the control module and the debugging interface if it is determined, based on the first signal, that debugging of the vehicle component is not permitted. The switching circuit is further used to send a second signal to the control circuit, wherein the second signal is used to indicate whether the debugging device is connected to the debugging interface.
[0009] In conjunction with the first aspect, in one feasible implementation, the control circuit is configured to determine, based on the first signal and the second signal, whether to control the power supply circuit to stop supplying power to the control module.
[0010] In conjunction with the first aspect, in one feasible implementation, the control circuit is configured to control the power supply circuit to stop supplying power to the control module when it is determined from the first signal that the vehicle component is not allowed to be debugged, and when it is determined from the second signal that the debugging interface is connected to the debugging device.
[0011] In conjunction with the first aspect, in one feasible implementation, the debugging module is further configured to supply power to the control module when it is determined, based on the first signal, that the vehicle-mounted component is allowed to be debugged, or when it is determined, based on the first signal, that the vehicle-mounted component is not allowed to be debugged and the debugging interface is not connected to the debugging device.
[0012] In conjunction with the first aspect, in one feasible implementation, the control module is used to acquire a third signal via the vehicle bus and determine whether the vehicle component is in debug mode based on the third signal.
[0013] In conjunction with the first aspect, in one feasible implementation, the third signal includes a target key, and the control module is further configured to determine that the vehicle-mounted component is in debug mode if it is determined that the target key is consistent with a preset key. The control module is also configured to determine that the vehicle-mounted component is not in debug mode if it is determined that the target key is inconsistent with the preset key.
[0014] Secondly, embodiments of this application provide a debugging method. This method is applied to an on-board component, which includes at least a control module, a debugging module, and a debugging interface. The debugging module is connected to both the control module and the debugging interface. The method includes: providing a first signal to the debugging module through the control module, wherein the first signal indicates whether debugging of the on-board component is permitted. If the debugging module determines, based on the first signal, that debugging of the on-board component is not permitted, and detects that a debugging device is connected to the debugging interface, it stops supplying power to the control module.
[0015] In conjunction with the second aspect, in one feasible implementation, the debugging module includes a debugging circuit and a power supply circuit. The debugging circuit is connected to the power supply circuit, the control module, and the debugging interface, respectively. The power supply circuit is also connected to the control module. The step of stopping power supply to the control module when the debugging module determines, based on the first signal, that debugging of the vehicle component is not permitted, and detects that a debugging device is connected to the debugging interface, includes: determining, based on the first signal, whether debugging of the vehicle component is permitted using the debugging circuit; detecting, based on the debugging circuit, whether a debugging device is connected to the debugging interface; and controlling the power supply circuit to stop supplying power to the control module when the debugging circuit determines that debugging of the vehicle component is not permitted, and detects that the debugging device is connected to the debugging interface.
[0016] In conjunction with the second aspect, in one feasible implementation, the debugging circuit includes at least a control circuit and a switching circuit. The control circuit is connected to the switching circuit, the control module, and the power supply circuit, respectively. The switching circuit is also connected to the control module and the debugging interface, respectively. Determining whether the vehicle component is allowed to be debugged based on the first signal through the debugging process includes: if the switching circuit determines that the vehicle component is allowed to be debugged based on the first signal, then establishing a connection between the control module and the debugging interface; if the switching circuit determines that the vehicle component is not allowed to be debugged based on the first signal, then disconnecting the connection between the control module and the debugging interface.
[0017] In conjunction with the second aspect, in one feasible implementation, detecting whether the debugging interface is connected to a debugging device via the debugging circuit includes: outputting a second signal via the switching circuit, wherein the second signal is used to indicate whether the debugging interface is connected to a debugging device.
[0018] In conjunction with the second aspect, in one feasible implementation, the step of controlling the power supply circuit to stop supplying power to the control module when the debugging circuit determines that the vehicle component is not allowed to be debugged and detects that the debugging interface is connected to the debugging device includes: controlling the power supply circuit to stop supplying power to the control module when the control circuit determines that the vehicle component is not allowed to be debugged according to the first signal and determines that the debugging interface is connected to the debugging device according to the second signal.
