Protection method and system for version fallback attack
By building a comprehensive protection system of multi-dimensional information and technology, multiple verifications of upgrade packages and authorization files are solved, and the problem of difficult to effectively protect version fallback attacks in the existing technology is significantly improved.
Patent Information
- Application Number
- CN202510259157.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-03-06
Smart Images

Figure CN119996036A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of automobile information security, and in particular relates to a protection method and system against version rollback attacks. Background Art
[0002] With the rapid development of intelligent and connected cars, Over-The-Air (OTA) technology has been widely used in software updates, bringing great convenience to users, such as allowing car manufacturers to remotely update software to improve vehicle performance, fix security vulnerabilities, and add new features. However, OTA technology also faces many security threats; among them, version rollback attacks are a common and serious attack method, which means that attackers use historical versions of upgrade packages and authorization files to force the vehicle software version to roll back to an old version with known vulnerabilities, thereby exploiting these vulnerabilities to gain control of the vehicle, endangering vehicle driving safety and user privacy.
[0003] In order to prevent version rollback attacks, although the existing technology provides protection to a certain extent, the protection means are relatively single and lack a comprehensive protection system, making it difficult to effectively resist complex and changeable attack scenarios; therefore, it is necessary to study a more comprehensive and effective protection system to ensure the safety and reliability of the vehicle. Summary of the invention
[0004] The purpose of the present invention is to overcome the deficiencies in the prior art and provide a method and system for protecting against version rollback attacks. By integrating multi-dimensional information and technology, an all-round protection system is constructed to effectively protect against version rollback attacks and improve the security and reliability of the version rollback mechanism.
[0005] To achieve the above object, the present invention is implemented by adopting the following technical solutions: In a first aspect, the present invention provides a protection method for version rollback attacks, the method being applied to a protection system, the protection system comprising a device end and a service end, the device end comprising a vehicle terminal and a mobile phone end, the service end referring to the destination end to which the device end requests communication, including an OTA platform and various service provision platforms; the method comprising: The device sends a version rollback request to the server; The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value, generates an identity identification number, calculates the first counter value, sets the operation type, obtains the first timestamp, and assembles the rollback version authorization file structure; The server signs the fallback version authorization file structure, generates a signature value, and constructs the fallback version authorization file; The server sends the upgrade package and the rollback version authorization file to the device; The device side sequentially performs a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to the verification being passed, the device performs version rollback.
[0006] In a second aspect, the present invention further provides a method for protecting against version rollback attacks, the method being applied to a server and comprising: Receive the version rollback request sent by the device; Collect version rollback information according to the version rollback request, and sequentially determine the upgrade package, calculate the first hash value, generate an identity identification number, calculate the first counter value, set the operation type, obtain the first timestamp, and assemble the rollback version authorization file structure; Signing the fallback version authorization file structure, generating a signature value, and constructing a fallback version authorization file; Send the upgrade package and the rollback version authorization file to the device end.
[0007] In combination with the second aspect, further, the version rollback information includes vehicle equipment information and software version information; The vehicle equipment information includes a vehicle identification number and an electronic controller unit serial number; The software version information includes the software name, the current software version number, the fallback software version number, and the second counter value in the current version authorization file.
[0008] In combination with the second aspect, further, the step of sequentially determining the upgrade package, calculating the first hash value, generating the identity identification number, calculating the first counter value, setting the operation type, obtaining the first timestamp, and assembling the rollback version authorization file structure includes: According to the software name and the rollback software version number, query and determine the rollback upgrade package; Performing a hash operation on the upgrade package to obtain a first hash value; Generate a unique identifier as the identification number of the fallback version authorization file; Adding one to the second counter value to obtain a first counter value; Set the operation type to version rollback operation; Get the current time as the first timestamp; The vehicle identification number, electronic controller unit serial number, software name, current software version number, fallback software version number, first hash value, identity identification number, first counter value, operation type and first timestamp are assembled to generate a fallback version authorization file structure.
