Intelligent networked automobile software offline upgrading method and device based on TPM (Trusted Platform Module) firmware
By using TPM firmware for upgrade package verification and access-end identity authentication during the offline software upgrade of intelligent connected vehicles, and conducting comprehensive functions and performance evaluation, the problems of upgrade package credibility and integrity guarantee, identity authentication and evaluation in the existing technology are solved, and higher software upgrade security and integrity are achieved.
Patent Information
- Application Number
- CN202411971868.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing software offline upgrade methods have shortcomings in terms of credibility and integrity guarantee of the upgrade package, identity authentication of the offline upgrade access terminal, and functional and performance evaluation after the upgrade, resulting in the failure to detect security risks and potential defects in a timely manner.
The intelligent connected car software offline upgrade method based on TPM firmware is adopted to obtain and verify the upgrade package through TPM firmware to ensure that the source of the upgrade package is trustworthy and the content is complete; strictly authenticate the access end; conduct comprehensive functional testing and performance evaluation after the upgrade, and record the security audit log.
It improves the integrity and security of software upgrades, ensures that the source of the upgrade package is trustworthy and the content is complete, enhances the identity authentication capabilities of the access end, and promptly detects potential software defects or security vulnerabilities.
Smart Images

Figure CN119938095A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method and device for offline upgrading of intelligent network-connected vehicle software based on TPM firmware. Background Art
[0002] The existing offline software upgrade methods mainly include downloading legal upgrade packages, transmitting them to the vehicle system offline, executing the upgrade, verifying the integrity of the upgrade, verifying whether the upgrade is successful, and recording and other related operations. However, the current offline software upgrade methods have shortcomings in many aspects, mainly reflected in the lack of credibility and integrity assurance of the upgrade package, the lack of strict verification of the source and the integrity check of the content, resulting in forged or tampered upgrade packages being incorrectly deployed to the system, thus bringing serious security risks. At the same time, the identity authentication measures for the offline upgrade access end are relatively weak, and unauthorized devices can easily access the system, further exacerbating security risks. In addition, after the upgrade is completed, it usually only relies on simple version number checks or surface verifications, lacking comprehensive functionality and performance evaluations. This method cannot detect potential software defects or security vulnerabilities in a timely manner. Summary of the invention
[0003] In view of this, the main purpose of the embodiments of the present invention is to provide a method and device for offline upgrading of intelligent connected vehicle software based on TPM firmware, in order to solve at least one of the problems of the prior art. The present invention can improve the integrity and security of software upgrades.
[0004] To achieve the above-mentioned purpose, an embodiment of the present invention provides a method for offline upgrading of intelligent connected vehicle software based on TPM firmware, the method comprising:
[0005] Obtain the target upgrade package through TPM firmware;
[0006] Verifying the target upgrade package through the TPM firmware to obtain an upgrade package verification result;
[0007] When the upgrade package verification result is successful, writing the target upgrade package into a storage device of the vehicle system to obtain the target vehicle software;
[0008] The target vehicle software is tested and a test result report is generated.
[0009] In some embodiments, a method for offline upgrading of intelligent connected vehicle software based on TPM firmware further includes:
[0010] By means of the TPM firmware, key events are recorded and a security audit log is generated;
[0011] Check the version of the TPM firmware and upgrade the TPM firmware.
[0012] In some embodiments, obtaining the target upgrade package through the TPM firmware includes the following steps:
[0013] obtaining first software content;
[0014] Performing hash calculation on the first software content to obtain a first hash value;
[0015] Signing the first hash value by using the storage root key of the TPM firmware to obtain a digital signature;
[0016] Obtaining an initial upgrade package according to the first software content, the first hash value and the digital signature;
[0017] Establishing an encrypted communication channel through the TPM firmware;
[0018] The initial upgrade package is transmitted to the access terminal through the encrypted communication channel to obtain the target upgrade package.
[0019] In some embodiments, transmitting the initial upgrade package to the access terminal through the encrypted communication channel to obtain the target upgrade package includes the following steps:
[0020] Extracting identity information from the request of the access terminal through the TPM firmware;
[0021] Verifying the identity information through the TPM firmware to obtain an identity authentication result;
[0022] When the identity authentication result is successful, transmitting the initial upgrade package to the access terminal to obtain the target upgrade package;
[0023] When the identity authentication result is a verification failure, the request to transmit the initial upgrade package to the access terminal is rejected and an error message is returned.
[0024] In some embodiments, the verifying the target upgrade package by the TPM firmware to obtain the upgrade package verification result includes the following steps:
[0025] Extracting target information of the target upgrade package; the target information includes the second software content and the digital signature;
[0026] Performing hash calculation on the second software content to obtain a second hash value;
[0027] The digital signature is verified through the TPM firmware, and the second hash value is compared with the first hash value to obtain the upgrade package verification result.
