Upgrading method, vehicle controller and vehicle

By agreeing with the vehicle controller during the OTA upgrade process to generate keys based on derived random numbers, the probability of successful identification after the identity authentication information is intercepted is solved, and the security of OTA upgrade is improved.

CN119996191AActive Publication Date: 2025-05-13ZHEJIANG GEELY HLDG GRP CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510107896.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-23
Publication Date
2025-05-13
Estimated Expiration
2045-01-23

AI Technical Summary

Technical Problem

How to improve the security of OTA upgrades and reduce the probability of successful identification after identity verification information is intercepted.

Method used

When determining that a new version of the preset program exists, the upgrade task information is sent to the vehicle controller and the key generated based on the derived random number is agreed with the vehicle controller. The first verification random number sent by the vehicle controller is received, and the ciphertext is generated based on the pre-configured encryption algorithm, the second verification random number and the key, and the ciphertext is transmitted to the vehicle controller.

Benefits of technology

This greatly reduces the probability of being identified after interception and improves the security of data transmission between the vehicle controller and the upgraded server. Even if the first verification random number is intercepted, it cannot be used correctly.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996191A_ABST
    Figure CN119996191A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of Internet of Vehicles, in particular to an upgrading method, a vehicle controller and a vehicle. The method comprises the steps that when it is determined that a preset program of a new version exists, upgrading task information is sent to a vehicle controller where the preset program is installed, and a secret key is agreed with the vehicle controller; wherein the key is generated based on a derived random number; receiving a first verification random number sent by the vehicle controller; generating a ciphertext based on a pre-configured encryption algorithm, the second verification random number and the key; and sending upgrading information containing the ciphertext to the vehicle controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of vehicle networking, and in particular to an upgrading method, a vehicle controller and a vehicle. Background Art

[0002] At present, with the gradual development of science and technology, more and more vehicles support software upgrades using Over-the-air Technology (OTA). When using OTA technology for upgrading, identity authentication is required. When the identity authentication is successful, the vehicle's Electronic Control Unit (ECU) will be unlocked to upgrade the software that needs to be upgraded.

[0003] Therefore, how to improve the security of OTA upgrades has become an urgent problem to be solved. Summary of the invention

[0004] In order to solve the above technical problems, the present disclosure provides an upgrade method, a vehicle controller and a vehicle, which are used to solve the problem of how to reduce the probability of successful identification after identity authentication information is intercepted.

[0005] In a first aspect, the present application provides an upgrade method, comprising: when it is determined that there is a new version of a preset program, sending upgrade task information to a vehicle controller on which the preset program is installed, and agreeing on a key with the vehicle controller; wherein the key is generated based on a derived random number; receiving a first verification random number sent by the vehicle controller; generating a ciphertext based on a pre-configured encryption algorithm, a second verification random number and a key; sending upgrade information containing the ciphertext to the vehicle controller; wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and the encryption algorithm, and when determining that the first verification random number and the second verification random number in the ciphertext are the same, generating a prompt information for prompting an upgrade of the preset program.

[0006] In some feasible examples, agreeing on a key with a vehicle controller includes: when determining that a new version of a preset program exists, sending upgrade task information to the vehicle controller where the preset program is installed; generating at least one derived random number based on a derivation multiplier, a main random number of a previous cycle, and a derived random number seed; and generating a key agreed upon with the vehicle controller based on the derived random number.

[0007] In some feasible examples, a key agreed upon with a vehicle controller is generated based on a derived random number, including: concatenating the derived random numbers into a long string; extracting a substring of a target length from the long string; using the substring as the key agreed upon with the vehicle controller; or, randomly selecting a derived random number from the derived random numbers as the key agreed upon with the vehicle controller.

[0008] In some feasible examples, when it is determined that there is a new version of the preset program, before sending the upgrade task information to the vehicle controller on which the preset program is installed, the upgrade method provided by the present disclosure also includes: agreeing on a sampling period with the vehicle controller; sampling a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generating a current derived random number seed based on the quantum random numbers; and generating a derivation multiplier based on the target quantum random number derivation rate and the sampling period.

[0009] In a second aspect, the present application provides an upgrade method, comprising: generating a first verification random number upon receiving upgrade task information sent by an upgrade server; wherein the upgrade task information is sent by the upgrade server when it determines that there is a new version of a preset program; agreeing on a key with the upgrade server; wherein the key is generated based on a derived random number; sending the first verification random number to the upgrade server; receiving upgrade information containing ciphertext sent by the upgrade server; decrypting the ciphertext based on the key and a pre-configured encryption algorithm to determine a second verification random number contained in the ciphertext; and generating a prompt message for prompting an upgrade of the preset program when the second verification random number is the same as the first verification random number.

[0010] In some feasible examples, agreeing on a key with an upgrade server includes: generating at least one derived random number based on a derivation multiplier, a main random number of a previous cycle, and a derived random number seed; and generating a key agreed with the upgrade server based on the derived random number.

[0011] In some feasible examples, a key agreed upon with an upgrade server is generated based on a derived random number, including: concatenating the derived random numbers into a long string; extracting a substring of a target length from the long string; using the substring as the key agreed upon with the upgrade server; or randomly selecting a derived random number from the derived random numbers as the key agreed upon with the upgrade server.

[0012] In some feasible examples, the upgrade method provided by the present disclosure also includes: agreeing on a sampling period with the upgrade server; sampling a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generating a current derived random number seed based on the quantum random numbers; generating a derivation multiplier based on the target quantum random number derivation rate and the sampling period.