[0019] In conjunction with the second aspect, in one feasible implementation, the method further includes: supplying power to the control module when the debugging module determines, based on the first signal, that the vehicle-mounted component is allowed to be debugged, or when the first signal determines that the vehicle-mounted component is not allowed to be debugged and the debugging interface is not connected to the debugging device.
[0020] In conjunction with the second aspect, in one feasible implementation, the method further includes: acquiring a third signal via the vehicle bus through the control module, and determining whether the vehicle component is in debugging mode based on the third signal.
[0021] In conjunction with the second aspect, in one feasible implementation, the third signal includes a target key, and the method further includes: if the control module determines that the target key is consistent with a preset key, then determining that the vehicle-mounted component is in debug mode; if the control module determines that the target key is inconsistent with the preset key, then determining that the vehicle-mounted component is not in debug mode.
[0022] Thirdly, embodiments of this application provide a vehicle. This vehicle may include the on-board components described in the first aspect.
[0023] By implementing this embodiment of the invention, the vehicle-mounted component, by adding a debugging module outside the control module, can stop supplying power to the control module when it is determined that debugging of the vehicle-mounted component is not allowed and a debugging device is detected connected to the debugging interface. This effectively prevents attackers from directly debugging the vehicle-mounted component through physical access of the debugging device, thereby improving the security of debugging the vehicle-mounted component. Furthermore, by placing the debugging module outside the control module, the vehicle-mounted component improves its practicality and reduces the cost of the control module. Attached Figure Description
[0024] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0025] Figure 1 is a structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application;
[0026] Figure 2 is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application;
[0027] Figure 3 is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application;
[0028] Figure 4 is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application;
[0029] Figure 5 is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application;
[0030] Figure 6 is a flowchart illustrating a debugging method provided in an embodiment of this application;
[0031] Figure 7 is another schematic flowchart of a debugging method provided in an embodiment of this application;
[0032] Figure 8 is another flowchart illustrating a debugging method provided in an embodiment of this application;
[0033] Figure 9 is a structural schematic diagram of a vehicle provided in an embodiment of this application.
[0034] Vehicle-mounted component 10, control module 11, debugging module 12, debugging interface 13, debugging circuit 121, power supply circuit 122, control circuit 1211, switching circuit 1212, debugging device 20, simulator 201, terminal equipment 30. Detailed Implementation
[0035] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0036] Existing secure debugging solutions primarily rely on purely software-based interaction to debug vehicle components. However, this method cannot prevent attackers from directly debugging vehicle components through physical access to the debugging device. Therefore, the technical problem this application aims to solve is: how to improve the security of debugging vehicle components.
[0037] Please refer to Figure 1, which is a structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application. As shown in Figure 1, the vehicle-mounted component 10 may include at least a control module 11, a debugging module 12, and a debugging interface 13. The debugging module 12 may be connected to the control module 11 and the debugging interface 13 respectively.
[0038] In a specific implementation, the control module 11 can be used to provide a first signal to the debugging module 12. Here, the first signal can be used to indicate whether debugging of the vehicle component 10 is permitted. The debugging module 12 can be used to stop supplying power to the control module 11 when it is determined from the first signal that debugging of the vehicle component 10 is not permitted, and when it is detected that a debugging device 20 is connected to the debugging interface 13.
[0039] It should be noted that the aforementioned first signal can be a level signal. For example, if the control module 11 provides a high-level signal to the debugging module 12, it indicates that the vehicle component 10 is allowed to be debugged. If the control module 11 provides a low-level signal to the debugging module 12, it indicates that the vehicle component 10 is not allowed to be debugged.
[0040] Optionally, the control module 11 can be any type of device with a control function, such as a control chip or controller. This application does not impose specific limitations on the implementation form of the control module 11.
[0041] Optionally, if the control module 11 is a control chip, the control chip can be packaged in a BGA (Ball Grid Array) package to avoid exposing its pins.
[0042] Optionally, the debugging interface 13 is an interface used for debugging the vehicle-mounted component 10, such as the JTAG (Joint TestAction Grid) interface. This application embodiment does not impose specific limitations on the implementation form of the debugging interface 13.
