ECU security access proxy authentication system and method, storage medium and computer program product

Through the ECU secure access proxy authentication system, secure authentication is performed between the device and the gateway device, which solves the problem that devices cannot safely access the ECU due to the lack of or inability to share security algorithms in the ECU, and achieves high security and flexible ECU access.

CN119921982APending Publication Date: 2025-05-02DONGFENG HONDA AUTOMOBILE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411912620.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

In the absence of or sharing security algorithms by the ECU, the device cannot access the ECU safely, resulting in the inability to perform necessary diagnostics or service operations.

Method used

By introducing the ECU secure access agent authentication system, secure authentication is performed between the device and the gateway device, and the gateway device performs a secure access agent for the ECU to ensure that the device can access the ECU safely.

Benefits of technology

It realizes that when ECU manufacturers do not share security algorithms, devices can access the ECU safely, improve the security and flexibility of the system, and reduce access failures caused by communication problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119921982A_ABST
    Figure CN119921982A_ABST
Patent Text Reader

Abstract

The invention discloses an ECU security access proxy authentication system and method, a storage medium and a computer program product. Comprising the following steps: confirming whether gateway equipment has a security agent function; when the gateway equipment has the security agent function, the equipment requests the gateway equipment to perform security authentication on the equipment; the gateway equipment carries out security authentication on the equipment; and after the equipment passes the security authentication of the gateway equipment, the equipment can access the ECU through the gateway equipment. According to the invention, security authentication is carried out between the newly added device and the gateway device, so that the existing ECU data security can be protected through the gateway device on the premise that an ECU manufacturer does not share a security algorithm, and the data security level of the newly developed ECU is not reduced; according to the method, hardware cost does not need to be increased, software of the gateway equipment can be modified, and the development or debugging period of a product is rapidly shortened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data access security, and in particular relates to an ECU security access proxy authentication system, method, storage medium and computer program product. Background Art

[0002] When performing certain operations on the ECU (Electronic Control Unit), such as downloading / uploading routines or data to / from a server and diagnostic services that read specific memory locations from a server, secure access or higher level access rights are required to avoid incorrect routines or data downloaded to the server that could damage the electronic equipment or other vehicle components, or jeopardize the vehicle's compliance with emissions, safety or security standards.

[0003] Obtaining security access rights usually requires the diagnostic device to perform security authentication and decryption on the ECU. Only after the decryption is completed can the corresponding operations be performed on the internal data of the ECU. During this process, the OEM (Original Equipment Manufacturer) needs to share security algorithms with different suppliers. However, some OEMs do not want to share these security algorithms with new suppliers for data security reasons. This may cause some problems, such as the new supplier's diagnostic equipment cannot communicate securely with the ECU, making it impossible to perform necessary diagnostic or service operations. Summary of the invention

[0004] In order to enable a device to access an ECU when the ECU lacks or cannot share a security algorithm, the present invention proposes an ECU security access proxy authentication system, method, storage medium and computer program product.

[0005] An ECU security access proxy authentication system to achieve one of the purposes of the present invention includes:

[0006] Function confirmation module: used to confirm whether the gateway device has the security proxy function;

[0007] The first security authentication request module is used for, when the gateway device has a security proxy function, the device requests the gateway device to perform security authentication on the device;

[0008] Security authentication module: used for the gateway device to perform security authentication on the device; when the device passes the security authentication of the gateway device, the device can access the ECU through the gateway device.

[0009] Furthermore, in the security authentication module, the method in which the gateway device performs security authentication on the device includes:

[0010] The device sends a seed generation request to the gateway device;

[0011] After receiving the seed generation request, the gateway device calls the gateway device's own security algorithm to generate a seed and a local key, and sends the seed to the device;

[0012] After receiving the seed, the device uses its own security algorithm to calculate the seed to obtain a key, and sends the key to the gateway device;

[0013] The gateway device compares the key with the local key. When the comparison result is consistent, it is considered that the device has passed the security authentication of the gateway device.

[0014] Furthermore, before the device sends a seed generation request to the gateway device, it also includes: the device sends a security algorithm call request to the gateway device; when the gateway device replies to the device with an affirmative response supporting the security algorithm call request, the device sends a request message for changing the diagnostic session mode of the ECU to the ECU through the gateway device, and after the ECU receives the request message, it changes the diagnostic session mode to an extended diagnostic session mode, so that the gateway device and the ECU can send and receive functional messages of specific services, including: $10 service, $28 service, and $10 service defined in ISO14229.

