Digital certificate calling method, electronic equipment and vehicle
By dividing playback protection memory blocks in a trusted execution system and allocating a playback protection sub-memory block to each subsystem, the problem of system jamming caused by different electronic controllers at the same time is solved, and the system stability and efficiency improvement is achieved.
Patent Information
- Application Number
- CN202510122983.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-27
AI Technical Summary
When different electronic controllers retrieve digital certificates at the same time, the system will be stuck.
By dividing playback protection memory blocks in a trusted execution system, a playback protection sub-memory block is allocated to each subsystem, storing and calling their respective digital certificates to avoid calling the same certificate at the same time.
It effectively avoids the system's stuck situation, ensures that different subsystems can independently retrieve their corresponding digital certificates, and improves the stability and efficiency of the system.
Smart Images

Figure CN120045300A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information technology, and in particular to a digital certificate calling method, electronic equipment and a vehicle. Background Art
[0002] When the vehicle's electronic controller needs to communicate with the cloud, it must perform two-way authentication with the cloud through a digital certificate.
[0003] In order to save vehicle development costs, different electronic control units (ECUs) will be integrated with each other, that is, after integration, different ECUs share a set of hardware. If different ECUs retrieve digital certificates at the same time, the system will freeze. Summary of the invention
[0004] In view of this, the purpose of the present disclosure is to propose a digital certificate calling method, electronic device and vehicle, so as to solve the problem that the system may be stuck when different electronic controllers call digital certificates at the same time.
[0005] Based on the above purpose, the first aspect of the present disclosure provides a digital certificate calling method, which is applied to a vehicle side, wherein the vehicle side includes a trusted execution system and an integrated system that establishes a communication connection, and the integrated system includes multiple subsystems, and the method includes:
[0006] The trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain a plurality of replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of the subsystems;
[0007] The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives a digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem;
[0008] For each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
[0009] Based on the same inventive concept, the second aspect of the present disclosure proposes a digital certificate calling device, which is arranged at the vehicle end, and the device includes a trusted execution system and an integrated system for establishing a communication connection, and the integrated system includes multiple subsystems.
[0010] The trusted execution system is configured to receive the number of subsystems in the integrated system, divide the replay protection memory block in the trusted execution system according to the number of subsystems to obtain a plurality of replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems; allocate a replay protection sub-memory block to each subsystem in the integrated system, receive a digital certificate sent by each subsystem in the integrated system, and store the digital certificate in the replay protection sub-memory block corresponding to the subsystem;
[0011] The integrated system is configured such that for each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
[0012] Based on the same inventive concept, the third aspect of the present disclosure proposes an electronic device, including a memory, a processor, and a computer program stored in the memory and executable by the processor, wherein the processor implements the digital certificate calling method as described above when executing the computer program.
[0013] Based on the same inventive concept, the fourth aspect of the present disclosure proposes a non-transitory computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute the digital certificate calling method as described above.
[0014] Based on the same inventive concept, the fifth aspect of the present disclosure provides a vehicle, including the digital certificate calling device described in the second aspect or the electronic device described in the third aspect or the storage medium described in the fourth aspect.
[0015] As can be seen from the above, the present disclosure proposes a digital certificate calling method, an electronic device and a vehicle, the method is applied to the vehicle side, the vehicle side includes a trusted execution system and an integrated system for establishing a communication connection, and the integrated system includes multiple subsystems. The trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain multiple replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems. Because the digital certificate needs to be stored in the trusted execution system, and the trusted execution system runs on the hardware replay protection memory block partition, the replay protection memory block is divided so that different certificates can be stored in different replay protection sub-memory blocks in the future. The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives the digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem. When calling it later, the certificates in different replay protection sub-memory blocks can be called separately to avoid the situation where the system is stuck due to calling the same certificate at the same time. For each subsystem in the integrated system, the subsystem calls the program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains the digital certificate corresponding to the subsystem. After the digital certificate is stored in the replay protection sub-memory block corresponding to the subsystem, different subsystems can respectively retrieve the certificates in their corresponding replay protection sub-memory blocks when calling, avoiding the situation where the system is stuck due to the simultaneous retrieval of the same certificate. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0017] Figure 1 A flowchart of a digital certificate calling method according to an embodiment of the present disclosure;
[0018] Figure 2 is a schematic diagram of an integrated hardware platform of an embodiment of the present disclosure;
[0019] Figure 3 It is a structural block diagram of a digital certificate calling device according to an embodiment of the present disclosure;
[0020] Figure 4 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0021] In order to make the objectives, technical solutions and advantages of the present disclosure more clearly understood, the present disclosure is further described in detail below in combination with specific embodiments and with reference to the accompanying drawings.
