Diagnostic device control method, storage medium, and program product

By using security chips and integrated circuits in diagnostic equipment, verifying the identity of the MCU and the legitimacy of the target program, the problem of unauthorized use of the MCU is solved, and the security of the diagnostic equipment and the correct execution of the target program is achieved.

CN119937428AActive Publication Date: 2025-05-06LAUNCH TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510223875.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-06
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

How to avoid the use of unauthorized microcontroller units (MCUs) of diagnostic devices to ensure the safety of diagnostic devices and perform the correct target procedures.

Method used

By introducing security chips and integrated circuits into the diagnostic equipment, the security chip generates random numbers and verifies the identity of the MCU and the legitimacy of the target program through public key encryption and private key decryption, thereby controlling the usage mode of the integrated circuit.

Benefits of technology

Effectively avoid the use of unauthorized MCUs, ensure the safety of the diagnostic equipment and the correct execution of target programs, thereby improving the safety of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119937428A_ABST
    Figure CN119937428A_ABST
Patent Text Reader

Abstract

The invention discloses a diagnostic device control method, a storage medium and a program product. Wherein the diagnosis equipment comprises an MCU and a diagnosis interface chip, the diagnosis interface chip comprises an integrated circuit and a safety chip, the integrated circuit is used for providing communication connection between the MCU and a vehicle, and the safety chip is used for controlling the on and off of the integrated circuit. And the security module encrypts the data through the MCU and verifies the MCU based on the encrypted data. And the security module is also used for obtaining the target program information from the MCU and verifying the target program information. The safety module allows the MCU to communicate with the vehicle through the opened integrated circuit under the condition that the MCU verification is passed and the target program information verification is passed, and forbids the MCU to communicate with the vehicle through the closed integrated circuit under the condition that the MCU verification is not passed or the target program information verification is not passed, so that the safety of the vehicle is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a diagnostic equipment control method, a storage medium and a program product. Background Art

[0002] With the continuous development of science and technology, the method of using diagnostic equipment to diagnose vehicles has become popular. Diagnostic equipment includes a microcontroller unit (MCU), which can obtain the vehicle's operating data and fault information to diagnose the vehicle. However, if an unauthorized MCU is used, the security of the diagnostic equipment may be affected because the MCU has not been inspected by the diagnostic equipment manufacturer. At the same time, unauthorized MCUs may tamper with the target program in the MCU. Therefore, how to prevent diagnostic equipment from using unauthorized MCUs and ensure that the diagnostic equipment executes the correct target program is a problem that needs to be solved urgently. Summary of the invention

[0003] The present application provides a diagnostic device control method, storage medium and program product, which can improve the safety of diagnostic device use. The technical solution is as follows:

[0004] In a first aspect, a method for controlling a diagnostic device is provided, the diagnostic device comprising a microcontroller unit MCU, a security chip and an integrated circuit, the integrated circuit being used to realize communication between the MCU and a vehicle, the security chip being used to control the MCU to use the integrated circuit, the MCU storing a public key, and the security chip storing a private key, the method comprising: the security chip generating first data, the first data being a random number; the security chip sending the first data to the MCU, obtaining second data returned by the MCU, the second data being obtained by the MCU encrypting the first data by the public key; the security chip decrypting the second data by the private key to obtain third data; the security chip verifying the first data and the third data; the security chip obtaining target program information from the MCU; the security chip verifying the target program information; the security chip operating in a first mode when the target program information is verified and the first data is verified and the third data is verified, and operating in a second mode when the target program information is not verified or the first data is not verified and the third data is not verified, the MCU is allowed to use the integrated circuit in the first mode, and the MCU is prohibited from using the integrated circuit in the second mode.

[0005] In combination with the first aspect, the security chip generates first data, including: after the security chip and the MCU are powered on and establish communication, the security chip receives a verification instruction sent by the MCU and generates the first data.

[0006] In combination with the first aspect, in some embodiments provided in the first aspect, the public key includes an asymmetric encryption algorithm public key, the private key includes an asymmetric encryption algorithm private key, and the security chip verifies the first data and the third data, including: the security chip compares the first data with the third data; if the first data is the same as the third data, the security chip determines that the first data and the third data have passed the verification; if the first data is different from the third data, the security chip determines that the first data and the third data have failed the verification.

[0007] In combination with the first aspect, in some implementations provided in the first aspect, the security chip obtains target program information from the MCU, including: the security chip obtains target program information from the MCU after power-on; wherein the integrated circuit is in a disabled state after the security chip is powered on.

[0008] In combination with the first aspect, in some embodiments provided in the first aspect, the security chip verifies the target program information, including: when the target program information includes program data and a digital signature, the security chip performs an encryption operation on the program data to obtain a first information summary; the security chip verifies the digital signature and the first information summary; if the digital signature and the first information summary are verified, the security chip determines that the target program information verification is passed; if the digital signature and the first information summary are not verified, the security chip determines that the target program information verification is not passed.

[0009] In combination with the first aspect, in some embodiments provided in the first aspect, the method also includes: the MCU sends a control instruction to the security chip when the diagnostic device is connected to the vehicle, and the control instruction is used to instruct the enabling of the integrated circuit; after the security chip receives the control instruction, when it is in the first mode, the security chip enables the integrated circuit according to the control instruction; when it is in the second mode, the security chip discards the control instruction to maintain the integrated circuit in a disabled state.

[0010] In combination with the first aspect, in some embodiments provided in the first aspect, the integrated circuit includes a first switch module, a transceiver module, and a second switch module, and the security chip enables the integrated circuit according to the control instruction, including: the security chip controls a first switch in the first switch module to be turned on according to the control instruction, controls a transceiver in the transceiver module to be powered on, and controls a second switch in the second switch module to be turned on.

[0011] It should be noted that, in the absence of conflict, the features of the various embodiments of the first aspect can be combined with each other, and any combination of features in different embodiments is also within the protection scope of this application. That is to say, the multiple embodiments described above can also be arbitrarily combined according to actual needs.

[0012] In a second aspect, a method for controlling a diagnostic device is provided, wherein the diagnostic device includes a microcontroller unit MCU, a security chip and an integrated circuit, wherein the integrated circuit is used to realize communication between the MCU and a vehicle, and the security chip is used to control the MCU to use the integrated circuit, wherein a public key is stored in the MCU, and a private key is stored in the security chip, wherein the method includes: the security chip generates first data, wherein the first data is a random number; the security chip sends the first data to the MCU, and obtains second data returned by the MCU, wherein the second data is obtained by encrypting the first data by the MCU using the public key; the security chip decrypts the second data by using the private key to obtain third data; the security chip verifies the first data and the third data; the security chip operates in a first mode if the first data and the third data are verified successfully, and operates in a second mode if the first data and the third data are not verified successfully, wherein the MCU is allowed to use the integrated circuit in the first mode, and the MCU is prohibited from using the integrated circuit in the second mode.

[0013] In a third aspect, a computer-readable storage medium is provided, on which computer instructions are stored. When the computer instructions are executed by a processor, they implement the first aspect or any one of the implementation modes of the first aspect or the method of the second aspect.

[0014] In a fourth aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the first aspect or any one of the embodiments of the first aspect or the method of the second aspect.