[0028] In some embodiments, when the upgrade package verification result is successful, writing the target upgrade package into a storage device of a vehicle system to obtain the target vehicle software comprises the following steps:
[0029] When the upgrade package verification result is successful, the TPM firmware is used to verify whether the state of the vehicle system meets the safety conditions. If the state of the vehicle system meets the safety conditions, the target upgrade package is written to the storage device of the vehicle system to obtain the target vehicle software.
[0030] In some embodiments, the detecting the target vehicle software and generating a detection result report comprises the following steps:
[0031] Testing the function of the target vehicle software through the TPM firmware to obtain a test result;
[0032] By means of the vehicle system, the performance of the target vehicle software is evaluated to obtain an evaluation result;
[0033] The test result report is generated according to the test result and the evaluation result.
[0034] To achieve the above object, another aspect of an embodiment of the present invention provides a device for offline upgrading software of an intelligent connected vehicle based on TPM firmware, the device comprising:
[0035] The first module is used to obtain the target upgrade package through the TPM firmware;
[0036] The second module is used to verify the target upgrade package through the TPM firmware to obtain an upgrade package verification result;
[0037] The third module is used to write the target upgrade package into the storage device of the vehicle system to obtain the target vehicle software when the upgrade package verification result is successful.
[0038] The fourth module is used to detect the target vehicle software and generate a detection result report.
[0039] To achieve the above-mentioned purpose, another aspect of an embodiment of the present invention provides an electronic device, which includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the aforementioned TPM firmware-based smart connected vehicle software offline upgrade method.
[0040] To achieve the above-mentioned purpose, another aspect of an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned TPM firmware-based intelligent connected vehicle software offline upgrade method.
[0041] To achieve the above-mentioned purpose, another aspect of the embodiment of the present invention provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device can read the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the aforementioned TPM firmware-based intelligent connected vehicle software offline upgrade method.
[0042] The embodiments of the present invention include at least the following beneficial effects: the present invention provides a method and device for offline upgrading of intelligent network-connected vehicle software based on TPM firmware, which obtains a target upgrade package through TPM firmware; verifies the target upgrade package through the TPM firmware to obtain an upgrade package verification result; when the upgrade package verification result is successful, writes the target upgrade package into a storage device of the vehicle system to obtain the target vehicle software; and detects the target vehicle software to generate a test result report. Based on TPM firmware, the present invention can ensure that the source of the upgrade package is credible and the content is complete, prevents forgery or tampering from the source, and improves the integrity and security of software upgrades. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0044] Figure 1 is a flow chart of a method for offline upgrading of intelligent connected vehicle software based on TPM firmware provided by an embodiment of the present invention;
[0045] Figure 2 It is a schematic diagram of an optional implementation process of offline upgrade of intelligent network-connected vehicle software based on TPM firmware provided by an embodiment of the present invention;
[0046] Figure 3 It is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the embodiments of the present invention, and they are only examples of devices and methods consistent with some aspects of the embodiments of the present invention as detailed in the attached claims.
[0048] It should be noted that, although the functional modules are divided in the system schematic diagram and the logical order is shown in the flow chart, in some cases, the steps shown or described may be performed in a different order than the module division in the system or the flow chart. The terms "first / S100" and "second / S200" in the specification and claims and the above-mentioned drawings may be used to describe various concepts in this article, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiment of the present invention, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determination".
[0049] The terms "at least one", "multiple", "each", "any", etc. used in the present invention, at least one includes one, two or more, multiple includes two or more, each refers to each of the corresponding multiple, and any refers to any one of the multiple.
[0050] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which the present invention belongs. The terms used herein are only for the purpose of describing the embodiments of the present invention and are not intended to limit the present invention.
[0051] Before describing the embodiments of the present invention in detail, some nouns and terms involved in the embodiments of the present invention are first described. The nouns and terms involved in the embodiments of the present invention are subject to the following explanations.
[0052] A security chip refers to a security chip that complies with the TPM standard. It can effectively protect the PC and prevent illegal users from accessing it.
[0053] Trusted Platform Module (TPM) is a hardware security module defined by the International Organization for Standardization (ISO). It is usually integrated into a computer motherboard or dedicated hardware to provide hardware-level encryption and data protection. The basic functions of TPM include:
[0054] (1) Key storage and management: TPM can store sensitive information such as encryption keys, certificates, and passwords. This information will not be exposed to the external environment, ensuring that the keys cannot be stolen or tampered with.
[0055] (2) Encryption and decryption operations: The hardware encryption function provided by TPM can efficiently perform operations such as symmetric or asymmetric encryption, digital signatures, and hash operations.
[0056] (3) Platform authentication: TPM can be used to generate a unique identity identifier (ID) for the device and bind it to the device’s firmware and operating system to ensure the security of firmware upgrades.
[0057] The Storage Root Key (SRK) is a non-exportable key inside the TPM that is used to encrypt or sign other data.