[0022] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should be understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the embodiments of the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing before the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connect" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.
[0023] The terms used in this disclosure are explained as follows:
[0024] ECU: ECU (Electronic Control Unit) is an electronic controller unit, also known as the "on-board computer" of a car. Its purpose is to control the driving status of the car and realize its various functions.
[0025] PKI certificate: digital certificate, Public Key Infrastructure (PKI) is a typical cryptographic application technology. In the PKI system, the digital certificate is issued by the Certification Authority (CA) and bound to the identity information and public key of the PKI user.
[0026] VIN: VIN is the abbreviation of Vehicle Identification Number, also known as Vehicle Frame Number. VIN consists of 17 characters, including numbers and letters.
[0027] UIN: UIN, the full name of which is User Identification Number, is usually called User Identification Code or User Identification Number in Chinese. It is a specific code or number combination used to uniquely identify a user in a specific system or service.
[0028] SN: SN code is the abbreviation of Serial Number, sometimes also called Serial No, which is the product serial number. It is the product's ID number, used to verify the "legal identity of the product", protect the user's genuine rights and interests, and enjoy legal services.
[0029] TBOX: TelematicsBOX (TBOX), T-BOX is mainly used for communication between the vehicle-side ECU and the background system to upload vehicle-side vehicle condition signals or command results.
[0030] HUT: Head unit controller.
[0031] TEE: Trusted Execution Environment (TEE) is a secure computing environment that provides an isolated space to protect data and code execution, ensuring its confidentiality and integrity.
[0032] RPMB: Replay Protected Memory Block (RPMB), RPMB is a contained security protocol (with its own command opcodes and data structures). The protocol's mechanisms include a shared key and an HMAC (Hash Message Authentication Code) to sign all read / write operations that access the secure area.
[0033] TA: program, that is, trusted application.
[0034] When the vehicle electronic controller needs to communicate with the cloud, it needs to perform two-way authentication with the cloud through a digital certificate. Each ECU must pre-make this PKI certificate before leaving the factory. In addition, the PKI certificates of different ECUs in the same car are also different, because the VIN, public key information, UIN, and SN of the ECU are required to issue the certificate. For the same car, different ECUs have the same SN and VIN, but different UIN and public key information, so the corresponding PKI certificates are also different.
[0035] Because the certificate is required to be stored in the secure area TEE, TEE can be regarded as a secure operating system running on the hardware RPMB partition. If the APP or system wants to use the certificate, it must call the certificate in RPMB through TA. For example, if system A wants to use the certificate, it must access the TEE system through TA, and then access the certificate stored in the RPMB partition.
[0036] In order to save vehicle development costs, different electronic controllers (ECUs) will be integrated with each other, that is, after integration, different electronic controllers share a set of hardware. Currently, TEE does not support different systems calling the same TA. At the same time, if different electronic controllers call digital certificates at the same time, the system will freeze.
[0037] Based on the above description, this embodiment proposes a digital certificate calling method, which is applied to a vehicle end, wherein the vehicle end includes a trusted execution system and an integrated system for establishing a communication connection, and the integrated system includes multiple subsystems, such as Figure 1 As shown, the method includes:
[0038] Step 101, the trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain multiple replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems.
[0039] Step 102: The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives a digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem.
[0040] Step 103, for each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
[0041] During specific implementation, the trusted execution system is in communication connection with the integrated system, and receives the subsystem number of the subsystems in the integrated system, where the subsystem number is the number of subsystems included in the integrated system.
[0042] Since the digital certificate needs to be stored in the trusted execution system, and the trusted execution system runs on the hardware replay protection memory block partition, the replay protection memory block in the trusted execution system is divided according to the number of subsystems to obtain multiple replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of the subsystems.
