Vehicle theft prevention authentication method and vehicle

By using handshake authentication between the central controller and the regional controller, and key authentication between the regional controller and the key, and employing the AES128 encryption algorithm and E2E verification algorithm, the problem of the anti-theft system being compromised after the modification of new energy vehicles has been solved, thereby improving the safety and reliability of the vehicles.

CN119975253BActive Publication Date: 2025-12-26GUANGZHOU AUTOMOBILE GROUP CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510288888.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-12-26
Estimated Expiration
2045-03-11

AI Technical Summary

Technical Problem

During the modification process of new energy vehicles, the engine management system and engine are removed, which damages the anti-theft system and prevents the learning and authentication process in the anti-theft procedure from being completed, resulting in a significant reduction in vehicle security.

Method used

Design a vehicle anti-theft authentication method that uses handshake authentication between the central controller and the area controller, and key authentication between the area controller and the key, and employs AES128 symmetric encryption algorithm and E2E verification algorithm for dual verification to ensure the consistency of encrypted data and keys, and generate anti-theft authentication success information.

Benefits of technology

It improves the safety of new energy vehicles by ensuring successful anti-theft certification through dual verification, thereby enhancing the safety and reliability of the vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119975253B_ABST
    Figure CN119975253B_ABST
Patent Text Reader

Abstract

The application provides a vehicle anti-theft authentication method and a vehicle. The method comprises the following steps: in response to an anti-theft authentication request signal, acquiring first encrypted data of the central controller, second encrypted data of the area controller, a first key pre-stored by the area controller and a second key pre-stored by the key; detecting whether the first encrypted data and the second encrypted data are consistent, and detecting whether the first key and the second key are consistent; in the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, generating anti-theft authentication success information. The application can perform double authentication between the central controller and the area controller, and between the area controller and the key, thereby ensuring the safety of the vehicle.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of vehicle control, in particular to a vehicle anti-theft authentication method and a vehicle. BACKGROUND

[0002] With the continuous development of vehicle technology, people's demand for life convenience and the global demand for environmental protection are becoming higher and higher, and new energy vehicles are gradually entering more and more families. Due to the popularity of new energy vehicles in the market, the configuration and safety of new energy vehicles are attracting more and more attention, so the anti-theft function has become a standard configuration of new energy.

[0003] The development process of new energy vehicles is generally based on the improvement of traditional fuel vehicles to shorten the development cycle and reduce the development cost. The anti-theft system of traditional fuel vehicles generally includes a keyless entry and start system, an engine management system, and a lock. After the traditional fuel vehicle is modified into a new energy vehicle, the engine management system and the engine are removed, thereby causing the anti-theft system to be damaged, resulting in the new energy vehicle being unable to implement the learning and authentication links in the anti-theft process, thereby greatly reducing the safety of the vehicle.

[0004] Therefore, how to design the anti-theft authentication of new energy vehicles to improve the safety of new energy vehicles has become a problem to be solved. SUMMARY

[0005] In view of the above, the embodiments of the present application provide a vehicle anti-theft authentication method and a vehicle, which can design the anti-theft authentication process of new energy vehicles, thereby improving the safety of new energy vehicles.

[0006] The embodiments of the present application provide a vehicle anti-theft authentication method applied to a vehicle, wherein the vehicle includes a central controller, a regional controller, and a key, the central controller, the regional controller, and the key are mutually connected in communication, the central controller is configured to send a control instruction to the regional controller, the regional controller is configured to control the vehicle to perform a corresponding operation according to the control instruction, and the key is configured to unlock the vehicle; the method comprises the following steps: in response to an anti-theft authentication request signal, acquiring first encrypted data of the central controller, second encrypted data of the regional controller, a first key pre-stored by the regional controller, and a second key pre-stored by the key; detecting whether the first encrypted data and the second encrypted data are consistent, and detecting whether the first key and the second key are consistent; in the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, generating anti-theft authentication success information.

[0007] The vehicle anti-theft authentication method of the embodiments of the present application, when responding to an anti-theft authentication request signal, the vehicle needs to perform anti-theft authentication to ensure the safety of the vehicle. First, after obtaining the first encrypted data, the second encrypted data, the first key and the second key, it is detected whether the first encrypted data and the second encrypted data are consistent to determine whether the authentication between the central controller and the area controller is successful, and whether the first key and the second key are consistent to determine whether the authentication between the area controller and the key is successful. Finally, when it is detected that the first encrypted data and the second encrypted data are consistent, it indicates that the authentication between the central controller and the area controller is successful, and when it is detected that the first key and the second key are consistent, it indicates that the authentication between the area controller and the key is successful. In the case where the authentication between the central controller and the area controller and the authentication between the area controller and the key are both successful, anti-theft authentication success information is generated. The vehicle anti-theft authentication method performs double verification of the central controller and the area controller and the area controller and the key to ensure the safety of the vehicle.

[0008] In some embodiments, in the case where it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, anti-theft authentication success information is generated, comprising:

[0009] In the case where it is detected that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, a first check code calculated by the area controller according to the first key is obtained;

[0010] The first key and the first check code are sent to the central controller by the area controller;

[0011] A second check code calculated by the central controller according to the first key is obtained;

[0012] In the case where the first check code and the second check code are consistent, the anti-theft authentication success information is generated.

[0013] In some embodiments, after the detection of whether the first key and the second key are consistent, further comprising:

[0014] In the case where it is detected that the first key and the second key are consistent, a first check code calculated by the area controller according to the first key is obtained;

[0015] The first key and the first check code are sent to the central controller by the area controller;

[0016] It is detected whether the central controller receives the first key and the first check code within a first preset time period;

[0017] In response to the anti-theft authentication request signal again, anti-theft authentication is performed according to the first key and the second key, in the case that it is detected that the central controller does not receive the first key and / or the first check code within the first preset time length.