[0009] In combination with the second aspect, further, signing the fallback version authorization file structure, generating a signature value, and constructing the fallback version authorization file includes: Use the private key to sign the rollback version authorization file structure to obtain a signature value; The fallback version authorization file structure, the signature value and the signature algorithm used for the signature are combined to generate a fallback version authorization file.
[0010] In combination with the second aspect, further, the fallback version authorization file structure and the fallback version authorization file are both in JSON format.
[0011] In a third aspect, the present invention further provides a method for protecting against version rollback attacks, the method being applied to a device end and comprising: Send a version rollback request to the server; Receive an upgrade package and a rollback version authorization file sent by a server, wherein the upgrade package is determined by the server according to the collected version rollback information, and the rollback version authorization file is constructed by the server according to the version rollback information, sequentially calculating a first hash value, generating an identity identification number, calculating a first counter value, setting an operation type, obtaining a first timestamp, and assembling a rollback version authorization file structure, and then signing the rollback version authorization file structure to generate a signature value; Sequentially perform a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to all verifications passing, version rollback is performed.
[0012] In combination with the third aspect, further, the fallback version authorization file includes the fallback version authorization file structure, signature value and signature algorithm used for the signature; the fallback version authorization file structure includes the vehicle identification number, electronic controller unit serial number, software name, current software version number, fallback software version number, first hash value, identity identification number, first counter value, operation type and first timestamp.
[0013] In combination with the third aspect, further, the step of sequentially performing a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file includes: Performing a hash operation on the upgrade package to obtain a second hash value; Use the server public key to verify the signature of the rollback version authorization file; In response to the first hash value being inconsistent with the second hash value and / or the signature verification failing, refusing version rollback, otherwise, using the server public key to verify the signature of the local current version authorization file; In response to a signature verification failure, rejecting version rollback, otherwise, obtaining a local vehicle identification number and a local electronic controller unit serial number; In response to the local vehicle identification number being inconsistent with the vehicle identification number in the fallback version authorization file and / or the local current version authorization file, and the local electronic controller unit serial number being inconsistent with the electronic controller unit serial number in the fallback version authorization file and / or the local current version authorization file, rejecting version rollback, otherwise, extracting the operation type, current software version number and fallback software version number in the fallback version authorization file; In response to the operation type being a non-rollback operation, or the operation type being a rollback operation and the current software version number being less than or equal to the rollback software version number, refusing version rollback, otherwise, extracting the first timestamp and the timestamp in the local current version authorization file; In response to the first timestamp being less than or equal to the timestamp in the local current version authorization file, rejecting version rollback, otherwise, extracting the first counter value and the counter value in the local current version authorization file; In response to the first counter value being less than or equal to the counter value in the local current version authorization file, version rollback is rejected; otherwise, version rollback is performed.
[0014] In a fourth aspect, the present invention further provides a protection system against version rollback attacks, the protection system comprising a device end and a service end, the device end comprising a vehicle terminal and a mobile phone end, the service end refers to the destination end to which the device end requests communication, including an OTA platform and various service provision platforms; the protection system is used to implement the following protection method: The device sends a version rollback request to the server; The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value, generates an identity identification number, calculates the first counter value, sets the operation type, obtains the first timestamp, and assembles the rollback version authorization file structure; The server signs the fallback version authorization file structure, generates a signature value, and constructs the fallback version authorization file; The server sends the upgrade package and the rollback version authorization file to the device; The device side sequentially performs a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to the verification being passed, the device performs version rollback.
[0015] Compared with the prior art, the present invention has the following beneficial effects: The protection method and system against version rollback attacks provided by the present invention build an all-round protection system by integrating multi-dimensional information and technologies such as digital signatures, operation types, timestamps, one-way counters, and vehicle equipment information; by performing multiple checks on upgrade packages and authorization files, version rollback attacks are effectively protected, greatly improving the security and reliability of the version rollback mechanism. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 It is a flow chart of a protection method against version rollback attacks provided by an embodiment of the present invention; Figure 2 It is a flow chart of a method for protecting a server against version rollback attacks provided by an embodiment of the present invention; Figure 3 It is a flowchart of a device-side protection method against version rollback attacks provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] The present invention will be further described below in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and cannot be used to limit the protection scope of the present invention.