[0043] Exemplarily, the number of subsystems is 3, which means that the number of subsystems included in the integrated system is 3, and the replay protection memory block in the trusted execution system is divided to obtain 3 replay protection sub-memory blocks.
[0044] In some embodiments, before dividing the replay protection memory block in the trusted execution system according to the number of subsystems, the trusted execution system can obtain the total memory amount of the replay protection memory block. When the trusted execution system divides the replay protection memory block in the trusted execution system according to the number of subsystems, it divides it equally according to the number of subsystems and the total memory amount, that is, the memory amount of each replay protection sub-memory block is equal. This avoids the problem that the memory amount of some replay protection sub-memory blocks is too small during random division, resulting in the inability to store digital certificates.
[0045] For example, the number of subsystems is 2, which means that the number of subsystems included in the integrated system is 2, and the total memory of the replay protection memory block is 10M. At this time, the memory is evenly divided according to the number of subsystems and the total memory to obtain two replay protection sub-memory blocks, and the memory capacity of each replay protection sub-memory block is 5M.
[0046] The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives a digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem.
[0047] The integrated system includes subsystems and programs corresponding to the subsystems. For each subsystem in the integrated system, the subsystem calls the program corresponding to the subsystem, and then accesses the replay protection sub-memory block corresponding to the subsystem according to the program to obtain the digital certificate corresponding to the subsystem.
[0048] Exemplarily, the integrated system includes subsystem A and subsystem B, the program corresponding to subsystem A is TA1, and the program corresponding to subsystem B is TA2. The trusted execution system includes replay protection submemory blocks RPMB1 and RPMB2, RPMB1 stores digital certificate 1 corresponding to subsystem A, and RPMB2 stores digital certificate 2 corresponding to subsystem B. Therefore, subsystem A can access digital certificate 1 in RPMB1 by calling TA1, and subsystem B can access digital certificate 2 in RPMB2 by calling TA2.
[0049] In some embodiments, different subsystems have their own corresponding programs, and a subsystem is only allowed to call its own corresponding program to obtain the corresponding digital certificate. A subsystem is not allowed to access the programs corresponding to other subsystems.
[0050] Based on the above example, subsystem A is only allowed to call TA1 and is not allowed to call TA2.
[0051] Through the above scheme, the number of subsystems in the integrated system is received, and the replay protection memory block in the trusted execution system is divided according to the number of subsystems to obtain multiple replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems. Because the digital certificate needs to be stored in the trusted execution system, and the trusted execution system runs on the hardware replay protection memory block partition, the replay protection memory block is divided so that different certificates can be stored in different replay protection sub-memory blocks later. A replay protection sub-memory block is allocated to each subsystem in the integrated system, and the digital certificate sent by each subsystem in the integrated system is received, and the digital certificate is stored in the replay protection sub-memory block corresponding to the subsystem. When calling subsequently, the certificates in different replay protection sub-memory blocks can be retrieved respectively to avoid the situation where the same certificate is retrieved at the same time and the system is stuck. Because the replay protection memory block in the trusted execution system is divided into multiple replay protection sub-memory blocks, after the digital certificate is stored in the replay protection sub-memory block corresponding to the subsystem, different subsystems can respectively call the certificate in their corresponding replay protection sub-memory blocks when calling, avoiding the situation where the system is stuck due to calling the same certificate at the same time.
[0052] In some embodiments, after storing the digital certificate in the replay protection sub-memory block corresponding to the sub-system, that is, after step 102, the following further includes:
[0053] Step 10A: The trusted execution system detects the network connection status.
[0054] Step 10B: The trusted execution system determines a target download mode according to the network connection status, downloads a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, and sends the digital certificate to the integrated system.
[0055] In step 10C, the integrated system receives the digital certificate.
[0056] During specific implementation, the trusted execution system checks the network connection status, wherein the network connection status is used to indicate whether the network is available, and the network connection status specifically includes a connected state or a disconnected state.
[0057] The trusted execution system determines a target download mode corresponding to the network connection state according to the determined network connection state, downloads a corresponding digital certificate for the subsystem in the integrated system based on the target download mode, and sends the digital certificate to the integrated system. The integrated system receives the digital certificate sent by the trusted execution system.