[0013] In the third aspect, the present application provides an upgrade server, comprising: a processing module, which is used to control the transceiver module to send upgrade task information to the vehicle controller where the preset program is installed when determining that there is a new version of the preset program, and agree on a key with the vehicle controller; wherein the key is generated based on a derived random number; the transceiver module is also used to receive a first verification random number sent by the vehicle controller; the processing module is also used to generate a ciphertext based on a pre-configured encryption algorithm, a second verification random number and a key obtained by the transceiver module; the processing module is also used to control the transceiver module to send upgrade information containing the ciphertext to the vehicle controller; wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and the encryption algorithm, and to generate a prompt information for prompting the upgrade of the preset program when determining that the first verification random number and the second verification random number in the ciphertext are the same.

[0014] In a fourth aspect, the present application provides a vehicle controller, comprising: a transceiver module, for generating a first verification random number upon receiving upgrade task information sent by an upgrade server; wherein the upgrade task information is sent when the upgrade server determines that there is a new version of a preset program; a processing module, for agreeing on a key with the upgrade server; the processing module, further for controlling the transceiver module to send the first verification random number to the upgrade server; the transceiver module, further for receiving upgrade information containing ciphertext sent by the upgrade server; the processing module, further for decrypting the ciphertext received by the transceiver module based on the key and a pre-configured encryption algorithm, and determining a second verification random number contained in the ciphertext; the processing module, further for generating a prompt message for prompting an upgrade of the preset program when the second verification random number is the same as the first verification random number.

[0015] In a fifth aspect, the present application provides a vehicle, which includes the vehicle control as above.

[0016] In a sixth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the above method.

[0017] Compared with the prior art, the technical solution provided by the present invention has the following advantages:

[0018] The upgrade method provided by the present disclosure sends upgrade task information to the vehicle controller that has installed the preset program when it is determined that there is a new version of the preset program, and agrees on a key with the vehicle controller; then, receives the first verification random number sent by the vehicle controller; generates a ciphertext based on the pre-configured encryption algorithm, the second verification random number and the key; and sends the upgrade information containing the ciphertext to the vehicle controller. Since the key is generated based on the derived random number, the probability of being identified after being intercepted can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved, thereby solving the problem of how to reduce the probability of successful identification after the identity authentication information is intercepted. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0020] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0021] Figure 1 One of the flowcharts of an upgrade method provided in the first embodiment is exemplarily shown in FIG.

[0022] Figure 2 FIG. 2 exemplarily shows a flow chart of an upgrade method provided in the first embodiment;

[0023] Figure 3 FIG3 is a flowchart of an upgrade method provided in the first embodiment of the present invention;

[0024] Figure 4 FIG4 is a flowchart of an upgrade method provided in the first embodiment of the present invention;

[0025] Figure 5 FIG. 5 exemplarily shows a flowchart of an upgrade method provided in the first embodiment;

[0026] Figure 6 FIG. 6 exemplarily shows a flowchart of an upgrade method provided in the first embodiment;

[0027] Figure 7FIG. 7 is a flowchart of an upgrade method provided in the first embodiment of the present invention;

[0028] Figure 8 FIG8 is an exemplary flowchart of an upgrade method provided in the first embodiment;

[0029] Fig. 9 FIG. 9 is a flowchart of an upgrade method provided in the first embodiment of the present invention;

[0030] Fig.10 FIG. 10 is a flowchart of an upgrade method provided in the first embodiment of the present invention;

[0031] Fig.11 One of the structural diagrams of the upgrade server provided in the second embodiment is exemplarily shown in FIG.

[0032] Fig.12 FIG. 2 exemplarily shows a second structural diagram of the upgrade server provided in the second embodiment of the present invention;

[0033] Fig.13 One of the structural diagrams of the vehicle controller provided in the second embodiment is exemplarily shown in FIG.

[0034] Fig.14 FIG. 2 exemplarily shows a second structural diagram of the vehicle controller provided in the second embodiment. DETAILED DESCRIPTION

[0035] In order to more clearly understand the above-mentioned objectives, features and advantages of the present disclosure, the scheme of the present disclosure will be further described below. It should be noted that the embodiments of the present disclosure and the features in the embodiments can be combined with each other without conflict.

[0036] In the following description, many specific details are set forth to facilitate a full understanding of the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; it is obvious that the embodiments in the specification are only part of the embodiments of the present disclosure, rather than all of the embodiments.

[0037] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0038] Embodiment 1

[0039] Figure 1 A flowchart of an upgrade method is shown in FIG. 1 . The execution subject of this example may be an upgrade server, such as Figure 1 As shown, the method includes:

[0040] S11. When it is determined that there is a new version of the preset program, an upgrade task message is sent to the vehicle controller where the preset program is installed, and a key is agreed with the vehicle controller, wherein the key is generated based on a derived random number.

[0041] In some examples, the vehicle controller and the upgrade server perform key negotiation through quantum key distribution (QKD) to generate an agreed-upon key.

[0042] S12. Receive a first verification random number sent by the vehicle controller.

[0043] In some examples, the first verification random number is generated by the vehicle controller when receiving the upgrade task information sent by the upgrade server.

[0044] S13. Generate ciphertext based on a pre-configured encryption algorithm, a second verification random number and a key.

[0045] In some examples, the second verification random number is the same as the first verification random number.

[0046] In some examples, the upgrade server encrypts the second verification random number and the key based on a preconfigured encryption algorithm to generate a ciphertext.

[0047] S14, sending upgrade information including ciphertext to the vehicle controller, wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and the encryption algorithm, and to generate prompt information for prompting to upgrade the preset program when the first verification random number and the second verification random number in the ciphertext are determined to be the same.

