Vehicle license management method, vehicle and related device
By protecting the integrity of the business function identifiers and establishing a secure transmission channel during the vehicle license management process, the information security risks are solved, information security is improved, and losses of vehicle manufacturers are reduced.
Patent Information
- Application Number
- CN202311604103.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-27
- Publication Date
- 2025-06-03
AI Technical Summary
There are information security risks in the vehicle license management process, which leads to the ordering list of business functions that may be reused and causes losses to vehicle manufacturers.
Through the control device, the service function identifier ordered by the user is protected and authenticated integrity, control messages are generated, and a secure dedicated transmission channel is established with the processing device to ensure that the service function identifier is not intercepted by the outside world.
It improves the information security of the vehicle license management process, reduces information security risks, and reduces losses of vehicle manufacturers.
Smart Images

Figure CN120087971A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicles, and particularly to a vehicle license management method, a vehicle, and related devices. Background Art
[0002] Currently, the vehicle license management process mainly includes a license file generation stage, a license file verification stage, and a business function enabling stage. Among them, in the license generation stage, the feature list of the business functions ordered by the user is mainly bound to the controller of the user's vehicle. In the license file verification stage, the license file is mainly verified for signature. After completing the license file verification stage, the controller can distribute corresponding execution instructions to the actuators related to the business functions ordered by the user to enable the corresponding business functions. This process is the business function enabling stage.
[0003] However, in the business function enabling stage, after the controller sends an execution instruction to the actuator, the execution instruction is easily intercepted. The intercepted execution instruction can be reused on other vehicles through some means. For example, the intercepted instruction is encapsulated in an external physical module, and the external physical module is connected to the actuator of other vehicles to bypass the license generation stage and the license verification stage, and directly send an execution instruction to the actuator through the external physical module to enable the business function. Thus, there are information security risk problems in this vehicle license management process. Vehicle manufacturers will lose the order lists of many business functions without being aware of it, bringing greater losses to vehicle manufacturers. Summary of the Invention
[0004] This application provides a vehicle license management method, a vehicle, and related devices, in order to improve the information security of the vehicle license management process, reduce information security risks, and reduce the losses of vehicle manufacturers.
[0005] In a first aspect, this application provides a vehicle license management method. This method is applied to a vehicle, and the vehicle includes a control device and a processing device. The method includes: the control device performs integrity protection on the first business function identifier of the first business function ordered by the user and authenticates the identity of the control device to generate a control message; the control device sends the control message to the processing device; the processing device verifies the integrity of the first business function identifier and the identity of the control device based on the control message to obtain the first business function identifier; where the processing device is the processor of an actuator or a central gateway.
[0006] It can be understood that the first business function may be one or more business functions ordered by the user, and this application does not limit this.
[0007] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the identity authentication and verification of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle permission management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be reduced.
[0008] In combination with the first aspect, in some possible implementation manners, the processing device is an actuator. After obtaining the first service function identifier, the method further includes: the actuator enables the first service function based on the first service function identifier.
[0009] In combination with the first aspect, in some possible implementation manners, the processing device is a processor of a central gateway, and the vehicle further includes an actuator. After obtaining the first service function identifier, the method further includes: the processor of the central gateway sends the first service function identifier to the actuator; the actuator enables the first service function based on the first service function identifier.
[0010] In combination with the first aspect, in some possible implementation manners, the method further includes: when it is detected that there is a second service function identifier, the processor of the central gateway sends an alarm message, and the alarm message is used to prompt that there is an information security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
[0011] It can be understood that the processor of the central gateway knows what content it has sent to the second actuator at what time. If the processor of the central gateway detects content that is not sent by itself to the second actuator, the processor of the central gateway can determine that there may be an external device sending a controller area network (CAN) instruction to the second actuator, that is, the processor of the central gateway determines that there may be an information security risk.
