Control method for safe flashing and safe starting of EVCC program of European standard vehicle
By designing a control method on the EVCC communication controller EVCC, the European standard electric vehicle is used to use DCAN tools and UPG file format, combined with the secure hash algorithm and the elliptic curve signature algorithm, the safe flash writing and secure startup of the EVCC program is realized, solving the problem that existing EVCC products cannot meet the requirements of European standard regulations and improving information security protection capabilities.
Patent Information
- Application Number
- CN202411830148.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-12
- Publication Date
- 2025-05-16
AI Technical Summary
The existing European standard electric vehicle communication controller EVCC products lack safe start and safe write functions and cannot meet the requirements of UNR155 and UNR156 regulations, especially those automotive electronic modules that do not contain HSM hardware safety modules.
By designing a control method without changing any existing EVCC hardware, using DCAN tools and UPG file format, combining the secure hashing algorithm SHA-256 and the elliptic curve signature algorithm ECDSA, the secure flash writing and secure startup of the EVCC program is realized.
It effectively realizes the safe start and safe write functions of EVCC, meets the requirements of European standard electric regulations, improves the information security protection capabilities of EVCC products, and ensures the network information security of vehicle-side EVCC products during charging and non-charging processes.
Smart Images

Figure CN120010866A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of automobile control technology, and in particular to a control method for safe flashing and safe starting of an EVCC program of a European standard vehicle. Background Art
[0002] As the implementation date of the European standard electric vehicle charging network security regulations UNR155 and UNR156 is approaching, the network security requirements of electric vehicle parts suppliers are also proposed by vehicle manufacturers. UNR155 and UNR156 are mandatory regulations formulated by the United Nations World Forum for Harmonization of Vehicle Regulations WP.29, which aim to ensure the compliance of vehicle network security and software updates. Among them, UNR155 requires automobile manufacturers to establish a comprehensive network security management system to prevent and respond to potential network threats; UNR156 puts forward requirements for software update management for vehicle manufacturers to ensure that vehicles can carry out software update activities safely and controllably throughout their life cycle. The European standard electric vehicle communication controller EVCC products of most manufacturers currently do not have the functions of secure boot and secure flashing. Therefore, EVCC products do not meet the requirements of UNR155 and UNR156 regulations. However, the existing methods for improving the information security of automobile gateways require that the MCU must have the support of the HSM hardware security module to achieve secure boot and secure flashing. The method is cumbersome and difficult to implement. For automotive electronic modules that do not originally contain the HSM hardware security module, the secure boot and secure flashing functions cannot be achieved. Summary of the invention
[0003] The purpose of the present invention is to provide a control method for safe flashing and safe starting of EVCC program of European standard vehicle, which can effectively realize the safe starting and safe flashing functions of EVCC without changing any existing hardware of EVCC and meeting the requirements of European standard electric regulations.
[0004] In order to achieve the above object, the technical solution adopted by the present invention is: a control method for safe flashing and safe starting of EVCC program of European standard vehicle, comprising the following steps: Step 1: Perform a safe flash of the EVCC program for European standard vehicles; Step 11, the programmer starts the DCAN tool on the host computer and opens the UPG file of the EVCC program to be upgraded; Step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded, and returns the verification result. If the verification passes, it proceeds to step 13, and if the verification fails, it proceeds to step 17; Step 13. The programmer clicks "Run" in the DCAN tool to execute the burning action. The DCAN tool sends the UPG file of the EVCC program to be upgraded to the Boot in the EVCC. Step 14, the Boot program receives and decrypts the UPG file, extracts the UPG header information, reads the UPG header signature, and uses the public key to decrypt and obtain the summary MD; Step 15, the Boot program reads the BIN file information of EVCC in UPG and uses the secure hash algorithm SHA-256 to calculate the digest MD2; Step 16, the Boot program compares MD and MD2. If the comparison is consistent, the BIN file content of EVCC is burned into the EVCC public area; if the comparison is inconsistent, the burning is stopped; Step 17, the DCAN program run button turns gray, prohibiting the burning operation; the burner closes the DCAN program; Step 2: Perform a safe start of the EVCC program for European standard vehicles; Step 21, after EVCC is powered on, the Boot program is started first. After the Boot program is started, a safety check is performed on the EVCC program that needs to be booted. If the safety check succeeds, the EVCC program is booted normally. If the safety check fails, an error record is made and the EVCC program is no longer booted.