[0043] In this embodiment, by adding a debugging module 12 outside the control module 11, the vehicle-mounted component 10 can stop supplying power to the control module 11 when it is determined that debugging of the vehicle-mounted component 10 is not allowed and a debugging device 20 is detected connected to the debugging interface 13. This effectively prevents attackers from directly debugging the vehicle-mounted component 10 through physical access of the debugging device, thereby improving the security of debugging the vehicle-mounted component. Furthermore, by placing the debugging module 12 outside the control module 11, the vehicle-mounted component 10 improves its practicality and reduces the cost of the control module 11.
[0044] It should be added that after the vehicle-mounted component 10 detects that an attacker is physically accessing the device to debug and stops supplying power to the control module 11, the vehicle-mounted component 10 can restore power to the control module 11 when the attacker stops debugging, so that the vehicle-mounted component 10 can work normally.
[0045] In an alternative implementation, the debugging module 12 can also be used to supply power to the control module 11 when it is determined, based on a first signal provided by the control module, that the vehicle component 10 is allowed to be debugged, or when it is determined, based on the first signal, that the vehicle component is not allowed to be debugged and it is detected that the debugging interface 13 is not connected to the debugging device 20.
[0046] In some feasible implementations, please refer to Figure 2, which is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application. As shown in Figure 2, the debugging module 12 may include a debugging circuit 121 and a power supply circuit 122. The debugging circuit 121 may be connected to the power supply circuit 122, the control module 11, and the debugging interface 13, respectively. The power supply circuit 122 may also be connected to the control module 11.
[0047] In a specific implementation, the debugging circuit 121 can be used to determine whether debugging of the vehicle component is permitted based on the first signal provided by the control module 11. The debugging circuit 121 can also be used to detect whether a debugging device is connected to the debugging interface 13. The debugging circuit 121 can also be used to control the power supply circuit 122 to stop supplying power to the control module 11 when it is determined that debugging of the vehicle component 10 is not permitted and a debugging device 20 is detected connected to the debugging interface 13.
[0048] It should be noted that when it is determined that the vehicle component 10 is not allowed to be debugged, and when it is detected that the debugging interface 13 is connected to the debugging device 20, it indicates that there is an anomaly in the debugging process of the vehicle component 10, that is, an attacker is trying to intrude to debug the vehicle component 10.
[0049] In an alternative implementation, the debugging circuit 121 can also be used to control the power supply circuit 122 to supply power to the control module 11 when it is determined that the vehicle component 10 is allowed to be debugged, or when it is determined that the vehicle component 10 is not allowed to be debugged and it is detected that the debugging interface 13 is not connected to the debugging device 20.
[0050] In one alternative implementation, the power supply circuit 122 may include at least a controllable switching device (hereinafter referred to as the first controllable switching device for ease of distinction), which may be connected to both the control module 11 and the debugging circuit 121. Specifically, the debugging circuit 121 may control the first controllable switching device to close to supply power to the control module 11 when it is determined that the vehicle component 10 is allowed to be debugged, or when it is determined that the vehicle component 10 is not allowed to be debugged and it is detected that the debugging interface 13 is not connected to the debugging device 20. The debugging circuit 121 may also control the first controllable switching device to open to stop supplying power to the control module 11 when it is determined that the vehicle component 10 is not allowed to be debugged and it is detected that the debugging interface 13 is connected to the debugging device 20.
[0051] It should be noted that in actual implementation, the power supply circuit 122 may also include components such as resistors, and this application embodiment does not impose specific limitations on this.
[0052] In some feasible implementations, please refer to Figure 3, which is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application. As shown in Figure 3, the debugging circuit 121 may include a control circuit 1211 and a switching circuit 1212. The control circuit 1211 may be connected to the switching circuit 1212, the control module 11, and the power supply circuit 122, respectively. The switching circuit 1212 may also be connected to the control module 11 and the debugging interface 13, respectively.
[0053] In a specific implementation, the switch circuit 1212 can be used to establish a connection between the control module 11 and the debugging interface 13 if it is determined, based on a first signal provided by the control module 11, that debugging of the vehicle component 10 is permitted. The switch circuit 1212 can also be used to disconnect the connection between the control module 11 and the debugging interface 13 if it is determined, based on the first signal, that debugging of the vehicle component 10 is not permitted. The switch circuit 1212 can also be used to send a second signal to the control circuit 1211. Here, the second signal is used to indicate whether the debugging interface 13 is connected to the debugging device 20.