[0058] Wherein, the target download mode is a digital certificate download mode, and the target download mode includes automatic certificate download or diagnostic flash certificate download. Specifically, if the network connection state is connected, the target download mode is automatic certificate download. If the network connection state is disconnected, the target download mode is diagnostic flash certificate download.
[0059] Through the above solution, the corresponding download method is determined according to the network connection status. The determined download method is more accurate, avoiding the failure of digital certificate download due to network problems, so as to further ensure the normal communication between the vehicle and the cloud.
[0060] In some embodiments, step 10B specifically includes:
[0061] Step 10B1, in response to the network connection state being a connected state, the trusted execution system detects that a first target subsystem in the integrated system lacks a target digital certificate, and determines a target public key corresponding to the first target subsystem;
[0062] Step 10B2: The trusted execution system uses the target public key to encrypt the target digital certificate to obtain an encrypted digital certificate, and sends the encrypted digital certificate to the integration system.
[0063] In specific implementation, if the network connection status is connected, it means that it is in a networked state. The trusted execution system detects each subsystem in the integrated system. If it is detected that the first target subsystem in the integrated system lacks a target digital certificate, the trusted execution system should automatically download the certificate for the first target subsystem, that is, the target download mode is automatic download.
[0064] The trusted execution system determines the target public key corresponding to the first target subsystem, and uses the target public key to encrypt the target digital certificate to obtain an encrypted digital certificate. The encrypted digital certificate is sent to the integrated system, so that the integrated system receives the encrypted digital certificate and decrypts it using the private key corresponding to the target public key to obtain the target digital certificate.
[0065] Through the above scheme, the trusted execution system automatically detects whether the subsystem in the integrated system lacks a digital certificate when connected to the network. If it is detected that a subsystem lacks a digital certificate, the corresponding public key is used for encryption to avoid the leakage of the digital certificate.
[0066] In some embodiments, when in a networked state, the trusted execution system automatically detects whether a subsystem in the integrated system lacks a digital certificate. If it is detected that a subsystem lacks a digital certificate, the trusted execution system uses the corresponding public key to encrypt and obtain the encrypted digital certificate. The trusted execution system sends the encrypted digital certificate to the integrated system. Step 10C specifically includes:
[0067] Step 10C1, the integrated system receives the encrypted digital certificate sent by the trusted execution system;
[0068] Step 10C2: the integrated system performs decryption processing using the target private key corresponding to the target public key to obtain a target digital certificate corresponding to the first target subsystem.
[0069] In specific implementation, PKI is a public key infrastructure, which is an infrastructure that follows the theory and technology of public key cryptography to provide a universal security service platform for e-commerce. Its basic principle is that a third-party authority, the identity authentication center CA, combines the public key held by the user with his or her identity information (such as name, phone number, etc.). Before the two are combined, the identity authentication center CA verifies the authenticity of the user's identity, and then the identity authentication center CA signs the certificate bundled with the user and his or her public key, and the signed certificate is valid.
[0070] Each user has a pair of public and private keys. The public key is public in the network and is used to encrypt information when sending files. The private key is confidential and only belongs to the user. It is used to decrypt and sign file information. When preparing to send a message, the sender uses the receiver's public key to encrypt the data to be transmitted. After receiving the data, the receiver uses the private key he holds to decrypt the data.
[0071] Therefore, when the integrated system receives the encrypted digital certificate sent by the trusted execution system, it indicates that the digital certificate needs to be flashed. The target public key corresponding to the encrypted digital certificate and the target private key corresponding to the target public key are determined, and the integrated system uses the target private key to decrypt the encrypted digital certificate to obtain the target digital certificate corresponding to the first target subsystem.
[0072] In some embodiments, when the network is disconnected, the target download method is to diagnose and flash the certificate. The method of diagnosing and flashing the certificate is to first download the certificate to the diagnostic device through the diagnostic device, and then flash it to the specific ECU through the diagnostic device. Therefore, step 10B specifically includes:
[0073] In step 10BA, in response to the network connection status being disconnected, the trusted execution system downloads the digital certificate to the diagnostic device, so that the diagnostic device receives the digital certificate and sends the diagnostic instruction and the digital certificate to the integrated system.