[0015] In a fifth aspect, a chip is provided, which is applied to an electronic device, and the chip includes one or more processors, and the processor is used to call computer instructions to enable the electronic device to execute the first aspect or any one of the embodiments of the first aspect or the method of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 is a flow chart of a diagnostic equipment control method provided by an embodiment of the present application;

[0017] Figure 2 is a schematic diagram of a diagnostic device module provided in an embodiment of the present application;

[0018] Figure 3 is a schematic diagram of a diagnostic device structure provided in an embodiment of the present application;

[0019] Figure 4 is a flow chart of an MCU control method provided by an embodiment of the present application;

[0020] Figure 5 is a schematic diagram of an MCU unit provided in an embodiment of the present application;

[0021] Figure 6 is a flow chart of a diagnostic interface chip control method provided by an embodiment of the present application;

[0022] Figure 7 is a schematic diagram of a diagnostic interface chip unit provided in an embodiment of the present application;

[0023] Figure 8 is a flow chart of another diagnostic device control method provided by an embodiment of the present application;

[0024] Fig. 9 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the objectives, technical solutions and advantages of the present application clearer, the implementation methods of the present application will be further described in detail below in conjunction with the accompanying drawings.

[0026] It should be understood that the "multiple" mentioned in this application refers to two or more. In the description of this application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is only a description of the association relationship of associated objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in order to facilitate the clear description of the technical solution of this application, the words "first" and "second" are used to distinguish between the same items or similar items with basically the same functions and effects. Those skilled in the art can understand that the words "first" and "second" do not limit the quantity and execution order, and the words "first" and "second" do not limit them to be different.

[0027] The phrases such as "one embodiment" or "some embodiments" described in the present application mean that the specific features, structures or characteristics described in the embodiment are included in one or more embodiments of the present application. Therefore, the phrases such as "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments" that appear in the differences in the present application do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. In addition, the terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0028] The application scenarios of the embodiments of the present application are described below.

[0029] The embodiments of the present application are applied to the scenario where the MCU in the diagnostic device is verified after the diagnostic device is powered on, so as to determine whether the diagnostic device is safe before the diagnostic device communicates with the vehicle, thereby ensuring the safety of the vehicle.

[0030] Normally, when the diagnostic equipment is diagnosing a vehicle, the MCU obtains the vehicle's operating data and fault information and diagnoses the vehicle accordingly. However, if the MCU is not certified by the diagnostic equipment manufacturer, using the uncertified MCU to communicate with the vehicle will affect vehicle safety. For example, an uncertified MCU may tamper with the target program preset by the diagnostic equipment manufacturer, affecting the normal diagnostic function of the vehicle.

[0031] Therefore, the embodiment of the present application provides a diagnostic device control method, which can verify and control the diagnostic device. The diagnostic device includes an MCU and a diagnostic interface chip, the diagnostic interface chip includes an integrated circuit and a security chip, the integrated circuit is used to provide a communication connection between the MCU and the vehicle, and the security module is used to control the conduction and interruption of the integrated circuit. The security module can control the conduction and interruption of the integrated circuit through the MCU verification result and the target program verification result.

[0032] The method for the security module to verify the MCU includes: the MCU communicates with the security chip, the security chip sends the first data, the MCU encrypts the first data by a public key to obtain the second data, the MCU sends the second data, the security chip decrypts the second data by a private key to obtain the third data, and compares the first data and the third data to verify whether they are consistent.

[0033] The method for the security module to verify the target program includes: the security chip obtains the target program information in the MCU, the target program information includes program data and a digital signature, the security chip generates a first information summary based on the program data, and compares the digital signature with the first information summary to verify the target program.

[0034] When the MCU verification passes and the target program verification passes, the security module turns on the integrated circuit and allows the MCU to communicate with the vehicle. When the MCU verification fails or the target program verification fails, the security module turns off the integrated circuit and prohibits the MCU from communicating with the vehicle to ensure vehicle safety.

[0035] The following four embodiments are used to describe the control method of the diagnostic device, the storage medium and the program product. Embodiments 1 to 3 describe a control method of a diagnostic device, and Embodiment 4 describes another control method of a diagnostic device. Among them, Embodiment 1 describes the complete process of the diagnostic device executing the control method, Embodiment 2 describes the complete process of the MCU executing the control method, and Embodiment 3 describes the complete process of the diagnostic interface chip executing the control method.

[0036] Example 1

[0037] Figure 1 1 is a flow chart of a diagnostic device control method provided by an embodiment of the present application. Figure 1 As shown, the method comprises the following steps:

[0038] S101. After the diagnosis interface chip and the MCU are powered on, the diagnosis interface chip and the MCU are connected to communicate via a first communication interface.

[0039] In an embodiment of the present application, the diagnostic interface chip includes a security chip and an integrated circuit. After the diagnostic interface chip is powered on, the security chip is in an enabled state, and the integrated circuit is in a disabled state after the security chip is powered on.

[0040] It should be noted that the integrated circuit can be in a disabled state after the security chip is powered on to prevent the MCU from communicating with the vehicle when verification has not been performed or has not passed verification, thereby affecting vehicle safety.

[0041] For example, the integrated circuit may be disabled by the security chip after the security chip is powered on, or the integrated circuit may not be powered on when the diagnostic device is powered on, so that the integrated circuit is in a disabled state.

[0042] In an embodiment of the present application, the first communication interface includes a joint test action group (JTAG) interface, a serial peripheral interface (SPI) and a universal asynchronous receiver / transmitter (UART).

[0043] The security chip is powered on, which means that the diagnostic device has just started, that is, the diagnostic device has not yet communicated with the vehicle, so the security chip can establish a connection with the MCU to verify the MCU through the connection.

[0044] Optionally, the security chip can communicate with the MCU via an SPI or UART interface.

[0045] Exemplarily, the security chip can send a communication request to the SPI (or UART) interface. After receiving the communication request, the SPI (or UART) interface can send the communication request to the MCU, and then return the MCU's response to the communication request to the security chip.

[0046] In other embodiments, the MCU may send a communication request to the SPI or UART interface, send the communication request to the security chip through the corresponding communication interface, and receive a response returned by the security chip.

[0047] Among them, SPI and UART are wired connections. The security chip and / or MCU can first detect whether the SPI and UART interfaces are connected to wires, and then communicate through the SPI or UART interface connected to the wires.

[0048] In some embodiments, the configuration of SPI and UART communication can be preset in the security chip and the MCU.

[0049] Exemplarily, the security chip detects that the SPI interface and the MCU are connected by a wire, and then sends a communication request preset for SPI communication to the SPI interface; the MCU receives the communication request, can determine a response from the SPI communication setting preset in the MCU, and then sends the response to the security chip.

[0050] In the embodiment of the present application, the security chip receives a response returned by the MCU through the first communication interface, indicating that the security chip has established a communication connection with the MCU. The security chip can send and receive data with the MCU through the communication connection.

[0051] S102. MCU sends an instruction to the security chip, and the security chip generates first data.

[0052] In an embodiment of the present application, the MCU may send a verification instruction to the security chip, where the verification instruction is used to instruct the security chip to start a verification procedure for the MCU.

[0053] In the embodiment of the present application, after generating the first data, the security chip sends the first data to the MCU through the communication connection established in the aforementioned step S101. At the same time, the security chip stores the first data for executing the verification method of the two data in the subsequent step S105.

[0054] The first data generated by the security chip is a random number, which can prevent the MCU from knowing the first data in advance and ensure the authenticity of the verification.

[0055] S103. The security chip sends the first data to the MCU. The MCU encrypts the first data using the public key to obtain the second data. The security chip obtains the second data returned by the MCU.

[0056] In the embodiment of the present application, the security chip sends the first data to the MCU through the first communication interface.