[0015] Furthermore, when the device sends a seed generation request to the gateway device, it also includes sending a security level request. The device sends a seed generation request to the gateway device. After the device passes the security authentication of the gateway device, the gateway device periodically sends a message to the ECU that the security level requested by the device has been released. The device performs corresponding operations on the ECU according to the requested security level. Its technical effects include: ensuring that the ECU can perform corresponding processing according to the corresponding security level when receiving the device operation, thereby improving the security and flexibility of the system.

[0016] Furthermore, it also includes a second security authentication request module, which is used for the device to request the ECU to perform security authentication on the device. Furthermore, when the ECU does not support security authentication on the device, the device requests the gateway device to perform security authentication on the device. Its technical effects include: increasing the flexibility of the system, so that the technical solution can be compatible with the scenario where the ECU supports or does not support security authentication on the device.

[0017] A method for ECU security access proxy authentication to achieve the second objective of the present invention includes:

[0018] Confirm whether the gateway device has the security proxy function;

[0019] When the gateway device has a security proxy function, the device requests the gateway device to perform security authentication on the device;

[0020] The gateway device performs security authentication on the device; when the device passes the security authentication of the gateway device, the device can access the ECU through the gateway device.

[0021] Furthermore, before or after confirming whether the gateway device has the security proxy function, it also includes confirming with the ECU whether the implementation conditions are met; the implementation conditions include: there is a diagnostic communication connection between the ECU and the OBD interface, and the CAN diagnostic message routing function between the device and the ECU is normal. Its technical effects include: reducing access failures caused by communication problems and improving the reliability and stability of the system.

[0022] The beneficial effects of the present invention include:

[0023] 1. Compared with the conventional method, the device of the present invention establishes a communication connection with the vehicle through the OBD interface, and the GW (gateway) is responsible for forwarding the CAN message information between the device and the xECU. Compared with the method in which the device and the xECU directly use the $27 service for security authentication, the present invention is based on this conventional method-the $27 security authentication scheme, and performs security authentication between the newly added device and the GW. Under the premise that the ECU manufacturer does not share the security algorithm with certain specific suppliers, the data security of the existing xECU can be protected by the GW without reducing the data security level of the newly developed xECU. The present invention does not need to increase the hardware cost, and only needs to modify the GW software, which quickly shortens the product development or debugging cycle;

[0024] 2. The present invention is not limited to authentication between the device and the GW. As long as there is a diagnostic communication connection between the xECU and the OBD interface, and the CAN diagnostic message routing function between the device and the xECU is available, the solution can be applied for secure proxy authentication, so that it can be quickly applied to different vehicles or systems without a lot of hardware or software redesign, which can significantly shorten the product development cycle. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 This is one of the schematic diagrams of the secure proxy authentication process in an embodiment of the present invention;

[0026] Figure 2 Schematic diagram of a secure proxy authentication firewall in an embodiment of the present invention;

[0027] Figure 3 This is the second schematic diagram of the secure proxy authentication process in an embodiment of the present invention;

[0028] Figure 4 It is a schematic diagram of the security authentication Seed-Key model in an embodiment of the present invention. DETAILED DESCRIPTION

[0029] The following specific implementations are used to explain the technical solutions of the claims of the present invention so that those skilled in the art can understand the claims. The protection scope of the present invention is not limited to the following specific implementation structures. The technical solutions of the claims of the present invention made by those skilled in the art but different from the following specific implementations are also within the protection scope of the present invention.

[0030] The embodiments of the present invention involve multiple services or messages in ISO14229, which are specifically explained as follows:

[0031] $10 service: Diagnostic Session Control service, which is mainly used to start different diagnostic sessions inside the ECU, allowing diagnostic tools (such as scanners or programming devices) to change the diagnostic session mode of the ECU by sending specific requests, and corresponding to specific diagnostic services and function combinations in different session modes. These session modes usually include default session mode, programming session mode and extended session mode;

[0032] $1001Default session: The session state maintained by the ECU when it is just powered on. Its service usage permissions are relatively small, that is, there are fewer functional unit services that can be operated. In the default session mode, some sensitive or advanced diagnostic services may not be available.

[0033] $1002 Programming session mode: Only used for diagnostic services related to flashing programs. In programming session mode, you can perform operations such as software downloads and firmware updates. However, it should be noted that programming sessions cannot usually be entered directly from the default session, but require entering an extended session first.

[0034] $1003 Extended session mode: Compared with the default session, it has greater permissions to use services, that is, more functional unit services can be operated. In the extended session mode, some diagnostic services that cannot be used in the default session can be used, such as writing data, reading extended information, etc.

