Vehicle diagnosis service processing method, cloud server, storage medium and equipment

By performing vehicle diagnostic service identity checking and data signature encryption on cloud servers, the problem of large security overhead of the vehicle electronic control unit and difficulty in updating and replacing certificates is solved, and the vehicle safety certification is lightweight and efficient.

CN120010443APending Publication Date: 2025-05-16DEEPAL AUTOMOBILE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510132962.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the vehicle-side electronic control unit needs to deploy security algorithms, certificates and keys, resulting in a large security overhead. After the vehicle is sold, certificate updates and key replacements are difficult to achieve.

Method used

The identity verification of the diagnostic service is carried out through the cloud server, the certificates and keys of the target electronic control units of the vehicle are stored, the identity verification request data of the diagnostic equipment is received, the permissions are verified, and the diagnostic service operation request data is signed and encrypted, and sent to the vehicle.

Benefits of technology

It reduces the security overhead of the electronic control unit on the vehicle, simplifies the certificate update and key replacement process, and meets the safety needs of the vehicle.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120010443A_ABST
    Figure CN120010443A_ABST
Patent Text Reader

Abstract

The invention relates to a vehicle diagnosis service processing method, which comprises the following steps of: receiving identity verification request data of a vehicle target electronic control unit sent by diagnosis equipment, and verifying whether the diagnosis equipment has an authority of performing diagnosis service on the target electronic control unit based on the identity verification request data; sending a verification result to the diagnosis equipment; and receiving diagnosis service operation request data sent by the diagnosis equipment after the verification result is received that the diagnosis equipment has the authority, signing and encrypting the diagnosis service operation request data, and sending the signed and encrypted diagnosis service operation request data to the vehicle. The invention further provides a cloud server, a storage medium and equipment. According to the invention, the security overhead of the vehicle-end electronic control unit can be reduced, the security requirement of the vehicle can be met, and the difficulty of certificate update and key replacement of the vehicle-end electronic control unit is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicle diagnostic services, and in particular to a vehicle diagnostic service processing method, a cloud server, a storage medium and a device. Background Art

[0002] The electronic control unit (ECU) of a vehicle often needs to perform operations involving security attributes, such as software flashing, configuration update, VIN code writing, routine control, and input / output control of the ECU. These operations are usually implemented based on diagnostic communication protocols. Before performing these operations involving security attributes, the ECU needs to authenticate the diagnostic service, also known as security authentication. Only after the authentication is passed can operations involving the security attributes of the ECU be performed.

[0003] The current method of authenticating diagnostic services is to directly authenticate the diagnostic equipment with the electronic control unit on the vehicle side, and each electronic control unit on the vehicle side needs to deploy the corresponding security algorithm, certificate and key. The current method of authenticating diagnostic services has the following technical problems: the security algorithm, certificate and key need to be deployed on the vehicle side, which is a large expense for the vehicle side; after the vehicle is sold, due to the large number of vehicles and their wide distribution, there is an inconvenience in updating the certificates stored on the vehicle side and replacing the keys stored on the vehicle side. Even if the over-the-air upgrade technology (OTA) is used, it is difficult to solve the problem of inconvenient certificate update and key replacement on the vehicle side. Summary of the invention

[0004] The object of the present invention is to provide a vehicle diagnostic service processing method, a cloud server, a storage medium and a device to alleviate or eliminate at least one of the above-mentioned technical problems.

[0005] A vehicle diagnostic service processing method according to the present invention is applied to a cloud server and comprises the following steps: Receiving identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verifying whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and sending the verification result to the diagnostic device; The diagnostic service operation request data is received after the diagnostic device receives the verification result that the diagnostic device has the authorization, signs and encrypts the diagnostic service operation request data, and sends the signed and encrypted diagnostic service operation request data to the vehicle.

[0006] Optionally, the verifying whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data includes the following steps: using the certificate and key corresponding to the target electronic control unit stored in the cloud server to verify the identity verification request data.

