Vehicle anti-theft authentication method and vehicle
By designing a dual verification mechanism between the central controller, regional controller and key in new energy vehicles, the problem of the anti-theft system of new energy vehicles is damaged and the safety of the vehicle is improved.
Patent Information
- Application Number
- CN202510288888.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-11
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-11
AI Technical Summary
During the modification process of new energy vehicles, the anti-theft system is destroyed, resulting in the inability to realize the learning and certification process in the anti-theft process, reducing the safety of the vehicle.
Design a vehicle anti-theft authentication method, and generates anti-theft authentication success information through two-factor verification between the central controller, the regional controller and the key. Specific steps include obtaining encrypted data and keys, detecting their consistency, and generating authentication success information when they are consistent.
The two-factor verification vehicle anti-theft authentication method improves the safety of new energy vehicles and ensures the success of the vehicle's learning and certification process in the anti-theft authentication process.
Smart Images

Figure CN119975253A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of vehicle control technology, and in particular to a vehicle anti-theft authentication method and a vehicle. Background Art
[0002] With the continuous development of vehicle technology, people's requirements for convenience of life and global environmental protection are getting higher and higher, and new energy vehicles are gradually pouring into more and more families. Due to the popularity of new energy vehicles in the market, people pay more and more attention to the configuration and safety of new energy vehicles, so the anti-theft function has become a standard feature of new energy vehicles.
[0003] The development process of new energy vehicles is generally improved on the basis of traditional fuel vehicles to shorten the development cycle and reduce development costs. The anti-theft system of traditional fuel vehicles generally includes keyless entry and start systems, engine management systems, and control locks. After traditional fuel vehicles are converted into new energy vehicles, the engine management system and engine will be removed, causing the anti-theft system to be damaged, resulting in the inability of new energy vehicles to complete the learning and certification process in the anti-theft process, which greatly reduces the safety of the vehicle.
[0004] Therefore, how to design anti-theft authentication for new energy vehicles to improve the safety of new energy vehicles has become an urgent problem to be solved. Summary of the invention
[0005] In view of the above, the embodiments of the present application provide a vehicle anti-theft authentication method and a vehicle, which can design an anti-theft authentication process for new energy vehicles, thereby improving the safety of new energy vehicles.
[0006] An embodiment of the present application provides a vehicle anti-theft authentication method, which is applied to a vehicle, wherein the vehicle includes a central controller, a regional controller and a key, wherein the central controller, the regional controller and the key are communicatively connected to each other, the central controller is used to send a control instruction to the regional controller, the regional controller is used to control the vehicle to perform a corresponding operation according to the control instruction, and the key is used to unlock the vehicle; the method includes: in response to an anti-theft authentication request signal, obtaining first encrypted data of the central controller, second encrypted data of the regional controller, a first key pre-stored in the regional controller and a second key pre-stored in the key; detecting whether the first encrypted data and the second encrypted data are consistent, and detecting whether the first key and the second key are consistent; and generating anti-theft authentication success information when it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent.
[0007] The vehicle anti-theft authentication method of the embodiment of the present application, when responding to the anti-theft authentication request signal, the vehicle needs to perform anti-theft authentication to ensure the safety of the vehicle. First, after obtaining the first encrypted data, the second encrypted data, the first key and the second key, it is detected whether the first encrypted data and the second encrypted data are consistent to determine whether the authentication between the central controller and the regional controller is successful, and whether the first key and the second key are consistent to determine whether the authentication between the regional controller and the key is successful. Finally, when it is detected that the first encrypted data and the second encrypted data are consistent, it indicates that the authentication between the central controller and the regional controller is successful, and when it is detected that the first key and the second key are consistent, it indicates that the authentication between the regional controller and the key is successful. When it is determined that the authentication between the central controller and the regional controller and the authentication between the regional controller and the key are both successful, anti-theft authentication success information is generated. The vehicle anti-theft authentication method performs double verification of the central controller and the regional controller and the regional controller and the key to ensure the safety of the vehicle.
[0008] In some embodiments, when it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, generating anti-theft authentication success information includes: When it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, obtaining a first verification code calculated by the regional controller according to the first key; Sending the first key and the first verification code to the central controller through the regional controller; Obtaining a second verification code calculated by the central controller according to the first key; When the first verification code and the second verification code are consistent, the anti-theft authentication success information is generated.
[0009] In some embodiments, after detecting whether the first key and the second key are consistent, the method further includes: When it is detected that the first key and the second key are consistent, obtaining a first verification code calculated by the regional controller according to the first key; Sending the first key and the first verification code to the central controller through the regional controller; Detecting whether the central controller receives the first key and the first verification code within a first preset time period; When it is detected that the central controller has not received the first key and / or the first verification code within the first preset time period, the central controller responds to the anti-theft authentication request signal again and performs anti-theft authentication according to the first key and the second key.
[0010] In some embodiments, the step of obtaining the first encrypted data includes: The central controller generates a random code, and performs symmetric encryption processing on the random code and a first fixed code pre-stored in the central controller to obtain the first encrypted data, wherein the random code is data randomly generated by the central controller.