[0058] The current offline software upgrade method has deficiencies in many aspects, mainly reflected in the lack of credibility and integrity protection of the upgrade package, the lack of strict verification of the source and the integrity check of the content, resulting in the possibility that forged or tampered upgrade packages may be mistakenly deployed to the system, thus bringing serious security risks. At the same time, the identity authentication measures for the offline upgrade access end are relatively weak, and unauthorized devices can easily access the system, further exacerbating the security risks. In addition, after the upgrade is completed, it usually only relies on simple version number checks or surface verifications, lacking comprehensive functionality and performance evaluations. This method cannot timely discover potential software defects or security vulnerabilities. The existing offline software upgrade method cannot provide full-process security protection from upgrade package generation, transmission, verification to installation, and there is a possibility that a single link can be exploited by attackers. More importantly, the existing technology lacks detailed security audit log records and credibility guarantees, making it difficult to trace the specific behavior and status of the upgrade process after a problem occurs. At the same time, its ability to respond to new threats is also insufficient, and it cannot be flexibly adjusted to solve dynamically changing attack methods.
[0059] In view of this, if Figure 1 As shown, an embodiment of the present invention provides a method for offline upgrading of intelligent network-connected vehicle software based on TPM firmware, which may include but is not limited to steps S100 to S400:
[0060] Step S100, obtaining a target upgrade package through the TPM firmware;
[0061] Step S200, verifying the target upgrade package through the TPM firmware to obtain an upgrade package verification result;
[0062] Step S300, when the upgrade package verification result is successful, writing the target upgrade package into a storage device of the vehicle system to obtain the target vehicle software;
[0063] Step S400, testing the target vehicle software and generating a test result report.
[0064] In some embodiments, step S100 may include but is not limited to steps S110 to S160:
[0065] Step S110, obtaining first software content;
[0066] Step S120, performing hash calculation on the first software content to obtain a first hash value;
[0067] Step S130, signing the first hash value by using the storage root key of the TPM firmware to obtain a digital signature;
[0068] Step S140, obtaining an initial upgrade package according to the first software content, the first hash value and the digital signature;
[0069] Step S150, establishing an encrypted communication channel through the TPM firmware;
[0070] Step S160: transmitting the initial upgrade package to the access terminal through the encrypted communication channel to obtain the target upgrade package.
[0071] In steps S110 to S140 of some embodiments, the required upgrade package is prepared, that is, the initial upgrade package is obtained, wherein the initial upgrade package includes new software content, version information, a hash value of the new software content, and a digital signature. Exemplarily, the required first software content is obtained, and the hash value of the first software content is calculated to obtain a first hash value. The TPM firmware uses the storage root key (Storage Root Key, SRK) to sign the first hash value (which may include version information and the first software content summary), and the signature generated by the TPM firmware can be used to verify whether the source of the upgrade package is credible. In addition, the signature is executed internally by the TPM, and the key has never been exposed, which can effectively prevent the forged signature. Through the trusted execution environment (Trusted Execution Environment, TEE) provided by the TPM, the operating environment security of the upgrade package generation and signing process can be ensured. By using the storage root key of the TPM to digitally sign the upgrade package, the integrity of the software content and signature information can be ensured. The TPM firmware can ensure the credibility of the source of the upgrade package by verifying the version information and source credentials during the generation of the upgrade package. In addition, the TPM firmware securely stores the upgrade package content and signature information to prevent it from being tampered with during transmission or storage.
[0072] In steps S150 to S160 of some embodiments, the encryption function (such as the transport layer security protocol) based on the certificate storage of the TPM firmware is used to establish an encrypted communication channel to ensure data security during the transmission process and prevent middleman attacks, tampering and data leakage. The initial upgrade package is transmitted to the vehicle access terminal through the established encrypted communication channel. During the transmission process, the TPM firmware can also monitor the integrity of the upgrade package and detect possible tampering by verifying the hash value.
[0073] In some embodiments, step S160 may include but is not limited to steps S161 to S164:
[0074] Step S161, extracting identity information from the request of the access terminal through the TPM firmware;
[0075] Step S162, verifying the identity information through the TPM firmware to obtain an identity authentication result;
[0076] Step S163, when the identity authentication result is successful, transmitting the initial upgrade package to the access terminal to obtain the target upgrade package;
[0077] Step S164: When the identity authentication result is a verification failure, the request to transmit the initial upgrade package to the access terminal is rejected and an error message is returned.