[0018] In some embodiments, the obtaining of the first encrypted data comprises:

[0019] generating a random code by the central controller, and performing symmetric encryption processing on the random code and a first fixed code pre-stored by the central controller to obtain the first encrypted data, wherein the random code is a data randomly generated by the central controller.

[0020] In some embodiments, the obtaining of the second encrypted data comprises:

[0021] sending the random code to the area controller by the central controller;

[0022] performing symmetric encryption processing on the random code and a second fixed code pre-stored by the area controller to obtain the second encrypted data by the area controller.

[0023] In some embodiments, after the symmetric encryption processing on the random code and the second fixed code pre-stored by the area controller to obtain the second encrypted data, the method further comprises:

[0024] sending the second encrypted data to the central controller by the area controller;

[0025] detecting whether the central controller receives the second encrypted data within a second preset time length;

[0026] if the central controller does not receive the second encrypted data within the second preset time length, sending the random code to the area controller again by the central controller.

[0027] In some embodiments, after the sending of the random code to the area controller again by the central controller, the method further comprises:

[0028] obtaining a sending frequency of sending the random code to the area controller by the central controller, wherein the sending frequency is a total number of times of sending the random code to the area controller by the central controller within a historical period;

[0029] generating anti-theft authentication failure information in the case that the sending frequency is not less than a preset frequency threshold.

[0030] In some embodiments, after the detection of whether the first encrypted data and the second encrypted data are consistent, the method further comprises:

[0031] In a case where it is detected that the first encrypted data and the second encrypted data are inconsistent, a new random code is generated by the central controller, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data;

[0032] The new random code is sent to the area controller by the central controller;

[0033] Symmetric encryption is performed on the new random code and a second fixed code pre-stored by the area controller to obtain new second encrypted data by the area controller;

[0034] The number of times that the random code is sent from the central controller to the area controller is obtained, wherein the number of times is the total number of times that the random code is sent from the central controller to the area controller in a historical period;

[0035] Anti-theft authentication is performed according to the new first encrypted data and the new second encrypted data, and in a case where the number of times is not less than a preset number of times threshold, anti-theft authentication failure information is generated.

[0036] In some embodiments, after the anti-theft authentication failure information is generated, the method further includes:

[0037] A time difference between a current time and a generation time of the anti-theft authentication failure information is calculated;

[0038] In a case where the time difference is greater than a preset time difference, a new random code is generated again by the central controller, and symmetric encryption is performed on the new random code and the first fixed code to obtain new first encrypted data;

[0039] The new random code is sent to the area controller by the central controller;

[0040] Symmetric encryption is performed on the new random code and the second fixed code by the area controller to obtain new second encrypted data;

[0041] It is detected whether the new first encrypted data and the new second encrypted data are consistent, and in a case where the central controller is in a hibernation state, the central controller stops generating a new random code.

[0042] In a second aspect, the embodiments of the present application further provide a vehicle for performing the vehicle anti-theft authentication method of the first aspect.

[0043] The vehicle corresponds to the vehicle anti-theft authentication method, and thus the beneficial effects achieved thereby can refer to the beneficial effects of the corresponding method provided above, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS

[0044] Figure 1 A step flow chart of a vehicle anti-theft authentication method according to an embodiment of the present application.

[0045] Figure 2 A step flow chart of a handshake authentication according to an embodiment of the present application.

[0046] Figure 3 Another step flow chart of a handshake authentication according to an embodiment of the present application.

[0047] Figure 4 An interaction schematic diagram of a vehicle anti-theft authentication according to an embodiment of the present application.

[0048] Figure 5 A structure schematic diagram of a vehicle controller according to an embodiment of the present application. DETAILED DESCRIPTION

[0049] In order to more clearly understand the above objectives, features and advantages of the present application, the present application will be described in detail below with reference to the accompanying drawings and specific embodiments. It should be noted that the embodiments of the present application and the features in the embodiments can be combined with each other as long as they do not conflict.

[0050] In the following description, a large number of specific details are set forth in order to facilitate a thorough understanding of the present application. The described embodiments are only some of the embodiments of the present application, and are not all the embodiments.

[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used in the description herein is for the purpose of describing particular embodiments only and is not intended to be limiting of the present application.

[0052] It should be further noted that, in this document, the terms "comprise", "comprise", or any other variant thereof are intended to cover non-exclusive inclusions, so that processes, methods, articles, or devices that include a series of elements not only include those elements, but also include other elements not explicitly listed, or inherent to such processes, methods, articles, or devices. Without more limitations, the element defined by the phrase "comprises a" does not exclude the presence of additional identical elements in the process, method, article, or device that includes the element.

[0053] In the present application, “at least one” means one or more, and “multiple” means two or more than two. “And / or” describes the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B can represent: A exists alone, A and B exist together, and B exists alone, where A and B can be singular or plural.

[0054] In the embodiments of the present application, the words such as “exemplary” or “for example” are used to mean serving as an example, instance, or illustration. Any embodiment or design scheme described as “exemplary” or “for example” in the embodiments of the present application should not be interpreted as being more preferred or having more advantages than other embodiments or design schemes. Rather, the use of “exemplary” or “for example” is intended to present relevant concepts in a specific manner.

[0055] With the continuous development of vehicle technology, people's requirements for life convenience and the global demand for environmental protection are becoming higher and higher, and new energy vehicles are gradually entering more and more families. Due to the popularity of new energy vehicles in the market, the configuration and safety of new energy vehicles are paid more and more attention by people, and therefore the anti-theft function has become a standard configuration of new energy.