[0019] Embodiment 1
[0020] This embodiment provides a protection method against version rollback attacks. In order to illustrate the method, the protection system for executing the method is introduced first. The system includes a device side and a server side. The device side includes related software and hardware resources such as vehicle terminals and mobile phones. The server side refers to the destination of the device side requesting communication, including OTA platforms and various service provision platforms, etc., and does not specifically refer to a server.
[0021] like Figure 1 FIG. 1 is a flow chart of the method provided in this embodiment, and the method mainly includes the following steps: S101: The device sends a version rollback request to the server; S102: The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value Hash1, generates the identity identification number LicenseID, calculates the first counter value CounterValue1, sets the operation type OpType, obtains the first timestamp GenerateTime1, and assembles the rollback version authorization file structure tbs (to be signed structure); S103: The server signs the rollback version authorization file structure tbs, generates a signature value Signature, and constructs the rollback version authorization file; S104: The server sends the upgrade package and the rollback version authorization file to the device; S105: The device performs a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file in sequence; S106: In response to the verification being passed, the device performs version rollback.
[0022] Specifically, the protection method provided in this embodiment mainly includes two process steps: a server-side authorization process composed of step S102 and step S103, and a device-side verification process corresponding to step S105.
[0023] It should be noted that in this embodiment, the device end is a vehicle-mounted terminal and the server end is an OTA platform. In actual applications, the device end can also be a smart phone, smart home device or various IoT devices, etc.; the server end can also be a manufacturer's server, a supplier's server or a cloud computing platform, etc.; it needs to be selected and judged according to the actual situation, as long as the steps of the corresponding method can be executed.
[0024] The protection method against version rollback attacks provided in this embodiment builds a comprehensive protection system by integrating multi-dimensional information and technologies such as digital signatures, operation types, timestamps, one-way counters, and vehicle equipment information. By performing multiple checks on upgrade packages and authorization files, version rollback attacks are effectively protected, greatly improving the security and reliability of the version rollback mechanism.
[0025] Embodiment 2
[0026] This embodiment provides a protection method against version rollback attacks. Figure 2 , is a flow chart of the method provided in this embodiment, the method is applied to the server, and mainly includes the following steps: S201: receiving a version rollback request sent by a device; S202: Collect version rollback information according to the version rollback request, and sequentially determine the upgrade package, calculate the first hash value Hash1, generate the identity identification number LicenseID, calculate the first counter value CounterValue1, set the operation type OpType, obtain the first timestamp GenerateTime1, and assemble the rollback version authorization file structure tbs; S203: Sign the rollback version authorization file structure tbs, generate a signature value Signature, and construct the rollback version authorization file; S204: Send the upgrade package and rollback version authorization file to the device.
[0027] Specifically, the server authorization process mainly refers to step S202 and step S203. Before starting the authorization process, the server first needs to collect version rollback information according to the version rollback request, mainly including the vehicle equipment information and software version information that need to be rolled back; among them, the vehicle equipment information mainly includes the vehicle identification number VIN and the electronic controller unit serial number ECUSN; the software version information mainly includes the software name SoftwareName, the current software version number OldVersion, the rollback software version number TargetVersion and the second counter value CounterValue2 in the current version authorization file.