[0012] For example, the processor of the central gateway may send the alarm information to the license control center to remind the relevant staff of the license control center of the information security risk in the license management process of the vehicle, so that the relevant staff can find and determine the specific reason and implement corresponding solutions or loss prevention measures. Another example is that the processor of the central gateway may also display the alarm information on the vehicle's display screen or send out the alarm information by voice or other means to warn the user (such as the vehicle owner or driver, etc.) of the information security risk. Therefore, in this implementation method, the information security risk in the vehicle license management process can be discovered in a timely manner and a risk alarm can be issued, which can reduce the losses of vehicle manufacturers.
[0013] Combined with the first aspect, in some possible implementation manners, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and performs identity authentication on the control device to generate a control message, including: the control device encrypts the first service function identifier of the first service function ordered by the user based on a second key; the control device performs integrity protection on the encrypted first service function identifier and performs identity authentication on the control device to generate the control message.
[0014] Combined with the first aspect, in some possible implementation manners, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message, and obtains the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; the processing device decrypts the encrypted first service function identifier based on a key corresponding to the second key to obtain the first service function identifier.
[0015] In this implementation manner, not only is integrity protection and integrity verification performed on the first service function identifier, and identity authentication and identity verification are performed on the control device, but also the first service function identifier is encrypted before that, which can further improve the information security of the vehicle license management process.
[0016] Combined with the first aspect, in some possible implementation manners, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and performs identity authentication on the control device to generate a control message, including: the control device performs integrity protection on the first service function identifier and performs identity authentication on the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on a third key to generate the control message.
[0017] In combination with the first aspect, in some possible implementation manners, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on the key corresponding to the third key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtains the first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful.
[0018] In this implementation manner, not only the integrity protection and integrity verification of the first service function identifier are performed, and the identity authentication and identity verification of the control device are performed, but also these information are encrypted further before sending, which can further improve the information security of the vehicle permission management process.
[0019] In combination with the first aspect, in some possible implementation manners, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and performs identity authentication on the control device to generate a control message, including: the control device encrypts the first service function identifier of the first service function ordered by the user based on the fourth key; the control device performs integrity protection on the encrypted first service function identifier and performs identity authentication on the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on the fifth key to generate the control message.
[0020] In combination with the first aspect, in some possible implementation manners, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on the key corresponding to the fifth key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtains the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; the processing device decrypts the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier.
[0021] In this implementation manner, not only the integrity protection and integrity verification of the first service function identifier are performed, and the identity authentication and identity verification of the control device are performed, but also the first service function identifier is encrypted before that, and these information are encrypted further before sending, which can further improve the information security of the vehicle permission management process.
[0022] In combination with the first aspect, in some possible implementation manners, before generating the control message, the method further includes: the control device obtains a license file, where the license file includes a service function identifier of the service function subscribed by the user, and the service function includes the first service function; the control device verifies the license file, and the control message is generated when the verification of the license file is successful.
[0023] In combination with the first aspect, in some possible implementation manners, the control device verifies the license file, including: the control device verifies the license file based on the chip identifier of the control device, the vehicle identification number (VIN) of the vehicle, and a preset second random number.
[0024] In this implementation manner, the chip identifier of the control device (i.e., the system-on-a-chip identifier (SOC ID) of the control device) cannot be modified. In this way, the security risk caused by the replacement of the control device of the vehicle can be avoided, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and thus the loss of the vehicle manufacturer can be reduced.
[0025] In combination with the first aspect, in some possible implementation manners, the control device verifies the license file, including: the control device verifies the license file based on a preset second random number.
[0026] In this implementation manner, the verification of the random number is introduced in the verification of the license file. When the verification of the random number is unsuccessful, the control device does not perform the subsequent process of generating the control message. In this way, the reuse of the license file on other vehicles can be prevented, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and thus the loss of the vehicle manufacturer can be reduced.
[0027] In combination with the first aspect, in some possible implementation manners, the control device verifies the license file, including: the control device verifies the license file based on the chip identifier of the control device, the VIN of the vehicle, and a preset second random number.