[0056] The development process of new energy vehicles is generally based on the improvement of traditional fuel vehicles to shorten the development cycle and reduce the development cost. The anti-theft system of the traditional fuel vehicle generally includes a keyless entry and start system, an engine management system, and a lock. After the traditional fuel vehicle is modified into a new energy vehicle, the engine management system and the engine are removed, thereby causing the anti-theft system to be damaged, resulting in that the new energy vehicle cannot realize the learning and authentication links in the anti-theft process, thereby greatly reducing the safety of the vehicle.

[0057] Therefore, how to design the anti-theft authentication of the new energy vehicle to improve the safety of the new energy vehicle has become a problem to be solved.

[0058] In order to solve this problem, the embodiments of the present application provide a vehicle anti-theft authentication method, which can be applied to a new energy vehicle. The new energy vehicle can be a hybrid vehicle or a pure electric vehicle, and the present application does not limit the type of new energy vehicle.

[0059] In the present embodiment, the new energy vehicle includes a central controller, a regional controller, and a key, the central controller, the regional controller, and the key are mutually communicated and connected, the central controller is used to send a control instruction to the regional controller, the regional controller is used to control the vehicle to perform a corresponding operation according to the control instruction, and the key is used to unlock the vehicle.

[0060] Further, the central controller can include one or more processing units, for example: the central controller can include an application processor (application processor, AP), a modem, a graphics processing unit (graphics processing unit, GPU), an image signal processor (image signal processor, ISP), a video codec, a digital signal processor (digital signal processor, DSP), a baseband processor, and / or a neural-network processing unit (neural-network processing unit, NPU), etc. Different processing units can be independent devices or integrated into one or more central controllers.

[0061] Similarly, the area controller can also include one or more processing units, for example: the area controller can include an application processor (application processor, AP), a modem, a graphics processing unit (graphics processing unit, GPU), an image signal processor (image signal processor, ISP), a video codec, a digital signal processor (digital signal processor, DSP), a baseband processor, and / or a neural-network processing unit (neural-network processing unit, NPU), etc. Different processing units can be independent devices or integrated into one or more area controllers.

[0062] The specific steps of the vehicle anti-theft authentication method will be described in detail below. Please combine Figure 1 , Figure 1 is the step flow chart of an embodiment of the vehicle anti-theft authentication method of the present application. According to different needs, the order of the steps in the flow chart can be changed, and some steps can be omitted. The vehicle anti-theft authentication method can include the following steps.

[0063] Step 101, in response to the anti-theft authentication request signal, the first encryption data of the central controller, the second encryption data of the area controller, the first key pre-stored by the area controller and the second key pre-stored by the key are obtained.

[0064] When the new energy vehicle responds to the anti-theft authentication request signal, it indicates that anti-theft authentication is needed. At this time, the new energy vehicle will obtain the first encryption data of the central controller, the second encryption data of the area controller, the first key pre-stored by the area controller and the second key pre-stored by the key, so as to facilitate subsequent anti-theft authentication.

[0065] In the embodiment, the anti-theft authentication request signal includes a first authentication request signal and a second authentication request signal. When the user carries the key close to the new energy vehicle, the central controller will be woken up, and the central controller will generate the first authentication request signal. The new energy vehicle acquires the first encrypted data of the central controller and the second encrypted data of the regional controller in response to the first authentication request signal. When the user steps on the brake or other controllers issue a driving request, the second authentication request signal is generated, and the new energy vehicle acquires the first key pre-stored by the regional controller and the second key pre-stored by the key in response to the second authentication request signal.

[0066] The first encrypted data acquisition step includes: generating a random code by the central controller, and performing symmetric encryption processing on the random code and the first fixed code pre-stored by itself to obtain the first encrypted data, wherein the random code is a data randomly generated by the central controller.

[0067] In the embodiment, the central controller needs to be in a woken-up state before the central controller generates the random code. Then, the central controller will automatically generate the random code. Finally, the central controller will use the anti-theft algorithm to perform symmetric encryption processing on the random code and the first fixed code pre-stored by itself to obtain the first encrypted data.

[0068] The anti-theft algorithm in the embodiment can use the symmetric encryption algorithm of AES128. This algorithm supports a 128-bit key length, can effectively resist brute force cracking and other attacks, and at the same time uses a highly complex algorithm, including multiple operations such as byte substitution, row shifting, and column confusion, so that it is difficult for attackers to find an effective attack path, effectively providing security and reliability. The anti-theft algorithm belongs to the prior art, and the present application will not be described again.

[0069] The second encrypted data acquisition step can include: sending a random code to the regional controller by the central controller. The regional controller performs symmetric encryption processing on the random code and the second fixed code pre-stored by itself to obtain the second encrypted data.

[0070] In the embodiment, the central controller sends the random code to the regional controller through the CANFD signal. When the regional controller receives the random code sent by the central controller, the regional controller will use the anti-theft algorithm to perform symmetric encryption processing on the random code and the second fixed code pre-stored by itself to obtain the second encrypted data.

[0071] Further, the regional controller sends the second encrypted data to the central controller in the form of a CANFD message. The CANFD message of the second encrypted data is an event frame, and the message is 64 bytes, of which the first 16 bytes are feedback encrypted data, the middle 16 bytes are ESK codes, and the other bytes are padding data.

[0072] The first fixed code and the second fixed code in the embodiment can be an ESK code of the vehicle, which is a set of fixed 16-byte numbers and is pre-stored data written by diagnosis in the offline process of the vehicle.

