JTAG port encryption method and system for BMS production line

By using a network security server in the BMS production line to generate and manage dynamic JTAG passwords, and write and lock the JTAG port on the BMS motherboard, the problem of insufficient dynamic key management and encryption control of the JTAG encryption protection solution in the prior art is solved, and high-security JTAG port protection and data transmission security are achieved.

CN119945667APending Publication Date: 2025-05-06NINGBO PREH JOYSON AUTOMOTIVE ELECTRONICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411905568.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing JTAG encryption protection solution cannot achieve dynamic and flexible key management and encryption control on the production line, and its security is insufficient, and the security during data transmission is difficult to ensure.

Method used

The JTAG password is generated through a network security server based on the Secure Debug ID read from the device by the EOL station, and the PBKDF algorithm is used to combine dynamic salt values ​​to generate a dynamic JTAG password. The HTTPS protocol is used to transmit data, and the JTAG port is written and locked on the BMS motherboard.

Benefits of technology

It improves the attack resistance of the JTAG debug port, ensures the security of data transmission, enhances the security of JTAG key management, prevents unauthorized JTAG access, and ensures the security of debugging of the product after leaving the factory.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945667A_ABST
    Figure CN119945667A_ABST
Patent Text Reader

Abstract

The invention provides a BMS production line JTAG port encryption method and system, and the method comprises the steps: S1, a network security server generates a JTAG password according to a Secure Debug ID read from equipment by an EOL station, and transmits the JTAG password back to the EOL station; and S2, the EOL station writes the data containing the JTAG password into the equipment, and locks the JTAG port of the equipment. The JTAG password generated by combining the dynamic salt value and using the PBKDF algorithm is higher in security, and the anti-attack capability of the JTAG debugging port is improved. And the security of data transmission is ensured by adopting an HTTPS protocol, and data leakage is effectively avoided. According to the enhanced multi-layer key management method, single-point leakage is effectively avoided, and the security of JTAG key management is improved. And an adopted production line locking mechanism effectively prevents unauthorized JTAG access, and ensures debugging safety after the product leaves the factory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a BMS production line encryption JTAG port method and system. Background Art

[0002] At present, there is an increasing demand for security protection of the debug port (Joint Test Action Group, JTAG) in the BMS (Battery Management System) battery management system to prevent unauthorized access and debugging behavior from posing a threat to the system, especially at the end-of-line (EOL) stage, where encryption protection of the JTAG port is more meaningful. In the prior art, access to the JTAG port is usually restricted by setting a static password or physical lock, but these solutions lack dynamism and advanced key management, making it difficult to provide highly customized security management and easy to be cracked, mainly manifested in:

[0003] 1. The existing JTAG encryption protection solution cannot achieve dynamic and flexible key management and encryption control of the production line, and its security is insufficient;

[0004] 2. The security of data during transmission is difficult to guarantee, and there is a risk of being intercepted or tampered with. Summary of the invention

[0005] The present invention aims to strengthen the dynamic key management and encryption control of the production line JTAG port and improve the security of production line data transmission, and provides a BMS production line JTAG port encryption method and system.

[0006] To achieve this object, the present invention adopts the following technical solutions:

[0007] A method for encrypting a JTAG port of a BMS production line is provided, comprising the steps of:

[0008] S1, the network security server generates a JTAG password according to the Secure Debug ID read from the device by the EOL station, and transmits it back to the EOL station;

[0009] S2, the EOL station writes data including the JTAG password into the device and locks the JTAG port of the device.

[0010] Preferably, the device is a BMS mainboard; the EOL station sends the read Secure Debug ID to the network security server via the HTTPS protocol; and the network security server returns the JTAG password to the EOL station via HTTPS.

[0011] Preferably, the method for generating the JTAG password comprises the steps of:

[0012] A1, concatenate the Secure Debug ID and Project ID of the device to obtain the device initialization;

[0013] A2, generates a dynamic salt value based on the current timestamp, Secure Debug ID and Project ID;

[0014] A3, using the PBKDF algorithm to generate the JTAG password according to the initial password and the dynamic salt value.