[0011] In some embodiments, the step of obtaining the second encrypted data includes: Sending the random code to the regional controller via the central controller; The regional controller symmetrically encrypts the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data.
[0012] In some embodiments, after the regional controller symmetrically encrypts the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data, the method further includes: sending the second encrypted data to the central controller through the regional controller; Detecting whether the central controller receives the second encrypted data within a second preset time period; If the central controller does not receive the second encrypted data within the second preset time period, the random code is sent to the regional controller again through the central controller.
[0013] In some embodiments, after the random code is sent again to the regional controller by the central controller, the method further includes: Acquire the number of times the central controller sends the random code to the regional controller, wherein the number of times the central controller sends the random code to the regional controller in a historical period; When the sending times is not less than the preset times threshold, anti-theft authentication failure information is generated.
[0014] In some embodiments, after detecting whether the first encrypted data and the second encrypted data are consistent, the method further includes: When it is detected that the first encrypted data and the second encrypted data are inconsistent, the central controller generates a new random code, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data; Sending the new random code to the regional controller via the central controller; The regional controller symmetrically encrypts the new random code and the second fixed code pre-stored in the regional controller to obtain new second encrypted data; Acquire the number of times the central controller sends the random code to the regional controller, wherein the number of times the central controller sends the random code to the regional controller in a historical period; The anti-theft authentication is performed according to the new first encrypted data and the new second encrypted data until the anti-theft authentication failure information is generated when the number of transmissions is not less than a preset number threshold.
[0015] In some embodiments, after generating the anti-theft authentication failure information, the method further includes: Calculating the time difference between the current time and the time when the anti-theft authentication failure information was generated; When the time difference is greater than the preset time difference, the central controller generates a new random code again, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data; Sending the new random code to the regional controller via the central controller; The regional controller symmetrically encrypts the new random code and the second fixed code to obtain new second encrypted data; Detect whether the new first encrypted data and the new second encrypted data are consistent, and stop generating new random codes through the central controller when the central controller is in a dormant state.
[0016] In a second aspect, an embodiment of the present application further provides a vehicle, which is used to execute the vehicle anti-theft authentication method as described in the first aspect.
[0017] The above-mentioned vehicle corresponds to the above-mentioned vehicle anti-theft authentication method. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1 The present invention is a flowchart of a vehicle anti-theft authentication method according to an embodiment of the present application.
[0019] Figure 2 A flowchart of the steps of handshake authentication provided according to an embodiment of the present application.
[0020] Figure 3 Another step flow chart of handshake authentication provided according to an embodiment of the present application.
[0021] Figure 4 The diagram is a schematic diagram of interaction during vehicle anti-theft authentication according to an embodiment of the present application.
[0022] Figure 5 A schematic diagram of the structure of a vehicle controller provided in one embodiment of the present application. DETAILED DESCRIPTION
[0023] In order to more clearly understand the above-mentioned purposes, features and advantages of the present application, the present application is described in detail below in conjunction with the accompanying drawings and specific implementation methods. It should be noted that the implementation methods of the present application and the features in the implementation methods can be combined with each other without conflict.
[0024] In the following description, many specific details are set forth to facilitate a full understanding of the present application. The described implementations are only part of the implementations of the present application, rather than all the implementations.
[0025] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0026] It should be further noted that, in this article, the terms "comprises", "includes" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.
[0027] In this application, "at least one" means one or more, and "more" means two or more than two. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural.
[0028] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.
[0029] With the continuous development of vehicle technology, people's requirements for convenience of life and global environmental protection are getting higher and higher, and new energy vehicles are gradually pouring into more and more families. Due to the popularity of new energy vehicles in the market, people pay more and more attention to the configuration and safety of new energy vehicles, so the anti-theft function has become a standard feature of new energy vehicles.
[0030] The development process of new energy vehicles is generally improved on the basis of traditional fuel vehicles to shorten the development cycle and reduce development costs. The anti-theft system of traditional fuel vehicles generally includes keyless entry and start systems, engine management systems, and control locks. After traditional fuel vehicles are converted into new energy vehicles, the engine management system and engine will be removed, causing the anti-theft system to be damaged, resulting in the inability of new energy vehicles to complete the learning and certification process in the anti-theft process, which greatly reduces the safety of the vehicle.
[0031] Therefore, how to design anti-theft authentication for new energy vehicles to improve the safety of new energy vehicles has become an urgent problem to be solved.
[0032] In order to solve this problem, the embodiment of the present application provides a vehicle anti-theft authentication method, which can be applied to new energy vehicles. The new energy vehicle can be a hybrid vehicle or a pure electric vehicle, and the present application does not limit the type of new energy vehicles.
[0033] In this embodiment, the new energy vehicle includes a central controller, a regional controller and a key. The central controller, the regional controller and the key are communicatively connected to each other. The central controller is used to send control instructions to the regional controller. The regional controller is used to control the vehicle to perform corresponding operations according to the control instructions. The key is used to unlock the vehicle.
[0034] Furthermore, the central controller may include one or more processing units, for example, the central controller may include an application processor (AP), a modem, a graphics processing unit (GPU), an image signal processor (ISP), a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more central controllers.