[0057] In some other embodiments, the security chip sends a verification instruction to the MCU, instructing the MCU to receive the first data generated by the security chip. After receiving a response returned by the MCU, the security chip sends the first data to the MCU.

[0058] In the embodiment of the present application, the public key stored in the MCU is an asymmetric encryption algorithm public key. Among them, data encrypted by the asymmetric encryption algorithm public key needs to be decrypted by the corresponding asymmetric encryption algorithm private key to be obtained.

[0059] Optionally, the asymmetric encryption algorithm includes an RSA encryption algorithm (RSA for short) and an SM2 encryption algorithm (SM2 for short).

[0060] Exemplarily, the MCU receives first data sent by the security chip, and encrypts the first data using an RSA public key to obtain second data.

[0061] Among them, the second data needs to be decrypted with the RSA private key corresponding to the RSA public key to obtain the first data. If the RSA private key used to decrypt the second data does not correspond to the encrypted RSA public key, decrypting the second data will obtain other data different from the first data.

[0062] In an embodiment of the present application, the MCU returns second data to the security chip through the first communication interface, and the second data is used to verify whether the public key stored in the MCU corresponds to the private key stored in the security chip.

[0063] Exemplarily, the public key can be preset in the storage space of the MCU, and the private key can be preset in the security chip. If the MCU is an original chip of the diagnostic device (such as an MCU pre-configured by the diagnostic device manufacturer), the public key stored in the MCU corresponds to the private key stored in the security chip, and the security chip can obtain the first data by decrypting the second data.

[0064] S104. The security chip decrypts the second data using the private key to obtain third data.

[0065] In the embodiment of the present application, the security chip decrypts the second data using a private key to obtain the third data.

[0066] Exemplarily, the security chip decrypts the second data using the RSA private key to obtain the third data.

[0067] The third data decrypted by the private key may be referred to as plaintext data. The security chip needs to compare the plaintext data with the random number generated in step S102 and execute step S105 to verify the MCU.

[0068] S105. The security chip verifies the MCU based on the first data and the third data.

[0069] In the embodiment of the present application, the consistency of the first data and the third data indicates that the public key in the MCU corresponds to the private key in the security chip, and the verification of the MCU passes. Conversely, the inconsistency of the first data and the third data indicates that the public key in the MCU does not correspond to the private key in the security chip, and the verification of the MCU fails.

[0070] It should be noted that if the security chip fails to decrypt the second data using the private key stored in the security chip, it means that the public key in the MCU has been tampered with, and it can be directly determined that the MCU verification has failed.

[0071] If the security chip successfully decrypts the second data using the private key stored in the security chip, the third data is obtained. In this case, if the first data is different from the third data, it means that the MCU has tampered with the first data, so it can be determined that the MCU verification has failed; if the first data is the same as the third data, it means that the MCU has not been tampered with, so it can be determined that the MCU verification has passed.

[0072] S106. The security chip obtains target program information from the MCU.

[0073] For example, the integrated circuit may be disabled by the security chip after the security chip is powered on, or the integrated circuit may not be powered on when the diagnostic device is powered on, so that the integrated circuit is in a disabled state.

[0074] The target program information is the program information that needs to be verified in the MCU.

[0075] The security chip is powered on, which means that the diagnostic device has just started, that is, the diagnostic device has not yet communicated with the vehicle, so the security chip can obtain the target program information from the MCU to verify the MCU.

[0076] Optionally, the security chip may obtain target program information from the MCU through the first communication interface.

[0077] For example, the security chip may send a program acquisition request to the first communication interface; after receiving the program acquisition request, the first communication interface may read target program information from the MCU, and then send the target program information to the security chip.

[0078] In some embodiments, the target program information may include program data and a digital signature.

[0079] The program data may be program data in the MCU. For example, the program data may be program code in the MCU.

[0080] The digital signature may be obtained by encrypting the hash value of the program data.

[0081] For example, during the production stage of the diagnostic device, for the program data in the MCU that needs to be verified when in use, the hash value of the program data can be encrypted using a security chip to obtain a digital signature, and the digital signature is stored in the MCU. In this way, after the diagnostic device leaves the factory, the program data in the MCU can be verified based on the digital signature when the diagnostic device is used subsequently.

[0082] In some embodiments, a preset storage address may be stored in the security chip, and the preset storage address is a storage address where the target program information is stored in the MCU. The security chip may obtain the target program information from the preset storage address in the MCU.

[0083] For example, the preset storage address may be set in the security chip during the production stage of the diagnostic device.

[0084] For example, the security chip can send a program acquisition request carrying a preset storage address to the first communication interface; after receiving the program acquisition request, the first communication interface can read the target program information from the preset storage address in the MCU, and then send the target program information to the security chip.

[0085] By way of example, the preset storage address may include a first storage address and a second storage address, the first storage address is used to store program data, and the second storage address is used to store a digital signature.

[0086] In this case, if the target program information obtained by the security chip includes the program data and the digital signature, it means that the complete target program information has been obtained, and the subsequent S107 step can be continued to verify the target program information; if the target program information obtained by the security chip does not include the program data and / or the digital signature, it means that the complete target program information has not been obtained, that is, the target program information in the MCU has been tampered with, so it can be directly determined that the target program information verification has failed.

[0087] S107. The security chip verifies the target program information.

[0088] Since the target program information includes a digital signature that can prove whether the program data in the MCU has been tampered with, the security chip can verify the target program information to determine whether the MCU is currently secure.

[0089] In some embodiments, the operation of step S107 may be: when the target program information includes program data and a digital signature, the security chip performs an encryption operation on the program data to obtain a first information summary. The security chip verifies the digital signature and the first information summary, for example, by decrypting the digital signature using an asymmetric encryption key, and then comparing it with the first information summary. If the digital signature and the first information summary pass the verification, it is determined that the target program information verification has passed; if the digital signature and the first information summary fail to pass the verification, it is determined that the target program information verification has failed.

[0090] Among them, if the digital signature and the first information summary verification fail, it means that the program data in the MCU has been tampered with, so it can be determined that the target program information verification has failed; if the digital signature and the first information verification pass, it means that the program data in the MCU has not been tampered with, so it can be determined that the target program information verification has passed.

[0091] In the embodiment of the present application, the security chip does not limit the order of verifying the MCU and verifying the target program information, that is, steps S106-S107 can be executed after step S101. The embodiment of the present application does not limit the specific execution order of steps S102-S105 and steps S106-S107.

[0092] S108. The security chip operates in the first mode when the target program information verification passes and the first data and the third data verification pass, and operates in the second mode when the target program information verification fails or the first data and the third data verification fails.

[0093] In the embodiment of the present application, the first mode is a mode that allows the MCU to control the integrated circuit, and the second mode is a mode that prohibits the MCU from controlling the integrated circuit.

[0094] If the MCU verification passes, it means that the program data in the MCU has not been tampered with; if the MCU verification fails, it means that the MCU is not the original MCU of the diagnostic device, or is an unauthorized MCU.

[0095] If the target program information verification passes, it means that the MCU is the original MCU of the diagnostic device; if the target program information verification fails, it means that the program data in the MCU has been tampered with.

[0096] If the MCU passes the verification and the target program information passes the verification, then when the MCU communicates with the vehicle, there will be no safety hazards to the vehicle, so the security chip can allow the MCU to use the integrated circuit.

[0097] If the MCU verification fails, or the target program information verification fails, then when the MCU communicates with the vehicle, it may bring safety hazards to the vehicle, so the security chip can prohibit the MCU from using the integrated circuit to ensure vehicle safety.