[0015] Preferably, in step A2, the method for generating the dynamic salt value comprises the steps of:

[0016] A21, obtains the current timestamp and concatenates it with the Secure Debug ID and Project ID to obtain the input data for the dynamic salt value generation algorithm;

[0017] A22, generating the dynamic salt value of fixed length by using a hash algorithm on the input data, the specific method is as follows:

[0018] DynamicSalt=Hash(Secure Debug ID∥Project ID∥Timestamp)

[0019] Wherein: DynamicSalt represents the dynamic salt value;

[0020] Hash represents a hash algorithm, which is used to generate a salt value of fixed length;

[0021] Timestamp represents the current timestamp;

[0022] “∥” indicates the string concatenation operation.

[0023] The dynamic salt value is generated by performing hash processing on the concatenated data of SecureDebugID, ProjectID and Timestamp.

[0024] Preferably, in step A3, the method for generating the JTAG password according to the salt value using the PBKDF algorithm comprises the steps of:

[0025] A31, setting PBKDF algorithm parameters, including the number of iterations, the JTAG password length, and a translation table, wherein the translation table is used to translate the output of the PBKDF algorithm into the readable JTAG password;

[0026] A32, inputting the initial password and the dynamic salt value into the PBKDF algorithm, the PBKDF algorithm combines the dynamic salt value, the initial password and the translation table, and performs multiple iterations by adjusting parameters, and finally outputs the JTAG password that meets the iteration termination condition, the specific process is as follows:

[0027] JTAGPassword = PBKDF (InitialPassword, DynamicSalt, Iterations, PasswordLength), the binary result output by the PBKDF algorithm is converted into character form through a translation table to form the final password;

[0028] JTAGPassword represents the JTAG password;

[0029] InitialPassword indicates the initial password of the device:

[0030] It is composed of the chip identification code (Secure Debug ID) and the project identification code (Project ID), ensuring that the password is device unique and project independent;

[0031] DynamicSalt indicates a dynamic salt value:

[0032] A unique value generated by combining the chip identification code, project identification code and current timestamp is used to prevent duplicate password generation and enhance security;

[0033] Iterations indicates the number of iterations:

[0034] The number of iterations of the PBKDF2 algorithm is used to increase the computational complexity of the generated password and improve the anti-cracking ability; it is set to 1000 times here;

[0035] PasswordLength represents the length of the JTAG password;

[0036] The iteration termination condition is that the PBKDF algorithm iteration meets a preset number of iterations.

[0037] Preferably, the network security server divides the JTAG password into segments and stores them in different security modules. The network security server divides the JTAG password into segments and stores them in different security modules. When the current network state is a secure connection state of https type, and the current time meets the set time period and the network access permission is met, the network security server forms the segmented keys distributed in each of the security modules into a complete JTAG password and transmits it back to the EOL station.

[0038] Preferably, in step S2, the EOL station writes the JTAG password into the UCB_DBG_ORIG field in the UCB configuration block of the BMS mainboard.

[0039] Preferably, in step S1, the Secure Debug ID read by the EOL station is written into a one-time programmable memory OTP of the BMS mainboard.

[0040] The present invention also provides a system for encrypting the JTAG port of a BMS production line, which can implement the method for encrypting the JTAG port of a BMS production line, and includes a network security server and an EOL station. The network security server generates a JTAG password according to the Secure Debug ID read from the device by the EOL station, and returns the password to the EOL station; the EOL station writes data containing the JTAG password into the device and locks the JTAG port of the device.

[0041] The BMS production line encryption JTAG port method provided in this application has the following beneficial effects:

[0042] 1. The JTAG password generated by combining dynamic salt value and PBKDF algorithm is more secure and improves the anti-attack capability of JTAG debugging port.