[0007] Optionally, the method further includes the following steps: receiving an operation result of the target electronic control unit after executing the diagnostic service operation request data, and sending the operation result to the diagnostic device.

[0008] Optionally, the method further includes the following steps: receiving a failure result sent by the vehicle indicating that the decryption and signature verification of the received diagnostic service operation request data failed, and sending the failure result to the diagnostic device.

[0009] Optionally, the method further includes the following steps: updating a certificate corresponding to the target electronic control unit stored in the cloud server.

[0010] Optionally, the method further includes the following steps: replacing the key corresponding to the target electronic control unit stored in the cloud server.

[0011] Optionally, the diagnostic service includes software flashing, configuration updating, VIN code writing, routine control and input / output control.

[0012] The present invention also proposes a cloud server, comprising: The identity verification module is used to: receive identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verify whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and send the verification result to the diagnostic device; The encryption signature module is used to: receive the diagnostic service operation request data sent by the diagnostic device after receiving the verification result that the diagnostic device has the authority, sign and encrypt the diagnostic service operation request data, and send the signed and encrypted diagnostic service operation request data to the vehicle.

[0013] The present invention also proposes a storage medium on which a computer program is stored. When the computer program is executed by a processor of a computer, the steps of the vehicle diagnostic service processing method described in any one of the above items are implemented.

[0014] The present invention also proposes a device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the vehicle diagnostic service processing method described in any one of the above items when executing the computer program.

[0015] The present invention can reduce the security overhead of the vehicle-side electronic control unit, can meet the security requirements of the vehicle, and reduces the difficulty of updating the certificate and replacing the key of the vehicle-side electronic control unit. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 is a flow chart of a vehicle diagnostic service processing method described in some embodiments; Figure 2 is a schematic diagram of a vehicle diagnostic service processing system described in some embodiments; Figure 3 The flowchart is a specific example of the vehicle diagnosis service processing method. DETAILED DESCRIPTION

[0017] The following will describe the embodiments of the present invention with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the contents disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention, not for limiting the scope of protection of the present invention.

[0018] It should be noted that the illustrations provided in the following embodiments are only schematic illustrations of the basic concept of the present invention, and thus the drawings only show components related to the present invention rather than being drawn according to the number, shape and size of components in actual implementation. In actual implementation, the type, quantity and proportion of each component may be changed arbitrarily, and the component layout may also be more complicated.

[0019] like Figure 1 A vehicle diagnostic service processing method is shown, and the vehicle diagnostic service processing method is applied to a cloud server. The vehicle diagnostic service processing method includes the following steps: S10: receiving identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verifying whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and sending the verification result to the diagnostic device; S20: receiving the diagnostic service operation request data sent by the diagnostic device after the verification result indicates that the device has the authority, signing and encrypting the diagnostic service operation request data, and sending the signed and encrypted diagnostic service operation request data to the vehicle.

[0020] The above diagnostic service identity verification method is applied to the cloud server, and the certificates and keys of each target electronic control unit on the vehicle side are stored in the cloud server, which can reduce the number of certificates and keys stored on the vehicle side. By updating and replacing the certificates and keys stored in the cloud server, the certificates and keys corresponding to each target electronic control unit on the vehicle side can be updated and replaced, thereby avoiding certificate updates and key replacements for a large number of vehicles distributed in various places, and reducing the difficulty of certificate updates and key replacements for electronic control units on the vehicle side.

[0021] With the above-mentioned diagnostic service identity verification method, identity authentication is performed by the cloud server, and each electronic control unit on the vehicle side does not need to develop this function, which reduces the software development work of the electronic control unit on the vehicle side. When performing diagnostic services, the vehicle can verify the signature of the data sent by the cloud server to ensure security requirements, achieving the effect of lightweight vehicle security authentication, while meeting the vehicle safety requirements and reducing the security overhead of each electronic control unit on the vehicle side.

[0022] As a specific example, verifying whether the diagnostic device has the authority to provide diagnostic services to the target electronic control unit based on the identity verification request data includes the following steps: using the certificate and key corresponding to the target electronic control unit stored in the cloud server to verify the identity verification request data.