[0028] Further, such as Figure 2 As shown, the method of how to sequentially determine the upgrade package, calculate the first hash value, generate the identity identification number, calculate the first counter value, set the operation type, obtain the first timestamp, and assemble the rollback version authorization file structure in step S202 is further explained: S2021: query and determine the upgrade package to be rolled back according to the name of the software to be rolled back SoftwareName and the version number of the rolled back software TargetVersion; S2022: Use SHA512 or SM3 to perform hash calculation on the rolled-back upgrade package; S2023: Generate a unique identifier as the identity number LicenseID of the fallback version authorization file, wherein the identity number LicenseID may be composed of a timestamp in the format of yyyymmddhhmmss and a 16-byte random number to ensure the uniqueness of the identity number LicenseID; S2024: Add 1 to the second counter value CounterValue2 to obtain the first counter value CounterValue1, that is, ; S2025: Setting the operation type OpType to a version rollback operation, wherein if OpType is 1, it represents a software upgrade operation, and OpType is 2, it represents a version rollback operation, then OpType is set to 2; S2026: Acquire the current time of the server as the generation time of the fallback version authorization file, and the format of the first timestamp GenerateTime1 is yyyymmddhhmmss; S2027: Assemble the vehicle identification number VIN, the electronic controller unit serial number ECUSN, the software name SoftwareName, the current software version number OldVersion, the fallback software version number TargetVersion, the first hash value Hash1, the identity identification number LicenseID, the first counter value CounterValue1, the operation type OpType and the first timestamp GenerateTime1 to generate the fallback version authorization file structure tbs to be signed.
[0029] In this embodiment, the processing of the rollback version authorization file structure in step S203 mainly includes the following steps: S2031: Use the rollback version authorization file structure tbs as the signature original text, use the server private key to sign the rollback version authorization file structure tbs, and obtain the signature value Signature; wherein the digital signature algorithm SignatureAlgorithm used for the signature can be SHA512WithECDSA or SM3WithSM2; S2032: Combine the rollback version authorization file structure tbs, the signature value Signature, and the signature algorithm SignatureAlgorithm used for the signature to generate a rollback version authorization file.
[0030] It should be noted that the fallback version authorization file structure tbs and the fallback version authorization file can both be in JSON format, and each field and data is represented in a key-value pair, which helps to query and obtain the corresponding data according to the corresponding field. In practical applications, the format of the fallback version authorization file structure tbs and the fallback version authorization file can also be other data formats that are easy to query and obtain data. In addition, the hash algorithm and the digital signature algorithm can also be other algorithms as long as the corresponding operation effect can be achieved.
[0031] The protection method against version rollback attacks provided in this embodiment forms a comprehensive and multi-level protection system by integrating multi-dimensional information and technologies such as digital signatures, operation types, timestamps, one-way counters, and vehicle equipment information. It can effectively protect against various complex version rollback attack methods.
[0032] This flowchart only shows the logical sequence of the method described in this embodiment. In other possible embodiments of the present invention, different methods may be used without conflict. Figure 2 The steps shown or described are completed in the order shown. The protection method against version rollback attacks provided in this embodiment can be applied to a terminal, and can be performed by a protection device against version rollback attacks, which can be implemented by software and / or hardware, and can be integrated in a terminal, for example: any smart phone, tablet computer or computer device with communication function.
[0033] Embodiment 3
[0034] This embodiment provides a protection method against version rollback attacks. Figure 3 , is a flow chart of the method provided in this embodiment, the method is applied to the device side, and mainly includes the following steps: S301: Send a version rollback request to the server; S302: receiving the upgrade package and the rollback version authorization file sent by the server, wherein the upgrade package is determined by the server according to the collected version rollback information, and the rollback version authorization file is constructed by the server according to the version rollback information, sequentially calculating the first hash value Hash1, generating the identity identification number LicenseID, calculating the first counter value CounterValue1, setting the operation type OpType, obtaining the first timestamp GenerateTime1, assembling the rollback version authorization file structure tbs, and then signing the rollback version authorization file structure tbs to generate the signature value Signature; S303: performing a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file in sequence; S304: In response to all verifications passing, version rollback is performed.