[0073] The random code, the first fixed code and the second fixed code in the embodiment can all be data of a first preset length, where the first preset length can be 16 bytes or 32 bytes, etc., and the application does not limit the byte size of the random code, the first fixed code and the second fixed code. As long as the byte sizes of the random code, the first fixed code and the second fixed code are the same, it is acceptable.

[0074] Similarly, the first key and the second key in the embodiment can be data of a second preset length, where the second preset length can be 16 bytes or 32 bytes, etc., and the application does not limit the byte size of the first key and the second key. As long as the byte sizes of the first key and the second key are the same, it is acceptable.

[0075] It should be noted that the central controller in the embodiment performs symmetric encryption processing on the random code and the first fixed code pre-stored by itself by using the anti-theft algorithm to obtain the first encrypted data; on the other hand, after the central controller sends the random code to the area controller, it continuously determines whether the second encrypted data sent by the area controller is received. And after determining that the second encrypted data sent by the area controller is received, the subsequent authentication step is performed.

[0076] In order to facilitate understanding of the technical content of the application, the authentication between the central controller and the area controller is referred to as a handshake authentication, and the authentication between the area controller and the key is referred to as a key authentication. At the same time, the central controller is taken as an execution subject in the handshake authentication, and the area controller is taken as an execution subject in the key authentication for example.

[0077] In other embodiments, the area controller can also perform symmetric encryption processing on the random code sent by the central controller and the second fixed code pre-stored by itself by using the anti-theft algorithm to obtain the second encrypted data; on the other hand, the area controller continuously determines whether the first encrypted data sent by the central controller is received. And after determining that the first encrypted data sent by the central controller is received, the subsequent authentication step is performed.

[0078] Step 102, detecting whether the first encrypted data and the second encrypted data are consistent, and detecting whether the first key and the second key are consistent.

[0079] In the embodiment, the central controller detects whether the first encrypted data and the second encrypted data are consistent to determine whether the authentication between the central controller and the area controller is successful; and the area controller detects whether the first key and the second key are consistent to determine whether the authentication between the area controller and the key is successful.

[0080] In step 103, in the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, generating the anti-theft authentication success information.

[0081] In this embodiment, when the central controller detects that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful, and the handshake authentication pass information can be generated; and when the regional controller detects that the first key and the second key are consistent, it indicates that the key authentication is successful, and the key authentication pass information can be generated.

[0082] Specifically, the regional controller feeds back the result of the key authentication to the central controller, so that the central controller can determine the result of the anti-theft authentication based on the result of the handshake authentication and the result of the key authentication. For example, when the central controller determines that the result of the handshake authentication is the handshake authentication pass information and the result of the key authentication is the key authentication pass information, the anti-theft authentication success information is generated. Otherwise, the anti-theft authentication failure information is generated. That is, in the case that the central controller determines that the double authentication of the handshake authentication and the key authentication is successful, the anti-theft authentication success information is generated. In this way, the new energy vehicle enters the drivable state and the user is allowed to switch the gear of the new energy vehicle.

[0083] In other embodiments, the central controller can feed back the result of the handshake authentication to the regional controller, so that the regional controller can determine the result of the anti-theft authentication based on the result of the handshake authentication and the result of the key authentication. For example, when the regional controller determines that the result of the handshake authentication is the handshake authentication pass information and the result of the key authentication is the key authentication pass information, the anti-theft authentication success information is generated. Otherwise, the anti-theft authentication failure information is generated.

[0084] The data in the handshake authentication and the key authentication process in this embodiment are transmitted through the CANFD message. In order to further improve the accuracy of the vehicle anti-theft authentication and the safety of the CANFD message in the transmission process, the E2E check algorithm is also used to check the key authentication. The E2E check algorithm is also called End-to-End Check Algorithm. The E2E check algorithm is mainly used to verify the data integrity and accuracy in the whole process from the data sending end to the receiving end. It emphasizes the check of the end-to-end of the whole transmission or processing link, rather than only checking a certain local link.

[0085] The E2E check algorithm has the advantages of flexible data layout, fixed technology length, reused counter length and special value processing, which can improve the communication efficiency, the convenience of data processing, and effectively improve the reliability and stability of the message.

[0086] The specific content of the key authentication using the E2E check algorithm is as follows:

[0087] In some embodiments, in the case where the area controller detects that the first key and the second key are consistent, the area controller obtains a first check code calculated by the area controller according to the first key. The area controller sends the first key and the first check code to the central controller, and obtains a second check code calculated by the central controller according to the first key. In the case where the central controller detects that the first check code and the second check code are consistent, success information of the key authentication is generated.

[0088] In the present embodiment, the area controller detects whether the first key pre-stored by itself and the second key pre-stored by the key are consistent, and in the case where the first key and the second key are consistent, the area controller sends a first check code calculated according to the first key to the central controller. The second check code calculated by the central controller according to the first key is obtained, and whether the first check code and the second check code are consistent is detected. In the case where the first check code and the second check code are consistent, success information of the anti-theft authentication is generated.

[0089] Further, in the case where the area controller detects that the first key and the second key are consistent, the first key and the first check code calculated are sent to the central controller. Then, whether the central controller receives the first key and the first check code within a first preset time length is detected. In the case where the central controller does not receive the first key and / or the first check code within the first preset time length, the anti-theft authentication is performed again according to the first key and the second key in response to the anti-theft authentication request signal.

[0090] The first preset time length can be 5 seconds or 10 seconds, which can be set according to actual anti-theft authentication requirements, and the specific value of the first preset time length is not limited in the present application.