[0043] 2. Use HTTPS protocol to ensure the security of transmitted data and effectively avoid data leakage.

[0044] 3. The enhanced multi-layer key management method effectively avoids single point leakage and improves the security of JTAG key management.

[0045] 4. The production line locking mechanism adopted effectively prevents unauthorized JTAG access and ensures the debugging safety of the product after leaving the factory.

[0046] 5. Combine the unique code of the device chip and the project identification code to generate a unique and traceable initial password, ensuring the encryption feature of "one device, one key", enhancing the traceability of security incidents, and facilitating subsequent management and problem location. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention, and for ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0048] Figure 1 It is a diagram of the implementation steps of the BMS production line encryption JTAG port method provided by an embodiment of the present invention;

[0049] Figure 2 Schematic diagram of the system structure of the BMS production line encrypted JTAG port provided in this embodiment. DETAILED DESCRIPTION

[0050] The technical solution of the present invention is further described below with reference to the accompanying drawings and through specific implementation methods.

[0051] Among them, the drawings are only used for illustrative explanations, and they only represent schematic diagrams rather than actual pictures, and should not be understood as limitations on this patent; in order to better illustrate the embodiments of the present invention, some parts of the drawings may be omitted, enlarged or reduced, and do not represent the size of the actual product; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the drawings may be omitted.

[0052] The same or similar numbers in the drawings of the embodiments of the present invention correspond to the same or similar parts; in the description of the present invention, it should be understood that if the terms "upper", "lower", "left", "right", "inner", "outer", etc. appear, the orientation or position relationship indicated is based on the orientation or position relationship shown in the drawings, which is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, the terms describing the position relationship in the drawings are only used for illustrative purposes and cannot be understood as a limitation on this patent. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to specific circumstances.

[0053] In the description of the present invention, unless otherwise clearly specified and limited, if the term "connection" or the like appears to indicate the connection relationship between components, the term should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, it can be the internal connection of two components or the interaction relationship between two components. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0054] The BMS production line encryption JTAG port method provided in this embodiment connects the BMS mainboard to the enterprise's internal network security server (Preh Cybersecurity Server, PCSS) and uses multi-layer key management, dynamic password generation, and data backup and recovery mechanisms to ensure the security of the JTAG port. The specific solution includes: using the PBKDF (Password-Based Key Derivation Function) algorithm to generate a dynamic JTAG password; transmitting the JTAG password to the EOL station through the HTTPS security protocol, writing and locking it on the BMS mainboard, and realizing comprehensive protection of dynamic encryption and JTAG port locking.

[0055] In order to increase security and flexibility, the present application specifically introduces the following innovations:

[0056] 1. Dynamic encryption and interface locking mechanism. At the EOL stage, a unique dynamic password associated with the ECU ID (ECU code) of the vehicle's electronic control unit (ECU) is generated and written through the JTAG port. Each ECU has its own encryption protection. This dynamic password is directly bound to the unique Secure Debug ID of the BMS motherboard (chip identification code, and the JTAG port is locked immediately after writing to ensure that debugging access can only be performed in a controlled environment). This strategy implements unique encryption protection for each ECU to prevent unauthorized access or tampering after leaving the factory, thereby significantly improving product security.

[0057] 2. Intelligent key generation algorithm. By combining the improved PBKDF algorithm with the dynamic salt value mechanism, the randomness of the JTAG password is increased and the anti-cracking ability is improved. The PBKDF parameters are adaptively adjusted based on historical data, which further improves the security of the JTAG password and ensures that the generated JTAG password is unique and difficult to infer.

[0058] 3. Dynamic segmented key management mechanism. Use the network security server (PCSS) for distributed key management. Through multi-level segmented storage and dynamic retrieval strategies, the keys are dispersedly stored in different security modules. The keys can only be fully accessed when specific network status and permissions are met, effectively reducing the risk of single point leakage.