[0035] Specifically, the device-side inspection process mainly refers to step S303. Before executing the inspection process, the device side needs to receive the upgrade package required for rollback from the server side and the rollback version authorization file returned after the server side authorizes the version rollback request submitted by the device side. Among them, the rollback version authorization file mainly includes the rollback version authorization file structure tbs, the signature value Signature and the signature algorithm SignatureAlgorithm used for the signature; the rollback version authorization file structure tbs includes the vehicle identification number VIN, the electronic controller unit serial number ECUSN, the software name SoftwareName, the current software version number OldVersion, the rollback software version number TargetVersion, the first hash value Hash1, the identity identification number LicenseID, the first counter value CounterValue1, the operation type OpType and the first timestamp GenerateTime1.
[0036] Further, such as Figure 3 As shown, the method of how to perform the first legitimacy check, the second legitimacy check, the device information consistency check, the operation type check, the timestamp check and the counter value check on the upgrade package and the rollback version authorization file in step S303 is further explained: S3031: Perform a hash operation on the upgrade package to obtain a second hash value Hash2; S3032: Use the server public key to verify the signature of the rollback version authorization file; S3033: In response to the inconsistency between the first hash value Hash1 and the second hash value Hash2 and / or the signature verification fails, reject the version rollback, otherwise, use the server public key to verify the signature of the local current version authorization file;
[0037] In the above steps, the device performs a first legitimacy check on the upgrade package and the rollback version authorization file, and realizes the authenticity and legitimacy of the upgrade package and the authorization data: the rollback upgrade package sent by the server is calculated by a hash algorithm to obtain a second hash value Hash2, wherein the hash algorithm should be the same as the hash algorithm used to generate the first hash value Hash1. Then the signature value Signature of the rollback version authorization file is verified and decrypted using the server public key and signature algorithm SignatureAlgorithm, wherein the signature algorithm SignatureAlgorithm should be the same as the algorithm used to generate the signature value Signature; if the signature verification passes, the first hash value Hash1 in the rollback version authorization file will be obtained. Finally, the first hash value Hash1 obtained after decryption is compared with the second hash value Hash2 generated by local calculation; if they are consistent, it means that the upgrade package has not been tampered with during the transmission process, the first legitimacy check passes, and the next check is continued; if they are inconsistent or the signature verification fails, it means that the upgrade package or the signature value Signature may be tampered with, and the device will refuse to roll back the version.
[0038] S3034: In response to the signature verification failure, reject the version rollback, otherwise, obtain the local vehicle identification number and the local electronic controller unit serial number; In the above steps, the device performs a second legitimacy check on the local current version of the authorization file to ensure the authenticity and legitimacy of the authorization data: the server public key and signature algorithm SignatureAlgorithm are used to verify the signature value of the local current version of the authorization file, where the signature algorithm SignatureAlgorithm should be the same as the algorithm used to generate the signature value Signature; if the signature verification passes, the second legitimacy check passes, and the next check is performed; if the signature verification fails, it means that the signature algorithm SignatureAlgorithm may have been tampered with, and the device will refuse to roll back the version.
[0039] S3035: In response to the local vehicle identification number being inconsistent with the vehicle identification number in the fallback version authorization file and / or the local current version authorization file, and the local electronic controller unit serial number being inconsistent with the electronic controller unit serial number in the fallback version authorization file and / or the local current version authorization file, rejecting version rollback, otherwise, extracting the operation type OpType, the current software version number OldVersion, and the fallback software version number TargetVersion in the fallback version authorization file; In the above steps, the device side performs a device information consistency check on the vehicle identification number and the electronic controller unit serial number to ensure the binding of the authorization information to the vehicle: first obtain the local vehicle identification number and the local electronic controller unit serial number. Then compare the local vehicle identification number, the vehicle identification number VIN in the fallback version authorization file, and the vehicle identification number in the local current version authorization file, and compare the local electronic controller unit serial number, the electronic controller unit serial number ECUSN in the fallback version authorization file, and the electronic controller unit serial number in the local current version authorization file. If the vehicle identification numbers are consistent and the electronic controller unit serial numbers are consistent, the device information consistency check passes and proceeds to the next check; if any of the items is inconsistent, it means that the vehicle device information stored on the server is wrong or there may be an illegal device attempting to perform a version rollback attack, and the device side will refuse the version rollback.