[0091] Since the present application simultaneously performs the handshake authentication and the key authentication, in the case where the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, the area controller obtains a first check code calculated according to the first key. The area controller sends the first key and the first check code to the central controller. The central controller obtains a second check code calculated according to the first key. In the case where the first check code and the second check code are consistent, success information of the anti-theft authentication is generated.

[0092] It should be noted that the process of the handshake authentication and the process of the key authentication are independent of each other and do not interfere with each other. When the handshake authentication passes and the key authentication also passes, success information of the anti-theft authentication is generated, otherwise, failure information of the anti-theft authentication is generated.

[0093] It should be noted that when the result of the handshake authentication is the handshake authentication success information, the handshake authentication success information will be saved for a period of time, and then the handshake authentication is performed again, that is, the handshake authentication is continuously performed within a certain time period until the central controller is in the sleep state. Therefore, the central controller is in the wake-up state, and the handshake authentication is continuously performed within a certain time period, which can ensure that the user can quickly complete the double verification after triggering the key authentication, thereby improving the driving experience of the user.

[0094] Compared with the prior art, the embodiment has at least the following advantages:

[0095] When responding to the anti-theft authentication request signal, the vehicle needs to perform anti-theft authentication to ensure the safety of the vehicle. First, the first encrypted data, the second encrypted data, the first key and the second key are obtained. Then, it is detected whether the first encrypted data and the second encrypted data are consistent to determine whether the handshake authentication is successful, and whether the first key and the second key are consistent to determine whether the key authentication is successful. Finally, when it is detected that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful, and when it is detected that the first key and the second key are consistent, it indicates that the key authentication is successful. In the case where it is determined that the handshake authentication and the key authentication are both successful, an anti-theft authentication success information is generated. The vehicle anti-theft authentication method simultaneously performs double verification of handshake authentication and key authentication, and in the process of key authentication, uses the E2E verification algorithm to improve the security of message transmission and the vehicle.

[0096] Reference Figure 2 As shown in FIG. 8, a step flow chart of the handshake authentication provided by the embodiment of the application is shown. As described above, after the central controller sends the random code to the area controller, it continuously determines whether the second encrypted data sent by the area controller is received. Figure 2 The processing process after the central controller determines whether the second encrypted data is received. The specific steps include:

[0097] Step 201, detecting whether the central controller receives the second encrypted data within a second preset time length.

[0098] In the embodiment, since the central controller needs to detect whether the first encrypted data calculated by itself is consistent with the second encrypted data calculated by the area controller. Therefore, the central controller needs to detect whether the second encrypted data sent by the area controller is received within a second preset time length, so as to avoid the problem that the handshake authentication cannot be performed due to the long time of not receiving the second encrypted data.

[0099] The second preset time length can be set to 10 seconds or 15 seconds, and the actual anti-theft authentication timeliness requirement can be set, and the application does not limit the specific value of the second preset time length.

[0100] Step 202, if the central controller does not receive the second encrypted data within the second preset time length, the central controller sends the random code to the area controller again.

[0101] In this embodiment, if the central controller does not receive the second encrypted data within the second preset time length, the area controller may not receive the random code sent by the central controller. In order to avoid the problem that the handshake authentication cannot be performed, the central controller sends the random code to the area controller again. The area controller calculates the second encrypted data according to the second fixed code and the random code by using the anti-theft algorithm, and sends the second encrypted data to the central controller. The central controller detects whether the first encrypted data and the second encrypted data are consistent.

[0102] It should be noted that the random code sent by the central controller to the area controller again can be the same as or different from the random code sent to the area controller before, and the present application does not limit this.

[0103] Step 203, obtain the sending times of the random code sent by the central controller to the area controller.

[0104] In this embodiment, the sending times are the total times of the random code sent by the central controller to the area controller in the historical period.

[0105] Step 204, generate an anti-theft authentication failure information in the case that the sending times are not less than a preset number threshold.

[0106] In this embodiment, in order to avoid the case that the central controller sends the random code to the area controller multiple times and does not receive the second encrypted data feedback by the area controller, resulting in the handshake authentication cannot be performed. The sending times of the random code sent by the central controller to the area controller are obtained, and it is detected whether the sending times are less than the preset number threshold.

[0107] If it is detected that the sending times are not less than the preset number threshold, it indicates that the central controller sends the random code to the area controller multiple times, so that the area controller can calculate the second encrypted data according to the second fixed code and the random code by using the anti-theft algorithm in time. However, there may be a case that the area controller fails to feedback the second encrypted data to the central controller, therefore, the anti-theft authentication failure information is generated.

[0108] The preset number threshold can be 5 times, 8 times or 10 times, which can be set according to actual needs, and the present application does not limit this.

[0109] Step 205, calculate the time difference between the current time and the generation time of the anti-theft authentication failure information.

[0110] In the embodiment, the generation time of the anti-theft authentication failure information is acquired, and the difference between the current time and the generation time is taken as the time difference.

[0111] In step 206, in the case that the time difference is greater than the preset time difference, a new random code is generated by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data.

[0112] In the embodiment, the random code generated after the generation of the anti-theft authentication failure information is different from the random code generated before the generation of the anti-theft authentication failure information. In this way, the central controller calculates new first encrypted data based on the new random code, and the regional controller calculates new second encrypted data based on the new random code, so that subsequent handshake authentication can be performed again, and the success rate of the handshake authentication is improved.

[0113] In step 207, the new random code is sent to the regional controller by the central controller.

[0114] In the embodiment, the central controller sends the new random code to the regional controller by CANFD message.

[0115] In step 208, the new random code and the second fixed code are symmetrically encrypted by the regional controller to obtain new second encrypted data.