[0074] In specific implementation, if it is determined that the network connection state is disconnected, the trusted execution system downloads the digital certificate to the diagnostic device. After receiving the digital certificate, the diagnostic device sends a diagnostic instruction and the digital certificate to the integrated system.
[0075] After receiving the diagnostic instruction and the digital certificate, the integrated system determines the second target subsystem according to the diagnostic instruction, and then writes the digital certificate to the second target subsystem.
[0076] Through the above solution, when in a disconnected environment, the digital certificate is first downloaded to the diagnostic device, and then flashed to the corresponding subsystem in the integrated system using the diagnostic device, thereby avoiding the failure of certificate download in the disconnected state.
[0077] In some embodiments, when in a disconnected environment, the trusted execution system downloads the digital certificate to the diagnostic device. After receiving the digital certificate, the diagnostic device sends a diagnostic instruction and the digital certificate to the integrated system. After receiving the diagnostic instruction and the digital certificate, the integrated system determines the second target subsystem according to the diagnostic instruction. That is, step 10C specifically further includes:
[0078] Step 10CA, after receiving the diagnostic instruction and the digital certificate sent by the diagnostic device, the integrated system identifies its own target configuration word and obtains an identification result, wherein the diagnostic instruction is an instruction sent by the diagnostic device after receiving the digital certificate sent by the trusted execution system;
[0079] Step 10CAB, the integrated system determines the second target subsystem corresponding to the diagnostic instruction according to the identification result, and writes the digital certificate to the second target subsystem.
[0080] In specific implementation, there may be a target configuration word in the integrated system. If there is a target configuration word, it means that there are multiple subsystems in the integrated system. If there is no target configuration word, it means that there is only one subsystem in the integrated system.
[0081] After receiving the diagnostic instruction and the digital certificate, the integrated system identifies its own target configuration word and obtains an identification result, wherein the diagnostic instruction is an instruction sent by the diagnostic device after receiving the digital certificate sent by the trusted execution system, and the identification result includes whether the target configuration word exists in the integrated system or whether the target configuration word does not exist in the integrated system.
[0082] The integrated system determines the second target subsystem corresponding to the diagnostic instruction according to the identification result, and writes the digital certificate to the second target subsystem, wherein the specific method of determining the second target subsystem corresponding to the diagnostic instruction according to the identification result is:
[0083] Step a: In response to the identification result that the target configuration word exists, the integrated system determines that the integrated system includes multiple subsystems, retrieves a preset configuration file, searches for the configuration file according to the diagnostic instruction, determines the subsystem corresponding to the diagnostic instruction, and uses the subsystem corresponding to the diagnostic instruction as the second target subsystem corresponding to the diagnostic instruction. Or,
[0084] Step b: In response to the identification result that the target configuration word does not exist, the integrated system determines that the integrated system includes a subsystem and uses the subsystem as a second target subsystem corresponding to the diagnostic instruction.
[0085] In a specific implementation, the integrated system identifies the target configuration word, which indicates that there are multiple subsystems in the integrated system. A preset configuration file is retrieved, wherein the configuration file includes a corresponding relationship between the diagnostic instructions and the subsystems.
[0086] The configuration file is searched according to the diagnostic instruction, the subsystem corresponding to the diagnostic instruction is determined, the subsystem corresponding to the diagnostic instruction is used as the second target subsystem, and the digital certificate is then flashed to the second target subsystem.
[0087] Exemplarily, in response to the diagnostic instruction being 0x211, it is found that the subsystem corresponding to 0x211 is subsystem A, that is, subsystem A is the second target subsystem, and the digital certificate is written to subsystem A. In response to the diagnostic instruction being 0x212, it is found that the subsystem corresponding to 0x212 is subsystem B, that is, subsystem B is the second target subsystem, and the digital certificate is written to subsystem B.
[0088] The integrated system does not recognize the target configuration word, which means that there is only one subsystem in the integrated system. The subsystem can be directly used as the second target subsystem, and the digital certificate can be flashed to the second target subsystem.