[0035] Similarly, the regional controller may also include one or more processing units, for example, the regional controller may include an application processor (AP), a modem, a graphics processing unit (GPU), an image signal processor (ISP), a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more regional controllers.
[0036] The following is a detailed description of the specific steps of the vehicle anti-theft authentication method. Figure 1 , Figure 1 This is a flowchart of the steps of an embodiment of the vehicle anti-theft authentication method of the present application. According to different requirements, the order of the steps in the flowchart can be changed, and some steps can be omitted. The vehicle anti-theft authentication method can include the following steps.
[0037] Step 101, in response to an anti-theft authentication request signal, obtain first encrypted data of a central controller, second encrypted data of a regional controller, a first key pre-stored in the regional controller, and a second key pre-stored in a key.
[0038] When the new energy vehicle responds to the anti-theft authentication request signal, it indicates that anti-theft authentication is required. At this time, the new energy vehicle will obtain the first encrypted data of the central controller, the second encrypted data of the regional controller, the first key pre-stored in the regional controller and the second key pre-stored in the key, so as to facilitate the subsequent anti-theft authentication.
[0039] In this embodiment, the anti-theft authentication request signal includes a first authentication request signal and a second authentication request signal. When the user brings the key close to the new energy vehicle, the central controller will be awakened, and the central controller will generate a first authentication request signal. The new energy vehicle responds to the first authentication request signal and obtains the first encrypted data of the central controller and the second encrypted data of the regional controller. When the user steps on the brakes or other controllers issue a driving request, a second authentication request signal is generated, and the new energy vehicle responds to the second authentication request signal and obtains the first key pre-stored in the regional controller and the second key pre-stored in the key.
[0040] The step of obtaining the first encrypted data includes: generating a random code through a central controller, and symmetrically encrypting the random code and a first fixed code pre-stored in the central controller to obtain the first encrypted data, wherein the random code is data randomly generated by the central controller.
[0041] In this embodiment, before the central controller generates the random code, the central controller needs to be in the awake state. Then, the central controller will automatically generate the random code. Finally, the central controller will use the anti-theft algorithm to perform symmetrical encryption processing on the random code and the first fixed code pre-stored in the central controller to obtain the first encrypted data.
[0042] The anti-theft algorithm in this embodiment can adopt the symmetric encryption algorithm of AES128, which supports a key length of 128 bits, can effectively resist brute force cracking and other attacks, and adopts a highly complex algorithm, including multiple operations such as byte replacement, row shift, and column confusion, making it difficult for attackers to find an effective attack path, effectively providing security and reliability. The anti-theft algorithm belongs to the prior art, and this application will not repeat it.
[0043] The step of acquiring the second encrypted data may include: sending a random code to the regional controller through the central controller, and controlling the regional controller to perform symmetric encryption processing on the random code and a second fixed code pre-stored in the regional controller to obtain the second encrypted data.
[0044] In this embodiment, the central controller sends the random code to the regional controller via the CANFD signal. When the regional controller receives the random code sent by the central controller, the regional controller uses the anti-theft algorithm to symmetrically encrypt the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data.
[0045] Furthermore, the regional controller sends the second encrypted data to the central controller in the form of a CANFD message. The CANFD message of the second encrypted data is an event frame, and the message is 64 bytes, of which the first 16 bytes are the feedback encrypted data, the middle 16 bytes are the ESK code, and the other bytes are padding data.
[0046] In this embodiment, the first fixed code and the second fixed code may be the ESK code of the vehicle. The ESK code is a set of fixed 16-byte numbers and is pre-stored data written by the vehicle through diagnosis during the offline process.
[0047] The random code, the first fixed code, and the second fixed code in this embodiment can all be data of a first preset length, wherein the first preset length can be 16 bytes or 32 bytes, etc. This application does not limit the byte size of the random code, the first fixed code, and the second fixed code, as long as the byte sizes of the random code, the first fixed code, and the second fixed code are the same.
[0048] Similarly, the first key and the second key in this embodiment may be data of a second preset length, wherein the second preset length may be 16 bytes or 32 bytes, etc. This application does not limit the byte size of the first key and the second key, as long as the byte sizes of the first key and the second key are the same.
[0049] It should be noted that the central controller in this embodiment uses an anti-theft algorithm to symmetrically encrypt the random code and the first fixed code pre-stored in the central controller to obtain the first encrypted data. On the other hand, after sending the random code to the regional controller, the central controller continuously determines whether the second encrypted data sent by the regional controller is received. After determining that the second encrypted data sent by the regional controller is received, the subsequent authentication steps are performed.
[0050] In order to facilitate understanding of the technical content of this application, the authentication between the central controller and the regional controller is referred to as handshake authentication, and the authentication between the regional controller and the key is referred to as key authentication. At the same time, the central controller is used as the execution subject in the handshake authentication, and the regional controller is used as the execution subject in the key authentication for example.
[0051] In other embodiments, the regional controller may also use an anti-theft algorithm to symmetrically encrypt the random code sent by the central controller and the second fixed code pre-stored in the regional controller to obtain the second encrypted data; on the other hand, the regional controller continuously determines whether the first encrypted data sent by the central controller is received, and after determining that the first encrypted data sent by the central controller is received, the regional controller performs subsequent authentication steps.