[0116] In the embodiment, the regional controller symmetrically encrypts the new random code and the second fixed code pre-stored by itself by using the anti-theft algorithm to obtain the new second encrypted data.

[0117] It should be noted that, since the new random code is different from the random code before the generation of the anti-theft authentication failure information, the new first encrypted data calculated by the central controller is also different from the previous first encrypted data. Similarly, the new second encrypted data calculated by the regional controller is also different from the previous second encrypted data.

[0118] In step 209, it is detected whether the new first encrypted data and the new second encrypted data are consistent, and in the case that the central controller is in the sleep state, the generation of the new random code is stopped by the central controller.

[0119] In the case that the central controller is in the wake-up state, in the case that the new first encrypted data and the new second encrypted data are detected to be inconsistent, the above steps are repeated until the first encrypted data and the second encrypted data are detected to be consistent, and the handshake authentication is successful, or until the central controller is in the sleep state, the generation of the new random code is stopped by the central controller, and the process of the handshake authentication is suspended. In this way, after the anti-theft authentication failure information is generated one or more times, the handshake authentication can be performed again after a period of time, so as to improve the probability of passing the anti-theft authentication.

[0120] Compared with the prior art, the embodiment has at least the following advantages:

[0121] After the central controller sends the random code to the area controller, it is detected whether the central controller receives the second encrypted data within a second preset time length, to avoid the problem that the handshake authentication cannot be performed due to the long time of not receiving the second encrypted data. If the central controller does not receive the second encrypted data within the second preset time length, the central controller is controlled to send the random code to the area controller again, and the area controller calculates the second encrypted data. Thus, the situation that the handshake authentication cannot be performed due to the fact that the area controller does not receive the random code sent by the central controller is avoided. Meanwhile, it is detected whether the sending times are less than a preset number threshold, to avoid the situation that the central controller sends the random code to the area controller for multiple times, but the second encrypted data fed back by the area controller is not received all the time, and the situation that the area controller is faulty and cannot feed back the second encrypted data to the central controller occurs. The anti-theft authentication failure information is directly generated, to ensure the safety of the vehicle.

[0122] Reference Figure 3 Fig. 4 shows another step flowchart of the handshake authentication provided by the embodiment of the application. In the embodiment, Figure 3 Fig. 5 shows a process after the first encrypted data and the second encrypted data are detected to be inconsistent in the handshake authentication. The specific steps include:

[0123] Step 301: In the case that the first encrypted data and the second encrypted data are detected to be inconsistent, a new random code is generated again by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data.

[0124] As described above, in the handshake authentication, it is detected whether the first encrypted data and the second encrypted data are consistent. If the first encrypted data and the second encrypted data are detected to be inconsistent, it indicates that the handshake authentication has not been successful. In order to increase the success rate of the handshake authentication, the central controller can be controlled to generate a new random code again, and the new random code and the first fixed code are symmetrically encrypted to obtain new first encrypted data. The central controller performs the handshake authentication based on the new random code subsequently.

[0125] It should be noted that in the case that the first encrypted data and the second encrypted data are detected to be inconsistent, the new random code generated by the central controller again can be the same as or different from the previous random code.

[0126] Step 302: The new random code is sent to the area controller by the central controller, and the area controller is controlled to symmetrically encrypt the new random code and the second fixed code pre-stored by itself to obtain new second encrypted data.

[0127] In the embodiment, the central controller sends the new random code to the area controller in the form of a CANFD message.

[0128] Step 303: Obtain the number of times the central controller sends the random code to the area controller.

[0129] In the embodiment, the total number of times the central controller sends the random code to the area controller in the historical period is obtained.

[0130] Step 304: Perform anti-theft authentication according to the new first encrypted data and the new second encrypted data, until an anti-theft authentication failure information is generated in the case that the number of times is not less than a preset number threshold.

[0131] In the embodiment, when the number of times is not less than the preset number threshold, it indicates that the central controller sends the random code to the area controller multiple times, and then detects whether the first encrypted data and the second encrypted data are consistent multiple times. And in the case that the first encrypted data and the second encrypted data are detected to be inconsistent multiple times, the handshake authentication fails, that is, the anti-theft authentication failure information is generated.

[0132] Step 305: Calculate the time difference between the current time and the generation time of the anti-theft authentication failure information.

[0133] In order to avoid the situation that the first encrypted data and the second encrypted data are detected to be inconsistent multiple times due to the failure of the central controller and / or the area controller, and the handshake authentication cannot be passed, after a period of time after the anti-theft authentication failure information is generated, the handshake authentication can be performed again. At this time, the time difference between the current time and the generation time of the anti-theft authentication failure information needs to be calculated. Whether the time difference is greater than a preset time difference is detected to determine whether the handshake authentication needs to be performed again.

[0134] Step 306: In the case that the time difference is greater than the preset time difference, a new random code is generated by the central controller, and the new random code and the first fixed code are symmetrically encrypted to obtain the new first encrypted data.

[0135] As shown above, after the anti-theft authentication failure information is generated, the new random code generated by the central controller is not the same as the previous random code.

[0136] Step 307: The central controller sends the new random code to the area controller, and controls the area controller to perform symmetric encryption on the new random code and the second fixed code to obtain the new second encrypted data.

[0137] Step 308, detecting whether the new first encrypted data and the new second encrypted data are consistent, until the central controller is in the sleep state, stopping the central controller from generating a new random code.

[0138] Steps 306 to 308 are the same as the contents of steps 216 to 219, and are not repeated here.