[0005] Preferably, before step 11, a packaging tool is used to package the EVCC program to be upgraded into a UPG file, and the secure hash algorithm SHA-256 is used to hash the EVCC application software BIN file to obtain the digest MD; the packaging tool reads the private key, and uses the elliptic curve signature algorithm ECDSA to sign the digest MD to obtain the program summary signature Signature, and the program summary signature Signature is written into the header of the UPG file.
[0006] Preferably, the private key and the public key are based on an asymmetric encryption suite, the public key is installed in the Boot of each EVCC and the DCAN upgrade tool, and the private key is stored within the company.
[0007] Preferably, in step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded, including: using the public key to verify the program summary signature Signature using the ECDSA with SHA 256 algorithm.
[0008] Preferably, after successfully verifying the UPG file of the EVCC program to be upgraded, the DCAN tool opens the UPG header information and outputs the UPG header information to the DCAN upgrade output area for display.
[0009] Preferably, the UPG header information in step 14 also includes program type, version, program size and CRC-16 checksum.
[0010] Preferably, the internal storage environment of the EVCC is divided into a secure area and a public area, the Boot and the public key are stored in the secure area, and the EVCC program is stored in the public area.
[0011] Preferably, the EVCC program includes Boot and an application program App, wherein the Boot is used to provide guidance and load the EVCC program, and the App is used to execute the EVCC European standard charging core function.
[0012] Preferably, before Boot starts the APP program in step 21, the public key verifies the program summary signature Signature; if the signature verification fails, it means that the EVCC program has been tampered with; if the signature verification passes, it means that the EVCC program has not been tampered with and can continue to be started.
[0013] The beneficial effects of the present invention are: This solution uses this control method without changing any existing EVCC hardware without the need for an HSM module, effectively realizing the safe startup and safe flashing functions of the EVCC, meeting the requirements of European electric regulations, improving the information security protection capabilities of EVCC products, and ensuring the network information security of vehicle-side EVCC products during the charging and non-charging processes. A UPG file format dedicated to EVCC program upgrades was designed, the DCAN upgrade tool and host computer software were implemented, and a control method for safe startup and safe flashing of the EVCC program was designed and implemented. EVCC products using this control method meet the requirements of network information security after TARA analysis, and this method is convenient, effective, and easy to deploy and implement. In addition, the host computer software of the DCAN upgrade tool is compatible with CAN adapters of other brands on the market, and can quickly and conveniently use CAN adapters of other brands and perform safe flashing functions of EVCC products. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0015] Figure 1 It is a UML timing diagram of the EVCC program flashing process of the present invention.
[0016] Figure 2 This is a flowchart of the EVCC program startup of the present invention.
[0017] Figure 3 This is a diagram of the EVCC program signature generation method of the present invention.
[0018] Figure 4 This is a signature flow chart for the EVCC program packaging of the present invention.
[0019] Figure 5 The EVCC program composition diagram after adding the program signature to the present invention.
[0020] Figure 6 It is a schematic diagram of the EVCC program installation package UPG file of the present invention.
[0021] Figure 7 This is a diagram of the internal storage environment of the EVCC of the present invention.
[0022] Figure 8 This is a program composition diagram in the EVCC of the present invention.
[0023] Fig. 9 This is a DCAN tool verification flow chart of the present invention. DETAILED DESCRIPTION
[0024] The present invention is further described in detail below in conjunction with embodiments and with reference to the accompanying drawings.