[0098] In some embodiments, when the security chip is running in the first mode, it can perform operations such as encryption, decryption, signing, signature verification, enabling or disabling integrated circuits to ensure normal use of the diagnostic device. When the security chip is running in the second mode, the use of the diagnostic device can be restricted by prohibiting the MCU from using the integrated circuit.

[0099] In the embodiment of the present application, after power-on, the security chip can send the first data to the MCU, receive the second data returned by the MCU, and verify the third data after decrypting the second data; after power-on, the security chip can also obtain the target program information in the MCU and verify the target program information. The security chip allows the MCU to use the integrated circuit if the MCU verification passes and the target program verification passes, and prohibits the MCU from using the integrated circuit if the MCU verification fails or the target program verification fails.

[0100] Based on the above method, when the MCU in the diagnostic device is unauthorized and / or the target program in the diagnostic device is tampered with, the security chip can limit the use of the diagnostic device before the MCU communicates with the vehicle, thereby improving vehicle safety.

[0101] In some embodiments, the security chip allows the MCU to use the integrated circuit, which may be that after receiving the control instruction for enabling the integrated circuit sent by the MCU, the security chip responds to the control instruction to enable the integrated circuit. The security chip prohibits the MCU from using the integrated circuit, which may be that after receiving the control instruction for enabling the integrated circuit sent by the MCU, the security chip does not respond to the control instruction, that is, does not enable the integrated circuit.

[0102] Exemplarily, when the diagnostic device is connected to the vehicle, the MCU can send a control instruction to the security chip to instruct the security chip to enable the integrated circuit; after the security chip receives the control instruction, when it is in the first mode, it can enable the integrated circuit according to the control instruction; when it is in the second mode, it can discard the control instruction to maintain the integrated circuit in a disabled state.

[0103] Figure 2 It is a schematic diagram of a diagnostic equipment module provided in an embodiment of the present application.

[0104] like Figure 2 As shown, the diagnostic device 10 may include an MCU 101 and a diagnostic interface chip 102 , wherein the diagnostic interface chip 102 may include an integrated circuit 1021 and a security module 1022 .

[0105] In the embodiment of the present application, the security module 1022 may include the aforementioned Figure 1 The security chip described above executes the Figure 1 The execution scheme of the security chip in steps S101-S108. MCU101 may belong to the aforementioned Figure 1 The MCU described in the previous section executes Figure 1 The integrated circuit 1021 may belong to the aforementioned Figure 1 The integrated circuit described in the above Figure 1Implementation scheme of the integrated circuit in steps S101-S108.

[0106] like Figure 2 As shown, MCU101 communicates with integrated circuit 1021 separately, and MCU101 also communicates with security module 1022 separately. Security module 1022 can receive data returned by MCU101 and control the communication of integrated circuit 1021. Integrated circuit 1021 can communicate with MCU101 through an internal interface, and can also communicate with the vehicle through an external interface. When integrated circuit 1021 is enabled, both the internal interface and the external interface are turned on, and MCU101 can communicate with the vehicle through integrated circuit 1021.

[0107] Exemplarily, the MCU 101 and the integrated circuit 1021 communicate using a second communication interface (such as a general-purpose input / output (GPIO) interface), and the MCU 101 and the security module 1022 communicate using a first communication interface (such as an SPI interface and a UART interface). The integrated circuit 1021 and the vehicle communicate using an on-board diagnostics (OBD) interface.

[0108] In this case, the MCU 101 and the integrated circuit 1021 may perform wired communication via the GPIO interface, and the MCU 101 and the security module 1022 may perform wired communication via the SPI interface and / or the UART interface.

[0109] Optionally, the connection interface between the MCU 101 and the security module 1022 may also include other communication interfaces. Exemplarily, the other communication interface may be a JTAG interface, a universal serial bus (USB), etc., which is not limited in the embodiment of the present application.

[0110] Specifically, the MCU 101 may communicate with the security module 1022 in the diagnostic interface chip 102 via a wired connection or a wireless connection. For example, the MCU 101 may be wiredly connected to the security module 1022 via an SPI interface and / or a UART interface.

[0111] Specifically, the MCU 101 may communicate with the integrated circuit 1021 in the diagnostic interface chip 102 via a wired connection or a wireless connection. For example, the MCU 101 may be connected to the integrated circuit 1021 via a GPIO interface.

[0112] In the embodiment of the present application, the diagnostic device 10 and the vehicle can communicate via a wired connection or a wireless connection.

[0113] Among them, MCU101 can communicate with the vehicle under the control of the diagnostic interface chip 102. The integrated circuit 1021 in the diagnostic interface chip 102 is used to provide a transceiver interface for the MCU101 to communicate with the vehicle, and is controlled by the security module 1022. The security module 1022 is used to control the switch of the transceiver in the integrated circuit 1021, thereby controlling the communication between the MCU101 and the vehicle, which is equivalent to controlling the communication between the diagnostic device 10 and the vehicle.

[0114] The integrated circuit 1021 is used to realize the communication between the MCU101 and the vehicle. Specifically, the integrated circuit 1021 can receive the communication data sent by the MCU101, convert the format of the communication data into a format recognizable by the vehicle and send it to the vehicle, and can receive the communication data sent by the vehicle, convert the format of the communication data into a format recognizable by the MCU101 and send it to the MCU101, so as to realize the communication between the MCU101 and the vehicle.

[0115] The security module 1022 is a module for implementing the security function of the diagnostic device 10. For example, the security module 1022 can be used for encryption, decryption, signing, signature verification, enabling or disabling the integrated circuit 1021, etc., which is not limited in the embodiment of the present application.

[0116] The security module 1022 may also be referred to as an encryption module. For example, the security module 1022 may be a secure element (SE) chip, or may be other modules capable of implementing security functions, which is not limited in the present embodiment of the application.

[0117] In the embodiment of the present application, the security module 1022 and the integrated circuit 1021 are integrated into the diagnostic interface chip 102, so the security module 1022 can directly enable or disable the integrated circuit 1021 inside the diagnostic interface chip 102 without being interfered by external commands. In this way, the operating safety of the diagnostic interface chip 102 can be improved.

[0118] Figure 3 It is a schematic diagram of a diagnostic device structure provided in an embodiment of the present application.

[0119] In the embodiments of the present application, Figure 3 As shown, the integrated circuit may include a first switch module, a transceiver module and a second switch module.

[0120] The first switch module may include n first switches, the transceiver module may include n transceivers, and the second switch module may include n second switches, where n is a positive integer.

[0121] The first ends of the n first switches are connected to the MCU, the second ends of the n first switches are connected one by one to the first ends of the n transceivers, the second ends of the n transceivers are connected one by one to the first ends of the n second switches, and the second ends of the n second switches are used to connect to the vehicle; the control ends of the n first switches, the control ends of the n transceivers, and the control ends of the n second switches are connected to the security chip.

[0122] The first switch module is used to control the on or off of the communication line between the MCU and the transceiver module. For example, the first switch module can be a GPIO switch circuit. Of course, the first switch module can also be other switch modules, which is not limited in the embodiment of the present application.

[0123] Each of the n first switches can control the on / off of a communication line between the MCU and one of the n transceivers.

[0124] The second switch module is used to control the on or off of the communication line between the transceiver module and the vehicle. For example, the second switch module can be an on-board diagnostics data link connector (OBD DLC) switch circuit. Of course, the second switch module can also be other switch modules, which is not limited in the embodiments of the present application.