[0048] As can be seen from the above, the upgrade method provided by the embodiment of the present disclosure sends upgrade task information to the vehicle controller that installs the preset program when it is determined that there is a new version of the preset program, and agrees on a key with the vehicle controller; since the key is generated based on a derived random number, the probability of being identified after interception can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used between the vehicle controller and the upgrade server is different each time, the security of data transmission between the vehicle controller and the upgrade server can be improved. Afterwards, the first verification random number sent by the vehicle controller is received; based on the pre-configured encryption algorithm, the second verification random number and the key, a ciphertext is generated; and the upgrade information containing the ciphertext is sent to the vehicle controller. If the upgrade information is intercepted, if the intercepted second verification random number is modified, at this time, since the vehicle controller and the upgrade server have agreed on the random number in advance, the second verification random number in the modified upgrade information will be different from the first verification random number. At this time, the vehicle controller does not execute the upgrade information, or does not modify the intercepted second verification random number, but uses the second verification random number for other purposes. At this time, since the random number is only used when upgrading the application, even if the vehicle controller determines that the second verification random number is the same as the first verification random number, it will not generate a prompt information for prompting the upgrade of the preset program, nor will it execute other functions, thereby improving the security of data transmission between the vehicle controller and the upgrade server.

[0049] In some possible implementation examples, combined with Figure 1 ,like Figure 2 As shown, the above S11 can be specifically implemented through the following S110-S112.

[0050] S110: When it is determined that a new version of the preset program exists, an upgrade task information is sent to the vehicle controller where the preset program is installed.

[0051] S111. Generate at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed.

[0052] In some examples, for the first cycle, the main random number of the previous cycle is zero. For cycles other than the first cycle, the main random number is equal to the length requirement |H| of the long string concatenated by waiting for the random numbers in the local quantum random number pool, and the long string of length |H| is used as the main random number.

[0053] In some examples, the vehicle controller uses a quantum random number derivation module to derive the main random number of the previous cycle and the derived random number seed DM times through a hash-based message authentication code (HMAC) technology to generate at least one derived random number, wherein the total number of derived random numbers is equal to DM.

[0054] In some examples, the main random number, the derived random number seed and the derived multiplier of the previous cycle can be input into the derivation model for derivation to generate at least one derived random number. The training process of the derivation model includes:

[0055] The training sample data and the marking results of the training sample data are obtained, wherein the training sample data includes the historical main random number, the derived random number seed and the derived multiplier, and the marking results include the historical main random number, the derived random number seed and at least one derived random number corresponding to the derived multiplier.

[0056] The training sample data is input into the neural network model for learning, and the prediction results of the neural network model for the training sample data are obtained.

[0057] Based on the prediction results and the labeling results, the network parameters of the neural network model are adjusted until the neural network model converges to obtain a derived model.

[0058] S112. Generate a key agreed upon with the vehicle controller based on the derived random number.

[0059] In some examples, a derived random number may be randomly selected from the derived random numbers as a key agreed upon with the vehicle controller; alternatively, the derived random numbers may be concatenated into a long string, a substring of a target length may be truncated from the long string, and the string may be used as the key agreed upon with the vehicle controller.

[0060] As can be seen from the above, the upgrade method provided by the embodiment of the present disclosure sends upgrade task information to the vehicle controller that has installed the preset program when it is determined that there is a new version of the preset program, and generates at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed, and generates a key agreed with the vehicle controller based on the derived random number; then, receives the first verification random number sent by the vehicle controller; generates a ciphertext based on the pre-configured encryption algorithm, the second verification random number and the key; and sends the upgrade information containing the ciphertext to the vehicle controller. Since the key is generated based on the derived random number, the probability of being identified after being intercepted can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved.

[0061] In some possible implementation examples, combined with Figure 2 ,like Figure 3 As shown, the above S112 can be specifically implemented through the following S1120-S1122.

[0062] S1120. Concatenate the derived random numbers into a long string.

[0063] S1121. Extract a substring of a target length from a long string.

[0064] In some examples, the target length may be a preset first length, or the target length may be determined based on a first total number of characters included in the long string, such as the target length is equal to half of the first total number.

[0065] S1122. Use the substring as a key agreed upon with the vehicle controller.

[0066] As can be seen from the above, the upgrade method provided by the embodiment of the present disclosure, when determining that there is a new version of the preset program, sends upgrade task information to the vehicle controller that has installed the preset program, and concatenates the derived random numbers into a long string, intercepts a substring of the target length in the long string, and uses the substring as the key agreed with the vehicle controller; then, receives the first verification random number sent by the vehicle controller; generates ciphertext based on the pre-configured encryption algorithm, the second verification random number and the key; and sends the upgrade information containing the ciphertext to the vehicle controller. Since the key is generated based on the derived random number, the probability of being identified after interception can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved.

[0067] In some possible implementation examples, combined with Figure 2 ,like Figure 4 As shown, the above S112 can be specifically implemented through the following S1123.

[0068] S1123. Randomly select a derived random number from the derived random numbers as a key agreed upon with the vehicle controller.

[0069] From the above, it can be seen that the upgrade method provided by the embodiment of the present disclosure, when determining that there is a new version of the preset program, sends upgrade task information to the vehicle controller that has installed the preset program, and randomly selects a derived random number from the derived random numbers as the key agreed with the vehicle controller. Afterwards, receive the first verification random number sent by the vehicle controller; generate a ciphertext based on the pre-configured encryption algorithm, the second verification random number and the key; and send the upgrade information containing the ciphertext to the vehicle controller. Since the key is generated based on the derived random number, the probability of being identified after interception can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved.

[0070] In some possible implementation examples, combined with Figure 2 ,like Figure 5 As shown, before executing S110, the upgrading method provided by the embodiment of the present disclosure further includes S15-S17.

[0071] S15. Agree on a sampling period with the vehicle controller.

[0072] In some examples, the upgrade server and the ECU obtain quantum random numbers through their directly connected quantum key distribution (QKD) devices. These random numbers are generated based on the principles of quantum mechanics, have extremely high randomness and security, and the first verification random numbers generated each time are different.

[0073] In some examples, the first verification random number obtained is stored in a local quantum random number pool of a QKD device corresponding to the vehicle controller, wherein the data structure of the local quantum random number pool may be a database, a file system, or other forms of structures.