[0025] The present invention discloses a control method for safe flashing and safe starting of EVCC program of European standard vehicle, which comprises the following steps: Step 1: Perform a safe flash of the EVCC program for European standard vehicles; like Figure 1 As shown, step 11, the programmer starts the DCAN tool of the host computer and opens the UPG file of the EVCC program to be upgraded; Step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded, and returns the verification result. If the verification passes, it proceeds to step 13, and if the verification fails, it proceeds to step 17; Step 13. The programmer clicks "Run" in the DCAN tool to execute the burning action. The DCAN tool sends the UPG file of the EVCC program to be upgraded to the Boot in the EVCC. Step 14, the Boot program receives and decrypts the UPG file, extracts the UPG header information, reads the UPG header signature, and uses the public key to decrypt and obtain the summary MD; Step 15, the Boot program reads the BIN file information of EVCC in UPG and uses the secure hash algorithm SHA-256 to calculate the digest MD2; Step 16, the Boot program compares MD and MD2. If the comparison is consistent, the BIN file content of EVCC is burned into the EVCC public area; if the comparison is inconsistent, the burning is stopped; Step 17, the DCAN program run button turns gray, prohibiting the burning operation; the burner closes the DCAN program; like Figure 2 As shown, step 2, perform a safe start of the EVCC program of the European standard vehicle; Step 21, after EVCC is powered on, the Boot program is started first. After the Boot program is started, a safety check is performed on the EVCC program that needs to be booted. If the safety check succeeds, the EVCC program is booted normally. If the safety check fails, an error record is made and the EVCC program is no longer booted.
[0026] like Figure 3 , 4 As shown, before step 11, the EVCC program to be upgraded is packaged into a UPG file using a packaging tool, and the EVCC application software BIN file is hashed using the secure hash algorithm SHA-256 to obtain the summary MD; the packaging tool reads the private key, and uses the elliptic curve signature algorithm ECDSA to sign the summary MD to obtain the program summary signature Signature, and writes the program summary signature Signature into the header of the UPG file. After adding the program signature, the EVCC program composition is as follows Figure 5 shown.
[0027] In the signing process, the BIN file is first hashed using the SHA-256 algorithm to obtain a 32-byte hash value, which is the "fingerprint" of the BIN file. The "fingerprint" is then digitally signed using the private key in the ECDSA-256 algorithm to obtain a 64-byte digital signature, which is then attached to the BIN file.
[0028] The private key and public key are based on an asymmetric encryption suite, which uses the ECDSA_with_SHA256 curve parameter of secp256r1. The public key is installed in the Boot of each EVCC and the DCAN upgrade tool, and the private key is stored within the company.
[0029] In step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded by using the public key and the ECDSA with SHA 256 algorithm to verify the program summary signature.
[0030] During the signature verification process, the BIN file is verified by BOOTLOADR when it is burned and run. The digital signature in the BIN file is verified together with the public key in the ECDSA-256 algorithm. If the verification passes, it proves that the BIN file is a legal file and can be burned or started. Otherwise, it is an illegal file and will not be burned or started. The hash algorithm and digital signature verification method are shown in Table 1 below: Table 1 After the DCAN tool successfully verifies the UPG file of the EVCC program to be upgraded, it opens the UPG header information and outputs the UPG header information to the DCAN upgrade output area for display. As shown in Table 2 below: Table 2 The UPG header information in step 14 also includes program type, version, program size and CRC-16 checksum, such as Figure 6 shown.
[0031] The EVCC internal storage environment is divided into a secure area and a public area. Boot and public keys are stored in the secure area, and EVCC programs are stored in the public area. The programs and public key information in the secure area will not be read or accessed by the outside world to prevent external tampering; the open area provides an external interface access method, and the EVCC program can be burned through the DCAN program of the host computer, such as Figure 7 shown.
[0032] The EVCC program includes Boot, application program App, such as Figure 8 As shown, the Boot is used to provide guidance and load the EVCC program, and the App is used to execute the EVCC European standard charging core function. When the EVCC product leaves the factory, the chip hardware interface such as JTAG / USB / USART has been physically isolated and disabled.
[0033] In step 21, before Boot starts the APP program, the public key verifies the program summary signature Signature; if the signature verification fails, it means that the EVCC program has been tampered with; if the signature verification passes, it means that the EVCC program has not been tampered with and can continue to be started.
[0034] During the EVCC software burning process, the following security flashing aspects are met: 1. Integrity check of the program to be upgraded: CRC-16 is used to ensure the integrity of the program file. 2. Compatibility check between the program to be upgraded and the target product to be burned: The header of the current version of the UPG file contains information about the upgrade program, which includes program type, version, size, etc. The DCAN tool will use this information to compare with the program information in the EVCC to be upgraded to complete the compatibility check. 3. Authenticity check of the program to be upgraded: The current DCAN burning tool verification process is as follows. 4. The verification algorithm used is: ECDSA_with_SHA256. When the verification passes, it means that the EVCC program UPG package is authentic and the burning operation can continue. When the verification fails, it means that the EVCC program UPG package is not authentic or does not support authenticity verification. The burning operation is stopped, and the user is prompted in text form in DCAN. The DCAN tool follows the following steps: Fig. 9 Verify the process.