[0139] Compared with the prior art, the embodiment has at least the following advantages:

[0140] In the case where the first encrypted data and the second encrypted data are detected to be inconsistent, it indicates that the handshake authentication has not been successful. In order to increase the success rate of the handshake authentication, the central controller can generate a new random code multiple times, so that the central controller and the area controller can calculate new first encrypted data and new second encrypted data based on the new random code. The first encrypted data and the second encrypted data are compared again to increase the pass rate of the handshake authentication. At the same time, if the central controller is in the wake-up state, if the anti-theft authentication failure information is generated, and after a period of time, a random code different from the previous one can be generated by the central controller, and the handshake authentication is performed again based on the new different random code, so as to increase the authentication times of the handshake authentication.

[0141] Reference Figure 4 Fig. 1 is a schematic diagram of the interaction between the central controller, the area controller and the key provided by the embodiment of the application when performing the anti-theft authentication. The embodiment takes the handshake authentication with the central controller as the execution subject and the key authentication with the area controller as the execution subject as an example for description.

[0142] Step S11, the central controller generates a random code, and performs symmetric encryption processing on the random code and a first fixed code pre-stored by itself to obtain first encrypted data.

[0143] As described above, when the user carries the key close to the new energy vehicle, the central controller will be woken up, and the central controller will generate a first authentication request signal and a random code. The random code and a first fixed code pre-stored by itself are symmetrically encrypted by using an anti-theft algorithm to obtain first encrypted data.

[0144] Step S12, the central controller sends the random code to the area controller.

[0145] In the embodiment, the central controller sends the random code to the area controller in the form of a CANFD message.

[0146] Step S13, the area controller performs symmetric encryption processing on the random code and a second fixed code pre-stored by itself to obtain second encrypted data.

[0147] In the embodiment, after the area controller receives the random code sent by the central controller, the area controller will use the anti-theft algorithm to symmetrically encrypt the random code and the second fixed code pre-stored by itself to obtain second encrypted data.

[0148] In step S14, the area controller sends the second encrypted data to the central controller.

[0149] In step S15, the central controller detects whether the first encrypted data and the second encrypted data are consistent, and generates a handshake authentication pass information in the case where it is detected that the first encrypted data and the second encrypted data are consistent.

[0150] In the embodiment, in the case where the central controller detects that the first encrypted data and the second encrypted data are consistent, it indicates that the handshake authentication is successful, and then the handshake authentication pass information is generated.

[0151] In step S21, the key sends a second key to the area controller.

[0152] In step S22, the area controller detects whether the first key and the second key of itself are consistent, and generates a key authentication success information in the case where it is detected that the first key and the second key are consistent.

[0153] In the embodiment, when the user steps on the brake or other controller issues a driving request, a second authentication request signal is generated, the new energy vehicle responds to the second authentication request signal, and the area controller acquires the first key of itself and the second key of the key.

[0154] In the embodiment, in the case where the area controller detects that the first key and the second key are consistent, it indicates that the key authentication is successful, and then the key authentication success information is generated.

[0155] In step S23, the area controller sends the key authentication success information to the central controller.

[0156] In step S16, the central controller generates an anti-theft authentication success information based on the handshake authentication pass information and the key authentication success information.

[0157] In the embodiment, the area controller sends the key authentication success information to the central controller, and the central controller generates the anti-theft authentication success information based on the double authentication pass information of the handshake authentication pass information and the key authentication success information. In this way, the new energy vehicle enters the drivable state and the user is allowed to switch the gear of the new energy vehicle.

[0158] Compared with the prior art, the embodiment has at least the following advantages:

[0159] When the vehicle needs to be authenticated, dual authentication of handshake authentication and key authentication is performed. In the case where both the handshake authentication and the key authentication are successful, anti-theft authentication success information is generated. In this way, the safety of the vehicle is improved.

[0160] As shown in Figure 5 The embodiments of the present application also provide a hardware structure diagram of a vehicle controller. The vehicle controller 1000 can include a processor 1001 and a memory 1002. The memory 1002 is configured to store one or more computer programs 1003. The one or more computer programs 1003 are configured to be executed by the processor 1001. The one or more computer programs 1003 include instructions. The vehicle controller 1000 can be a regional controller, a central controller, etc.

[0161] It can be understood that the structure shown in the embodiments does not constitute a specific limitation on the vehicle controller 1000. In other embodiments, the vehicle controller 1000 can include more or fewer components than shown, or combine certain components, or split certain components, or different component arrangements.

[0162] The processor 1001 can include one or more processing units. For example, the processor 1001 can include an application processor (AP), a modem, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units can be independent devices or integrated into one or more processors 1001.

[0163] The processor 1001 can also be provided with a memory 1002 for storing instructions and data. In some embodiments, the memory 1002 in the processor 1001 is a cache memory. The memory 1002 can save instructions or data that the processor 1001 has just used or repeatedly uses. If the processor 1001 needs to use the instructions or data again, it can be directly called from the memory 1002. This avoids repeated access and reduces the waiting time of the processor 1001, thereby improving the efficiency of the system.

[0164] In some embodiments, the processor 1001 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM interface, and / or a USB interface, etc.

[0165] In some embodiments, the processor 1001 is configured to execute single instruction multiple data (SIMD), very long instruction word (VLIW), or other acceleration schemes.

[0166] In some embodiments, the memory 1002 can include a high-speed random access memory, and can further include a non-volatile memory, such as a hard disk, a memory card, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory device.

[0167] The embodiments also provide a vehicle, which can be used to execute the above-mentioned related method steps to implement the methods in the above embodiments.

[0168] In the embodiments, the vehicle controller 1000 and the vehicle are configured to execute the corresponding methods provided above, and thus can achieve the beneficial effects of the corresponding methods provided above, which will not be described here again.