[0074] In some examples, the upgrade server and the vehicle controller determine an initial sampling period T through negotiation. This sampling period can be fixed or dynamically adjusted according to actual needs.

[0075] In some examples, when the upgrade server and the vehicle controller determine an initial sampling period T through negotiation, this can be done through a secure communication protocol (such as Transport Layer Security (TLS)) to ensure the security of the negotiation process.

[0076] S16. Sample a target number of quantum random numbers from a random number pool of a quantum random number generator according to a sampling period, and generate a current derived random number seed based on the quantum random numbers.

[0077] In some examples, the vehicle controller and the upgrade server agree on a sampling period within each random number sampling period T. Afterwards, the upgrade server samples a target number of quantum random numbers from the random number pool of the corresponding quantum key distribution device according to the sampling period, and generates the current derived random number seed SDKS based on the quantum random numbers.

[0078] In some examples, the upgrade server slides and samples a certain number of quantum random numbers from the random number pool of the quantum key distribution device to generate the derived random number seed SDKS for this cycle.

[0079] In some examples, the target amount is equal to the derivative multiplier.

[0080] In some examples, when sampling a target number of quantum random numbers in a random number pool of a quantum key distribution device according to a sampling period, sliding sampling can be performed, such as performing sliding sampling in a random number pool of a quantum key distribution device according to a time window or a fixed number within the sampling period to obtain a target number of quantum random numbers. The sliding sampling strategy can be a uniform distribution or a weighted distribution to ensure the randomness and fairness of the sliding sampling. For example, a pseudo-random number generator (PRNG) can be used to determine the position of each sliding sampling.

[0081] S17. Generate a derivation multiplier based on the target quantum random number derivation rate and sampling period.

[0082] In some examples, the target quantum random number derivation rate refers to the number of random numbers generated per unit time that a user desires.

[0083] In some examples, the derived multiplier can be calculated by the following formula:

[0084]

[0085] Among them, DM indicates the derived multiplier, R d represents the target quantum random number derivation rate, T represents the sampling period, and |H| represents the length of the string output by the hash function.

[0086] As can be seen from the above, the upgrade method provided by the embodiment of the present disclosure sends upgrade task information to the vehicle controller that has installed the preset program when it is determined that there is a new version of the preset program. Afterwards, a sampling period is agreed upon with the vehicle controller, and a target number of quantum random numbers are sampled from the random number pool of the quantum random number generator according to the sampling period, and the current derived random number seed is generated based on the quantum random number, and the derivation multiplier is generated based on the target quantum random number derivation rate and the sampling period. Afterwards, at least one derived random number is generated based on the derivation multiplier, the main random number of the previous period, and the derived random number seed, and a key agreed with the vehicle controller is generated based on the derived random number; afterward, a first verification random number sent by the vehicle controller is received; a ciphertext is generated based on a pre-configured encryption algorithm, a second verification random number, and a key; and upgrade information containing the ciphertext is sent to the vehicle controller. Since the key is generated based on a derived random number, the probability of being identified after interception can be greatly reduced. At the same time, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly. At the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved.

[0087] Embodiment 2

[0088] Figure 6 A flowchart of an upgrade method is shown in FIG. 1 . The execution subject of this example may be a vehicle controller, such as Figure 6 As shown, the method includes:

[0089] S20: upon receiving the upgrade task information sent by the upgrade server, generating a first verification random number, wherein the upgrade task information is sent by the upgrade server when determining that a new version of a preset program exists, and the preset program is installed in the vehicle controller.

[0090] In some examples, the vehicle controller includes a main upgrade electronic control unit (ECU) for interacting with the upgrade server and a sub-ECU for at least one target device. The target device includes any one of an engine, a transmission, an anti-lock braking system, etc. After the main ECU receives the upgrade task information sent by the upgrade server, the main ECU determines at least one target device that needs to be upgraded based on the upgrade task information. After that, the main ECU pushes the upgrade task information to the sub-ECU of each target device that needs to be upgraded. For the sub-ECU that receives the upgrade task information, when the sub-ECU receives the upgrade task information sent by the upgrade server, a first verification random number is generated. It can be seen that the encrypted SAC (Sum of Absolute Changes) value is not generated or transmitted between the upgrade server and the sub-ECU, which prevents hackers from intercepting and using it, thereby improving the security of data transmission between the vehicle controller and the upgrade server.

[0091] In some examples, the upgrade server is used to provide OTA services. After the vehicle controller establishes a communication connection with the upgrade server, the upgrade server can provide OTA services for the applications installed in the vehicle controller.

[0092] In some examples, when the upgrade server determines that there is a new version of the preset program, it sends the upgrade task information to the vehicle controller. At this time, after receiving the upgrade task information sent by the upgrade server, the vehicle controller generates a first verification random number, such as: the vehicle controller generates the first verification random number based on a preset generator, or generates the first verification random number through a quantum key distribution device.

[0093] In some examples, one vehicle controller corresponds to one Quantum Key Distribution (QKD) device.

[0094] In some examples, a security protocol such as Transport Layer Security (TLS) / Secure Sockets Layer (SSL) is typically used for communication between the upgrade server and the main ECU or sub-ECU.

[0095] In some examples, when the vehicle controller generates the first verification random number, the first verification random number may be generated by a preset generator, wherein the preset generator includes any one of a pseudo-random number generator (PRNG), a true random number generator (TRNG), and a quantum random number generator (QRNG).

[0096] In some examples, the first verification random number between the vehicle controller and the upgrade server is transmitted in plain text.

[0097] In some examples, when the preset generator includes a QRNG, when the sub-ECU receives the upgrade task information, the QRNG is triggered to generate a first verification random number. The following conditions need to be met when the QRNG generates the first verification random number:

[0098] Hardware preparation: First, ensure that a QRNG chip is integrated in the sub-ECU. This chip is usually based on quantum physics principles, such as quantum state measurement of photons, quantum tunneling effect, etc., and can generate true random numbers.