[0078] In steps S161 to S164 of some embodiments, after the vehicle receives the transmission request of the initial upgrade package, the TPM firmware will authenticate the access terminal of the vehicle. Only authenticated devices can interact with the vehicle, and the TPM will check whether the identity information of the access terminal of the vehicle matches the preset security policy. Exemplarily, the identity information is extracted from the request of the access terminal through the TPM firmware, wherein the identity information may include device ID, device type, device public key, certificate chain, etc. The extracted identity information is compared and verified with the preset security policy through the TPM firmware, and the TPM firmware will verify whether the identity information of the access terminal is within the allowed range, and then generate an identity authentication result. When the identity authentication result is successful, the access terminal is allowed to interact with the vehicle subsequently, and the vehicle receives the initial upgrade package transmitted by the access terminal and obtains the target upgrade package. When the identity authentication result is a verification failure, the request of the access terminal to transmit the initial upgrade package is rejected, and the reason for the failure is recorded (such as device ID mismatch, certificate invalidity, etc.). At the same time, the identity authentication result is fed back to the access terminal. Among them, the preset security policies include a list of allowed device IDs, a whitelist of device types, a trust chain of device public keys, etc.
[0079] It should be noted that the initial upgrade package can also be called the target upgrade package. Similarly, the target upgrade package can also be called the initial upgrade package. Here, the terms "initial" and "target" are only used to distinguish the upgrade packages in different transmission and processing processes.
[0080] In some embodiments, during the process of identity information verification, the TPM combines the measured boot (MeasuredBoot) function to verify whether the operating environment of the access terminal is credible to ensure the security of the interaction process. And the anti-hammer function of TPM is used to limit the number of authentication failures, and enter the locked state after exceeding the set threshold to prevent brute force attacks. Optionally, in the TPM 2.0 anti-hammer function, there are clearly defined behaviors, and the default setting is to lock after 32 failed attempts, and automatically forget a failure every 10 minutes. After more than 32 failures, the TPM enters a locked state, and the lock lasts for 10 minutes. When the system is running normally, the lock will be gradually released, but the lock state will not be reset when the system is shut down or in sleep. The system administrator can immediately reset the anti-hammer protection through the TPM owner password.
[0081] In some embodiments, step S200 may include but is not limited to steps S210 to S230:
[0082] Step S210, extracting target information of the target upgrade package; the target information includes the second software content and the digital signature;
[0083] Step S220, performing hash calculation on the second software content to obtain a second hash value;
[0084] Step S230: Verify the digital signature through the TPM firmware, and compare the second hash value with the first hash value to obtain the upgrade package verification result.
[0085] In steps S210 to S230 of some embodiments, before installing the target upgrade package, the TPM firmware will perform integrity and signature verification on the upgrade package. The TPM firmware will check the digital signature of the target upgrade package to ensure that it has not been tampered with and is from a trusted publisher. Exemplarily, relevant information is extracted from the received target upgrade package, which may include the second software content, digital signature, version information, publisher certificate, etc. in the target upgrade package. At the same time, a hash calculation is performed on the second software content to obtain a second hash value. Through the TPM firmware, the digital signature is verified using the public key to check whether the digital signature is valid to ensure that the upgrade package has not been tampered with. And the TPM firmware will compare the expected hash value (Expected Hash Value) with the actual calculated hash value (Calculated Hash Value), that is, compare the first hash value with the second hash value, to implement an integrity check on the content of the upgrade package to ensure the integrity of the content of the upgrade package. The verification result of the upgrade package can be obtained. If the verification result of the upgrade package is successful, the verification program allows the software installation process to continue; if the verification result of the upgrade package is a verification failure, the verification program will reject the installation request and record the failure reason (such as invalid signature, integrity check failure, etc.). At the same time, the verification program will feedback the verification result of the upgrade package to the access end, and the access end will decide whether to continue the subsequent operation (such as retrying the installation or terminating the operation) based on the feedback result.
[0086] In step S300 of some embodiments, before the installation begins, the TPM firmware also needs to verify whether the state of the vehicle system meets the security conditions bound to the upgrade package to ensure that the installation operation is performed only in a trusted environment. Exemplarily, when the upgrade package verification result is successful, the TPM firmware verifies whether the state of the vehicle system meets the security conditions bound to the upgrade package. When the state of the vehicle system meets the security conditions, the software installation process is started. In this process, the target upgrade package is written to the storage device of the vehicle system, and the installation process is monitored in real time by the TPM firmware during the writing process, and the success and failure information of each writing step is recorded. If an abnormality is detected (such as tampering, data mismatch, etc.), the installation operation is terminated immediately to ensure the integrity of the writing operation and the software installation process.
[0087] In some embodiments, step S400 may include but is not limited to steps S410 to S430:
[0088] Step S410, testing the function of the target vehicle software through the TPM firmware to obtain a test result;
[0089] Step S420, evaluating the performance of the target vehicle software through the vehicle system to obtain an evaluation result;
[0090] Step S430: Generate the test result report according to the test result and the evaluation result.