[0054] Optionally, the switching circuit 1212 can be used to establish a connection between the control module 11 and the debugging interface 13 if it is determined that the first signal provided by the control module 11 is a first type of signal. Here, the first type of signal can be used to indicate that the vehicle component 10 is allowed to be debugged. The switching circuit 1212 can also be used to disconnect the connection between the control module 11 and the debugging interface 13 if it is determined that the first signal is a second type of signal. Here, the second type of signal can be used to indicate that the vehicle component 10 is not allowed to be debugged.
[0055] It should be noted that the second signal mentioned above can be a level signal.
[0056] For example, if the switching circuit 1212 determines that the debugging interface 13 is connected to the debugging device 20, it can send a high-level signal to the control circuit 1211. If the switching circuit 1212 determines that the debugging interface 13 is not connected to the debugging device 20, it can send a low-level signal to the control circuit 1211.
[0057] In an alternative implementation, the control circuit 1211 is further configured to determine, based on the first signal and the second signal, whether to control the power supply circuit 122 to stop supplying power to the control module 11.
[0058] In an alternative implementation, the control circuit 1211 can be used to control the power supply circuit 122 to stop supplying power to the control module 11 when it is determined from a first signal that the vehicle component 10 is not allowed to be debugged, and when it is determined from a second signal that the debugging interface 13 is connected to the debugging device 20.
[0059] In an alternative implementation, the control circuit 1211 can be used to control the power supply circuit 122 to supply power to the control module 11 when it is determined from the first signal that the vehicle component 10 is allowed to be debugged, or when it is determined from the first signal that the vehicle component 10 is not allowed to be debugged and the debugging interface 13 is not connected to the debugging device 20 from the second signal.
[0060] Optionally, the switching circuit 1212 may include at least one controllable switching device (hereinafter referred to as the second controllable switching device for easy distinction), which may be connected to the control circuit 1211, the control module 11, and the debugging interface 13 respectively.
[0061] In a specific implementation, the second controllable switch can be closed to establish a connection between the control module 11 and the debugging interface 13 if the first signal provided by the control module 11 determines that the vehicle component 10 is allowed to be debugged. Alternatively, the second controllable switch can be opened to disconnect the connection between the control module 11 and the debugging interface 13 if the first signal determines that the vehicle component 10 is not allowed to be debugged.
[0062] In this embodiment, the second controllable switch can be a JTAG connection switch, used to establish a connection between the control module 11 and the debugging interface 13.
[0063] It should be noted that, in actual implementation, the switch circuit 1212 may also include other components such as resistors. This application does not impose specific limitations on the implementation form of the switch circuit 1212.
[0064] In one alternative implementation, please refer to Figure 4, which is another structural schematic diagram of a vehicle-mounted component provided in an embodiment of this application. As shown in Figure 4, the control circuit 1211 may include an N×OR gate and an OR gate. The N×OR gate may be connected to the control module 11, the switching circuit 1212, and the OR gate, respectively, and the OR gate may also be connected to the power supply circuit 122.
[0065] In a specific implementation, the XNOR gate can be used to output a sixth signal based on the first signal output by the control module 11 and the second signal output by the switching circuit 1212. The OR gate can be used to output a seventh signal based on the sixth signal and the first signal output by the control module 11. Here, the seventh signal can be used to indicate whether the power supply circuit 122 is supplying power to the control module 11.
[0066] In some feasible implementations, the control module 11 can also be used to acquire a third signal through the vehicle's onboard bus and determine whether the onboard component 10 is in debug mode based on the third signal.
[0067] In other words, the control module 11 can establish a communication connection with the vehicle via the vehicle bus to obtain the corresponding strategy to determine whether the vehicle component 10 is in debug mode. By obtaining the strategy through the communication connection between the control module 11 and the vehicle, the strategy can be updated in real time as needed, thereby improving the safety of the vehicle component 10.
[0068] In one alternative implementation, the control module 11 can establish a communication connection with the vehicle via a CAN (Controller Area Network) bus to obtain a third signal to determine whether the on-board component 10 is in debug mode.
[0069] Optionally, the third signal may include a key or unlocking protocol to determine whether the vehicle component 10 is in debug mode; this embodiment does not impose specific limitations on this. Specifically, when the third signal includes a key, the key may be encrypted using asymmetric encryption; this embodiment does not impose specific limitations on this.