[0028] In this implementation manner, the chip identifier of the control device is introduced in the verification of the license file, and the security risk caused by the replacement of the control device of the vehicle can be avoided; the verification of the random number is also introduced. In this way, the reuse of the license file on other vehicles can be better prevented, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and thus the loss of the vehicle manufacturer can be reduced.
[0029] Second aspect, the present application provides a vehicle permit management method, which includes: performing integrity protection on the first service function identifier of the first service function subscribed by the user and authenticating the identity of the control device to generate a control message; sending the control message to the processing device.
[0030] The steps of this method can be executed by the control device, or, this method can also be executed by components (such as chips, chip systems, etc.) configured in the control device, or, it can also be implemented by a logic module or software that can implement all or part of the functions of the control device. The present application does not make any limitations in this regard.
[0031] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of performing integrity protection and integrity verification on the first service function identifier, as well as the identity authentication and identity verification of the control device. It is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle permit management process can be improved, the information security risk can be reduced, and thus the losses of vehicle manufacturers can be reduced.
[0032] Combined with the second aspect, in some possible implementation manners, performing integrity protection on the first service function identifier of the first service function subscribed by the user and authenticating the identity of the control device to generate a control message includes: encrypting the first service function identifier of the first service function subscribed by the user based on the second key; performing integrity protection on the encrypted first service function identifier and authenticating the identity of the control device to generate the control message.
[0033] Combined with the second aspect, in some possible implementation manners, performing integrity protection on the first service function identifier of the first service function subscribed by the user and authenticating the identity of the control device to generate a control message includes: performing integrity protection on the first service function identifier and authenticating the identity of the control device to generate a preliminary control message; encrypting the preliminary control message based on the third key to generate the control message.
[0034] Combined with the second aspect, in some possible implementation manners, performing integrity protection on the first service function identifier of the first service function subscribed by the user and authenticating the identity of the control device to generate a control message includes: encrypting the first service function identifier of the first service function subscribed by the user based on the fourth key; performing integrity protection on the encrypted first service function identifier and authenticating the identity of the control device to generate a preliminary control message; encrypting the preliminary control message based on the fifth key to generate the control message.
[0035] In combination with the second aspect, in some possible implementation manners, before generating the control message, the method further includes: obtaining a license file, where the license file includes a service function identifier of the service function ordered by the user, and the service function includes the first service function; and verifying the license file, and the control message is generated when the verification of the license file is successful.
[0036] In combination with the second aspect, in some possible implementation manners, verifying the license file includes: verifying the license file based on the chip identifier of the control device and the VIN of the vehicle; or verifying the license file based on a preset second random number; or verifying the license file based on the chip identifier of the control device, the VIN of the vehicle, and a preset second random number.
[0037] When the chip identifier of the control device is introduced in the verification of the license file, the security risk caused by the replacement of the control device of the vehicle can be avoided; when a random number is introduced in the verification of the license file, the reuse of the license file on other vehicles can be better prevented; thereby, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and the loss of the vehicle manufacturer can be reduced.
[0038] In combination with the first aspect and the second aspect, in some possible implementation manners, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device, including: the control device performs integrity protection on the first service function identifier and authenticates the identity of the control device based on a first key, a first random number, and the device certificate of the control device.
[0039] In a third aspect, the present application provides a vehicle license management method, and the method includes: receiving a control message from a control device, where the control message includes a service function identifier of a first service function ordered by the user; and verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier.
[0040] The steps of the method may be executed by a processing device, or the method may also be executed by a component (such as a chip, a chip system, etc.) configured in the processing device, or may also be implemented by a logic module or software capable of implementing all or part of the functions of the processing device. The present application does not make any limitation thereto.
[0041] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the identity authentication and verification of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle permission management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be minimized.
[0042] Combined with the third aspect, in some possible implementation manners, when the processing device is an actuator, after obtaining the first service function identifier, the method further includes: the actuator enables the first service function based on the first service function identifier.