[0099] Power supply and interface: Ensure that the QRNG chip has a stable power supply and a reliable communication interface with the main control unit of the sub-ECU, such as the Serial Peripheral Interface (SPI), Inter-Integrated Circuit (I2C), or General Purpose Input / Output (GPIO).

[0100] The process of QRNG generating the first verification random number includes:

[0101] 1. Initialize the QRNG chip

[0102] Power-on reset: When the sub-ECU starts, the QRNG chip is powered on and reset to ensure that it is in the initial state.

[0103] Configuration parameters: As needed, configure the parameters of the QRNG chip through the communication interface between the sub-ECU and the QRNG chip, such as the length and generation rate of the generated random numbers.

[0104] 2. Trigger random number generation

[0105] Generate request: When the sub-ECU receives the upgrade task information sent by the main ECU, it triggers the QRNG chip to start generating the first verification random number.

[0106] Read random number: The sub-ECU reads the first verification random number generated from the QRNG chip through the communication interface with the QRNG chip. This process needs to ensure the reliability and security of data transmission.

[0107] 3. Data processing

[0108] Data verification: After reading the first verification random number, some basic data verification can be performed, such as checking whether the data length meets expectations and whether there are obvious repetitive patterns.

[0109] Data storage: The generated first verification random number is stored in the secure memory area of ​​the sub-ECU for subsequent use.

[0110] In some examples, the preset generator includes a quantum random number generator; the above S20 can be specifically implemented by the following S200 and S201.

[0111] S200: upon receiving the upgrade task information sent by the upgrade server, generating at least one derived random number based on the derivation multiplier, the main random number of the previous cycle and the derived random number seed.

[0112] In some examples, the process by which the vehicle controller generates at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed is the same as the process by which the upgrade server generates at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed, and is not repeated here.

[0113] S201. Generate a first verification random number based on the derived random number.

[0114] In some examples, a derived random number may be randomly selected from the derived random numbers as the first verification random number; or, the derived random numbers may be concatenated into a long string, a substring of a target length may be truncated from the long string, and a derived random number may be randomly selected from the derived random numbers contained in the substring as the first verification random number.

[0115] In some feasible examples, the above S201 can be specifically implemented through the following S2010.

[0116] S2010. Randomly select a derived random number from the derived random numbers as a first verification random number.

[0117] In some feasible examples, the above S201 can be specifically implemented through the following S2011-S2013.

[0118] S2011. Concatenate the derived random numbers into a long string.

[0119] S2012. Extract a substring of a specified length from a long string.

[0120] In some examples, the specified length may be a preset first length, or the specified length may be determined based on a first total number of characters included in the long string, such as: the specified length is equal to half of the first total number.

[0121] S2013. Randomly select a character of a preset length in the substring as a first verification random number.

[0122] In some examples, the preset length may be a preset second length, or the preset length may be determined based on a second total number of characters included in the substring, such as the preset length being equal to half of the second total number.

[0123] In some feasible examples, the upgrading method provided by the embodiments of the present disclosure, when executing S200, also needs to execute S26-S28.

[0124] S26. Obtain the sampling period agreed upon with the upgrade server.

[0125] S27. Sample a target number of quantum random numbers from a random number pool of a quantum key distribution device according to a sampling period, and generate a current derived random number seed based on the quantum random numbers.

[0126] In some examples, the process in which the vehicle controller samples a target number of quantum random numbers from the random number pool of the quantum key distribution device according to a sampling period and generates a current derived random number seed based on the quantum random numbers is the same as the process in which the upgrade server samples a target number of quantum random numbers from the random number pool of the quantum random number generator according to a sampling period and generates a current derived random number seed based on the quantum random numbers, and is not repeated here.

[0127] S28. Generate a derivation multiplier based on the target quantum random number derivation rate and sampling period.

[0128] In some examples, the process by which the vehicle controller generates a derivation multiplier based on a target quantum random number derivation rate and a sampling period is the same as the process by which the upgrade server generates a derivation multiplier based on a target quantum random number derivation rate and a sampling period, and is not repeated here.

[0129] S21. Agree on a key with the upgrade server, wherein the key is generated based on a derived random number.

[0130] S22. Send the first verification random number to the upgrade server.

[0131] In some examples, the sub-ECU sends the first verification random number to the upgrade server via a secure communication protocol (such as TLS / SSL). This step ensures the confidentiality and integrity of the data during transmission.

[0132] In some examples, the first verification random number is the same as the second verification random number.

[0133] In some examples, the encryption algorithm may be an AES128 algorithm, or a secure hash function.

[0134] S23. Receive the upgrade information including the ciphertext sent by the upgrade server.

[0135] S24. Decrypt the ciphertext based on the key and a pre-configured encryption algorithm to determine a second verification random number contained in the ciphertext.

[0136] S25. When the second verification random number is the same as the first verification random number, generate prompt information for prompting to upgrade the preset program.

[0137] In some examples, when the second verification random number is different from the first verification random number, there may be a risk of being attacked by the network, so the vehicle controller does not need to execute the upgrade information to avoid the vehicle controller becoming unusable due to the attack.

[0138] As can be seen from the above, the upgrade method provided by the embodiment of the present disclosure, even if the first verification random number is intercepted, since the role of the intercepted first verification random number is not limited, even if the first verification random number is intercepted, it cannot be used correctly; at the same time, since the first verification random number used each time between the vehicle controller and the upgrade server is different, the security of data transmission between the vehicle controller and the upgrade server can be improved. At the same time, if the upgrade information is intercepted, if the intercepted second verification random number is modified, at this time, since the vehicle controller and the upgrade server have agreed on the random number in advance, the second verification random number in the modified upgrade information will be different from the first verification random number. At this time, the vehicle controller does not execute the upgrade information, or does not modify the intercepted second verification random number, but uses the second verification random number for other purposes. At this time, since the random number is only used when the application is upgraded, even if the vehicle controller determines that the second verification random number is the same as the first verification random number, it will not generate a prompt information for prompting the upgrade of the preset program, and will not execute other functions, thereby improving the security of data transmission between the vehicle controller and the upgrade server.