[0089] Through the above scheme, it is determined whether there are multiple subsystems in the integrated system according to the target configuration word. When there are multiple subsystems, the target subsystem can be determined from the multiple subsystems according to the diagnostic instructions, avoiding the problem of being unable to determine the target subsystem during the diagnostic flash, thereby ensuring the accuracy of the diagnostic flash certification.
[0090] Based on the same inventive concept, another embodiment of the present disclosure provides an interactive process of a digital certificate calling method, involving a trusted execution system, a diagnostic device, and an integrated system, which is applied to an integrated hardware platform. The schematic diagram of the integrated hardware platform is shown in FIG. Figure 2 As shown, the interaction process specifically includes:
[0091] The trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain multiple replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems.
[0092] The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives a digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem.
[0093] For each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
[0094] The trusted execution system detects a network connection state, determines a target download mode according to the network connection state, and downloads a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, specifically:
[0095] In response to the network connection state being a connection state, the trusted execution system detects that there is a first target subsystem in the integrated system that lacks a target digital certificate, determines a target public key corresponding to the first target subsystem, encrypts the target digital certificate using the target public key to obtain an encrypted digital certificate, and sends the encrypted digital certificate to the integrated system. The integrated system receives the encrypted digital certificate sent by the trusted execution system, decrypts it using a target private key corresponding to the target public key, and obtains a target digital certificate corresponding to the first target subsystem.
[0096] In response to the network connection state being a disconnected state, the trusted execution system downloads the digital certificate to the diagnostic device, so that the diagnostic device receives the digital certificate and sends the diagnostic instruction and the digital certificate to the integrated system.
[0097] The diagnostic device receives the digital certificate and sends a diagnostic instruction and the digital certificate to the integrated system.
[0098] After receiving the diagnostic instruction and digital certificate sent by the diagnostic device, the integrated system identifies its own target configuration word and obtains an identification result, wherein the diagnostic instruction is an instruction sent by the diagnostic device after receiving the digital certificate sent by the trusted execution system.
[0099] The integrated system determines the second target subsystem corresponding to the diagnostic instruction according to the identification result, and writes the digital certificate to the second target subsystem, specifically:
[0100] In response to the identification result that the target configuration word exists, it is determined that the integrated system includes multiple subsystems, the integrated system calls a preset configuration file, searches for the configuration file according to the diagnostic instruction, determines the subsystem corresponding to the diagnostic instruction, and uses the subsystem corresponding to the diagnostic instruction as the second target subsystem corresponding to the diagnostic instruction. Or,
[0101] In response to the identification result that the target configuration word does not exist, it is determined that the integrated system includes a subsystem, and the integrated system uses the subsystem as a second target subsystem corresponding to the diagnostic instruction.
[0102] It should be noted that the method of the embodiment of the present disclosure can be performed by a single device, such as a computer or a server. The method of the present embodiment can also be applied in a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present disclosure, and the multiple devices will interact with each other to complete the described method.
[0103] It should be noted that the above describes some embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0104] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides a digital certificate calling device.
[0105] refer to Figure 3 , Figure 3 The digital certificate calling device of the embodiment is set at the vehicle end. The device includes a trusted execution system 301 and an integrated system 302 for establishing a communication connection. The integrated system includes multiple subsystems.
[0106] The trusted execution system is configured to receive the number of subsystems in the integrated system, divide the replay protection memory block in the trusted execution system according to the number of subsystems to obtain a plurality of replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of subsystems; allocate a replay protection sub-memory block to each subsystem in the integrated system, receive a digital certificate sent by each subsystem in the integrated system, and store the digital certificate in the replay protection sub-memory block corresponding to the subsystem;
[0107] The integrated system is configured such that for each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
[0108] In some embodiments, the trusted execution system is specifically configured to: detect a network connection state, determine a target download mode according to the network connection state, download a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, and send the digital certificate to the integrated system;
[0109] The integrated system is specifically configured to: receive the digital certificate.
[0110] In some embodiments, the trusted execution system is specifically configured as follows: in response to the network connection status being a connected state, it is detected that there is a first target subsystem in the integrated system that lacks a target digital certificate, and a target public key corresponding to the first target subsystem is determined; the target digital certificate is encrypting using the target public key to obtain an encrypted digital certificate, and the encrypted digital certificate is sent to the integrated system.