[0035] $22 service: ReadDataByIdentifier service, the main function of this service is to allow the client (such as diagnostic tools or ECU development software) to request data record values ​​identified by one or more data identifiers (DIDs) from the server (usually the vehicle's ECU). The client can read the data associated with these DIDs stored in the ECU by sending a $22 request message containing a specific DID. The DID value is used to identify the data records maintained by the server; these data may include analog input and output signals (such as speed signals), digital input and output signals (such as door signals), internal data, and system status information. After receiving the request, the server will access the data elements specified by each DID in turn and return the corresponding data record value in a positive response. Diagnostic tools can use this service to read fault codes, sensor data, and system status information in the ECU, thereby helping technicians quickly locate and solve vehicle faults. In addition, during the ECU development and debugging process, developers can also use this service to verify the functionality and performance of the ECU.

[0036] $27 service: Also known as the Security Access Service, the main purpose of this service is to provide restricted access to data or diagnostic services, which is usually due to confidentiality, emissions or safety considerations. The Security Access Service allows clients (such as diagnostic tools) to unlock the security level of the ECU (Electronic Control Unit) by sending specific requests before accessing sensitive data or performing sensitive operations, thereby ensuring that only authorized diagnostic tools can access or modify key data in the ECU. The request message of the Security Access Service usually includes a service identifier (SID, that is, $27), sub-function parameters, and security access data records. The sub-function parameters are used to specify the type of operation that the client is requesting (such as requesting a seed or sending a key), while the security access data record may contain some additional information, such as the client's identifier. After receiving the request message, the ECU will perform the corresponding operation according to the content of the request and send a positive response or negative response message to the client. A positive response indicates that the request has been successfully executed and may contain a seed generated by the ECU or confirmation information that the unlocking is successful. A negative response indicates that the request failed to execute and will contain the reason code for the failure (NRC, i.e. negative response code).

[0037] $28 service: used to control the sending and receiving of messages in the network, and can turn on or off the sending and / or receiving of specific messages of one or more controllers. These messages can be application communication messages or network management messages. In certain cases, such as during the ECU flashing process, sending $28 messages can suppress the sending and receiving of other unnecessary messages, thereby reducing the load of the network bus and improving the ECU download efficiency. After the flashing is completed, send 28 messages again to re-enable the sending and receiving of related messages.

[0038] $85 service: Also known as the ControlDTCSetting service, it is mainly used to stop or resume the update of the DTC (Diagnostic Trouble Code) status bit in the ECU (Engine Control Unit); specifically, the ControlDTCSetting service request message can be used to stop setting diagnostic trouble codes in a single server (ECU) or a group of servers. This is usually very useful in the diagnostic flashing process, because in this process, a certain ECU node is often flashed separately, while other ECU nodes are still in normal working state. At this time, the function address can be sent to each ECU node to stop recording DTC, and then the DTC recording function can be restarted after the flashing is completed. In addition, this service can also be used in some special scenarios where DTC recording is not required. The sub-function parameter of the ControlDTCSetting service can be set to "on" or "off". When set to "on", the ECU will restart the diagnostic trouble code setting according to normal operating conditions; when set to "off", the ECU will stop the diagnostic trouble code setting. When requesting the ControlDTCSetting service, the client sends a request message containing a service identifier (SID) and sub-function parameters to the server (ECU). After receiving the request, the server will perform the corresponding operation according to the content of the request and send a positive response or negative response message to the client. If the server cannot stop the update of the DTC status bit, it will respond with a negative response message and indicate the reason for the rejection. In general, the $85 message (ControlDTCSetting service) in ISO 14229 plays an important role in the vehicle diagnostic system, which can help maintenance personnel perform fault diagnosis and repair work more effectively.

[0039] Example 1

[0040] A proxy authentication method for secure access to ECU

[0041] like Figure 1The schematic diagram of the security proxy authentication process is shown in the figure. The detailed design of data interaction between the device, GW (gateway device), and xECU is as follows Figure 3 As shown, the specific steps include:

[0042] 1. Before the device performs data operations on xECU, the device uses $22 service to obtain the implementation conditions of xECU from xECU. The implementation conditions include: as long as there is a diagnostic communication connection between the ECU and the OBD interface, and the CAN diagnostic message routing function between the device and the ECU, the technical solution of ECU secure access proxy authentication of the present invention can be applied for secure proxy authentication.