[0023] In some embodiments, in order to better feedback the results of the diagnostic service operation to the operator, the diagnostic service identity verification method also includes the following steps: receiving the operation results after the target electronic control unit executes the diagnostic service operation request data, and sending the operation results to the diagnostic device.

[0024] In some embodiments, in order to better provide feedback to the operator on the results of the diagnostic service operation, the diagnostic service identity verification method also includes the following steps: receiving a failure result sent by the vehicle for decrypting and verifying the received diagnostic service operation request data, and sending the failure result to the diagnostic device.

[0025] In some embodiments, the diagnostic service identity verification method further includes the following steps: updating the certificate corresponding to the target electronic control unit stored in the cloud server. Updating the certificate stored in the cloud server is easy to implement.

[0026] In some embodiments, the diagnostic service identity verification method further includes the following steps: replacing the key corresponding to the target electronic control unit stored in the cloud server. Replacing the key stored in the cloud server has the characteristic of being easy to implement.

[0027] In specific implementations, diagnostic services include software flashing, configuration updating, VIN code writing, routine control, and input / output control.

[0028] In specific implementation, the following can be used Figure 2 The vehicle diagnostic service processing system shown implements the above-mentioned vehicle diagnostic service processing method, and the vehicle diagnostic service processing system includes a diagnostic device 100, a cloud server 200, a vehicle 300 and a target electronic control unit 400. The diagnostic device 100 is a device that provides diagnostic services / electrical inspection services, and can realize the initiation of diagnostic service requests. The diagnostic service request includes an identity authentication request and other operation requests related to the security attributes of the electronic control unit. The cloud server 200 can serve as a security portal for the vehicle 300. The cloud server 200 performs a unified identity verification on the diagnostic service issued by the diagnostic device 100. Each target electronic control unit 400 of the vehicle 300 does not need to perform identity verification separately, nor does it need to store a large number of certificates and keys on each vehicle. The cloud server 200 stores the certificates and keys corresponding to each electronic control unit of the vehicle as a whole. After the vehicle 300 receives the diagnostic service request data from the cloud server 200, it is necessary to verify the signature of the data diagnostic service request data to ensure the authenticity and integrity of the diagnostic service request data. The target electronic control unit 400 is an on-board electronic control unit of the vehicle 300, which can respond to the diagnostic service operation request.

[0029] In order to better illustrate the vehicle diagnostic service processing method proposed in this application, a specific example is given in combination with the above-mentioned vehicle diagnostic service processing system to illustrate the specific implementation process of the vehicle diagnostic service processing method. Figure 3 As shown, in this example, the vehicle diagnostic service processing method includes identity verification, data signature verification and operation implementation.

[0030] More specifically, identity verification includes the following steps: S50: The diagnostic device initiates an identity authentication request and sends identity verification request data to the cloud server.

[0031] S10: After receiving the identity authentication request data, the cloud server performs identity verification according to the certificate and key corresponding to the target electronic control unit stored in the cloud server, and feeds back the verification result to the diagnostic device.

[0032] After receiving the verification result, the diagnostic device judges the verification result. If the verification result is not passed, the identity verification fails and the diagnostic service request is exited. If the verification result is passed, the data signature is executed.

[0033] Data verification includes the following steps: S60: The diagnostic device sends diagnostic service operation request data to the cloud server.

[0034] S201: After receiving the diagnostic service operation request data, the cloud server signs and encrypts the diagnostic service operation request data, and sends the signed and encrypted diagnostic service operation request data to the vehicle.

[0035] S70: The vehicle decrypts and verifies the signature and encrypted diagnostic service operation request data sent by the cloud server, verifies the integrity and authenticity of the diagnostic service operation request data, and discards the data and records the log if the decryption and verification fail; if the verification passes, the operation is performed. In the specific implementation, after discarding the data and recording the log, the following steps are also included: S30: The vehicle sends the verification failure result to the cloud server, notifying the cloud server of the verification failure; the cloud server sends the verification failure result to the diagnostic device, notifying the diagnostic device of the verification failure or the operation failure.