[0059] 4. Multi-level data verification and recovery mechanism. A data backup mechanism is set up during the data writing process, which can quickly recover when a writing error occurs to ensure the integrity and reliability of the written data. This mechanism greatly reduces the risk of writing failures that may occur during the debugging process through automated detection and data recovery, and improves the stability of the system.

[0060] The following is a detailed description of the BMS production line encryption JTAG port method provided in this embodiment:

[0061] The BMS production line encrypted JTAG system provided in this embodiment includes: BMS mainboard, network security server and EOL station at the end of the production line, and ensures the security of the JTAG port through multiple encryption and identity authentication processes to prevent unauthorized debugging or access. The entire process includes multiple steps such as Secure Debug ID reading, JTAG password generation and writing, data locking and storage.

[0062] 1. Secure Debug ID reading and JTAG password generation

[0063] 1.1 Reading Secure Debug ID

[0064] During the production process, the EOL station first reads the Secure Debug ID from the BMS motherboard through the JTAG port. This ID is the unique identifier of each BMS motherboard and is used for subsequent JTAG password generation and identity verification.

[0065] 1.2Secure Debug ID Transmission

[0066] The EOL station sends the read Secure Debug ID to the network security server (PCSS) via the HTTPS protocol. The HTTPS protocol ensures the integrity of the data during transmission and avoids man-in-the-middle attacks and data interception.

[0067] 1.3JTAG password generation

[0068] After receiving the Secure Debug ID, the network security server uses the improved PBKDF (Password-BasedKey Derivation Function) algorithm to generate the JTAG password. The generation process is as follows:

[0069] Input parameters: PCSS takes Secure Debug ID and device initial password (generated by Secure Debug ID (chip identification code) and Project ID (project identification code)) as input. The device initial password is generated as follows:

[0070] A11, get the chip identification code and project identification code:

[0071] Chip identification code (Secure Debug ID): Extracts a unique identifier from the chip hardware to ensure device uniqueness.

[0072] Project Identification Code (ProjectID): Define a unique identifier for each project to ensure the independence of different projects.

[0073] A12, generate the initial password:

[0074] Combine the chip identification code and project identification code obtained in step A11 to generate an initial password. This password will serve as the basic input of the PBKDF algorithm in subsequent steps to ensure that the password uniquely identifies each project and device.

[0075] PBKDF processing: The PBKDF algorithm performs multiple iterative calculations on the input parameters and combines the dynamic salt value mechanism to generate the JTAG password to ensure the uniqueness and security of the password.

[0076] In this embodiment, a dynamic salt value change mechanism is added based on the PBKDF algorithm. First, a dynamic salt value is generated based on the unique hardware feature chip identification code (Secure Debug ID) and project identification code (Project ID) of the device, so that the JTAG password generation is more random, thereby enhancing the anti-attack ability of the JTAG password. In this way, even if an attacker obtains some cryptographic information, it is difficult to make repeated guesses or reproduce. The method for generating a dynamic salt value based on the unique hardware feature chip identification code and project identification code of the device specifically includes the following steps:

[0077] A21, get timestamp;

[0078] Get the current timestamp and combine it with the chip identification code and the project identification code to obtain the input data of the dynamic salt value generation algorithm. The method of combining the current timestamp with the chip identification code and the project identification code is as follows: . . . .

[0079] DynamicSalt=Hash(SecureDebugID∥ProjectID∥Timestamp)

[0080] in:

[0081] Hash: The hash algorithm is used to generate a salt value of fixed length.

[0082] SecureDebugID: Unique identifier of the chip, ensuring the uniqueness of the device.

[0083] ProjectID: The unique identifier of the project, ensuring the independence of the project.

[0084] Timestamp: The current timestamp (for example, UTC seconds or milliseconds).

[0085] ∥: indicates the string concatenation operation.

[0086] A dynamic and unpredictable salt value is generated by hashing the concatenated data of SecureDebugID, ProjectID, and Timestamp.