[0052] Step 102: Detect whether the first encrypted data and the second encrypted data are consistent, and detect whether the first key and the second key are consistent.
[0053] In this embodiment, the central controller detects whether the first encrypted data and the second encrypted data are consistent to determine whether the authentication between the central controller and the regional controller is successful; and the regional controller detects whether the first key and the second key are consistent to determine whether the authentication between the regional controller and the key is successful.
[0054] Step 103: When it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, an anti-theft authentication success message is generated.
[0055] In this embodiment, when the central controller detects that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful and handshake authentication pass information can be generated; and when the regional controller detects that the first key and the second key are consistent, it indicates that the key authentication is successful and key authentication pass information can be generated.
[0056] Specifically, the regional controller feeds back the result of the key authentication to the central controller, so that the central controller can determine the result of the anti-theft authentication based on the result of the handshake authentication and the result of the key authentication. For example, when the central controller determines that the result of the handshake authentication is the handshake authentication pass information and the result of the key authentication is the key authentication pass information, the anti-theft authentication success information is generated. Otherwise, the anti-theft authentication failure information is generated. That is, when the central controller determines that both the handshake authentication and the key authentication are successful, the anti-theft authentication success information is generated. In this way, the new energy vehicle enters a drivable state and allows the user to switch the gear of the new energy vehicle.
[0057] In other embodiments, the central controller may feed back the result of the handshake authentication to the regional controller, so that the regional controller may determine the result of the anti-theft authentication based on the result of the handshake authentication and the result of the key authentication. For example, when the regional controller determines that the result of the handshake authentication is the handshake authentication pass information and the result of the key authentication is the key authentication pass information, the anti-theft authentication success information is generated. Otherwise, the anti-theft authentication failure information is generated.
[0058] The data in the handshake authentication and key authentication processes in this embodiment are all transmitted through CANFD messages. In order to further improve the accuracy of vehicle anti-theft authentication and the security of CANFD messages during transmission, the E2E verification algorithm is also used to verify the key during authentication. Among them, the E2E verification algorithm is also called the end-to-end verification algorithm (End-to-End Check Algorithm). The E2E verification algorithm is mainly used to verify the integrity and accuracy of data in the entire process from the data sender to the receiver. It emphasizes the end-to-end verification of data in the entire transmission or processing link, rather than just checking a local link in the link.
[0059] The E2E verification algorithm has the advantages of flexible data layout, fixed technical length, reused counter length and special value processing. It can improve communication efficiency, convenience of data processing, and effectively improve the reliability and stability of messages.
[0060] The specific contents of key authentication using the E2E verification algorithm are as follows: In some embodiments, when the regional controller detects that the first key and the second key are consistent, the regional controller obtains a first verification code calculated by the regional controller according to the first key. The regional controller is controlled to send the first key and the first verification code to the central controller, and the central controller obtains a second verification code calculated by the central controller according to the first key. When the central controller detects that the first verification code and the second verification code are consistent, a key authentication success message is generated.
[0061] In this embodiment, the regional controller detects whether the first key stored in the regional controller and the second key stored in the key are consistent. When the first key and the second key are detected to be consistent, the regional controller calculates the first verification code according to the first key and sends the first key and the first verification code to the central controller. The central controller calculates the second verification code according to the first key and detects whether the first verification code and the second verification code are consistent. When the first verification code and the second verification code are detected to be consistent, the anti-theft authentication success information is generated.
[0062] Furthermore, when the regional controller detects that the first key and the second key are consistent, the first key and the calculated first verification code will be sent to the central controller. Then, it is detected whether the central controller receives the first key and the first verification code within the first preset time. When it is detected that the central controller does not receive the first key and / or the first verification code within the first preset time, it responds to the anti-theft authentication request signal again and performs anti-theft authentication according to the first key and the second key.
[0063] Among them, the first preset time length can be 5 seconds or 10 seconds, which can be set according to the actual anti-theft authentication requirements. This application does not limit the specific value of the first preset time length.
[0064] Since the present application performs dual authentication of handshake authentication and key authentication at the same time, when it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, the first verification code calculated by the regional controller according to the first key is obtained. The regional controller is controlled to send the first key and the first verification code to the central controller. The second verification code calculated by the central controller according to the first key is obtained. When the first verification code and the second verification code are consistent, the anti-theft authentication success information is generated.
[0065] It should be noted that the handshake authentication process and the key authentication process are independent of each other and do not interfere with each other. When the handshake authentication passes and the key authentication passes, an anti-theft authentication success message is generated, otherwise, an anti-theft authentication failure message is generated.
[0066] It should also be noted that when the result of the handshake authentication is a handshake authentication success message, the handshake authentication success message will be saved for a period of time, and then the handshake authentication will be performed again, that is, the handshake authentication will be continuously performed within a certain period of time until the central controller is in a dormant state. Therefore, when the central controller is in an awake state and continuously performs handshake authentication within a certain period of time, it can ensure that the user can quickly complete the double verification after triggering the key authentication, thereby improving the user's driving experience.