[0040] S3036: In response to the operation type OpType being a non-rollback operation, or the operation type OpType being a rollback operation and the current software version number OldVersion being less than or equal to the rollback software version number TargetVersion, rejecting version rollback, otherwise, extracting the first timestamp GenerateTime1 and the timestamp in the local current version authorization file; In the above steps, the device side performs an operation type check on the current software version number OldVersion and the rollback software version number TargetVersion, and realizes the confirmation of the rollback business behavior: first, it is necessary to extract the operation type OpType, the current software version number OldVersion, and the rollback software version number TargetVersion in the rollback version authorization file. If the operation type OpType is 1, it means that a software upgrade is required, and the device side will refuse version rollback. If the operation type OpType is 2, it means that a version rollback is required. At this time, it is also necessary to compare the current software version number OldVersion and the rollback software version number TargetVersion; if the current software version number OldVersion is greater than the rollback software version number TargetVersion, it corresponds to the operation type OpType, then the operation type check passes, and the next check continues; otherwise, it means that there may be a risk of version rollback attack, and the device side will refuse version rollback.
[0041] S3037: In response to the first timestamp GenerateTime1 being less than or equal to the timestamp in the local current version authorization file, rejecting version rollback, otherwise, extracting the first counter value CounterValue1 and the counter value in the local current version authorization file; In the above steps, the device verifies the first timestamp GenerateTime1, ensuring the real-time performance of the rollback operation: first, the first timestamp GenerateTime1 and the timestamp in the local current version authorization file need to be extracted and then compared. If the first timestamp GenerateTime1 is greater than (that is, later than) the timestamp in the local current version authorization file, the timestamp verification passes and the next test is performed; otherwise, it indicates that there may be a risk of version rollback attack, and the device will refuse to roll back the version.
[0042] S3038: In response to the first counter value CounterValue1 being less than or equal to the counter value in the local current version authorization file, version rollback is rejected; otherwise, version rollback is executed.
[0043] In the above steps, the device verifies the counter value of the first counter value CounterValue1, and ensures the unidirectionality of the rollback operation: first, the first counter value CounterValue1 and the counter value in the local current version authorization file need to be extracted and then compared. If the first counter value CounterValue1 is greater than the counter value in the local current version authorization file, the counter value verification passes and the next test is continued; otherwise, it indicates that there may be a risk of version rollback attack, and the device will refuse version rollback.
[0044] The protection method against version rollback attacks provided in this embodiment performs multiple security checks on the upgrade package and the authorization file, wherein the digital signature check realizes the authenticity and legality of the upgrade package and the authorization data, the operation type check realizes the confirmation of the rollback business behavior, the vehicle equipment information check ensures the binding of the authorization information and the vehicle, and the timestamp check and the one-way counter check respectively realize the real-time and one-way nature of the rollback operation. By integrating multi-dimensional information and technology, the version rollback attack is effectively protected, and the security and reliability of the version rollback mechanism are greatly improved.
[0045] In addition, the protection method against version rollback attacks provided in this embodiment can protect against: using vulnerable old version upgrade software and authorization files to carry out malicious rollback attacks, tampering with version information in authorization files to carry out malicious rollback attacks, and copying other vehicles' upgrade software and authorization files to carry out malicious rollback attacks. By improving the security and reliability of the version rollback mechanism, the legitimate interests of car manufacturers are guaranteed, and the lives and property of car owners are protected.
[0046] This flowchart only shows the logical sequence of the method described in this embodiment. In other possible embodiments of the present invention, different methods may be used without conflict. Figure 3The steps shown or described are completed in the order shown. The protection method against version rollback attacks provided in this embodiment can be applied to a terminal, and can be performed by a protection device against version rollback attacks, which can be implemented by software and / or hardware, and can be integrated in a terminal, for example: any smart phone, tablet computer or computer device with communication function.