[0111] In some embodiments, the integrated system is specifically configured to: receive an encrypted digital certificate sent by a trusted execution system; and perform decryption processing using a target private key corresponding to the target public key to obtain a target digital certificate corresponding to the first target subsystem.
[0112] In some embodiments, the trusted execution system is specifically configured to: in response to the network connection state being disconnected, download the digital certificate to the diagnostic device, so that the diagnostic device receives the digital certificate and sends the diagnostic instruction and the digital certificate to the integrated system.
[0113] In some embodiments, the integrated system is specifically configured as follows: after receiving the diagnostic instruction and digital certificate sent by the diagnostic device, identifying its own target configuration word to obtain an identification result, wherein the diagnostic instruction is an instruction sent by the diagnostic device after receiving the digital certificate sent by the trusted execution system; determining the second target subsystem corresponding to the diagnostic instruction based on the identification result, and flashing the digital certificate to the second target subsystem.
[0114] In some embodiments, the integrated system is specifically configured to: in response to the identification result that the target configuration word exists, determine that the integrated system includes multiple subsystems, call a preset configuration file, search for the configuration file according to the diagnostic instruction, determine the subsystem corresponding to the diagnostic instruction, and use the subsystem corresponding to the diagnostic instruction as the second target subsystem corresponding to the diagnostic instruction; or,
[0115] In response to the identification result that the target configuration word does not exist, it is determined that the integrated system includes a subsystem, and the subsystem is used as a second target subsystem corresponding to the diagnostic instruction.
[0116] In some embodiments, the trusted execution system is specifically configured to: receive the number of subsystems in the integrated system, and obtain the total memory amount of the replay protection memory block in the trusted execution system; evenly divide the replay protection memory block according to the number of subsystems and the total memory amount to obtain multiple replay protection sub-memory blocks, wherein the memory amount of any two replay protection sub-memory blocks is the same.
[0117] For the convenience of description, the above device is described by dividing it into various modules according to its functions. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0118] The device of the above embodiment is used to implement the corresponding digital certificate calling method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0119] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the digital certificate calling method described in any of the above embodiments is implemented.
[0120] Figure 4 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.
[0121] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0122] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0123] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0124] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).
[0125] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).
[0126] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.
[0127] The electronic device of the above embodiment is used to implement the corresponding digital certificate calling method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0128] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides a non-transitory computer-readable storage medium, wherein the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the digital certificate calling method described in any of the above embodiments.
[0129] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device.
[0130] The computer instructions stored in the storage medium of the above embodiment are used to enable the computer to execute the digital certificate calling method described in any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0131] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments, the present application also provides a vehicle, including the digital certificate calling device in the above-mentioned embodiment, the electronic device in the above-mentioned embodiment, and the computer-readable storage medium in the above-mentioned embodiment, and the vehicle equipment implements the digital certificate calling method described in any of the above embodiments.
[0132] The vehicle of the above-mentioned embodiment is used to implement the digital certificate calling method described in any of the above-mentioned embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be repeated here.
[0133] It is understandable that before using the technical solutions of each embodiment of the present disclosure, the type, scope of use, usage scenarios, etc. of the personal information involved will be informed to the user in an appropriate manner, and the user's authorization will be obtained.
[0134] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly remind the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can independently choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present disclosure according to the prompt message.
[0135] As an optional but non-limiting implementation, in response to receiving the user's active request, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0136] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation of the present disclosure. Other methods that meet relevant laws and regulations may also be applied to the implementation of the present disclosure.
[0137] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present disclosure is limited to these examples. Based on the concept of the present disclosure, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present disclosure as described above, which are not provided in detail for the sake of simplicity.
[0138] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present disclosure difficult to understand, the known power / ground connections to the integrated circuit (IC) chips and other components may or may not be shown in the provided figures. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present disclosure will be implemented (that is, these details should be fully within the scope of understanding of those skilled in the art). Where specific details (e.g., circuits) are set forth to describe exemplary embodiments of the present disclosure, it is apparent to those skilled in the art that the embodiments of the present disclosure can be implemented without these specific details or with changes in these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0139] Although the present disclosure has been described in conjunction with specific embodiments of the present disclosure, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.