[0043] Combined with the third aspect, in some possible implementation manners, when the processing device is the processor of the central gateway, after obtaining the first service function identifier, the method further includes: sending the first service function identifier to the actuator.
[0044] Combined with the third aspect, in some possible implementation manners, the method further includes: when detecting the existence of a second service function identifier, sending an alarm message, where the alarm message is used to prompt the existence of an information security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
[0045] In this implementation manner, the information security risk in the vehicle permission management process can be discovered in a timely manner and risk alarm can be given, so as to reduce the losses of vehicle manufacturers.
[0046] Combined with the third aspect, in some possible implementation manners, verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: verifying the integrity of the first service function identifier and the identity of the control device based on the control message, and obtaining the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; decrypting the encrypted first service function identifier based on a key corresponding to a second key, where the second key is the key for encrypting the first service function identifier, to obtain the first service function identifier.
[0047] In combination with the third aspect, in some possible implementation manners, verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: decrypting the control message based on a key corresponding to a third key to obtain a preliminary control message, where the third key is the key used to encrypt the control message; verifying the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtaining the first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful.
[0048] In combination with the third aspect, in some possible implementation manners, verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: decrypting the control message based on a key corresponding to a fifth key to obtain a preliminary control message, where the fifth key is the key used to encrypt the preliminary control message; verifying the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtaining the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; decrypting the encrypted first service function identifier based on a key corresponding to a fourth key to obtain the first service function identifier, where the fourth key is the key used to encrypt the first service function identifier.
[0049] In a fourth aspect, the present application provides a control device, which can implement the execution steps of the control device in the first aspect and any possible implementation manner of the first aspect, or can implement the methods in the second aspect and any possible implementation manner of the second aspect. The device includes corresponding modules for executing the above methods. The modules included in the device can be implemented in software and / or hardware manners.
[0050] In a fifth aspect, the present application provides a control device, which includes a processor. The processor is coupled to a memory and can be used to execute a program in the memory to implement the execution steps of the control device in the first aspect and any possible implementation manner of the first aspect, or can implement the methods in the second aspect and any possible implementation manner of the second aspect.
[0051] Optionally, the control device further includes a memory.
[0052] Optionally, the control device further includes a communication interface, and the processor is coupled to the communication interface.
[0053] In a sixth aspect, the present application provides a processing device, which can implement the execution steps of the processing device in the above first aspect and any possible implementation manner of the first aspect, or can implement the method in the above third aspect and any possible implementation manner of the third aspect. The device includes corresponding modules for executing the above methods. The modules included in the device can be implemented in software and / or hardware manners.
[0054] In a seventh aspect, the present application provides a processing device, which includes a processor. The processor is coupled to a memory and can be used to execute a program in the memory to implement the execution steps of the processing device in the above first aspect and any possible implementation manner of the first aspect, or can implement the method in the above third aspect and any possible implementation manner of the third aspect.
[0055] Optionally, the processing device further includes a memory.
[0056] Optionally, the processing device further includes a communication interface, and the processor is coupled to the communication interface.
[0057] In an eighth aspect, the present application provides a vehicle, which includes a control device and a processing device. The control device is used to execute the functions of the control device in the above first aspect and any possible implementation manner of the first aspect, and the processing device is used to execute the functions of the processing device in the above first aspect and any possible implementation manner of the first aspect.
[0058] In a ninth aspect, the present application provides a vehicle, which includes a control device and a processing device. The control device can implement the method in the above second aspect and any possible implementation manner of the second aspect, and the processing device can implement the method in the above third aspect and any possible implementation manner of the third aspect.
[0059] In a tenth aspect, the present application provides a chip system, which includes at least one processor for supporting the implementation of the functions involved in the above first aspect to the third aspect and any possible implementation manner of the first aspect to the third aspect, for example, receiving or processing the data and / or indication information involved in the above method.