[0091] In steps S410 to S430 of some embodiments, after the target vehicle software is installed, the TPM firmware will execute a self-test program to verify the running state of the new software, including a comprehensive test of the software functions to ensure that it meets the expected performance standards. Exemplarily, after the target vehicle software is installed, the TPM provides a trusted execution environment (Trusted Execution Environment, TEE) independent of the operating system, in which the self-test program is started, the self-test code or logic is run, and the running state of the target vehicle software is verified. In the process of self-test, the functional test and performance evaluation of the target vehicle software are included, and the test results (Test Results) of the functional test and the evaluation results (Performance Evaluation) of the performance evaluation are obtained respectively. According to the obtained test results and evaluation results, the self-test program generates a test result report. Among them, the content of the test result report includes test results, evaluation results, and any problems found (Issues Found). Then the self-test program feeds back the test result report to the access terminal, and the access terminal decides whether to continue to use the target vehicle software or further troubleshoot according to the feedback results.
[0092] In some embodiments, a method for offline upgrading of intelligent connected vehicle software based on TPM firmware may further include steps S500 to S600:
[0093] Step S500, recording key events and generating a security audit log through the TPM firmware;
[0094] Step S600, checking the version of the TPM firmware and upgrading the TPM firmware.
[0095] In step S500 of some embodiments, during the entire upgrade process, the TPM firmware will record all key events and status information, including the receipt, verification, installation, test results of functional tests, and evaluation results of performance evaluation of the upgrade package, and generate a security audit log. The TPM firmware uses the approval key to sign and protect the security audit log to ensure that the content of the security audit log is credible and cannot be tampered with. In addition, the TPM firmware can provide a trusted log report to support remote servers or system administrators to audit and verify the upgrade process.
[0096] In step S600 of some embodiments, the system periodically checks the TPM firmware version to ensure that the TPM firmware can cope with the latest security threats. The TPM firmware dynamically adjusts key management, signature verification, and anti-hammer protection strategies according to new threats to ensure that system security keeps pace with the times.
[0097] refer to Figure 2 , Figure 2 An optional implementation process of offline upgrade of intelligent connected vehicle software based on TPM firmware provided by an embodiment of the present invention is illustrated as follows:
[0098] Step S1: Preparation stage
[0099] operate:
[0100] 1) Prepare the upgrade package, including: new software content, version information, hash value, and digital signature;
[0101] 2) TPM uses the storage root key to digitally sign the upgrade package.
[0102] Output: A complete package containing the upgrade package content, signature information, version information, and hash value.
[0103] Step S2: Transmission phase
[0104] operate:
[0105] 1) Establish a secure channel such as TLS (Transport Layer Security Protocol) to ensure transmission encryption;
[0106] 2) Use TPM to verify certificates and protect communication channels;
[0107] 3) Safely transmit the upgrade package to the vehicle access terminal.
[0108] Output: The upgrade package is complete and arrives safely at the access end.
[0109] Note: Monitor data integrity in real time during transmission to prevent tampering.
[0110] Step S3: Access point authentication
[0111] S31. Extracting identity information
[0112] Operation: The TPM extracts identity information from the access point's request.
[0113] Parameters: The extracted identity information includes: Device ID, Device Type, Device Public Key, and Certificate Chain.
[0114] S32. Verify identity information
[0115] Action: The TPM compares the extracted identity information with the preset security policy.
[0116] Parameters: The preset security policies include: allowed device ID list, whitelist of device types, trust chain of device public keys, etc.
[0117] S33. Authentication results
[0118] Action: The TPM generates an authentication result.
[0119] The returned parameters include: verification status (success / failure), failure reason (such as device ID mismatch, invalid certificate, etc.), etc.
[0120] Function: If the verification is successful, the access point is allowed to interact with the vehicle in the future; if the verification fails, the access point's request is rejected and the reason for the failure is recorded.
[0121] S34, feedback to the access end
[0122] Action: Feedback the verification result to the access end.
[0123] Step S4: Upgrade package verification
[0124] S41. Extract upgrade package information
[0125] Action: Extract relevant information from the received upgrade package.
[0126] Parameters: The extracted upgrade package information includes: upgrade package content, digital signature, version information, and publisher certificate.
[0127] S42. Verify digital signature
[0128] Operation: The TPM firmware verifies the digital signature using the public key.
[0129] Parameters: The parameters required for verification include: the publisher's public key, the extracted digital signature, and the hash value of the upgrade package content.
[0130] Function: The TPM firmware checks whether the digital signature is valid to ensure that the upgrade package has not been tampered with.
[0131] S43. Check integrity
[0132] Action: The TPM firmware performs an integrity check on the contents of the upgrade package.
[0133] Parameters: The parameters required for integrity check include: expected hash value (Expected Hash Value), actual calculated hash value (Calculated Hash Value).
[0134] Function: The TPM firmware compares the expected hash value with the actually calculated hash value to ensure the integrity of the upgrade package content.
[0135] S44, verification result generation
[0136] Action: Generate upgrade package verification results.
[0137] Parameters: The returned parameters include: verification status (success / failure), failure reason (such as invalid signature, integrity check failure, etc.).
[0138] Function: If verification succeeds, the verification program allows the software installation to proceed; if verification fails, the verification program rejects the installation request and records the reason for the failure.