[0070] In an alternative implementation, if the third signal includes a target key, the control module 11 can also be used to determine that the vehicle component 10 is in debug mode, i.e., debug is allowed, if the target key is determined to be consistent with a preset key. Alternatively, the control module 11 can be used to determine that the vehicle component 10 is not in debug mode, i.e., debug is not allowed, if the target key is determined to be inconsistent with a preset key.
[0071] Optionally, the debugging device 20 can be an electronic device capable of debugging the vehicle-mounted component 10, such as a simulator. This application embodiment does not impose specific limitations on the implementation of the debugging device 20.
[0072] Optionally, if the debugging device 20 is a simulator 201, please refer to Figure 5, which is another structural schematic diagram of an on-board component provided in an embodiment of this application. As shown in Figure 5, the simulator 201 can be connected to the debugging interface 13 and the terminal device 30 respectively.
[0073] In a specific implementation, the terminal device 30 can transmit a debugging control signal to the control module 11 of the vehicle component 10 through the debugging device 20 to debug the vehicle component 10. Here, the debugging control signal is used to obtain code or data from the control module 11.
[0074] In other words, when the debugging module 12 determines that the vehicle component 10 is allowed to be debugged and detects that the debugging interface 13 is connected to the debugging device 20, the debugging device 20 can transmit the control signal output by the terminal device 30 to the control module 11 in sequence through the debugging interface 13 and the debugging module 12, so that the simulator 201 and the control module 11 can communicate directly, thereby obtaining the code or data in the control module 11 of the vehicle component 10 and realizing the debugging of the vehicle component 10.
[0075] Optionally, the terminal device 30 can be any type of electronic device with simulation testing capabilities, such as a smartphone, laptop, desktop computer, or tablet computer. This application embodiment does not impose specific limitations on the implementation form of the terminal device 30.
[0076] It should be noted that, in this embodiment, the vehicle component 10 can be a PCB (Printed Circuit Board) of a vehicle's component system, such as the PCB of an engine system or a braking system. This embodiment does not impose specific limitations on this.
[0077] Please refer to Figure 6, which is a flowchart illustrating a debugging method provided in an embodiment of this application. This debugging method is applicable to the vehicle-mounted component 10 described in the preceding embodiments. In this embodiment, the specific structure and function of the vehicle-mounted component 10 can be found in the corresponding descriptions in the preceding embodiments, and will not be repeated here. As shown in Figure 6, the debugging method specifically includes the following steps:
[0078] S101 provides the first signal to the debugging module through the control module.
[0079] In some feasible implementations, the vehicle-mounted component 10 can provide a first signal to the debugging module 12 via the control module 11. Here, the first signal can be used to indicate whether the vehicle-mounted component 10 allows debugging.
[0080] Here, the specific process by which the vehicle-mounted component 10 provides the first signal to the debugging module through the control module 11 can be found in the process described above where the control module 11 provides the first signal to the debugging module 12, and will not be repeated here.
[0081] S102, when the debugging module determines that the vehicle component is not allowed to be debugged based on the first signal and detects that a debugging device is connected to the debugging interface, it stops supplying power to the control module.
[0082] In some feasible implementations, the vehicle component 10 can stop supplying power to the control module 11 when the debugging module 12 determines that the vehicle component 10 is not allowed to be debugged according to a first signal and detects that the debugging interface 13 is connected to the debugging device 20.
[0083] Here, the specific process by which the vehicle component 10 stops supplying power to the control module 11 when the debugging module 12 determines that the vehicle component 10 is not allowed to be debugged according to the first signal and detects that the debugging interface 13 is connected to the debugging device 20 can be referred to in the above description of the process by which the debugging module 12 stops supplying power to the control module 11 when the debugging module 10 determines that the vehicle component 10 is not allowed to be debugged according to the first signal and detects that the debugging interface 13 is connected to the debugging device 20. It will not be repeated here.
[0084] In an optional implementation, when the debugging module 12 includes a debugging circuit 121 and a power supply circuit 122, the vehicle-mounted component 10 can determine whether debugging is permitted based on a first signal using the debugging circuit 121. The vehicle-mounted component 10 can also detect whether a debugging device 20 is connected to the debugging interface 13 using the debugging circuit 121. Furthermore, if the debugging circuit 121 determines that debugging is not permitted and detects that a debugging device 20 is connected to the debugging interface 13, the vehicle-mounted component 10 can control the power supply circuit 122 to stop supplying power to the control module 11. The specific process is detailed in the preceding description and will not be repeated here.