[0067] Compared with the prior art, this embodiment has at least the following advantages: When responding to the anti-theft authentication request signal, the vehicle needs to perform anti-theft authentication to ensure the safety of the vehicle. First, the first encrypted data, the second encrypted data, the first key and the second key are obtained. Then, it is detected whether the first encrypted data and the second encrypted data are consistent to determine whether the handshake authentication is successful, and it is detected whether the first key and the second key are consistent to determine whether the key authentication is successful. Finally, when it is detected that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful, and when it is detected that the first key and the second key are consistent, it indicates that the key authentication is successful. When it is determined that both the handshake authentication and the key authentication are successful, an anti-theft authentication success message is generated. The vehicle anti-theft authentication method simultaneously performs dual verification of handshake authentication and key authentication, and, during the key authentication process, uses an E2E verification algorithm to improve message transmission and the safety of the vehicle.
[0068] refer to Figure 2 As shown, it is a flow chart of the steps of handshake authentication provided by the embodiment of the present application. As described above, after sending the random code to the regional controller, the central controller continuously determines whether the second encrypted data sent by the regional controller is received. Figure 2 The processing process after the central controller determines whether to receive the second encrypted data. The specific steps include: Step 201, detecting whether the central controller receives second encrypted data within a second preset time period.
[0069] In this embodiment, since the central controller needs to detect whether the first encrypted data calculated by itself is consistent with the second encrypted data calculated by the regional controller, the central controller needs to detect whether the second encrypted data sent by the regional controller is received within the second preset time period to avoid the problem of failure to perform handshake authentication due to failure to receive the second encrypted data for a long time.
[0070] Among them, the second preset time length can be set to 10 seconds or 15 seconds, which can be set according to the actual timeliness requirements of anti-theft authentication. This application does not limit the specific value of the second preset time length.
[0071] Step 202: If the central controller does not receive the second encrypted data within the second preset time period, the random code is sent to the regional controller again through the central controller.
[0072] In this embodiment, if the central controller does not receive the second encrypted data within the second preset time, it is possible that the regional controller has not received the random code sent by the central controller. In order to avoid this problem and the situation where handshake authentication cannot be performed, the central controller is controlled to send the random code to the regional controller again. The regional controller uses the anti-theft algorithm based on its own second fixed code and random code to calculate the second encrypted data, and sends the second encrypted data to the central controller. The central controller detects whether the first encrypted data and the second encrypted data are consistent.
[0073] It should be noted that the random code sent by the central controller to the regional controller again may be the same as or different from the random code sent to the regional controller previously, and this application does not limit this.
[0074] Step 203, obtaining the number of times the central controller sends the random code to the regional controller.
[0075] In this embodiment, the number of transmissions is the total number of times the central controller transmits random codes to the regional controllers during a historical period.
[0076] Step 204: if the number of transmissions is not less than a preset number threshold, generate anti-theft authentication failure information.
[0077] In this embodiment, in order to avoid the situation where the central controller repeatedly sends random codes to the regional controller but never receives the second encrypted data fed back by the regional controller, resulting in failure of handshake authentication, the number of times the central controller sends the random code to the regional controller is obtained, and it is detected whether the number of times is less than a preset number threshold.
[0078] If it is detected that the number of transmissions is not less than the preset number threshold, it indicates that the central controller has sent the random code to the regional controller multiple times, so that the regional controller can use the anti-theft algorithm in time to calculate the second encrypted data according to its own second fixed code and random code. However, there may be a situation where the regional controller fails and cannot feed back the second encrypted data to the central controller, thus generating anti-theft authentication failure information.
[0079] Among them, the preset number threshold can be 5 times, 8 times or 10 times, which can be set according to actual needs, and this application does not limit this.
[0080] Step 205, calculating the time difference between the current time and the time when the anti-theft authentication failure information is generated.
[0081] In this embodiment, the generation time of the anti-theft authentication failure information is obtained, and the difference between the current time and the generation time is used as the time difference.
[0082] Step 206, when the time difference is greater than the preset time difference, a new random code is generated by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data.
[0083] In this embodiment, the random code generated after the anti-theft authentication failure information is generated is different from the random code generated before the anti-theft authentication failure information is generated. In this way, the central controller calculates new first encrypted data based on the new random code and the regional controller calculates new second encrypted data based on the new random code, so that handshake authentication can be performed again later, thereby improving the success rate of handshake authentication.
[0084] Step 207: Send the new random code to the regional controller via the central controller.
[0085] In this embodiment, the central controller sends the new random code to the regional controller via a CANFD message.
[0086] Step 208: The regional controller symmetrically encrypts the new random code and the second fixed code to obtain new second encrypted data.
[0087] In this embodiment, the zone controller uses an anti-theft algorithm to perform symmetrical encryption processing on the new random code and the second fixed code pre-stored in the zone controller to obtain new second encrypted data.
[0088] It should be noted that, since the new random code is different from the random code before the anti-theft authentication failure information is generated, the new first encrypted data calculated by the central controller is also different from the previous first encrypted data. Similarly, the new second encrypted data calculated by the regional controller is also different from the previous second encrypted data.
[0089] Step 209, detecting whether the new first encrypted data and the new second encrypted data are consistent, until the central controller is in a dormant state, and then stopping generating new random codes through the central controller.