[0060] In a possible design, the chip system further includes a memory, and the memory is used to store program instructions and data. The memory is located inside or outside the processor.
[0061] The chip system can be composed of chips or can include chips and other discrete devices.
[0062] In the eleventh aspect, the present application provides a readable storage medium, on which a program (which may also be referred to as code or instruction) is stored. When the computer program is run by a processor, the methods in the first aspect to the third aspect and any possible implementation manner of the first aspect to any possible implementation manner of the third aspect are executed.
[0063] In the twelfth aspect, the present application provides a program product, which includes: a program (which may also be referred to as code or instruction). When the program is run, the methods in the first aspect to the third aspect and any possible implementation manner of the first aspect to any possible implementation manner of the third aspect are executed.
[0064] It should be understood that the technical solutions of the fourth aspect to the twelfth aspect of the present application correspond to those of the first aspect to the third aspect of the present application. The beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated herein. Description of the Drawings
[0065] Figure 1 is a schematic flowchart of a vehicle license management method;
[0066] Figure 2 is another schematic flowchart of a vehicle license management method;
[0067] Figure 3 is a structural block diagram of a vehicle provided by an embodiment of the present application;
[0068] Figure 4 is a schematic flowchart of a vehicle license management method provided by an embodiment of the present application;
[0069] Figure 5 is a schematic diagram of a control device generating a control message and a processing device decrypting the control message provided by an embodiment of the present application;
[0070] Figure 6 is a schematic diagram of information interaction between a vehicle and a license control center provided by an embodiment of the present application;
[0071] Figure 7 is another schematic flowchart of a vehicle license management method provided by an embodiment of the present application;
[0072] Figure 8 is yet another schematic flowchart of a vehicle license management method provided by an embodiment of the present application;
[0073] Figure 9 is a schematic block diagram of a control device applicable to the vehicle license management method provided by the present application;
[0074] Figure 10It is a schematic block diagram of a processing device applicable to the vehicle permit management method provided in this application;
[0075] Figure 11 It is a schematic block diagram of a device applicable to the vehicle permit management method provided in this application. Detailed implementation manners
[0076] Next, the technical solutions in this application will be described with reference to the accompanying drawings.
[0077] First, in this application, the terms "include" and "have" and any of their variations are intended to cover non-exclusive inclusion. For example, a device, system, product, or equipment that includes a series of modules, modules, or units does not necessarily have to be limited to those modules, modules, or units clearly listed, but may include other modules, modules, or units that are not clearly listed or are inherent to these devices, systems, products, or equipment.
[0078] Second, in this application, words such as "exemplarily" and "for example" are used to represent examples, illustrations, or explanations. Any embodiment or design solution described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of words such as "exemplarily" or "for example" is intended to present relevant concepts in a specific manner.
[0079] Third, in this application, "when...", "in the case of...", "if", and "if" all mean that the device will perform corresponding processing under certain objective circumstances, which does not limit the time, and it is not required that the device must have a judgment action when implemented, nor does it mean that there are other limitations.
[0080] Fourth, in this application, words such as "first" and "second" are used to distinguish the same items or similar items with basically the same functions and roles. For example, the first actuator and the second actuator are used to distinguish different data, and their order is not limited. Those skilled in the art can understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit them to be different.
[0081] Fifth, in this application, "preset" can be understood as predefined, defined, pre-defined, stored, pre-stored, pre-negotiated, prefabricated, pre-set, or pre-configured, etc.
[0082] Sixth, in this application, "at least one (item)" means one (item) or more than one (item). "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, or B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship, but it does not exclude the case where the associated objects before and after are in an "and" relationship. The specific meaning can be understood in combination with the context.
[0083] Seventh, "send" and "receive" in this application represent the direction of signal transmission. For example, "The control device sends a control message to the processing device" can be understood as the destination of the control message being the processing device, which can include direct sending through the air interface, connection line, or bus, and also include indirect sending by other units or modules through the air interface, connection line, or bus. "The processing device receives a control message from the control device" can be understood as the source of the control message being the control device, which can include directly receiving from the control device through the air interface, connection line, or bus, and can also include indirectly receiving from the control device through the air interface, connection line, or bus from other units or modules. "Send" can also be understood as the "output" of the chip interface, and "receive" can also be understood as the "input" of the chip interface.