[0047] Embodiment 4
[0048] This embodiment also provides a protection system against version rollback attacks, which includes a device end and a server end, and is used to implement the following protection method: The device sends a version rollback request to the server; The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value, generates an identity identification number, calculates the first counter value, sets the operation type, obtains the first timestamp, and assembles the rollback version authorization file structure; The server signs the fallback version authorization file structure, generates a signature value, and builds the fallback version authorization file; The server sends the upgrade package and rollback version authorization file to the device; The device performs the first legitimacy check, the second legitimacy check, the device information consistency check, the operation type check, the timestamp check and the counter value check on the upgrade package and the rollback version authorization file in sequence; In response to the verification being passed, the device performs version rollback.
[0049] In the description of the present invention, it is to be understood that the terms "first", "second", etc. are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first", "second", etc. may explicitly or implicitly include one or more of the feature. In the description of the present invention, unless otherwise specified, "plurality" means two or more.
[0050] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0051] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0052] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0053] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0054] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation methods. The above-mentioned specific implementation methods are merely illustrative and not restrictive. Under the enlightenment of the present invention, ordinary technicians in this field can also make many forms without departing from the scope of protection of the purpose of the present invention and the claims, which all fall within the protection of the present invention.
Claims
1. A protection method against version rollback attacks, characterized in that: The method is applied to a protection system, which includes a device end and a service end, wherein the device end includes a vehicle terminal and a mobile phone end, and the service end refers to the destination end of the device end requesting communication, including an OTA platform and various service provision platforms; the method includes: The device sends a version rollback request to the server; The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value, generates an identity identification number, calculates the first counter value, sets the operation type, obtains the first timestamp, and assembles the rollback version authorization file structure; The server signs the fallback version authorization file structure, generates a signature value, and constructs the fallback version authorization file; The server sends the upgrade package and the rollback version authorization file to the device; The device side sequentially performs a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to the verification being passed, the device performs version rollback.
2. A protection method against version rollback attacks, characterized in that: The method is applied to the server, and includes: Receive the version rollback request sent by the device; Collect version rollback information according to the version rollback request, and sequentially determine the upgrade package, calculate the first hash value, generate an identity identification number, calculate the first counter value, set the operation type, obtain the first timestamp, and assemble the rollback version authorization file structure; Signing the fallback version authorization file structure, generating a signature value, and constructing a fallback version authorization file; Send the upgrade package and the rollback version authorization file to the device end.
3. The method for protecting against version rollback attacks according to claim 2, characterized in that: The version rollback information includes vehicle equipment information and software version information; The vehicle equipment information includes a vehicle identification number and an electronic controller unit serial number; The software version information includes the software name, the current software version number, the fallback software version number, and the second counter value in the current version authorization file.
4. The method for protecting against version rollback attacks according to claim 3, characterized in that: The steps of sequentially determining the upgrade package, calculating the first hash value, generating an identity identification number, calculating the first counter value, setting the operation type, obtaining the first timestamp, and assembling the rollback version authorization file structure include: According to the software name and the rollback software version number, query and determine the rollback upgrade package; Performing a hash operation on the upgrade package to obtain a first hash value; Generate a unique identifier as the identification number of the fallback version authorization file; Adding one to the second counter value to obtain a first counter value; Set the operation type to version rollback operation; Get the current time as the first timestamp; The vehicle identification number, electronic controller unit serial number, software name, current software version number, fallback software version number, first hash value, identity identification number, first counter value, operation type and first timestamp are assembled to generate a fallback version authorization file structure.
5. The method for protecting against version rollback attacks according to claim 2, characterized in that: The step of signing the rollback version authorization file structure, generating a signature value, and constructing the rollback version authorization file includes: Use the private key to sign the rollback version authorization file structure to obtain a signature value; The fallback version authorization file structure, the signature value and the signature algorithm used for the signature are combined to generate a fallback version authorization file.