[0169] In practical applications, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0170] In several embodiments provided in the present application, the disclosed apparatus and method can be implemented in other manners. For example, the division of the apparatus embodiments described above is merely illustrative. For example, the division of the modules or units can be other division manners. For example, multiple units or components can be combined or integrated into another apparatus, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, apparatuses or units, and can be in electrical, mechanical or other forms.

[0171] The units described as separate components can or can not be physically separate, and the components shown as units can be one physical unit or multiple physical units, i.e., can be located in one place, or can be distributed in multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the embodiments.

[0172] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0173] When the integrated unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solutions of the embodiments of the present application essentially or the parts that make contributions to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The software product is stored in a storage medium, and includes several instructions to make a device (which can be a single-chip microcomputer, a chip, etc.) or a processor execute all or part of the steps of the method described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.

[0174] The above description is merely a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application should be covered within the protection scope of the present application.

Claims

1. A vehicle theft prevention authentication method characterized by comprising: The application is applied to a vehicle, the vehicle comprises a central controller, a regional controller and a key, the central controller, the regional controller and the key are connected with each other, the central controller is used for sending a control instruction to the regional controller, the regional controller is used for controlling the vehicle to perform corresponding operation according to the control instruction, and the key is used for unlocking the vehicle; the method comprises the following steps: In response to an anti-theft authentication request signal, first encrypted data of the central controller, second encrypted data of the regional controller, a first key pre-stored by the regional controller and a second key pre-stored by the key are acquired, the first encrypted data acquisition step comprises the following steps: generating a random code by the central controller, and performing symmetric encryption processing on the random code and a first fixed code pre-stored by itself to obtain the first encrypted data, wherein the random code is data randomly generated by the central controller; It is detected whether the first encrypted data and the second encrypted data are consistent, and whether the first key and the second key are consistent; In the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, anti-theft authentication success information is generated; After detecting whether the first encrypted data and the second encrypted data are consistent, the following steps are further included: In the case that the first encrypted data and the second encrypted data are inconsistent, a new random code is generated by the central controller, and symmetric encryption processing is performed on the new random code and the first fixed code to obtain new first encrypted data; The new random code is sent to the regional controller by the central controller; The new random code and a second fixed code pre-stored by the regional controller are subjected to symmetric encryption processing by the regional controller to obtain new second encrypted data; The number of times that the central controller sends the random code to the regional controller is acquired, wherein the number of times is the total number of times that the central controller sends the random code to the regional controller in a historical period; Anti-theft authentication is performed according to the new first encrypted data and the new second encrypted data, and until in the case that the number of times is not less than a preset number of times threshold, anti-theft authentication failure information is generated; After the anti-theft authentication failure information is generated, the following steps are further included: The time difference between the current time and the generation time of the anti-theft authentication failure information is calculated; In the case that the time difference is greater than a preset time difference, a new random code is generated again by the central controller.

2. The vehicle theft prevention authentication method according to claim 1, characterized by, In the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, the following steps are included: In the case that the first encrypted data and the second encrypted data are consistent, and the first key and the second key are consistent, a first check code calculated by the regional controller according to the first key is acquired; The first key and the first check code are sent to the central controller by the regional controller; acquiring a second check code calculated by the central controller according to the first key; generating the anti-theft authentication success information in a case where the first check code and the second check code are consistent.

3. The vehicle theft prevention authentication method according to claim 1, characterized by, After the detecting whether the first key and the second key are consistent, further comprising: acquiring a first check code calculated by the area controller according to the first key in a case where it is detected that the first key and the second key are consistent; sending the first key and the first check code to the central controller by the area controller; detecting whether the central controller receives the first key and the first check code within a first preset time length; in a case where it is detected that the central controller does not receive the first key and / or the first check code within the first preset time length, again performing anti-theft authentication according to the first key and the second key in response to the anti-theft authentication request signal.

4. The vehicle theft prevention authentication method according to claim 1, characterized by, The acquiring of the second encrypted data comprises: sending the random code to the area controller by the central controller; performing symmetric encryption processing on the random code and a second fixed code pre-stored by the area controller to obtain the second encrypted data.

5. The vehicle theft prevention authentication method according to claim 4, characterized by, After the performing symmetric encryption processing on the random code and the second fixed code pre-stored by the area controller to obtain the second encrypted data, further comprising: sending the second encrypted data to the central controller by the area controller; detecting whether the central controller receives the second encrypted data within a second preset time length; if the central controller does not receive the second encrypted data within the second preset time length, sending the random code to the area controller again by the central controller.

6. The vehicle theft prevention authentication method according to claim 5, characterized by, After the sending the random code to the area controller again by the central controller, further comprising: acquiring a sending frequency of sending the random code to the area controller by the central controller, wherein the sending frequency is a total number of times of sending the random code to the area controller by the central controller within a historical period; generating anti-theft authentication failure information in a case where the sending frequency is not less than a preset frequency threshold.

7. The vehicle theft prevention authentication method according to claim 1, characterized by, After the generating the new random code again by the central controller, further comprising: performing symmetric encryption processing on the new random code and the first fixed code to obtain new first encrypted data; sending the new random code to the area controller by the central controller; performing symmetric encryption processing on the new random code and the second fixed code by the area controller to obtain new second encrypted data; detecting whether the new first encrypted data and the new second encrypted data are consistent, and stopping generating the new random code by the central controller in a case where the central controller is in a hibernation state.

8. A vehicle characterized by comprising: The vehicle is configured to perform the vehicle anti-theft authentication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for anti-theft authentication of pure electric vehicle

    CN106627489A

  • Vehicle anti-theft method and device, storage medium, vehicle control unit and vehicle

    CN112693425A