[0087] A22, generate dynamic salt value:

[0088] The data in step A21 is used to generate a dynamic salt value of fixed length through a hash algorithm to ensure that each generated salt value is unique and difficult to predict. To further improve security, the salt value is stored in segments and managed in multiple storage areas. Each salt value segment uses a different generation method and storage solution, making the salt value difficult to recover and predict.

[0089] After the dynamic salt value is generated, the PBKDF parameters are adjusted according to the historical data to generate the JTAG password. The generation method specifically includes the following steps:

[0090] A31, set PBKDF algorithm parameters:

[0091] Iterations: Define the number of iterations at project start, with a minimum setting of 10,000 to ensure the computational strength of the password generation process.

[0092] Password length: Set the password length according to project requirements to meet the security needs of different devices.

[0093] Translation table: defines a mapping table from binary values ​​to letters AZ, az, 0-9 and special characters (such as - and _) for converting PBKDF output into readable passwords.

[0094] A32, enter the dynamic salt value and initial password:

[0095] Dynamic salt value: The dynamic salt value generated by combining steps A21 and A22.

[0096] Initial password: Generate the initial password of the device based on the Secure Debug ID and Project ID of the device to ensure that the password generated for each project is unique and isolated.

[0097] A33, generate JTAG password:

[0098] The dynamic salt value, initial password, and translation table are combined through the PBKDF algorithm, and the parameters are adjusted for multiple iterations to output a JTAG password that meets the requirements.

[0099] A34, cleaning after short-term use:

[0100] After the JTAG password is generated and delivered, the locally stored dynamic salt value, intermediate data, and password are immediately cleaned to reduce the risk of data leakage.

[0101] 1.4 Enhanced Key Management Method

[0102] In this embodiment, by adopting a dynamic segmented key storage mechanism in the PCSS server, the segmented keys are stored in different security modules in a dispersed manner, or a distributed key management system is adopted, so that the complete key can be accessed only when meeting specific network status and permissions, thereby avoiding the risk of single point leakage and further improving the confidentiality of the JTAG password.

[0103] 1.5JTAG password transmission

[0104] The generated JTAG password is sent back to the EOL station via the HTTPS protocol to ensure that the JTAG password is not stolen or tampered with during transmission.

[0105] 2. Data writing and locking

[0106] 2.1 Write Secure Debug ID and checksum CRC

[0107] After receiving the JTAG password, the EOL station writes the Secure Debug ID and CRC (CyclicRedundancy Check) into the OTP (One-Time Programmable) of the BMS mainboard through the JTAG port. The OTP memory cannot be changed after the data is written, ensuring the uniqueness and non-tamperability of the Secure Debug ID.

[0108] 2.2BMS motherboard burning HEX file

[0109] After writing the Secure Debug ID and CRC, the EOL station burns the entire firmware (HEX file) to the BMS mainboard. All the information that constitutes the entire firmware, including all BMS programs and key data such as the JTAG password and UCB (user configuration block, where the password is written), is written into the storage area of ​​the BMS mainboard to ensure that the BMS mainboard functions normally.

[0110] 2.3 Multi-level data verification and recovery mechanism

[0111] During the data writing process, the system will first encrypt and back up the data to a secure storage area so that the data can be quickly restored if an error occurs during the writing process. This multi-level data verification and recovery mechanism improves data integrity and reliability and ensures the stability of system operation.

[0112] 2.4JTAG password writing and locking

[0113] After data verification, the EOL station writes the generated JTAG password to the UCB_DBG_ORIG field in the UCB configuration block of the BMS mainboard through the JTAG port. This field is only used for permission control of the debug interface to ensure the security of the debug function. After writing, the EOL station performs the above-mentioned "read-check consistency" operation again to ensure that the JTAG password is written correctly.

[0114] 2.5JTAG interface lock

[0115] Once the JTAG password is written successfully, the EOL station will lock the JTAG port so that the JTAG port can only be accessed under authorized conditions, ensuring that the BMS motherboard will not be illegally accessed or modified after leaving the factory.