[0090] When the central controller is in the awake state, if it is detected that the new first encrypted data and the new second encrypted data are inconsistent, the above steps will be repeated until the first encrypted data and the second encrypted data are consistent, and the handshake authentication is successful, or, when the central controller is in the dormant state, the central controller stops generating new random codes and suspends the handshake authentication process. In this way, after generating anti-theft authentication failure information once or multiple times, the handshake authentication can be performed again after a period of time to increase the probability of passing the anti-theft authentication.
[0091] Compared with the prior art, this embodiment has at least the following advantages: After the central controller sends the random code to the regional controller, it is detected whether the central controller has received the second encrypted data within the second preset time period to avoid the problem of failure to perform handshake authentication due to failure to receive the second encrypted data for a long time. If the central controller does not receive the second encrypted data within the second preset time period, the central controller is controlled to send the random code to the regional controller again, and the regional controller calculates the second encrypted data. This avoids the situation where the handshake authentication cannot be performed due to the regional controller not receiving the random code sent by the central controller. At the same time, it is detected whether the number of transmissions is less than the preset number threshold to avoid the central controller sending random codes to the regional controller multiple times, but not receiving the second encrypted data fed back by the regional controller, and the situation where the regional controller may fail and fail to feed back the second encrypted data to the central controller. The anti-theft authentication failure information is directly generated to ensure the safety of the vehicle.
[0092] refer to Figure 3 As shown, it is another step flow chart of handshake authentication provided in the embodiment of the present application. In this embodiment, Figure 3 This is a process for detecting that the first encrypted data and the second encrypted data are inconsistent during handshake authentication. The specific steps include: Step 301, when it is detected that the first encrypted data and the second encrypted data are inconsistent, a new random code is generated again by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data.
[0093] As described above, in the handshake authentication, it is detected whether the first encrypted data and the second encrypted data are consistent. If it is detected that the first encrypted data and the second encrypted data are inconsistent, it indicates that the handshake authentication has not succeeded. In order to increase the success rate of the handshake authentication, the central controller can be controlled to generate a new random code again, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data. The subsequent central controller performs handshake authentication based on the new random code.
[0094] It should be noted that, when it is detected that the first encrypted data and the second encrypted data are inconsistent, the new random code generated again by the central controller may be the same as or different from the previous random code.
[0095] Step 302: The central controller sends the new random code to the regional controller, and controls the regional controller to perform symmetric encryption processing on the new random code and the second fixed code pre-stored in the regional controller to obtain new second encrypted data.
[0096] In this embodiment, the central controller sends the new random code to the regional controller in the form of a CANFD message.
[0097] Step 303, obtaining the number of times the central controller sends the random code to the regional controller.
[0098] In this embodiment, the total number of times the central controller sends random codes to the regional controllers during the historical period is obtained.
[0099] Step 304, performing anti-theft authentication according to the new first encrypted data and the new second encrypted data, until the anti-theft authentication failure information is generated when the number of transmissions is not less than a preset number threshold.
[0100] In this embodiment, when the number of transmissions is not less than the preset number threshold, it indicates that the central controller has sent the random code to the regional controller multiple times, and then has repeatedly detected whether the first encrypted data and the second encrypted data are consistent. If the first encrypted data and the second encrypted data are detected to be inconsistent multiple times, the handshake authentication fails, that is, the anti-theft authentication failure information is generated.
[0101] Step 305, calculating the time difference between the current time and the time when the anti-theft authentication failure information is generated.
[0102] In order to avoid the situation that the first encrypted data and the second encrypted data are inconsistent due to multiple detections due to a malfunction of the central controller and / or the regional controller, and the handshake authentication cannot be obtained, the handshake authentication can be performed again after a period of time after the anti-theft authentication failure information is generated. At this time, it is necessary to calculate the time difference between the current time and the time when the anti-theft authentication failure information is generated. Check whether the time difference is greater than the preset time difference to determine whether the handshake authentication needs to be performed again.
[0103] Step 306, when the time difference is greater than the preset time difference, a new random code is generated by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data.
[0104] As shown above, after the anti-theft authentication failure information is generated, the new random code generated by the central controller is different from the previous random code.
[0105] Step 307: Send the new random code to the regional controller through the central controller, and control the regional controller to perform symmetric encryption processing on the new random code and the second fixed code to obtain new second encrypted data.
[0106] Step 308, detecting whether the new first encrypted data and the new second encrypted data are consistent, until the central controller is in a dormant state, and then stopping generating new random codes through the central controller.
[0107] The contents of steps 306 to 308 are the same as those of steps 216 to 219, and will not be described again here to avoid repetition.
[0108] Compared with the prior art, this embodiment has at least the following advantages: When it is detected that the first encrypted data and the second encrypted data are inconsistent, it indicates that the handshake authentication has not been successful. In order to increase the success rate of the handshake authentication, the central controller can generate new random codes multiple times, so that the central controller and the regional controller can calculate new first encrypted data and new second encrypted data based on the new random codes. The first encrypted data and the second encrypted data are compared multiple times to increase the pass rate of the handshake authentication. At the same time, if the central controller is in the awake state, if the anti-theft authentication failure information is generated, and after a period of time, the central controller can also generate a random code different from the previous one, and based on the new and different random code, the handshake authentication is performed again to increase the number of handshake authentications.