[0125] Each of the n second switches can control the on / off of a communication line between one of the n transceivers and the vehicle.

[0126] The transceiver module is used to realize the conversion of communication data format between MCU and vehicle.

[0127] The communication protocols supported by different transceivers among the n transceivers may be different.

[0128] By way of example, the n transceivers may include one or more of a controller area network bus (CANBUS) transceiver, a K-line transceiver, a serial communication interface (SCI) transceiver, a society of automotive engineers (SAE) transceiver, a single wire (SW) CAN transceiver, etc. By way of example, the SAE transceiver may include one or more of a SAE J1708 transceiver, a SAE J1850 transceiver, etc.

[0129] The security chip is used to control each of the n first switches to be turned on or off, to control each of the n transceivers to be powered on or off, and to control each of the n second switches to be turned on or off.

[0130] In some embodiments, the operation of the integrated circuit enabled by the security chip according to the control instruction may be: the security chip controls a first switch in the first switch module to be turned on, controls a transceiver in the transceiver module to be powered on, and controls a second switch in the second switch module to be turned on according to the control instruction. In this way, the MCU can communicate with the vehicle through the turned-on first switch, the powered-on transceiver, and the turned-on second switch.

[0131] In some embodiments, the operation of the security chip disabling integrated circuit can be: the security chip controls all first switches in the first switch module to be turned off, and / or controls all transceivers in the transceiver module to be powered off, and / or controls all second switches in the second switch module to be turned off.

[0132] It should be noted that, since the transceiver module in the diagnostic device can integrate multiple different types of transceivers, compared with the diagnostic device that only includes one type of transceiver, the diagnostic device provided by the embodiment of the present application can support the diagnosis of vehicles with different communication protocol types, which can improve the usability of the diagnostic device. In addition, compared with the method of purchasing multiple diagnostic devices to diagnose different vehicles separately, the diagnostic device provided by the embodiment of the present application can also reduce the diagnostic cost.

[0133] In an embodiment of the present application, the diagnostic device includes an MCU and a diagnostic interface chip, the diagnostic interface chip includes an integrated circuit and a security chip, and the integrated circuit is used to realize communication between the MCU and the vehicle. The security chip can generate first data and send it to the MCU. The MCU encrypts the first data by a public key to obtain second data and returns it to the security chip. The security chip decrypts the second data by a private key to obtain third data, and compares the first data with the third data to verify the MCU. The security chip can also obtain target program information from the MCU, including program data and digital signatures. The security chip can obtain a first information summary based on the program data, and verify the target program information by verifying the digital signature and the first information summary.

[0134] The MCU is allowed to use the integrated circuit when the MCU verification passes and the target program information verification passes. The MCU is prohibited from using the integrated circuit when the MCU verification fails or the target program information verification fails. Since the diagnostic interface chip integrates both the security chip and the integrated circuit, the security chip can directly enable or disable the integrated circuit inside the diagnostic interface chip without being interfered with by external commands, so the operation security of the diagnostic interface chip is relatively high. In this case, when the MCU is tampered with (i.e., the MCU is not original to the manufacturer) or when the program data in the MCU is tampered with, the security chip in the diagnostic interface chip can limit the use of the diagnostic equipment by prohibiting the MCU from using the integrated circuit in the diagnostic interface chip, thereby improving vehicle safety.

[0135] It should be noted that the security chip can obtain the first information digest through encryption operations. The encryption operations may include message digest algorithm (Message-Digest Algorithm 5, MD5), SM2 and hash encryption, etc., which is not limited in the embodiments of the present application.

[0136] It should be noted that the MCU can encrypt the first data by an encryption algorithm, and the security chip can decrypt the second data by the same encryption algorithm. Exemplarily, the encryption algorithm can include an asymmetric encryption algorithm, such as RSA, SM2, etc., which is not limited in the embodiments of the present application.

[0137] Example 2

[0138] Figure 4 : is a flow chart of an MCU control method provided by an embodiment of the present application. Figure 4 As shown, the method comprises the following steps:

[0139] S201. MCU is powered on and establishes a communication connection with the diagnostic interface chip.

[0140] In the embodiment of the present application, the method for establishing communication with the diagnostic interface chip device after the MCU is powered on can refer to the aforementioned Figure 1 The step S101 will not be described in detail here.

[0141] S202. MCU sends an instruction to the security chip to obtain the first data.

[0142] In the embodiment of the present application, the MCU sends a verification instruction to the security chip in the diagnostic device through the first communication interface, and the security chip generates the first data. The execution method of the security chip can refer to the aforementioned Figure 1 Step S102 will not be described in detail here.

[0143] In an embodiment of the present application, the MCU may automatically send a verification instruction after establishing a communication connection with the security chip, and the MCU may also send a verification instruction after receiving an operation from the user.

[0144] Exemplarily, the diagnostic device receives a verification operation on the diagnostic device from a user, and instructs the MCU to send a verification instruction to the security chip.

[0145] In some implementations, the MCU stores a verification instruction. The MCU may directly obtain the verification instruction from a storage unit, or the MCU may generate the verification instruction from a verification-related program.

[0146] Optionally, the MCU stores the acquired first data in a storage unit of the MCU.

[0147] S203. The MCU encrypts the first data using the public key to obtain second data, and sends the second data to the security chip.

[0148] In the embodiment of the present application, for a specific description of encrypting the first data by the MCU to obtain the second data, please refer to the aforementioned Figure 1 Step S103 will not be described in detail here.

[0149] The second data is the ciphertext data after the first data is encrypted, and a corresponding decryption method is required to restore the encrypted first data.

[0150] Exemplarily, if the second data is ciphertext data encrypted by a public key in an asymmetric encryption algorithm, the private key corresponding to the public key is required to decrypt the first data. The public key and the private key may belong to different devices or components, respectively, and the device or component having the public key and the private key may be determined as an authentication device (i.e., an authorized device) or an authentication component (i.e., an authorized component).

[0151] Optionally, the second data acquired by the MCU may be stored in a storage unit of the MCU, and the encryption algorithm of the first data by the MCU may also be stored in the storage unit of the MCU.

[0152] In the embodiment of the present application, the MCU may return the second data to the security chip through the first communication interface as a response to the security chip sending the first data.

[0153] The security chip receives the second data, decrypts it using the stored private key to obtain the third data, and compares the third data with the first data to obtain a verification result. The specific method for the security chip to obtain the third data can be referred to in the aforementioned Figure 1 In step S104, the specific method of the security chip verifying the MCU can refer to the above Figure 1 Step S105 will not be described in detail here.

[0154] S204. The MCU receives the request from the security chip to obtain the target program information, and sends the target program information to the security chip.

[0155] In the embodiment of the present application, the target program information is stored in the MCU. The specific execution method of the MCU can refer to the aforementioned Figure 1 Step S106 will not be described in detail here.

[0156] In the embodiment of the present application, after the MCU establishes a communication connection with the security chip, it can receive a request sent by the security chip to obtain the target program information, that is, step S204 can be executed after step S201. The embodiment of the present application does not limit the specific execution order of steps S202-S203 and step S204.

[0157] S205. MCU obtains the verification result of the security chip and executes the plan corresponding to the detection result.

[0158] In the embodiment of the present application, the security chip can send the verification result to the MCU. Based on the different modes of the security chip, the MCU executes different methods.

[0159] Specifically, the security chip determines the operating mode of the MCU based on the verification result. If the security chip enters the first mode, the MCU is allowed to control the integrated circuit; if the security chip enters the second mode, the MCU is prohibited from controlling the integrated circuit. For the specific verification method of the security chip, please refer to the above Figure 1 Step S108 will not be described in detail here.