[0116] 3. Storage and key management

[0117] 3.1BMS motherboard data storage and locking

[0118] The Secure Debug ID and JTAG password on the BMS motherboard are locked after being written into the OTP and UCB configuration blocks, respectively, ensuring that these sensitive data cannot be tampered with or reconfigured. The one-time write feature of the OTP memory ensures the uniqueness of the BMS motherboard and the security of the debug interface.

[0119] 3.2 Key Management

[0120] The PCSS network security server uses a multi-level segmented storage and dynamic retrieval mechanism, combined with a distributed key management system, to ensure that the JTAG password is only accessible under specific network conditions. The system key used to generate the Secure Debug ID and JTAG password is stored in the PCSS and is not directly exposed to the BMS motherboard or EOL station. This key management strategy further improves the security of the system and ensures the uniqueness and non-replicability of the key. In the process of generating the JTAG password, the PCSS uses the PBKDU algorithm combined with dynamic salt value processing to make the JTAG password derivation process more secure.

[0121] 4 System connection and control logic

[0122] 4.1 Device Connection

[0123] The system of the BMS production line encryption JTAG port provided in this embodiment is as follows: Figure 2 As shown in the figure, the BMS motherboard is connected to the EOL station through the JTAG port. The EOL station communicates with the PCSS through the HTTPS protocol to ensure the security and integrity of data transmission. The PCSS generates a unique JTAG password through the PBKDF algorithm and a dynamic salt value, which can be securely transmitted to the EOL station through HTTPS.

[0124] 4.2 Control Flow

[0125] The whole process control is as follows:

[0126] Step 1: The EOL station reads the Secure Debug ID on the BMS mainboard.

[0127] Step 2: The EOL station sends the Secure Debug ID to the PCSS via HTTPS.

[0128] Step 3: After receiving the Second Debug ID, the PCSS generates a unique JTAG password for the BMS motherboard.

[0129] Step 4: PCSS sends the JTAG password back to the EOL station via HTTPS.

[0130] Step 5: After receiving the JTAG password, the EOL station writes it, the Secure Debug ID, the check code CRC, etc. to the BMS mainboard.

[0131] Step 6: The EOL station performs data burning, verification and JTAG locking to ensure the uniqueness and irreversibility of the BMS motherboard debugging interface.

[0132] In short, the BMS production line encryption JTAG port method provided in this embodiment is as follows: Figure 1 Said, comprising the steps of:

[0133] S1, the network security server generates a JTAG password based on the Secure Debug ID read from the device by the EOL station and sends it back to the EOL station;

[0134] S2, the EOL station writes data containing the JTAG password into the device and locks the JTAG port of the device.

[0135] In summary, the BMS production line encryption JTAG port method provided in this embodiment has the following beneficial effects:

[0136] 1. The JTAG password generated by combining dynamic salt value and PBKDF algorithm is more secure and improves the anti-attack capability of JTAG debugging port.

[0137] 2. Use HTTPS protocol to ensure the security of transmitted data and effectively avoid data leakage.

[0138] 3. The enhanced multi-layer key management method effectively avoids single point leakage and improves the security of JTAG key management.

[0139] 4. The production line locking mechanism adopted effectively prevents unauthorized JTAG access and ensures the debugging safety of the product after leaving the factory.

[0140] It should be noted that the above specific implementations are only preferred embodiments of the present invention and the technical principles used. Those skilled in the art should understand that various modifications, equivalent substitutions, changes, etc. can be made to the present invention. However, as long as these changes do not deviate from the spirit of the present invention, they should be within the scope of protection of the present invention. In addition, some terms used in the specification and claims of this application are not restrictive, but are only for the convenience of description.

Claims

1. A method for encrypting JTAG ports in a BMS production line, characterized in that: Includes steps: S1, the network security server generates a JTAG password according to the Secure Debug ID read from the device by the EOL station, and transmits it back to the EOL station; S2, the EOL station writes data including the JTAG password into the device and locks the JTAG port of the device.