[0139] S45, feedback to the access end
[0140] Operation: The verification program feeds back the verification result to the access end.
[0141] Parameters: The feedback parameters include: verification status and related error information.
[0142] Function: The access end decides whether to continue subsequent operations (such as retrying the installation or terminating the operation) based on the feedback results.
[0143] Step S5: Software Installation
[0144] After verification, the software installation process will be started. This process includes writing the new software to the vehicle's storage device, and the TPM firmware monitors the installation status in real time during the writing process, records the success and failure information of each writing step, and immediately terminates the installation operation if an abnormality is detected (such as tampering, data mismatch, etc.) to ensure the integrity of the writing operation.
[0145] Step S6: Self-check after upgrading
[0146] S61, start the self-test program
[0147] Operation: The TPM can provide a trusted execution environment independent of the operating system, in which self-test programs are started, self-test code or logic is run, and the running status of new software is verified.
[0148] The parameters required to start the self-test include: new software version information, which is used to confirm whether the currently running software meets the expected version for the upgrade; self-test configuration file, including customized self-test logic, test scope, priority and performance evaluation indicators.
[0149] Function: TPM firmware provides a trusted execution environment, loads and verifies self-test configuration, and initializes functional testing.
[0150] S62, perform functional test
[0151] Principle: TPM can store and protect sensitive data related to upgrades (such as configuration files or key function status). During the self-check process, these protected data are read through the sealing and unsealing mechanism to verify whether the new software meets the expected conditions.
[0152] Operation: TPM tests the functions of new software. The sealing mechanism of TPM binds specific keys or data to a specific system state (such as software version). During the self-test process, TPM can confirm whether the software state is consistent with the binding conditions by unsealing the data.
[0153] The parameters required for the test include:
[0154] 1) Sealed data: version information of the new software, configuration files or initialization data of the new software, specific functional status or key attributes of the new software (such as function switch status).
[0155] 2) Current system status: Read the platform configuration register (PCR) of the TPM to obtain the measurement value of the current software version (such as hash value) and the real-time measurement of the current operating status (such as performance data) for comparison with the expected conditions bound to the sealed data. The TPM confirms whether the system environment is in a trusted state through measurement values and real-time measurements.
[0156] 3) Functional test cases: Specific test steps and expected results for new software functions, used to verify whether the various functions of the new software are operating normally.
[0157] S63, Performance Evaluation
[0158] Operation: The vehicle self-test program evaluates the performance of the new software. TPM can encrypt and store this data to prevent the obtained performance data from being tampered with.
[0159] The parameters required for evaluation include: performance metrics (such as response time, processing speed, etc.) and load testing conditions.
[0160] Function: The TPM firmware records performance data and compares it to expected standards, which prevents the performance data from being tampered with.
[0161] S64, Generate self-test report
[0162] Action: The self-test program generates a report of the self-test results.
[0163] The report includes: test results (Test Results), performance evaluation (PerformanceEvaluation), and any issues found (Issues Found).
[0164] Function: The self-check report provides a basis for subsequent maintenance and problem solving.
[0165] S65, feedback to the access end
[0166] Operation: The self-test program feeds back the self-test results to the access end.
[0167] The feedback parameters may include: self-test status (success / failure) and related error information.
[0168] Function: The access end decides whether to continue using the new software or conduct further troubleshooting based on the feedback results.
[0169] Step S7: Security audit log recording
[0170] During the entire upgrade process, the TPM firmware will record all key events and status information, including the receipt, verification, installation and self-test results of the upgrade package, and generate a security audit log to provide a reliable basis for problem tracing and subsequent analysis.
[0171] Step S8: Continuously update and adapt to new threats
[0172] The TPM firmware has the ability to be continuously updated. The system will regularly check the version of the TPM firmware and upgrade it as needed to ensure that it can meet new security challenges.
[0173] The embodiment of the present invention further provides a device for offline upgrading of intelligent network-connected vehicle software based on TPM firmware, which can implement the above-mentioned method for offline upgrading of intelligent network-connected vehicle software based on TPM firmware. The device includes:
[0174] The first module is used to obtain the target upgrade package through the TPM firmware;
[0175] The second module is used to verify the target upgrade package through the TPM firmware to obtain an upgrade package verification result;
[0176] The third module is used to write the target upgrade package into the storage device of the vehicle system to obtain the target vehicle software when the upgrade package verification result is successful.
[0177] The fourth module is used to detect the target vehicle software and generate a detection result report.
[0178] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0179] The embodiment of the present invention further provides an electronic device, which includes a processor and a memory, wherein the memory stores a computer program, and when the processor executes the computer program, the above-mentioned method for offline upgrading of intelligent networked vehicle software based on TPM firmware is implemented. The electronic device can be any intelligent terminal including a tablet computer, a vehicle-mounted computer, etc.