[0160] Figure 5 is a schematic diagram of an MCU unit provided in an embodiment of the present application. Figure 5 , the MCU may include an encryption unit 201 , a first storage unit 202 , and a first communication unit 203 .

[0161] Specifically, the encryption unit 201 is used to encrypt the first data acquired by the MCU. The encryption unit 201 may encrypt the first data based on an asymmetric encryption algorithm.

[0162] Exemplarily, the MCU obtains first data generated by the security chip, and the encryption unit 201 encrypts the first data using an RSA algorithm public key to obtain second data.

[0163] The first storage unit 202 is used to store the data of the MCU, wherein the data of the MCU includes the first data, the second data, the target program information and the encryption algorithm in the MCU.

[0164] The first communication unit 203 is used to communicate with the diagnosis interface chip.

[0165] The first communication unit 203 communicates with the security chip in the diagnostic interface chip through the first communication interface and communicates with the integrated circuit in the diagnostic interface chip through the second communication interface. The first communication interface includes wired communication and wireless communication, and the second communication interface includes wired communication and wireless communication.

[0166] Exemplarily, the first communication interface includes a wired communication interface such as SPI and UART, and the MCU can use SPI or UART in the first communication unit 203 to communicate with the security chip by wire. The second communication interface includes a GPIO wired communication interface, and the MCU can use GPIO in the first communication unit 203 to communicate with the integrated circuit by wire. The embodiment of the present application does not limit the specific communication method of the first communication unit 203.

[0167] In some embodiments, the MCU may further include an execution module, the execution module is based on Figure 4 The verification result obtained in step S205 is executed in the corresponding method. For example, if the security chip verification indicates the first mode, the integrated circuit is connected, and the MCU can communicate with the vehicle through the integrated circuit; if the security chip verification indicates the second mode, the integrated circuit is disconnected, and the MCU cannot communicate with the vehicle.

[0168] The specific implementation methods of the above-mentioned corresponding steps will not be described in detail in the embodiments of the present application.

[0169] It is understandable that the functional division between the units illustrated in the embodiments of the present application is only for illustrative purposes and does not constitute a limitation on the functions of the MCU. In other embodiments of the present application, the MCU may also use units different from those in the above embodiments, or a combination of multiple units to implement the functions of the MCU.

[0170] Example 3

[0171] Figure 6 1 is a flow chart of a diagnostic interface chip control method provided by an embodiment of the present application. Figure 6 As shown, the method comprises the following steps:

[0172] S301. The diagnostic interface chip is powered on and establishes a communication connection with the MCU.

[0173] In the embodiment of the present application, the diagnostic interface chip is powered on to establish communication with the MCU, and the above Figure 1 The step S101 will not be described in detail here.

[0174] S302. The diagnostic interface chip receives the instruction sent by the MCU and sends the generated first data to the MCU.

[0175] In the embodiment of the present application, the security chip in the diagnostic interface chip receives the verification instruction sent by the MCU and generates the first data. For the specific method of the security chip receiving the verification instruction of the MCU to generate the first data, please refer to the aforementioned Figure 1 Step S102 will not be described in detail here.

[0176] The MCU encrypts the received first data to obtain the second data, and executes the above Figure 1 Step S103 will not be described in detail here.

[0177] S303. The diagnostic interface chip receives the second data returned by the MCU and decrypts it using the private key to obtain the third data.

[0178] In the embodiment of the present application, the security chip stores the decryption algorithm corresponding to the MCU encryption algorithm, and the security chip can decrypt the second data by using the private key. The specific method of decrypting the security chip by using the private key to obtain the third data can refer to the aforementioned Figure 1 Step S104 will not be described in detail here.

[0179] S304. The diagnostic interface chip verifies the MCU based on the first data and the third data.

[0180] In the embodiment of the present application, the security chip verifies the MCU based on the first data and the third data. For details, please refer to the aforementioned Figure 1 Step S105 will not be described in detail here.

[0181] S305. The diagnostic interface chip obtains the target program information from the MCU and verifies the target program information.

[0182] In the embodiment of the present application, the security chip obtains the target program information from the MCU and verifies the target program information. Figure 1 Steps S106-S107 will not be described in detail here.

[0183] In the embodiment of the present application, the diagnostic interface chip does not restrict the order of verifying the MCU and verifying the target program information, that is, steps S304-S305 can be executed after step S301. The embodiment of the present application does not restrict the specific execution order of steps S302-S303 and steps S304-S305.

[0184] S306. The diagnostic interface chip operates in the first mode when the target program information verification passes and the first data and the third data verification pass; the diagnostic interface chip operates in the second mode when the target program information verification fails or the first data and the third data verification fails.

[0185] In the embodiment of the present application, the security chip verifies the MCU and the target program information, and instructs the security chip and the MCU to execute different solutions under different verification results. For details, please refer to the above Figure 1 Step S108 will not be described in detail here.

[0186] Figure 7 is a schematic diagram of a diagnostic interface chip unit provided in an embodiment of the present application. Figure 7 The diagnostic interface chip may include a decryption unit 301 , a verification unit 302 , an integrated circuit unit 303 , a second storage unit 304 and a second communication unit 305 .

[0187] Specifically, the decryption unit 301 is used to decrypt the second data acquired by the diagnosis interface chip.

[0188] The verification unit 302 is used to verify the MCU, by verifying the data before encryption and the data after decryption in the diagnostic interface chip, verifying whether the data before encryption and the data after decryption are consistent, thereby determining whether the MCU that encrypts the data is an authorized MCU. The verification unit 302 is also used to verify the target program information, calculate the first information digest for the program data in the target program information, and verify the first information digest with the digital signature in the target program information, thereby determining whether the target program information in the MCU has not been tampered with.

[0189] The integrated circuit unit 303 is used to communicate with the MCU and is controlled by the verification result of the verification unit 302. If the verification result of the verification unit 302 is that the MCU has passed the verification (that is, the MCU is an authorized MCU) and the target program information has not been tampered with, the integrated circuit unit 303 is enabled and the MCU can communicate with the vehicle through the integrated circuit unit; if the verification result of the verification unit 302 is that the MCU has not passed the verification or the target program information has been tampered with, the integrated circuit unit 303 is disabled.

[0190] The second storage unit 304 is used to store data generated, received and acquired by the diagnostic interface chip, including random numbers (first data) generated by the diagnostic interface chip, encrypted data (second data) received by the diagnostic interface chip, and data (third data) decrypted and acquired by the diagnostic interface chip. It is also used to store target program information acquired from the MCU. It is also used to store an algorithm for generating the first data, an algorithm for decrypting the second data, and an algorithm for verifying the target program information.

[0191] The second communication unit 305 is used to communicate with the MCU and also used to communicate with the vehicle.

[0192] The second communication unit 305 includes a first communication interface and a second communication interface. The security chip in the diagnostic interface chip communicates with the MCU via the first communication interface, and the integrated circuit in the diagnostic interface chip communicates with the MCU via the second communication interface. The first communication interface includes wired communication and wireless communication, and the second communication interface includes wired communication and wireless communication.

[0193] Exemplarily, the first communication interface includes wired communication such as SPI and UART, and the security chip can use SPI or UART in the second communication unit 305 to communicate with the security chip by wire. The second communication interface includes GPIO wired communication, and the integrated circuit can use GPIO in the second communication unit 305 to communicate with the MCU by wire. The embodiment of the present application does not limit the specific communication method of the second communication unit 305.