[0085] In an optional implementation, when the debugging circuit 121 includes a control circuit 1211 and a switching circuit 1212, the vehicle component 10 can establish a connection between the control module 11 and the debugging interface 13 if the switching circuit 1212 determines that debugging of the vehicle component 10 is permitted based on a first signal. Alternatively, the vehicle component 10 can disconnect the connection between the control module 11 and the debugging interface 13 if the switching circuit 1212 determines that debugging of the vehicle component 10 is not permitted based on the first signal. The specific process is detailed in the preceding description and will not be repeated here.
[0086] Optionally, the vehicle-mounted component 10 can also output a second signal via the switching circuit 1212. Here, the second signal is used to indicate whether the debugging interface 13 is connected to the debugging device 20. The specific process of the vehicle-mounted component 10 outputting the second signal via the switching circuit 1212 can be found in the previously described process of the switching circuit 1212 outputting the second signal, and will not be repeated here.
[0087] Optionally, the vehicle component 10 can control the power supply circuit 122 to stop supplying power to the control module 11 when the vehicle component 10 is not allowed to be debugged according to the first signal and the debugging interface 13 is connected to the debugging device 20 according to the second signal.
[0088] In some feasible implementations, please refer to Figure 7, which is another schematic flowchart of a debugging method provided in an embodiment of this application. As shown in Figure 7, the debugging method may further include the following steps:
[0089] S103, the debugging module supplies power to the control module when it is determined from the first signal that the vehicle component is allowed to be debugged, or when it is determined from the first signal that the vehicle component is not allowed to be debugged and the debugging interface is not connected to a debugging device.
[0090] In some feasible implementations, the vehicle-mounted component 10 can be powered by the debugging module 12 when the debugging module 12 determines that the vehicle-mounted component 10 is allowed to be debugged according to the first signal, or when the debugging module 10 is not allowed to be debugged according to the first signal and the debugging interface 13 is not connected to the debugging device 20.
[0091] Here, the specific process by which the vehicle component 10 supplies power to the control module 11 when the debugging module 12 determines that the vehicle component 10 is allowed to be debugged based on the first signal, or when the debugging module 12 determines that the vehicle component 10 is not allowed to be debugged based on the first signal and the debugging interface 13 is not connected to the debugging device 20, can be referred to in the previous section on the process by which the debugging module 12 supplies power to the control module 11 when the debugging module 12 determines that the vehicle component 10 is allowed to be debugged based on the first signal, or when the debugging module 10 is not allowed to be debugged based on the first signal and the debugging interface 13 is not connected to the debugging device 20. It will not be repeated here.
[0092] In some feasible implementations, please refer to Figure 8, which is another flowchart illustrating a debugging method provided by an embodiment of this application. It should be understood that step S104 can be performed before step S101. As shown in Figure 8, the debugging method may further include the following steps:
[0093] S104 obtains a third signal via the vehicle bus through the control module and determines whether the vehicle component is in debugging mode based on the third signal.
[0094] In some feasible implementations, the vehicle component 10 can obtain a third signal through the vehicle bus via the control module 11, and determine whether the vehicle component 10 is in debugging mode based on the third signal.
[0095] Here, the specific process by which the vehicle component 10 obtains the third signal through the vehicle bus via the control module 11 and determines whether the vehicle component 10 is in the debugging mode based on the third signal can be found in the previous section on the process by which the control module 11 obtains the third signal through the vehicle bus and determines whether the vehicle component 10 is in the debugging mode based on the third signal. It will not be repeated here.
[0096] In some feasible implementations, when the third signal includes a target key, the vehicle-mounted component 10 can determine that it is in debug mode if the control module 11 determines that the target key matches the preset key. Alternatively, the vehicle-mounted component 10 can determine that it is not in debug mode if the control module 11 determines that the target key does not match the preset key. The specific process is described above and will not be repeated here.