[0140] The embodiments of the present disclosure are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the present application. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present disclosure should be included in the protection scope of the present disclosure.
Claims
1. A digital certificate calling method, characterized in that: Applied to the vehicle side, the vehicle side includes a trusted execution system and an integrated system for establishing a communication connection, and the integrated system includes multiple subsystems, The method comprises: The trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain a plurality of replay protection sub-memory blocks, wherein the number of the replay protection sub-memory blocks is equal to the number of the subsystems; The trusted execution system allocates a replay protection sub-memory block to each subsystem in the integrated system, receives a digital certificate sent by each subsystem in the integrated system, and stores the digital certificate in the replay protection sub-memory block corresponding to the subsystem; For each subsystem in the integrated system, the subsystem calls a program corresponding to the subsystem, accesses the replay protection sub-memory block corresponding to the subsystem according to the program, and obtains a digital certificate corresponding to the subsystem.
2. The method according to claim 1, after storing the digital certificate in the replay protection sub-memory block corresponding to the subsystem, further comprises: The trusted execution system detects the network connection status; The trusted execution system determines a target download mode according to the network connection state, downloads a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, and sends the digital certificate to the integrated system; The integrated system receives the digital certificate.
3. The method according to claim 2, characterized in that The trusted execution system determines a target download mode according to the network connection state, downloads a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, and sends the digital certificate to the integrated system, including: In response to the network connection state being a connected state, the trusted execution system detects that a first target subsystem in the integrated system lacks a target digital certificate, and determines a target public key corresponding to the first target subsystem; The trusted execution system encrypts the target digital certificate using the target public key to obtain an encrypted digital certificate, and sends the encrypted digital certificate to the integration system.
4. The method according to claim 3, characterized in that The integrated system receives the digital certificate, including: The integrated system receives the encrypted digital certificate sent by the trusted execution system; The integrated system performs decryption processing using the target private key corresponding to the target public key to obtain a target digital certificate corresponding to the first target subsystem.
5. The method according to claim 2, characterized in that: The trusted execution system determines a target download mode according to the network connection state, and downloads a corresponding digital certificate for a subsystem in the integrated system based on the target download mode, including: In response to the network connection state being a disconnected state, the trusted execution system downloads the digital certificate to the diagnostic device, so that the diagnostic device receives the digital certificate and sends the diagnostic instruction and the digital certificate to the integrated system.
6. The method according to claim 5, characterized in that The integrated system receives the digital certificate, including: After receiving the diagnostic instruction and digital certificate sent by the diagnostic device, the integrated system identifies its own target configuration word and obtains an identification result, wherein the diagnostic instruction is an instruction sent by the diagnostic device after receiving the digital certificate sent by the trusted execution system; The integrated system determines the second target subsystem corresponding to the diagnostic instruction according to the identification result, and writes the digital certificate to the second target subsystem.
7. The method according to claim 6, characterized in that The integrated system determines the second target subsystem corresponding to the diagnostic instruction according to the recognition result, including: In response to the identification result that the target configuration word exists, the integrated system determines that the integrated system includes multiple subsystems, calls a preset configuration file, searches for the configuration file according to the diagnostic instruction, determines the subsystem corresponding to the diagnostic instruction, and uses the subsystem corresponding to the diagnostic instruction as the second target subsystem corresponding to the diagnostic instruction; or In response to the identification result that the target configuration word does not exist, the integrated system determines that the integrated system includes a subsystem and uses the subsystem as a second target subsystem corresponding to the diagnostic instruction.
8. The method according to claim 1, characterized in that The trusted execution system receives the number of subsystems in the integrated system, and divides the replay protection memory block in the trusted execution system according to the number of subsystems to obtain a plurality of replay protection sub-memory blocks, including: The trusted execution system receives the number of subsystems in the integrated system and obtains the total memory amount of the replay protection memory block in the trusted execution system; The trusted execution system evenly divides the replay protection memory block according to the number of subsystems and the total amount of memory to obtain multiple replay protection sub-memory blocks, wherein the memory amounts of any two replay protection sub-memory blocks are the same.
9. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 8 is implemented.
10. A vehicle, characterized in that: The vehicle includes the electronic device according to claim 9.