[0194] The second communication unit 305 also includes an interface for communicating with the vehicle, such as an OBD interface.

[0195] In some embodiments, the diagnostic interface chip may further include an execution module, which executes the Figure 6 The verification result obtained in step S306 is used to execute the corresponding method. For example, if the MCU verification passes, the diagnostic interface chip can enable the integrated circuit through the security chip, so that the MCU can communicate with the vehicle through the integrated circuit; if the MCU verification fails, the diagnostic interface chip can interrupt the integrated circuit through the security chip, so that the MCU cannot communicate with the vehicle.

[0196] The specific implementation methods of the above-mentioned corresponding steps will not be described in detail in the embodiments of the present application.

[0197] It is understandable that the functional division between the units illustrated in the embodiments of the present application is only for illustrative purposes and does not constitute a limitation on the functions of the diagnostic interface chip. In other embodiments of the present application, the diagnostic interface chip may also use units different from those in the above embodiments, or a combination of multiple units to implement the functions of the diagnostic interface chip.

[0198] Example 4

[0199] Figure 8 is a flow chart of another diagnostic device control method provided by an embodiment of the present application. Figure 8 As shown, the method comprises the following steps:

[0200] S401. After the diagnosis interface chip and the MCU are powered on, the diagnosis interface chip and the MCU are connected to communicate via a first communication interface.

[0201] In an embodiment of the present application, the diagnostic interface chip includes a security chip and an integrated circuit. After the diagnostic interface chip is powered on, the security chip is in an enabled state, and the integrated circuit is in a disabled state after the security chip is powered on. For a specific description of the diagnostic interface chip, reference can be made to the aforementioned step S101, which will not be repeated here.

[0202] S402. MCU sends an instruction, and the security chip generates first data.

[0203] For a specific description of the MCU instructing the security chip to generate the first data, reference may be made to the aforementioned step S102, which will not be described in detail here.

[0204] S403. The security chip sends the first data to the MCU. The MCU encrypts the first data using the public key to obtain the second data. The security chip obtains the second data returned by the MCU.

[0205] The specific description of encrypting the first data by the MCU to obtain the second data can be referred to the aforementioned step S103, which will not be described here in detail.

[0206] S404. The security chip decrypts the second data using the private key to obtain third data.

[0207] The specific description of how the security chip decrypts the second data to obtain the third data can refer to the aforementioned step S104, which will not be described in detail here.

[0208] S405. The security chip compares the first data and the third data to see if they are consistent: if they are consistent, the integrated circuit is enabled, and the security chip and the MCU enter the first mode; if they are inconsistent, the integrated circuit is disabled, and the security chip and the MCU enter the second mode.

[0209] In the embodiment of the present application, the first mode is a mode that allows the MCU to control the integrated circuit, and the second mode is a mode that prohibits the MCU from controlling the integrated circuit.

[0210] In the embodiment of the present application, the consistency of the first data and the third data indicates that the public key in the MCU corresponds to the private key in the security chip, and the verification of the MCU passes. Conversely, the inconsistency of the first data and the third data indicates that the public key in the MCU does not correspond to the private key in the security chip, and the verification of the MCU fails.

[0211] If the MCU verification passes, it means that the MCU is the original MCU of the diagnostic device, or it is an authorized MCU. Then, when the MCU communicates with the vehicle, it will not bring safety hazards to the vehicle, so the security chip can allow the MCU to use the integrated circuit; if the MCU verification fails, it means that the MCU is not the original MCU of the diagnostic device, or it is an unauthorized MCU. Then, when the MCU communicates with the vehicle, it may bring safety hazards to the vehicle, so the security chip can prohibit the MCU from using the integrated circuit to ensure vehicle safety.

[0212] In some embodiments, when the security chip is running in the first mode, it can perform operations such as encryption, decryption, signing, signature verification, enabling or disabling integrated circuits to ensure normal use of the diagnostic device. When the security chip is running in the second mode, the use of the diagnostic device can be restricted by prohibiting the MCU from using the integrated circuit.

[0213] In the embodiment of the present application, after power-on, the security chip can send the first data to the MCU, receive the second data returned by the MCU, and verify the third data after decrypting the second data. The security chip allows the MCU to use the integrated circuit if the verification passes, and prohibits the MCU from using the integrated circuit if the verification fails.

[0214] Based on the above method, when the MCU in the diagnostic device is unauthorized, the security chip can limit the use of the diagnostic device before the MCU communicates with the vehicle, thereby improving vehicle safety.

[0215] In some embodiments, the security chip allows the MCU to use the integrated circuit, which may be that after receiving the control instruction for enabling the integrated circuit sent by the MCU, the security chip responds to the control instruction to enable the integrated circuit. The security chip prohibits the MCU from using the integrated circuit, which may be that after receiving the control instruction for enabling the integrated circuit sent by the MCU, the security chip does not respond to the control instruction, that is, does not enable the integrated circuit.

[0216] Exemplarily, when the diagnostic device is connected to the vehicle, the MCU can send a control instruction to the security chip to instruct the security chip to enable the integrated circuit; after the security chip receives the control instruction, when it is in the first mode, it can enable the integrated circuit according to the control instruction; when it is in the second mode, it can discard the control instruction to maintain the integrated circuit in a disabled state.

[0217] Fig. 9A schematic diagram of the structure of a computer device provided in an embodiment of the present application. The computer device 900 includes: a processor 901, a memory 902, a communication module 904, and a computer program 903 stored in the memory 902 and executable on the processor 901. When the processor 901 executes the computer program 903, the steps in the embodiment of the vehicle ECU flashing method are implemented.

[0218] Exemplarily, the computer program 903 may be divided into one or more units / modules, and the one or more units / modules are stored in the memory 902 and executed by the processor 901 to complete the present application.

[0219] The above one or more units / modules may be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the above computer program 903 in the above computer device 900. For example, the above computer program 903 may be used to generate a random number in the diagnostic interface chip, obtain and encrypt the random number through the MCU, decrypt the random number through the diagnostic interface chip, compare the data before encryption and after decryption to see if they are consistent, determine whether the MCU is an authorized MCU, etc. It may also be used to verify target program information, and the specific functions or mechanisms have been described in the above embodiments, and will not be repeated here.

[0220] Those skilled in the art will understand that Fig. 9 It is only an example of the computer device 900 and does not constitute a limitation of the computer device 900. It may include more or fewer components than shown in the figure, or a combination of certain components, or different components. For example, the above-mentioned computer device 900 may also include input and output devices, network access devices, buses, etc.

[0221] The processor 901 may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.

[0222] In some embodiments, the processor 901 may include one or more interfaces, which may include an inter-integrated circuit (I2C) interface, a UART interface, a GPIO interface, and / or a USB interface.

[0223] It is understandable that the interface connection relationship between the modules illustrated in the embodiment of the present application is only a schematic illustration and does not constitute a structural limitation on the computer device 900. In other embodiments of the present application, the computer device 900 may also adopt different interface connection methods in the above embodiments, or a combination of multiple interface connection methods.

[0224] In some embodiments, the computer device 900 may connect internal devices and modules through one or more interfaces. For example, the computer device 900 may connect the security chip to the MCU through an SPI and / or UART interface, and may also connect the integrated circuit to the MCU through a GPIO interface. The integrated circuit may convert the GPIO interface type of the MCU into other types of interface types as an interface conversion device for connecting external devices to the MCU.