[0043] When the implementation condition data interaction confirmation is completed, start applying for ECU Security to release the relevant access rights; $27 service security authentication, that is, before TypeX Security is released, the device applies for security authentication to GW;

[0044] 2. The device confirms whether the gateway device has the security proxy function; it uses the $22 service to confirm to the gateway device GW whether it has the security proxy authentication function of the $27 service. If the gateway device GW has this function, it proceeds to the next step, otherwise it ends;

[0045] 3. After confirming that GW has the security proxy authentication function, the device uses the $22 service to send a request to retrieve the security algorithm to the target xECU and GW in turn. If the xECU does not have the security proxy authentication function, it needs to feedback a specific NRC 0x7F negative response to the device, indicating that the xECU cannot directly process this "retrieve security algorithm" request;

[0046] 4. When xECU does not have the security proxy authentication function and GW has the security proxy authentication function, the device uses the $10 service to request the gateway device GW and xECU to enter the extended session mode. Functional addressing can be used. In this extended session mode, GW removes some data routing function restrictions and can forward $28 service and $85 service to the target xECU.

[0047] 5. Next, GW performs security authentication on the device. The HEX value of the ISO14229 protocol used in security authentication can be customized by the user. It must avoid conflicts with the values ​​defined in ISO14229. Alternatively, the $27 service can still be used to release the corresponding TypeX security level by setting the value of the sub-function field in the $27 service (the sub-function value represents the security level).

[0048] The method for performing security authentication between the device and the GW is as follows: Figure 4 As shown, including:

[0049] The device sends a security algorithm call request to the gateway device; this request can be carried by the $22 service in ISO14229;

[0050] The gateway device replies to the device with a positive response that supports the security algorithm invocation request or a negative response that does not support the security algorithm invocation request;

[0051] When the device receives a positive response from the gateway device that supports the security algorithm call request, it sends a seed generation request and a security level request to the gateway device; and the device sends a request message for changing the diagnostic session mode of the ECU to the ECU through the gateway device, and after the ECU receives the request message, it changes the diagnostic session mode to the extended diagnostic session mode;

[0052] After receiving the seed generation request, the gateway device calls the gateway device's own security algorithm to generate a seed and a local key, and sends the seed to the device;

[0053] After receiving the seed, the device uses its own security algorithm to calculate the seed to obtain a key, and sends the key to the gateway device;

[0054] The gateway device compares the key with the local key. When the comparison result is consistent, it is considered that the device has passed the security authentication of the gateway device.

[0055] Before the device sends a security algorithm call request to the gateway device, the device sends a security algorithm call request to the xECU. If the xECU replies with a negative response that the security algorithm call request is not supported, the device sends the security algorithm call request to the network sending device. This step can make the present invention compatible with application scenarios where the xECU has a function of performing security authentication on the device, so as to improve the compatibility of the method described in the present invention and can automatically adapt to two application scenarios.

[0056] 6. After the device passes the security authentication of GW, GW removes all restrictions on data routing functions and can forward ProgrammingSession and EngineeringSession requests to meet the reprogramming data interaction. GW also periodically sends the result of TypeX Security (i.e. the security level requested by the device) to xECU through CAN messages, so that the device can perform corresponding operations on the target xECU according to the requested security level.

[0057] The device uses the $27 service to request xECU to release the TypeX Security function, which can be retained to make the present invention compatible with the scenario where xECU has the 27 security authentication function. When xECU does not have the 27 security authentication function, xECU can reply with the corresponding NRC.

[0058] It should be understood that the order of execution of the steps in the above embodiment does not necessarily mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention.

[0059] Example 2

[0060] An ECU security access proxy authentication system, comprising:

[0061] Function confirmation module: used to confirm whether the gateway device has the security proxy function; Figure 3 In the process, the device uses the $22 service to confirm with the GW whether there is a proxy authentication function parameter retrieval request from the $27 service;

[0062] The first security authentication request module is used for, when the gateway device has a security proxy function, the device requests the gateway device to perform security authentication on the device;

[0063] Security authentication module: used for the gateway device to perform security authentication on the device; when the device passes the security authentication of the gateway device, the device can access the ECU through the gateway device.

[0064] In some embodiments, in the security authentication module, the method in which the gateway device performs security authentication on the device includes:

[0065] The device sends a seed generation request to the gateway device;

[0066] After receiving the seed generation request, the gateway device calls the gateway device's own security algorithm to generate a seed and a local key, and sends the seed to the device;

[0067] After receiving the seed, the device uses its own security algorithm to calculate the seed to obtain a key, and sends the key to the gateway device;

[0068] The gateway device compares the key with the local key. If the comparison result is consistent, it is considered that the device has passed the security authentication of the gateway device. Figure 2 As shown, the gateway device acts as a firewall in this system. Only when the device passes the security authentication of the gateway device can the device send related services or messages (such as $85 / $28 / $10 services) to the target ECU through the gateway device.