[0139] In some possible implementation examples, combined with Figure 6 ,like Figure 7 As shown, the above S21 can be specifically implemented through the following S210 and S211.

[0140] S210, generating at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed;

[0141] S211. Generate a key agreed with the upgrade server based on the derived random number.

[0142] In some examples, the vehicle controller generates at least one derived random number based on the derivation ratio, the main random number of the previous cycle, and the derived random number seed; and the process of generating a key agreed with the upgrade server based on the derived random number is similar to the process of the upgrade server generating at least one derived random number based on the derivation ratio, the main random number of the previous cycle, and the derived random number seed; and generating a key agreed with the vehicle controller based on the derived random number, and will not be repeated here.

[0143] In some possible implementation examples, combined with Figure 7 ,like Figure 8 As shown, the above S211 can be specifically implemented through the following S2110-S2112.

[0144] S2110, concatenating the derived random numbers into a long string;

[0145] S2111, extracting a substring of target length from a long string;

[0146] S2112. Use the substring as a key agreed upon with the upgrade server.

[0147] In some examples, the vehicle controller concatenates the derived random numbers into a long string; extracts a substring of the target length from the long string; and uses the substring as a key agreed upon with the upgrade server. This process is similar to the process in which the upgrade server concatenates the derived random numbers into a long string; extracts a substring of the target length from the long string; and uses the substring as a key agreed upon with the vehicle controller, and is not repeated here.

[0148] In some possible implementation examples, combined with Figure 7 ,like Fig. 9 As shown, the above S211 can be specifically implemented through the following S2113.

[0149] S2113. Randomly select a derived random number from the derived random numbers as a key agreed upon with the upgrade server.

[0150] In some examples, the process by which the vehicle controller randomly selects a derived random number from the derived random numbers as a key agreed upon with the upgrade server is similar to the process by which the upgrade server randomly selects a derived random number from the derived random numbers as a key agreed upon with the vehicle controller, and is not repeated here.

[0151] In some possible implementation examples, combined with Figure 7 ,like Fig.10 As shown, the upgrade method provided in the embodiment of the present disclosure also includes S29-S31.

[0152] S29. Agree on a sampling period with the upgrade server;

[0153] S30, sampling a target number of quantum random numbers from a random number pool of a quantum random number generator according to a sampling period, and generating a current derived random number seed based on the quantum random numbers;

[0154] S31. Generate a derivation multiplier based on a target quantum random number derivation rate and a sampling period.

[0155] In some examples, the vehicle controller and the upgrade server agree on a sampling period; sample a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generate a current derived random number seed based on the quantum random numbers; generate a derivation multiplier based on a target quantum random number derivation rate and a sampling period. The process is similar to the process in which the upgrade server and the upgrade server agree on a sampling period; sample a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generate a current derived random number seed based on the quantum random numbers; generate a derivation multiplier based on a target quantum random number derivation rate and a sampling period, and will not be repeated here.

[0156] Embodiment 3

[0157] Fig.11 The structural diagram of the upgrade server provided in the third embodiment of the present application is exemplarily shown in FIG. Fig.11 As shown, the upgrade server includes: a processing module 81 and a transceiver module 82.

[0158] The processing module 81 is used to control the transceiver module 82 to send the upgrade task information to the vehicle controller where the preset program is installed, and agree on a key with the vehicle controller when determining that a new version of the preset program exists; wherein the key is generated based on a derived random number;

[0159] The transceiver module 82 is also used to receive a first verification random number sent by the vehicle controller;

[0160] The processing module 81 is further used to generate a ciphertext based on a pre-configured encryption algorithm, a second verification random number and a key obtained by the transceiver module 82;

[0161] The processing module 81 is also used to control the transceiver module 82 to send upgrade information containing ciphertext to the vehicle controller; wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and encryption algorithm, and to generate a prompt information for prompting the upgrade of the preset program when determining that the first verification random number and the second verification random number in the ciphertext are the same.

[0162] In some implementable examples, the processing module 81 is specifically used to control the transceiver module 82 to send upgrade task information to the vehicle controller where the preset program is installed when determining that there is a new version of the preset program; the processing module 81 is specifically used to generate at least one derived random number based on the derivation multiplier, the main random number of the previous cycle and the derived random number seed; the processing module 81 is specifically used to generate a key agreed with the vehicle controller based on the derived random number.

[0163] In some implementable examples, the processing module 81 is specifically used to concatenate the derived random numbers into a long string; the processing module 81 is specifically used to intercept a substring of a target length from the long string; the processing module 81 is specifically used to use the substring as a key agreed upon with the vehicle controller.

[0164] In some implementable examples, the processing module 81 is specifically configured to randomly select a derived random number from the derived random numbers as a key agreed upon with the vehicle controller.

[0165] In some implementable examples, the processing module 81 is further used to agree on a sampling period with the vehicle controller; the processing module 81 is further used to sample a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generate a current derived random number seed based on the quantum random numbers; the processing module 81 is further used to generate a derivation multiplier based on a target quantum random number derivation rate and a sampling period.

[0166] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, and its role will not be repeated here.

[0167] Of course, the upgrade server provided in the embodiment of the present invention includes but is not limited to the above modules, for example, the upgrade server may also include a storage module 83. The storage module 83 may be used to store the program code of the upgrade server, and may also be used to store data generated during the operation of the upgrade server, such as diagnostic data.

[0168] Fig.12 A schematic diagram of the structure of an upgrade server provided by an embodiment of the present invention, such as Fig.12 As shown, the upgrade server may include: at least one processor 51 , a memory 52 , a communication interface 53 and a communication bus 54 .