[0036] The implementation includes the following steps: S80: The vehicle sends the decrypted diagnostic service operation request data to the target electronic control unit.

[0037] S90: After receiving the decrypted diagnostic service operation request data, the target electronic control unit executes the operation request corresponding to the diagnostic service operation request data, and feeds back the operation result to the cloud server.

[0038] S40: The cloud server forwards the operation result to the diagnostic device and notifies the diagnostic device that the operation is completed.

[0039] The present invention also proposes a cloud server, including an identity verification module and an encryption signature module, the identity verification module is used to: receive identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verify whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and send the verification result to the diagnostic device; the encryption signature module is used to: receive diagnostic service operation request data sent by the diagnostic device after receiving the verification result that the diagnostic device has the authority, sign and encrypt the diagnostic service operation request data, and send the signed and encrypted diagnostic service operation request data to the vehicle. In a specific implementation, the cloud server also includes a storage module for storing certificates and keys.

[0040] The present invention also proposes a storage medium on which a computer program is stored. When the computer program is executed by a processor of a computer, the steps of the vehicle diagnostic service processing method described in any one of the above items are implemented.

[0041] The present invention also proposes a device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the vehicle diagnostic service processing method described in any one of the above items when executing the computer program.

[0042] The above embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or changes made by those skilled in the art on the basis of the present invention are all within the protection scope of the present invention. In the description of this specification, the description of reference terms "one embodiment", "some embodiments", "example", "specific example" or "some examples" etc. means that the specific features, structures, materials or characteristics of the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art can combine and combine the different embodiments or examples described in this specification.

Claims

1. A vehicle diagnostic service processing method, characterized in that: Applied to cloud servers, including the following steps: Receiving identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verifying whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and sending the verification result to the diagnostic device; The diagnostic service operation request data is received after the diagnostic device receives the verification result that the diagnostic device has the authorization, signs and encrypts the diagnostic service operation request data, and sends the signed and encrypted diagnostic service operation request data to the vehicle.

2. The vehicle diagnostic service processing method according to claim 1, characterized in that: The verification of whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data includes the following steps: using the certificate and key corresponding to the target electronic control unit stored in the cloud server to verify the identity verification request data.

3. The vehicle diagnostic service processing method according to claim 1, characterized in that: The following steps are also included: The operation result after the target electronic control unit performs the operation according to the diagnostic service operation request data is received, and the operation result is sent to the diagnostic device.

4. The vehicle diagnostic service processing method according to claim 1, characterized in that: The following steps are also included: A failure result sent by the vehicle indicating failure in decrypting and verifying the received diagnostic service operation request data is received, and the failure result is sent to the diagnostic device.

5. The vehicle diagnostic service processing method according to claim 1, characterized in that: The following steps are also included: The certificate corresponding to the target electronic control unit stored in the cloud server is updated.

6. The vehicle diagnostic service processing method according to claim 1, characterized in that: The following steps are also included: The key corresponding to the target electronic control unit stored in the cloud server is replaced.

7. The vehicle diagnostic service processing method according to claim 1, characterized in that: The diagnostic services include software flashing, configuration updating, VIN code writing, routine control and input / output control.

8. A cloud server, characterized in that: include: The identity verification module is used to: receive identity verification request data of a target electronic control unit of a vehicle sent by a diagnostic device, verify whether the diagnostic device has the authority to perform diagnostic services on the target electronic control unit based on the identity verification request data, and send the verification result to the diagnostic device; The encryption signature module is used to: receive the diagnostic service operation request data sent by the diagnostic device after receiving the verification result that the diagnostic device has the authority, sign and encrypt the diagnostic service operation request data, and send the signed and encrypted diagnostic service operation request data to the vehicle.

9. A storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a processor of a computer, the steps of the vehicle diagnostic service processing method described in any one of claims 1 to 7 are implemented.

10. A device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the vehicle diagnostic service processing method described in any one of claims 1 to 7 are implemented.