[0180] It can be understood that the contents of the above method embodiments are all applicable to the present device embodiments, the functions specifically implemented by the present device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0181] refer to Figure 3 , Figure 3 The hardware structure of an electronic device of another embodiment is illustrated, and the electronic device includes:
[0182] The processor 701 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present invention.
[0183] The memory 702 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 702 can store an operating system and other applications. When the technical solution provided in the embodiment of this specification is implemented by software or firmware, the relevant program code is stored in the memory 702, and the processor 701 calls and executes the offline upgrade method of the intelligent networked vehicle software based on TPM firmware of the embodiment of the present invention;
[0184] Input / output interface 703, used to implement information input and output;
[0185] Communication interface 704, used to realize communication interaction between the device and other devices, which can be realized through wired mode (such as USB, network cable, etc.) or wireless mode (such as mobile network, WIFI, Bluetooth, etc.);
[0186] A bus 705 that transmits information between the various components of the device (e.g., the processor 701, the memory 702, the input / output interface 703, and the communication interface 704);
[0187] The processor 701 , the memory 702 , the input / output interface 703 and the communication interface 704 are connected to each other in communication within the device via a bus 705 .
[0188] An embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned TPM firmware-based intelligent connected vehicle software offline upgrade method.
[0189] It can be understood that the contents of the above method embodiments are all applicable to the present storage medium embodiments, the functions specifically implemented by the present storage medium embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0190] The embodiment of the present invention also provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. The processor of the computer device can read the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the aforementioned TPM firmware-based intelligent networked vehicle software offline upgrade method.
[0191] In summary, the TPM firmware-based intelligent connected vehicle software offline upgrade method and device according to the embodiment of the present invention has the following advantages:
[0192] 1. The embodiment of the present invention uses the key management function of TPM to generate a digital signature in the preparation stage, and combines the trusted execution environment (TEE) to ensure the security of the operating environment of the upgrade package generation and signing process. TPM uses the storage root key (SRK) to sign the hash value and version information of the upgrade package to ensure the integrity of the software content and signature information and prevent tampering and forgery. In addition, TPM encrypts and stores the content and signature information of the upgrade package to prevent it from being tampered with during transmission or storage. This improves the credibility and integrity of the upgrade package.
[0193] 2. The embodiment of the present invention uses the trusted execution environment (TEE) provided by TPM to ensure security and credibility throughout the entire process of upgrade package generation, transmission, verification, installation and post-upgrade self-checking. In each stage, through TPM's real-time monitoring, hash verification, digital signature verification and sealing and unsealing mechanisms, it is ensured that the upgrade package and software operations are executed under trusted conditions, thus achieving a highly reliable upgrade process throughout the entire process.
[0194] 3. The TPM firmware of the embodiment of the present invention combines digital signature, key management, secure storage and trusted root functions to strictly verify the upgrade package during the transmission and installation stages. It automatically detects forged or tampered upgrade packages. If tampering or data abnormality is detected, the TPM firmware terminates the operation and records the event, reducing the need for manual intervention, significantly improving the overall security of intelligent connected vehicles, and enhancing the detection capabilities of forgery and tampering.
[0195] 4. In the access end authentication phase, the embodiment of the present invention extracts identity information such as device ID, public key, and certificate chain through TPM, matches it with the preset security policy, and strengthens identity authentication. The anti-hammer function of TPM limits the number of identity authentication failures, and combines the measured boot function to verify the credibility of the access end operating environment, ensuring that only authenticated devices can interact with the vehicle, thereby strengthening the authentication mechanism of the access end.
[0196] 5. In the post-upgrade self-check phase, the embodiment of the present invention uses the sealing and unsealing mechanism of TPM to bind the baseline data with the current system status, and performs functional testing and performance evaluation through the self-check program to verify whether the new software meets the expected requirements. TPM provides an isolated TEE to execute the self-check logic and encrypts and stores the test data to ensure that the self-check process is credible and the results are tamper-proof, which improves the verification after the upgrade.
[0197] 6. In the security audit phase of the embodiment of the present invention, the TPM firmware records all key events from receiving the upgrade package to completing the self-test, including verification, installation, and performance test results, forming a detailed security audit log. The TPM uses the approved key to sign the log to ensure the log's credibility and non-tamperability, support remote servers or system administrators to verify and trace the upgrade process, and provide security audit and traceability capabilities.
[0198] 7. In the continuous update stage of the embodiment of the present invention, the system regularly checks the TPM firmware version and adapts to new threats by dynamically adjusting strategies (such as key management and signature verification), thereby ensuring continuous improvement of vehicle safety and functionality and enhancing the ability to adapt to new threats.
[0199] In some selectable embodiments, the function / operation mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the function / operation involved, the two boxes shown in succession can actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiment presented and described in the flow chart of the present invention is provided by way of example, for the purpose of providing a more comprehensive understanding of technology. The disclosed method is not limited to the operation and logic flow presented herein. Selectable embodiments are expected, wherein the order of various operations is changed and the sub-operation of a part for which is described as a larger operation is performed independently.