6. The protection method against version rollback attacks according to any one of claims 2 to 5, characterized in that: The fallback version authorization file structure and the fallback version authorization file are both in JSON format.
7. A protection method against version rollback attacks, characterized in that: The method is applied to a device, and includes: Send a version rollback request to the server; Receive an upgrade package and a rollback version authorization file sent by a server, wherein the upgrade package is determined by the server according to the collected version rollback information, and the rollback version authorization file is constructed by the server according to the version rollback information, sequentially calculating a first hash value, generating an identity identification number, calculating a first counter value, setting an operation type, obtaining a first timestamp, and assembling a rollback version authorization file structure, and then signing the rollback version authorization file structure to generate a signature value; Sequentially perform a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to all verifications passing, version rollback is performed.
8. The method for protecting against version rollback attacks according to claim 7, characterized in that: The fallback version authorization file includes the fallback version authorization file structure, signature value and signature algorithm used for signature; the fallback version authorization file structure includes the vehicle identification number, electronic controller unit serial number, software name, current software version number, fallback software version number, first hash value, identity identification number, first counter value, operation type and first timestamp.
9. The method for protecting against version rollback attacks according to claim 8, characterized in that: The step of sequentially performing a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file includes: Performing a hash operation on the upgrade package to obtain a second hash value; Use the server public key to verify the signature of the rollback version authorization file; In response to the first hash value being inconsistent with the second hash value and / or the signature verification failing, refusing version rollback, otherwise, using the server public key to verify the signature of the local current version authorization file; In response to a signature verification failure, rejecting version rollback, otherwise, obtaining a local vehicle identification number and a local electronic controller unit serial number; In response to the local vehicle identification number being inconsistent with the vehicle identification number in the fallback version authorization file and / or the local current version authorization file, and the local electronic controller unit serial number being inconsistent with the electronic controller unit serial number in the fallback version authorization file and / or the local current version authorization file, rejecting version rollback, otherwise, extracting the operation type, current software version number and fallback software version number in the fallback version authorization file; In response to the operation type being a non-rollback operation, or the operation type being a rollback operation and the current software version number being less than or equal to the rollback software version number, refusing version rollback, otherwise, extracting the first timestamp and the timestamp in the local current version authorization file; In response to the first timestamp being less than or equal to the timestamp in the local current version authorization file, rejecting version rollback, otherwise, extracting the first counter value and the counter value in the local current version authorization file; In response to the first counter value being less than or equal to the counter value in the local current version authorization file, version rollback is rejected; otherwise, version rollback is performed.
10. A protection system against version rollback attacks, characterized in that: The protection system includes a device side and a service side. The device side includes a vehicle terminal and a mobile phone side. The service side refers to the destination side of the device side requesting communication, including an OTA platform and various service provision platforms. The protection system is used to implement the following protection methods: The device sends a version rollback request to the server; The server collects version rollback information according to the version rollback request, and sequentially determines the upgrade package, calculates the first hash value, generates an identity identification number, calculates the first counter value, sets the operation type, obtains the first timestamp, and assembles the rollback version authorization file structure; The server signs the fallback version authorization file structure, generates a signature value, and constructs the fallback version authorization file; The server sends the upgrade package and the rollback version authorization file to the device; The device side sequentially performs a first legitimacy check, a second legitimacy check, a device information consistency check, an operation type check, a timestamp check, and a counter value check on the upgrade package and the rollback version authorization file; In response to the verification being passed, the device performs version rollback.
Citation Information
Patent Citations
Software protection and authorization method, system and device
CN114357385A
Database version rollback method and device, electronic equipment and storage medium
CN118312501A
Degradation method and device for upgraded application, equipment and storage medium
CN118467024A
Remote upgrading method and system, computer equipment and vehicle
CN118612198A
Computer control method
CN119127273A