[0069] In some embodiments, when the device sends a seed generation request to the gateway device, it also includes sending a security level request. The device sends a seed generation request to the gateway device. When the device passes the security authentication of the gateway device, the gateway device periodically sends a message to the ECU via a CAN message indicating that the security level requested by the device has been released. The device performs corresponding operations on the ECU according to the requested security level.

[0070] In some embodiments, a second security authentication request module is further included, which is used for the device to request the ECU to perform security authentication on the device. When the ECU does not support security authentication on the device, the device requests the gateway device to perform security authentication on the device.

[0071] Example 3

[0072] A non-transitory computer-readable storage medium stores a computer program, which includes program instructions. When the program instructions are executed by a processor, the various steps of the method described in the present invention are implemented, which will not be repeated here.

[0073] The computer-readable storage medium may be the data transmission device provided in any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart memory card (smartmedia card, SMC), a secure digital (secure digital, SD) card, a flash card (flash card), etc., provided on the computer device.

[0074] Furthermore, the computer-readable storage medium may include both an internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data to be output or has been output.

[0075] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0076] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0077] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0078] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0079] Example 4

[0080] A computer program product, comprising a computer program / instruction, which, when executed by a processor, implements the steps of the ECU security access proxy authentication method

[0081] The contents not described in detail in this specification belong to the prior art known to professional and technical personnel in this field.

Claims

1. An ECU security access proxy authentication system, characterized in that: include: Function confirmation module: used to confirm whether the gateway device has the security proxy function; The first security authentication request module is used for, when the gateway device has a security proxy function, the device requests the gateway device to perform security authentication on the device; Security authentication module: used by the gateway device to perform security authentication on the device; After the device passes the security authentication of the gateway device, the device can access the ECU through the gateway device.

2. The ECU security access proxy authentication system according to claim 1, characterized in that: In the security authentication module, the method in which the gateway device performs security authentication on the device includes: The device sends a seed generation request to the gateway device; After receiving the seed generation request, the gateway device calls the gateway device's own security algorithm to generate a seed and a local key, and sends the seed to the device; After receiving the seed, the device uses its own security algorithm to calculate the seed to obtain a key, and sends the key to the gateway device; The gateway device compares the key with the local key. When the comparison result is consistent, it is considered that the device has passed the security authentication of the gateway device.

3. The ECU security access proxy authentication system as claimed in claim 2, characterized in that: Before the device sends a seed generation request to the gateway device, it also includes: the device sends a security algorithm call request to the gateway device; when the gateway device replies to the device with an affirmative response supporting the security algorithm call request, the device sends a request message for changing the diagnostic session mode of the ECU to the ECU through the gateway device, and after the ECU receives the request message, it changes the diagnostic session mode to the extended diagnostic session mode.

4. The ECU security access proxy authentication system according to any one of claims 2 to 3, characterized in that: When the device sends a seed generation request to the gateway device, it also includes sending a security level request. The device sends a seed generation request to the gateway device. When the device passes the security authentication of the gateway device, the gateway device periodically sends a message to the ECU indicating that the security level requested by the device has been released. The device performs corresponding operations on the ECU based on the requested security level.

5. The ECU security access proxy authentication system according to claim 1, characterized in that: It also includes a second security authentication request module, which is used for the device to request the ECU to perform security authentication on the device.

6. The ECU security access proxy authentication system as claimed in claim 5, characterized in that: When the ECU does not support security authentication of the device, the device requests the gateway device to perform security authentication on the device.

7. An ECU security access proxy authentication method, characterized in that: include: Confirm whether the gateway device has the security proxy function; When the gateway device has a security proxy function, the device requests the gateway device to perform security authentication on the device; The gateway device performs security authentication on the device; when the device passes the security authentication of the gateway device, the device can access the ECU through the gateway device.

8. The ECU security access proxy authentication method according to claim 7, characterized in that: Before or after confirming whether the gateway device has the security proxy function, it also includes confirming with the ECU whether the implementation conditions are met; the implementation conditions include: there is a diagnostic communication connection between the ECU and the OBD interface, and the CAN diagnostic message routing function between the device and the ECU is normal.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, any step of the ECU security access proxy authentication method according to claim 7 or 8 is implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, any step of the ECU security access proxy authentication method described in claim 7 or 8 is implemented.

Citation Information

Cited By

  • Vehicle-mounted ECU identity authentication method and system based on multi-factor random seed and multiple security levels

    CN121770758A