[0109] refer to Figure 4 The figure is a schematic diagram of the interaction between the central controller, the regional controller and the key during the anti-theft authentication provided by the embodiment of the present application. This embodiment is described by taking the handshake authentication with the central controller as the execution subject and the key authentication with the regional controller as the execution subject as an example.
[0110] In step S11, the central controller generates a random code, and performs symmetric encryption processing on the random code and a first fixed code pre-stored in the central controller to obtain first encrypted data.
[0111] As described above, when the user brings the key close to the new energy vehicle, the central controller will be awakened, and the central controller will generate a first authentication request signal and a random code. The random code and the first fixed code pre-stored in the central controller are symmetrically encrypted using an anti-theft algorithm to obtain first encrypted data.
[0112] Step S12: the central controller sends the random code to the regional controller.
[0113] In this embodiment, the central controller sends the random code to the regional controller in the form of a CANFD message.
[0114] Step S13: the regional controller performs symmetric encryption processing on the random code and the second fixed code pre-stored in the regional controller to obtain second encrypted data.
[0115] In this embodiment, after the regional controller receives the random code sent by the central controller, the regional controller will use the anti-theft algorithm to symmetrically encrypt the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data.
[0116] Step S14: the regional controller sends the second encrypted data to the central controller.
[0117] In step S15, the central controller detects whether the first encrypted data and the second encrypted data are consistent, and generates handshake authentication pass information when it is detected that the first encrypted data and the second encrypted data are consistent.
[0118] In this embodiment, when the central controller detects that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful, and then generates handshake authentication pass information.
[0119] In step S21, the key sends a second key to the zone controller.
[0120] In step S22, the zone controller detects whether its first key and second key are consistent, and generates key authentication success information when it is detected that the first key and the second key are consistent.
[0121] In this embodiment, when the user steps on the brakes or other controllers issue a driving request, a second authentication request signal is generated, the new energy vehicle responds to the second authentication request signal, and the control area controller obtains its own first key and the second key of the key.
[0122] In this embodiment, when the zone controller detects that the first key and the second key are consistent, it indicates that the key authentication is successful, and key authentication success information is generated.
[0123] Step S23: the regional controller sends key authentication success information to the central controller.
[0124] Step S16: The central controller generates anti-theft authentication success information based on the handshake authentication pass information and the key authentication success information.
[0125] In this embodiment, the regional controller sends the key authentication success information to the central controller, and the central controller generates the anti-theft authentication success information based on the double authentication information of the handshake authentication success information and the key authentication success information. In this way, the new energy vehicle enters a drivable state and allows the user to switch the gear of the new energy vehicle.
[0126] Compared with the prior art, this embodiment has at least the following advantages: When the vehicle needs to be authenticated for anti-theft, both handshake authentication and key authentication are performed simultaneously. If both handshake authentication and key authentication are successful, anti-theft authentication success information is generated. In this way, the safety of the vehicle is improved.
[0127] like Figure 5As shown, the embodiment of the present application also provides a schematic diagram of the hardware structure of a vehicle controller. The vehicle controller 1000 may include a processor 1001 and a memory 1002. The memory 1002 is used to store one or more computer programs 1003. The one or more computer programs 1003 are configured to be executed by the processor 1001. The one or more computer programs 1003 include instructions. The vehicle controller 1000 may be a regional controller, a central controller, etc.
[0128] It is understandable that the structure shown in this embodiment does not constitute a specific limitation on the vehicle controller 1000. In other embodiments, the vehicle controller 1000 may include more or fewer components than shown, or combine some components, or separate some components, or arrange the components differently.
[0129] The processor 1001 may include one or more processing units, for example, the processor 1001 may include an application processor (AP), a modem, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or may be integrated in one or more processors 1001.
[0130] The processor 1001 may also be provided with a memory 1002 for storing instructions and data. In some embodiments, the memory 1002 in the processor 1001 is a cache memory. The memory 1002 may store instructions or data that the processor 1001 has just used or cyclically used. If the processor 1001 needs to use the instruction or data again, it may be directly called from the memory 1002. This avoids repeated access, reduces the waiting time of the processor 1001, and thus improves the efficiency of the system.
[0131] In some embodiments, the processor 1001 may include one or more interfaces. The interface may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM interface, and / or a USB interface, etc.
[0132] In some embodiments, processor 1001 is used to execute acceleration schemes such as single instruction multiple data (SIMD) and very long instruction word (VLIW).
[0133] In some embodiments, memory 1002 may include high-speed random access memory and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0134] This embodiment also provides a vehicle, which can be used to execute the above-mentioned related method steps to implement the method in the above-mentioned embodiment.
[0135] Among them, the vehicle controller 1000 and the vehicle provided in this embodiment are used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.
[0136] In practical applications, the above functions can be distributed to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.
[0137] In several embodiments provided in the present application, the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are schematic. For example, the division of the modules or units is a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0138] The unit described as a separate component may or may not be physically separated, and the component shown as a unit may be one physical unit or multiple physical units, that is, it may be located in one place or distributed in multiple different places. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiment.