[0097] This application also provides a vehicle, as shown in Figure 9, which is a structural schematic diagram of a vehicle provided in this application embodiment. As shown in Figure 9, the vehicle may include the on-board components 10 described in the above embodiments. The vehicle may also include multiple wheels, seats, on-board power supplies, electrical equipment, etc.
[0098] It should be noted that, for the sake of simplicity, all embodiments of the above-described vehicle-mounted components, debugging methods, and vehicles are described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to this application.
[0099] The terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish different objects, not to describe a specific order. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps is not limited to the steps listed, but may optionally include steps not listed, or may optionally include other steps inherent to these processes, methods, products, or apparatuses.
[0100] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0101] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out this application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. While different dependent claims may recite certain measures, this does not imply that these measures cannot be combined to produce a good effect.
[0102] The embodiments of this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of a vehicle-mounted component, debugging method, and vehicle of this application. The descriptions of the embodiments above are intended to help understand the methods and core ideas of this application. At the same time, for those skilled in the art, based on the ideas of a vehicle-mounted component, debugging method, and vehicle of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.
[0103] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this application can be implemented using hardware, software, firmware, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. Computer-readable media include computer storage media and communication media, wherein communication media include any medium that facilitates the transmission of a computer program from one place to another. Storage media can be any available medium accessible to a general-purpose or special-purpose computer.
[0104] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of this application. It should be understood that the above description is only a specific embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of this application should be included within the scope of protection of this application.
Claims
1. A vehicle-mounted component, characterized in that, The vehicle-mounted component includes a control module, a debugging module, and a debugging interface. The debugging module is connected to the control module and the debugging interface, respectively. The control module provides a first signal to the debugging module, wherein the first signal indicates whether debugging of the vehicle-mounted component is permitted. The debugging module stops supplying power to the control module when it determines, based on the first signal, that debugging of the vehicle-mounted component is not permitted, and detects that a debugging device is connected to the debugging interface. The debugging module includes a debugging circuit and a power supply circuit. The debugging circuit is connected to the power supply circuit, the control module, and the debugging interface, respectively. The circuit is also connected to the control module; the debugging circuit is used to determine whether the vehicle component is allowed to be debugged based on the first signal; the debugging circuit is also used to detect whether the debugging interface is connected to the debugging device; the debugging circuit is also used to control the power supply circuit to stop supplying power to the control module when it is determined that the vehicle component is not allowed to be debugged and the debugging interface is detected to be connected to the debugging device; the debugging circuit includes a control circuit and a switching circuit, the control circuit is connected to the switching circuit, the control module, and the power supply circuit respectively, and the switching circuit is also connected to the control module and the debugging interface respectively; A switching circuit is used to establish a connection between the control module and the debugging interface if it is determined from the first signal that the vehicle component is allowed to be debugged; the switching circuit is also used to disconnect the connection between the control module and the debugging interface if it is determined from the first signal that the vehicle component is not allowed to be debugged; the switching circuit is also used to send a second signal to the control circuit, wherein the second signal is used to indicate whether the debugging interface is connected to the debugging device; the control circuit is used to determine whether to control the power supply circuit to stop supplying power to the control module based on the first signal and the second signal; the control circuit is used to control the power supply circuit to stop supplying power to the control module when it is determined from the first signal that the vehicle component is not allowed to be debugged and based on the second signal that the debugging interface is connected to the debugging device; the control circuit includes a XNOR gate and an OR gate, the XNOR gate being connected to the control module, the switching circuit, and the OR gate respectively, and the OR gate being connected to the power supply circuit; the XNOR gate is used to output a sixth signal to the OR gate based on the first signal and the second signal; the OR gate is used to output a seventh signal to the power supply circuit based on the sixth signal and the first signal, the seventh signal being used to indicate whether the power supply circuit supplies power to the control module.
2. The vehicle-mounted component according to claim 1, characterized in that, The debugging module is also used to supply power to the control module when it is determined from the first signal that the vehicle component is allowed to be debugged, or when it is determined from the first signal that the vehicle component is not allowed to be debugged and the debugging interface is not connected to the debugging device.
3. The vehicle-mounted component according to claim 1 or 2, characterized in that, The control module is used to acquire a third signal through the vehicle bus and determine whether the vehicle component is in debugging mode based on the third signal.