[0225] The memory 902 may be an internal storage unit of the computer device 900, such as a hard disk or a memory of the computer device 900. The memory 902 may also include both an internal storage unit of the computer device 900 and an external storage device.

[0226] The memory 902 is used to store the computer program and other programs and data required by the computer device 900. The memory 902 can also be used to temporarily store data that has been output or is to be output, for example, the memory 902 can store the first data generated by the diagnostic interface chip, the second data obtained by encrypting the first data by the MCU, the third data obtained by decrypting the second data by the diagnostic interface chip, the target program information stored in the MCU, etc. It can also store the algorithm for the diagnostic interface device to generate the first data, and the encryption algorithm for the diagnostic interface device and the MCU to perform asymmetric encryption.

[0227] The communication module 904 can provide wireless communication solutions for application on the computer device 900, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication technology (NFC), infrared technology (IR), etc.

[0228] The communication module 904 may be one or more devices integrating at least one communication processing module. The communication module 904 receives electromagnetic waves via the sky, demodulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 901 .

[0229] The communication module 904 can also receive the signal to be sent from the processor 901, modulate the frequency of the signal, amplify the signal, and convert it into electromagnetic waves for radiation through the antenna.

[0230] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the above-mentioned device can be divided into different functional units or modules to complete all or part of the functions described above.

[0231] The functional units and modules in the embodiments may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated units may be implemented in the form of hardware or in the form of software functional units.

[0232] In the embodiments of the present application, the specific names of the functional units and modules are only for the convenience of distinguishing each other and are not used to limit the scope of protection of the present application.

[0233] It should be understood that each step in the above method embodiment provided by the present application can be completed by an integrated logic circuit of hardware in a processor or by instructions in the form of software. The method steps disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware processor, or by a combination of hardware and software modules in a processor.

[0234] The present application also provides a computer program product, which includes: a computer program (also referred to as code, or instruction), which, when executed, enables a computer to execute the method executed by the vehicle inspection device in the above embodiment.

[0235] The present application also provides a computer-readable storage medium, which stores a computer program (also referred to as code or instruction). When the computer program is executed, the computer executes the method executed by the electronic device in any of the above embodiments.

[0236] The various implementation modes of the present application can be combined arbitrarily to achieve different technical effects.

[0237] In the foregoing embodiments, all or part of the embodiments may be implemented by software, hardware, firmware, or any combination thereof. When implemented by software, all or part of the embodiments may be implemented in the form of a computer program product.

[0238] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in this application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device.

[0239] The computer instructions may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, server or data center to another website, computer, server or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0240] The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state disk).

[0241] Those skilled in the art can understand that to implement all or part of the processes in the aforementioned embodiments, the processes can be completed by computer programs to instruct related hardware, and the programs can be stored in computer-readable storage media. When the programs are executed, they can include the processes in the aforementioned method embodiments. The aforementioned storage media include: ROM or random access memory RAM, magnetic disk or optical disk and other media that can store program codes.

[0242] In short, the above description is only an embodiment of the technical solution of the present invention, and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made according to the disclosure of the present invention shall be included in the protection scope of the present invention.

Claims

1. A diagnostic equipment control method, characterized in that: The diagnostic device comprises a microcontroller unit MCU, a security chip and an integrated circuit, wherein the integrated circuit is used to realize communication between the MCU and the vehicle, the security chip is used to control the MCU to use the integrated circuit, the MCU stores a public key, and the security chip stores a private key, and the method comprises: The security chip generates first data, where the first data is a random number; The security chip sends the first data to the MCU, and obtains second data returned by the MCU, where the second data is obtained by encrypting the first data by the MCU using the public key; The security chip decrypts the second data using the private key to obtain third data; The security chip verifies the first data and the third data; The security chip obtains target program information from the MCU; The security chip verifies the target program information; The security chip operates in a first mode when the target program information verification passes and the first data and the third data verification pass, and operates in a second mode when the target program information verification fails or the first data and the third data verification fails. In the first mode, the MCU is allowed to use the integrated circuit, and in the second mode, the MCU is prohibited from using the integrated circuit.

2. The method according to claim 1, characterized in that The security chip generates first data, including: After the security chip and the MCU are powered on and establish communication, the security chip receives a verification instruction sent by the MCU and generates the first data.

3. The method according to claim 1, characterized in that The public key includes an asymmetric encryption algorithm public key, the private key includes an asymmetric encryption algorithm private key, and the security chip verifies the first data and the third data, including: The security chip compares the first data with the third data; If the first data is the same as the third data, the security chip determines that the first data and the third data are verified successfully; If the first data is different from the third data, the security chip determines that the first data and the third data have failed verification.

4. The method according to claim 1, characterized in that The security chip obtains target program information from the MCU, including: The security chip obtains target program information from the MCU after power-on; wherein the integrated circuit is in a disabled state after the security chip is powered on.

5. The method according to claim 4, characterized in that The security chip verifies the target program information, including: The security chip performs encryption operation on the program data to obtain a first information summary when the target program information includes program data and a digital signature; The security chip verifies the digital signature and the first information digest; If the digital signature and the first information digest pass verification, the security chip determines that the target program information verification passes; If the digital signature and the first information digest fail to pass the verification, the security chip determines that the target program information fails to pass the verification.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: The MCU sends a control instruction to the security chip when the diagnostic device is connected to the vehicle, wherein the control instruction is used to instruct to enable the integrated circuit; After receiving the control instruction, the security chip enables the integrated circuit according to the control instruction when in the first mode; and discards the control instruction to maintain the integrated circuit in a disabled state when in the second mode.

7. The method according to claim 6, characterized in that The integrated circuit includes a first switch module, a transceiver module, and a second switch module. The security chip enables the integrated circuit according to the control instruction, including: The security chip controls a first switch in the first switch module to be turned on according to the control instruction, controls a transceiver in the transceiver module to be powered on, and controls a second switch in the second switch module to be turned on.

8. A diagnostic equipment control method, characterized in that: The diagnostic device comprises a microcontroller unit MCU, a security chip and an integrated circuit, wherein the integrated circuit is used to realize communication between the MCU and the vehicle, the security chip is used to control the MCU to use the integrated circuit, the MCU stores a public key, and the security chip stores a private key, and the method comprises: The security chip generates first data, where the first data is a random number; The security chip sends the first data to the MCU, and obtains second data returned by the MCU, where the second data is obtained by encrypting the first data by the MCU using the public key; The security chip decrypts the second data using the private key to obtain third data; The security chip verifies the first data and the third data; The security chip operates in a first mode when the first data and the third data are verified successfully, and operates in a second mode when the first data and the third data are not verified successfully. In the first mode, the MCU is allowed to use the integrated circuit, and in the second mode, the MCU is prohibited from using the integrated circuit.

9. A computer-readable storage medium having computer instructions stored thereon, characterized in that: When the computer instructions are executed by a processor, the method of any one of claims 1 to 7 or claim 8 is implemented.

10. A computer device comprising a memory, a processor and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the method of any one of claims 1 to 7 or claim 8.

Citation Information

Patent Citations

  • Vehicle control unit of electric vehicle, vehicle and method

    CN108536045A

  • Communication method of vehicle diagnosis equipment and vehicle diagnosis equipment

    CN110011809A

  • Vehicle-mounted diagnostic system firmware protection method and system

    CN113138775A

  • Authentication method and device of vehicle diagnosis equipment, electronic equipment and medium

    CN114513310A

  • Remote diagnosis control system, method and device and electric vehicle

    CN114675616A