[0169] Combine the following Fig.12 A detailed introduction to the various components of the upgrade server:

[0170] The processor 51 is the control center of the upgrade server, and may be a processor or a general term for multiple processing elements. For example, the processor 51 is a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as one or more DSPs, or one or more field programmable gate arrays (FPGAs).

[0171] In a specific implementation, as an embodiment, the processor 51 may include one or more CPUs, such as Fig.12 Also, as an embodiment, the upgrade server may include multiple processors, such as Fig.12 51 and 55 are shown in FIG. Each of these processors may be a single-core processor (Single-CPU) or a multi-core processor (Multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0172] The memory 52 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 52 may exist independently and be connected to the processor 51 via a communication bus 54. The memory 52 may also be integrated with the processor 51.

[0173] In a specific implementation, the memory 52 is used to store the data of the present invention and execute the software program of the present invention. The processor 51 can execute various functions of the air conditioner by running or executing the software program stored in the memory 52 and calling the data stored in the memory 52.

[0174] The communication interface 53 uses any transceiver-like device to communicate with other devices or communication networks, such as Radio Access Network (RAN), Wireless Local Area Networks (WLAN), terminals, cloud, etc. The communication interface 53 may include a transceiver module to implement the acquisition function.

[0175] The communication bus 54 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.12 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0176] As an example, combining Fig.11 , the functions implemented by the transceiver module 82 of the upgrade server are the same as Fig.12 The function of the communication interface 53 in the upgrade server is the same as that of the processing module 81 in the upgrade server. Fig.12 The functions of the processor 51 in the upgrade server are the same as those of the storage module 83 in the upgrade server. Fig.12 The function of the memory 52 in is the same.

[0177] Embodiment 4

[0178] Fig.13 The structural diagram of the vehicle controller provided by the fourth embodiment of the present application is exemplarily shown in FIG. Fig.13 As shown, the vehicle controller includes: a transceiver module 91 and a processing module 92.

[0179] The transceiver module 91 is used to generate a first verification random number when receiving the upgrade task information sent by the upgrade server; wherein the upgrade task information is sent when the upgrade server determines that a new version of the preset program exists;

[0180] A processing module 92 is used to agree on a key with the upgrade server; wherein the key is generated based on a derived random number;

[0181] The processing module 92 is further used to control the transceiver module 91 to send the first verification random number to the upgrade server;

[0182] The transceiver module 91 is also used to receive the upgrade information including the ciphertext sent by the upgrade server;

[0183] The processing module 92 is further used to decrypt the ciphertext received by the transceiver module 91 based on the key and the pre-configured encryption algorithm, and determine the second verification random number contained in the ciphertext;

[0184] The processing module 92 is further configured to generate a prompt message for prompting to upgrade the preset program when the second verification random number is the same as the first verification random number.

[0185] In some implementable examples, the processing module 92 is specifically used to generate at least one derived random number based on the derivation multiplier, the main random number of the previous cycle and the derived random number seed; the processing module 92 is specifically used to generate a key agreed with the upgrade server based on the derived random number.

[0186] In some implementable examples, the processing module 92 is specifically used to concatenate the derived random numbers into a long string; the processing module 92 is specifically used to intercept a substring of a target length from the long string; the processing module 92 is specifically used to use the substring as a key agreed with the upgrade server.

[0187] In some implementable examples, the processing module 92 is specifically configured to randomly select a derived random number from the derived random numbers as a key agreed upon with the upgrade server.

[0188] In some implementable examples, the processing module 92 is further used to agree on a sampling period with the upgrade server; the processing module 92 is further used to sample a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generate a current derived random number seed based on the quantum random numbers; the processing module 92 is further used to generate a derivation multiplier based on a target quantum random number derivation rate and a sampling period.

[0189] Among them, all relevant contents of each step involved in the above method embodiment can be referred to the functional description of the corresponding functional module, and its role will not be repeated here.

[0190] Of course, the vehicle controller provided by the embodiment of the present invention includes but is not limited to the above modules, for example, the vehicle controller may also include a storage module 93. The storage module 93 may be used to store the program code of the vehicle controller, and may also be used to store data generated by the vehicle controller during operation, such as diagnostic data.

[0191] Fig.14 A schematic diagram of the structure of a vehicle controller provided by an embodiment of the present invention is shown in FIG. Fig.14 As shown, the vehicle controller may include: at least one processor 61 , a memory 62 , a communication interface 63 and a communication bus 64 .

[0192] Combine the following Fig.14 A detailed introduction to the various components of the vehicle controller:

[0193] The processor 61 is the control center of the vehicle controller, which may be a processor or a general term for multiple processing elements. For example, the processor 61 is a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiment of the present invention, such as one or more DSPs, or one or more field programmable gate arrays (FPGAs).

[0194] In a specific implementation, as an embodiment, the processor 61 may include one or more CPUs, such as Fig.14 Also, as an embodiment, the vehicle controller may include multiple processors, such as Fig.14 61 and 65 are shown in FIG. Each of these processors may be a single-core processor (Single-CPU) or a multi-core processor (Multi-CPU). The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0195] The memory 62 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 62 may exist independently and be connected to the processor 61 via a communication bus 64. The memory 62 may also be integrated with the processor 61.

[0196] In a specific implementation, the memory 62 is used to store the data of the present invention and execute the software program of the present invention. The processor 61 can execute various functions of the air conditioner by running or executing the software program stored in the memory 62 and calling the data stored in the memory 62.

[0197] The communication interface 63 uses any transceiver-like device to communicate with other devices or communication networks, such as Radio Access Network (RAN), Wireless Local Area Networks (WLAN), terminals, cloud, etc. The communication interface 63 may include a transceiver module to implement the acquisition function.