[0035] It should be noted that the parts not described in detail in the above embodiments are all prior art.
[0036] The above description is only a preferred embodiment of the present invention and does not constitute any form of limitation to the present invention. Although the present invention has been disclosed as a preferred embodiment as above, it is not intended to limit the present invention. Any technician familiar with the profession can make some changes or modifications to equivalent embodiments of equivalent changes using the technical contents disclosed above without departing from the scope of the technical solution of the present invention. However, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention should be covered within the protection scope of the present invention.
Claims
1. A control method for safe flashing and safe starting of EVCC program of European standard vehicle, characterized by: The following steps are involved: Step 1: Perform a safe flash of the EVCC program for European standard vehicles; Step 11, the programmer starts the DCAN tool on the host computer and opens the UPG file of the EVCC program to be upgraded; Step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded, and returns the verification result. If the verification passes, it proceeds to step 13, and if the verification fails, it proceeds to step 17; Step 13, the programmer clicks "Run" in the DCAN tool to execute the burning action, and the DCAN tool sends the UPG file of the EVCC program to be upgraded to the Boot in the EVCC; Step 14, the Boot program receives and decrypts the UPG file, extracts the UPG header information, reads the UPG header signature, and uses the public key to decrypt and obtain the summary MD; Step 15, the Boot program reads the BIN file information of EVCC in UPG and uses the secure hash algorithm SHA-256 to calculate the digest MD2; Step 16, the Boot program compares MD and MD2. When the comparison is consistent, the BIN file content of EVCC is burned into the EVCC public area; If the comparison is inconsistent, stop the programming; Step 17, the DCAN program run button turns gray, prohibiting the burning operation; the burner closes the DCAN program; Step 2: Perform a safe start of the EVCC program for European standard vehicles; Step 21, after the EVCC is powered on, the Boot program is started first. After the Boot program is started, a safety check is performed on the EVCC program that needs to be booted; When the safety check succeeds, the EVCC program is booted normally; when the safety check fails, an error record is made and the EVCC program is not booted again.
2. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 1 is characterized in that: Before step 11, the EVCC program to be upgraded is packaged into a UPG file using a packaging tool, and the EVCC application software BIN file is hashed using the secure hash algorithm SHA-256 to obtain the digest MD; the packaging tool reads the private key, and uses the elliptic curve signature algorithm ECDSA to sign the digest MD to obtain the program summary signature Signature, and writes the program summary signature Signature into the header of the UPG file.
3. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 2 is characterized in that: The private key and public key are based on an asymmetric encryption suite. The public key is installed in the Boot of each EVCC and the DCAN upgrade tool, and the private key is stored within the company.
4. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 1 is characterized in that: In step 12, the DCAN tool verifies the UPG file of the EVCC program to be upgraded by using the public key and the ECDSA with SHA 256 algorithm to verify the program summary signature.
5. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 4 is characterized in that: After successfully verifying the UPG file of the EVCC program to be upgraded, the DCAN tool opens the UPG header information and outputs the UPG header information to the DCAN upgrade output area for display.
6. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 2 is characterized by: The UPG header information in step 14 also includes program type, version, program size and CRC-16 checksum.
7. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 1 is characterized by: The internal storage environment of the EVCC is divided into a secure area and a public area. Boot and public keys are stored in the secure area, and the EVCC program is stored in the public area.
8. The control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 1 is characterized by: The EVCC program includes Boot and an application program App. The Boot is used to provide guidance and load the EVCC program, and the App is used to execute the EVCC European standard charging core function.
9. A control method for safe flashing and safe starting of EVCC program of European standard vehicle according to claim 8, characterized in that: In step 21, before Boot starts the APP program, the public key verifies the program summary signature Signature; if the signature verification fails, it means that the EVCC program has been tampered with; if the signature verification passes, it means that the EVCC program has not been tampered with and can continue to be started.