2. The BMS production line encryption JTAG port method according to claim 1, characterized in that: The device is a BMS mainboard; the EOL station sends the read Secure Debug ID to the network security server through the HTTPS protocol; the network security server returns the JTAG password to the EOL station through HTTPS.

3. The BMS production line encryption JTAG port method according to claim 1, characterized in that: The method for generating the JTAG password comprises the steps of: A1, concatenate the Secure Debug ID and Project ID of the device to obtain the device initial password; A2, generates a dynamic salt value based on the current timestamp, Secure Debug ID and Project ID; A3, using the PBKDF algorithm to generate the JTAG password according to the initial password and the dynamic salt value.

4. The BMS production line encryption JTAG port method according to claim 3 is characterized in that: In step A2, the method for generating the dynamic salt value comprises the steps of: A21, obtains the current timestamp and concatenates it with the Secure Debug ID and Project ID to obtain the input data for the dynamic salt value generation algorithm; A22, generating the dynamic salt value of fixed length by using a hash algorithm on the input data, the specific method is as follows: DynamicSalt=Hash(Secure Debug ID∥Project ID∥Timestamp) Wherein: DynamicSalt represents the dynamic salt value; Hash represents a hash algorithm, which is used to generate a salt value of fixed length; Timestamp represents the current timestamp; "∥" indicates the string concatenation operation. The dynamic salt value is generated by performing hash processing on the concatenated data of SecureDebugID, ProjectID and Timestamp.

5. The BMS production line encryption JTAG port method according to claim 3, characterized in that: In step A3, the method of generating the JTAG password according to the salt value using the PBKDF algorithm includes the following steps: A31, setting PBKDF algorithm parameters, including the number of iterations, the JTAG password length, and a translation table, wherein the translation table is used to translate the output of the PBKDF algorithm into the readable JTAG password; A32, inputting the initial password and the dynamic salt value into the PBKDF algorithm, the PBKDF algorithm combines the dynamic salt value, the initial password and the translation table, and performs multiple iterations by adjusting parameters, and finally outputs the JTAG password that meets the iteration termination condition, the specific process is as follows: JTAGPassword = PBKDF (InitialPassword, DynamicSalt, Iterations, PasswordLength), the binary result output by the PBKDF algorithm is converted into character form through a translation table to form the final password; JTAGPassword represents the JTAG password; InitialPassword represents the initial password of the device; DynamicSalt represents the dynamic salt value; Iterations indicates the number of iterations; PasswordLength represents the length of the JTAG password; The iteration termination condition is that the PBKDF algorithm iteration meets a preset number of iterations.

6. The BMS production line encryption JTAG port method according to claim 1, characterized in that: The network security server segments the JTAG password and stores it in different security modules. The network security server segments the JTAG password and stores it in different security modules. When the current network state is a secure connection state of https type, and the current time meets the set time period and meets the network access permission, the network security server forms the segmented keys distributed in each of the security modules into a complete JTAG password and transmits it back to the EOL station.

7. The BMS production line encryption JTAG port method according to claim 1, characterized in that: In step S2, the EOL station writes the JTAG password into the UCB_DBG_ORIG field in the UCB configuration block of the BMS mainboard.

8. The BMS production line encryption JTAG port method according to claim 1, characterized in that: In step S1, the Secure Debug ID read by the EOL station is written into the one-time programmable memory OTP of the BMS mainboard.

9. A system for encrypting JTAG ports of a BMS production line, which can implement the method for encrypting JTAG ports of a BMS production line as described in any one of claims 1 to 8, characterized in that: The invention comprises a network security server and an EOL station. The network security server generates a JTAG password according to the Secure Debug ID read from the device by the EOL station and transmits the password back to the EOL station. The EOL station writes data containing the JTAG password into the device and locks the JTAG port of the device.