4. The vehicle-mounted component according to claim 3, characterized in that, The third signal includes a target key. The control module is further configured to determine that the vehicle component is in debug mode if the target key is consistent with a preset key; the control module is further configured to determine that the vehicle component is not in debug mode if the target key is inconsistent with the preset key.
5. A debugging method, characterized in that, An application to an automotive component, the automotive component including at least a control module, a debugging module, and a debugging interface, wherein the debugging module is connected to the control module and the debugging interface respectively, the method comprising: providing a first signal to the debugging module through the control module, wherein the first signal is used to indicate whether the automotive component is allowed to be debugged; and stopping power supply to the control module when the debugging module determines, based on the first signal, that the automotive component is not allowed to be debugged, and detects that a debugging device is connected to the debugging interface; the debugging module including a debugging circuit and a power supply circuit, the debugging circuit being connected to the power supply circuit, the control module, and the debugging interface respectively, the power supply circuit also being connected to the control module, the step of stopping power supply to the control module when the debugging module determines, based on the first signal, that the automotive component is not allowed to be debugged, and detects that a debugging device is connected to the debugging interface includes: determining, based on the first signal, whether the automotive component is allowed to be debugged through the debugging circuit; detecting, based on the debugging circuit, whether a debugging device is connected to the debugging interface; and controlling the power supply circuit to stop power supply to the control module when the debugging module determines that the automotive component is not allowed to be debugged, and detects that a debugging device is connected to the debugging interface. The debugging circuit includes at least a control circuit and a switching circuit. The control circuit is connected to the switching circuit, the control module, and the power supply circuit, respectively. The switching circuit is also connected to the control module and the debugging interface, respectively. Determining whether the vehicle component is allowed to be debugged based on the first signal through the debugging circuit includes: if the switching circuit determines that the vehicle component is allowed to be debugged based on the first signal, establishing a connection between the control module and the debugging interface; if the switching circuit determines that the vehicle component is not allowed to be debugged based on the first signal, disconnecting the connection between the control module and the debugging interface. Detecting whether the debugging interface is connected to a debugging device through the debugging circuit includes: outputting a second signal through the switching circuit, wherein the second signal is used to indicate whether the debugging interface is connected to a debugging device. Controlling the power supply circuit to stop supplying power to the control module when the debugging circuit determines that the vehicle component is not allowed to be debugged and detects that the debugging interface is connected to the debugging device includes: controlling the power supply circuit to stop supplying power to the control module when the control circuit determines that the vehicle component is not allowed to be debugged based on the first signal and determines that the debugging interface is connected to the debugging device based on the second signal.The control circuit includes a XNOR gate and an OR gate. The XNOR gate is connected to the control module, the switching circuit, and the OR gate, respectively. The OR gate is connected to the power supply circuit. The step of controlling the power supply circuit to stop supplying power to the control module when the control circuit determines, based on the first signal, that the vehicle component is not allowed to be debugged, and based on the second signal, that the debugging interface is connected to the debugging device, includes: outputting a sixth signal to the OR gate through the XNOR gate based on the first and second signals; and outputting a seventh signal to the power supply circuit through the OR gate based on the sixth signal and the first signal. The seventh signal is used to indicate whether the power supply circuit is supplying power to the control module.
6. The method according to claim 5, characterized in that, The method further includes: supplying power to the control module when the debugging module determines, based on the first signal, that the vehicle-mounted component is allowed to be debugged, or when the first signal determines that the vehicle-mounted component is not allowed to be debugged and the debugging interface is not connected to the debugging device.
7. The method according to claim 5 or 6, characterized in that, The method further includes: acquiring a third signal via the vehicle bus through the control module, and determining whether the vehicle component is in debugging mode based on the third signal.
8. The method according to claim 7, characterized in that, The third signal includes a target key, and the method further includes: if the control module determines that the target key is consistent with a preset key, then the vehicle component is determined to be in debug mode; if the control module determines that the target key is inconsistent with the preset key, then the vehicle component is determined not to be in debug mode.
9. A vehicle, characterized in that, The vehicle includes the on-board components as described in any one of claims 1-4.
Citation Information
Patent Citations
Chip access methods, security control modules, chips and debugging equipment
CN110337652B
Vehicle machine debugging method, vehicle machine and server
CN114721924A
Detecting and remediating unauthorized debug sessions
US20220003817A1