[0139] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0140] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, ROM), random access memory (Random Access Memory, RAM), disk or optical disk and other media that can store program code.
[0141] The above description is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions within the technical scope disclosed in the present application should be included in the protection scope of the present application.
Claims
1. A vehicle anti-theft authentication method, characterized in that: Applied to a vehicle, the vehicle comprises a central controller, a regional controller and a key, the central controller, the regional controller and the key are communicatively connected with each other, the central controller is used to send a control instruction to the regional controller, the regional controller is used to control the vehicle to perform a corresponding operation according to the control instruction, and the key is used to unlock the vehicle; the method comprises: In response to the anti-theft authentication request signal, acquiring the first encrypted data of the central controller, the second encrypted data of the regional controller, the first key pre-stored in the regional controller, and the second key pre-stored in the key; Detecting whether the first encrypted data and the second encrypted data are consistent, and detecting whether the first key and the second key are consistent; When it is detected that the first encrypted data is consistent with the second encrypted data, and the first key is consistent with the second key, anti-theft authentication success information is generated.
2. The vehicle anti-theft authentication method according to claim 1, characterized in that: The generating anti-theft authentication success information when detecting that the first encrypted data is consistent with the second encrypted data and the first key is consistent with the second key includes: When it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, obtaining a first verification code calculated by the regional controller according to the first key; Sending the first key and the first verification code to the central controller through the regional controller; Obtaining a second verification code calculated by the central controller according to the first key; When the first verification code and the second verification code are consistent, the anti-theft authentication success information is generated.
3. The vehicle anti-theft authentication method according to claim 1, characterized in that: After detecting whether the first key and the second key are consistent, the method further includes: When it is detected that the first key and the second key are consistent, obtaining a first verification code calculated by the regional controller according to the first key; Sending the first key and the first verification code to the central controller through the regional controller; Detecting whether the central controller receives the first key and the first verification code within a first preset time period; When it is detected that the central controller has not received the first key and / or the first verification code within the first preset time period, the central controller responds to the anti-theft authentication request signal again and performs anti-theft authentication according to the first key and the second key.
4. The vehicle anti-theft authentication method according to claim 1, characterized in that: The step of obtaining the first encrypted data comprises: The central controller generates a random code, and performs symmetric encryption processing on the random code and a first fixed code pre-stored in the central controller to obtain the first encrypted data, wherein the random code is data randomly generated by the central controller.
5. The vehicle anti-theft authentication method according to claim 4, characterized in that: The step of obtaining the second encrypted data comprises: Sending the random code to the regional controller via the central controller; The regional controller symmetrically encrypts the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data.
6. The vehicle anti-theft authentication method according to claim 5, characterized in that: After the regional controller symmetrically encrypts the random code and the second fixed code pre-stored in the regional controller to obtain the second encrypted data, the method further includes: sending the second encrypted data to the central controller through the regional controller; Detecting whether the central controller receives the second encrypted data within a second preset time period; If the central controller does not receive the second encrypted data within the second preset time period, the random code is sent to the regional controller again through the central controller.
7. The vehicle anti-theft authentication method according to claim 6, characterized in that: After the random code is sent again to the regional controller by the central controller, the method further includes: Acquire the number of times the central controller sends the random code to the regional controller, wherein the number of times the central controller sends the random code to the regional controller in a historical period; When the sending times is not less than the preset times threshold, anti-theft authentication failure information is generated.
8. The vehicle anti-theft authentication method according to claim 4, characterized in that: After detecting whether the first encrypted data and the second encrypted data are consistent, the method further includes: When it is detected that the first encrypted data and the second encrypted data are inconsistent, the central controller generates a new random code, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data; Sending the new random code to the regional controller via the central controller; The regional controller symmetrically encrypts the new random code and the second fixed code pre-stored in the regional controller to obtain new second encrypted data; Acquire the number of times the central controller sends the random code to the regional controller, wherein the number of times the central controller sends the random code to the regional controller in a historical period; The anti-theft authentication is performed according to the new first encrypted data and the new second encrypted data until the anti-theft authentication failure information is generated when the number of transmissions is not less than a preset number threshold.
9. The vehicle anti-theft authentication method according to claim 7 or 8, characterized in that: After the anti-theft authentication failure information is generated, the method further includes: Calculating the time difference between the current time and the generation time of the anti-theft authentication failure information; When the time difference is greater than the preset time difference, the central controller generates a new random code again, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data; Sending the new random code to the regional controller via the central controller; The regional controller symmetrically encrypts the new random code and the second fixed code to obtain new second encrypted data; Detect whether the new first encrypted data and the new second encrypted data are consistent, and stop generating new random codes through the central controller when the central controller is in a dormant state.
10. A vehicle, characterized in that: The vehicle is used to execute the vehicle anti-theft authentication method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Method and system for anti-theft authentication of pure electric vehicle
CN106627489A
Vehicle anti-theft method and device, storage medium, vehicle control unit and vehicle
CN112693425A
Anti-theft authentication method and system for vehicle, vehicle and storage medium
CN116101221A
Vehicle anti-theft method, device and system and storage medium
CN117341628A
Key pairing and binding method and system and vehicle
CN119131937A