[0198] The communication bus 64 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig.14 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0199] As an example, combining Fig.13The functions implemented by the transceiver module 91 of the vehicle controller are similar to Fig.14 The function of the communication interface 63 in the vehicle controller is the same as that of the processing module 92 in the vehicle controller. Fig.14 The functions of the processor 61 in the vehicle controller are the same as those of the storage module 93 in the vehicle controller. Fig.14 The function of the memory 62 in is the same.

[0200] An embodiment of the present application also provides a vehicle, which may include the vehicle controller in any embodiment.

[0201] An embodiment of the present application further provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method in any embodiment.

[0202] The above description is only a specific embodiment of the present disclosure, so that those skilled in the art can understand or implement the present disclosure. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to the embodiments described herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. An upgrading method, characterized in that: include: When it is determined that there is a new version of the preset program, an upgrade task message is sent to a vehicle controller where the preset program is installed, and a key is agreed upon with the vehicle controller; wherein the key is generated based on a derived random number; Receiving a first verification random number sent by the vehicle controller; Generate a ciphertext based on a preconfigured encryption algorithm, a second verification random number and the key; Sending upgrade information including the ciphertext to the vehicle controller; wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and the encryption algorithm, and to generate a prompt information for prompting the upgrade of the preset program when determining that the first verification random number and the second verification random number in the ciphertext are the same.

2. The upgrading method according to claim 1, characterized in that: The step of agreeing on a key with the vehicle controller comprises: Generate at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed; Based on the derived random number, a key agreed upon with the vehicle controller is generated.

3. The upgrading method according to claim 2, characterized in that: The generating a key agreed with the vehicle controller based on the derived random number comprises: Concatenate the derived random numbers into a long string; Extract a substring of a target length from the long string; Using the substring as a key agreed upon with the vehicle controller; or, A derived random number is randomly selected from the derived random numbers as a key agreed upon with the vehicle controller.

4. The upgrading method according to claim 2, characterized in that: When it is determined that there is a new version of the preset program, before sending the upgrade task information to the vehicle controller where the preset program is installed, the method further includes: Agreeing on a sampling period with the vehicle controller; Sampling a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generating a current derived random number seed based on the quantum random numbers; A derivation multiplier is generated based on a target quantum random number derivation rate and the sampling period.

5. An upgrading method, characterized in that: include: Upon receiving the upgrade task information sent by the upgrade server, generating a first verification random number; wherein the upgrade task information is sent by the upgrade server when determining that a new version of the preset program exists; Agreeing on a key with the upgrade server; wherein the key is generated based on a derived random number; Sending the first verification random number to the upgrade server; Receiving the upgrade information including the ciphertext sent by the upgrade server; Decrypting the ciphertext based on the key and a preconfigured encryption algorithm to determine a second verification random number contained in the ciphertext; When the second verification random number is the same as the first verification random number, a prompt message for prompting to upgrade the preset program is generated.

6. The upgrading method according to claim 5, characterized in that: The step of agreeing on a key with the upgrade server comprises: Generate at least one derived random number based on the derivation multiplier, the main random number of the previous cycle, and the derived random number seed; Based on the derived random number, a key agreed with the upgrade server is generated.

7. The upgrading method according to claim 6, characterized in that: The generating a key agreed with the upgrade server based on the derived random number includes: concatenating the derived random numbers into a long string; Extract a substring of a target length from the long string; Using the substring as a key agreed with the upgrade server; or, A derived random number is randomly selected from the derived random numbers as a key agreed upon with the upgrade server.

8. The upgrading method according to claim 6, characterized in that: The method further comprises: Agreeing on a sampling period with the upgrade server; Sampling a target number of quantum random numbers from a random number pool of a quantum random number generator according to the sampling period, and generating a current derived random number seed based on the quantum random numbers; A derivation multiplier is generated based on a target quantum random number derivation rate and the sampling period.

9. An upgrade server, characterized in that: include: The processing module is used to control the transceiver module to send upgrade task information to the vehicle controller where the preset program is installed, and agree on a key with the vehicle controller when determining that a new version of the preset program exists, wherein the key is generated based on a derived random number; The transceiver module is further used to receive a first verification random number sent by the vehicle controller; The processing module is further used to generate a ciphertext based on a preconfigured encryption algorithm, a second verification random number and the key obtained by the transceiver module; The processing module is also used to control the transceiver module to send upgrade information containing the ciphertext to the vehicle controller; wherein the upgrade information is used to instruct the vehicle controller to decrypt the ciphertext based on the key and the encryption algorithm, and to generate a prompt information for prompting to upgrade the preset program when determining that the first verification random number and the second verification random number in the ciphertext are the same.

10. A vehicle controller, characterized in that: include: A transceiver module, configured to generate a first verification random number upon receiving upgrade task information sent by an upgrade server; wherein the upgrade task information is sent when the upgrade server determines that a new version of a preset program exists; A processing module, used for agreeing on a key with the upgrade server; The processing module is further used to control the transceiver module to send the first verification random number to the upgrade server; The transceiver module is further used to receive the upgrade information including the ciphertext sent by the upgrade server; The processing module is further used to decrypt the ciphertext received by the transceiver module based on the key and a pre-configured encryption algorithm to determine a second verification random number contained in the ciphertext; The processing module is further configured to generate prompt information for prompting to upgrade the preset program when the second verification random number is the same as the first verification random number.

11. A vehicle, characterized in that: Comprising a vehicle controller as claimed in claim 10.

12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the upgrade method according to any one of claims 1 to 4, or which, when executed by a processor, are used to implement the upgrade method according to any one of claims 5 to 8.

Citation Information

Patent Citations

  • Continuous security key derivation method and system based on dynamic key sampling

    CN117650883A

  • Block chain key generation method and device, equipment, medium and product

    CN118316601A

  • Quantum key charging system and method and computing device

    CN118353623A

  • Communication encryption method and device

    US8767957B1