[0200] In addition, although the present invention is described in the context of functional modules, it should be understood that, unless otherwise specified, one or more of the functions and / or features described may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is unnecessary for understanding the present invention. More specifically, in view of the properties, functions, and internal relationships of the various functional modules in the device disclosed herein, the actual implementation of the module will be understood within the conventional skills of the engineer. Therefore, those skilled in the art can implement the present invention set forth in the claims without excessive experimentation using ordinary techniques. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present invention, which is determined by the full scope of the appended claims and their equivalents.
[0201] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc., which can store program codes.
[0202] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.
[0203] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.
[0204] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0205] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0206] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
[0207] The above is a specific description of the preferred implementation of the present invention, but the present invention is not limited to the described embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present invention. These equivalent modifications or substitutions are all included in the scope defined by the claims of the present invention.
Claims
1. An offline upgrade method for intelligent connected vehicle software based on TPM firmware, characterized in that: The following steps are involved: Obtain the target upgrade package through TPM firmware; Verifying the target upgrade package through the TPM firmware to obtain an upgrade package verification result; When the upgrade package verification result is successful, writing the target upgrade package into a storage device of the vehicle system to obtain the target vehicle software; The target vehicle software is tested and a test result report is generated.
2. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 1, characterized in that: The following steps are also included: By means of the TPM firmware, key events are recorded and a security audit log is generated; Check the version of the TPM firmware and upgrade the TPM firmware.
3. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 1, characterized in that: The step of obtaining the target upgrade package through the TPM firmware includes the following steps: obtaining first software content; Performing hash calculation on the first software content to obtain a first hash value; Signing the first hash value by using the storage root key of the TPM firmware to obtain a digital signature; Obtaining an initial upgrade package according to the first software content, the first hash value and the digital signature; Establishing an encrypted communication channel through the TPM firmware; The initial upgrade package is transmitted to the access terminal through the encrypted communication channel to obtain the target upgrade package.
4. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 3, characterized in that: The method of transmitting the initial upgrade package to the access terminal through the encrypted communication channel to obtain the target upgrade package includes the following steps: Extracting identity information from the request of the access terminal through the TPM firmware; Verifying the identity information through the TPM firmware to obtain an identity authentication result; When the identity authentication result is successful, transmitting the initial upgrade package to the access terminal to obtain the target upgrade package; When the identity authentication result is a verification failure, the request to transmit the initial upgrade package to the access terminal is rejected and an error message is returned.
5. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 3, characterized in that: The method of verifying the target upgrade package by the TPM firmware to obtain an upgrade package verification result includes the following steps: Extracting target information of the target upgrade package; the target information includes the second software content and the digital signature; Performing hash calculation on the second software content to obtain a second hash value; The digital signature is verified through the TPM firmware, and the second hash value is compared with the first hash value to obtain the upgrade package verification result.
6. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 1, characterized in that: When the upgrade package verification result is successful, writing the target upgrade package into a storage device of the vehicle system, Obtaining the target vehicle software includes the following steps: When the upgrade package verification result is successful, the TPM firmware is used to verify whether the state of the vehicle system meets the safety conditions. If the state of the vehicle system meets the safety conditions, the target upgrade package is written to the storage device of the vehicle system to obtain the target vehicle software.
7. The method for offline upgrading of intelligent connected vehicle software based on TPM firmware according to claim 1, characterized in that: The step of testing the target vehicle software and generating a test result report comprises the following steps: Testing the function of the target vehicle software through the TPM firmware to obtain a test result; By means of the vehicle system, the performance of the target vehicle software is evaluated to obtain an evaluation result; The test result report is generated according to the test result and the evaluation result.
8. An offline upgrade device for intelligent connected vehicle software based on TPM firmware, characterized in that: include: The first module is used to obtain the target upgrade package through the TPM firmware; The second module is used to verify the target upgrade package through the TPM firmware to obtain an upgrade package verification result; The third module is used to write the target upgrade package into the storage device of the vehicle system to obtain the target vehicle software when the upgrade package verification result is successful. The fourth module is used to detect the target vehicle software and generate a detection result report.
9. An electronic device, characterized in that: including a processor and a memory; The memory is used to store programs; The processor executes the program to implement the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The storage medium stores a program, and the program is executed by a processor to implement the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
A processing method of embedded system firmware and a related device
CN109271189A
Construction method of vehicle OTA upgrade security mechanism
CN116707819A
Vehicle security upgrading method and system
CN116909603A
Vehicle ECU upgrading method, device, medium, equipment and system
CN117648105A
Vehicle OTA upgrading method and device, electronic equipment and storage medium
CN117707574A
Cited By
Method and system for encrypting and isolating storage data of credential mobile terminal
CN121365414A