[0084] In other words, sending and receiving can be carried out between devices. For example, between the control device and the processing device; it can also be carried out within a device. For example, sending or receiving between components, modules, chips, software modules, or hardware modules within a device through a bus, trace, or interface.
[0085] First, a brief explanation of the terms involved in this application is given.
[0086] 1. Integrity protection: In the field of cryptography, integrity protection includes protecting the reliability and correctness of data. Integrity protection can prevent unauthorized data from being changed and ensure that the data is accurate and not replaced.
[0087] 2. Identity authentication: In the field of cryptography, identity authentication can be to determine the identity of a subject based on the information held by the subject and grant the corresponding permissions to the subject.
[0088] 3. Central Gateway: It can be simply referred to as the gateway (GW). As the data interaction hub of the vehicle network, GW enables data to be transmitted safely and reliably among multiple networks within the vehicle (such as CAN, local interconnect network (LIN), media oriented system transport (MOST), FlexRay, etc.). The relevant hardware of GW can include switches, transceivers of various network types (CAN, LIN, MOST, FlexRay, etc.), and system chips.
[0089] 4. Vehicle Control Unit (VCU): It is the core electronic control unit that realizes vehicle control decisions. It is equivalent to the brain of the vehicle and can also be called the command and management center of the vehicle. It plays a role in controlling the vehicle's operation.
[0090] 5. Telematics Box (T-BOX): The interface for the vehicle to communicate externally, which can provide services such as remote control, remote query, and security.
[0091] Currently, the vehicle license management process mainly includes the license file generation stage, the license file verification stage, and the business function enabling stage.
[0092] Figure 1 It is a schematic flowchart of a vehicle license management method.
[0093] As Figure 1 shown, in this vehicle license management method, the license file generation stage includes binding the license control information with the electronic serial number (ESN) of the vehicle controller, and then the vehicle factory license management platform signs the bound information (i.e., the combined data of the license control information and the ESN of the vehicle controller) to obtain the license file (which can also be called the license control file).
[0094] Among them, the license control information may include the product name of the product (or feature), the product version number, and the enabling status (for example, 1 may indicate allowed to use, 0 may indicate not allowed to use) or the ordering status (for example, 1 may indicate ordered, 0 may indicate not ordered) of each business function item (which can be simply referred to as a function item or business function) of the product. The license control information is derived from the product list (or feature list) ordered by the end user. The business function items included in the product list can be jointly implemented by the hardware and software of one or several actuators. For example, if the user purchases the seat heating function, this business function can be controlled by the software on the seat temperature actuator to heat the seat.
[0095] ESN is the globally unique code of a vehicle controller. Binding the license control information to the ESN of the vehicle controller means specifying a certain vehicle controller to load the enabling status of certain business functions. Signing the license information is for subsequent verification, or rather, to prevent the license information from being counterfeited or tampered with. The private key used for signing can be held by the license management platform, and the public key paired with this private key can be deployed in the vehicle controller.
[0096] During the verification stage of the license file, when the software of the vehicle controller starts, the vehicle controller can use the pre-stored public key to verify the signature of the license file. After the verification passes, the vehicle controller can load the corresponding function modules according to the identification and usage status (i.e., the feature list) of the business function items in the license file, so as to enable the corresponding business functions; in addition, for some business functions that are not executed by this controller, this controller can send the identification of the business functions related to certain actuators and the enabling status of the business functions to these actuators in plain text, so that these actuators can enable the corresponding business functions.
[0097] And Figure 1 corresponding to the schematic flowchart of a vehicle license management method shown in Figure 2 is another schematic flowchart of a vehicle license management method.
[0098] As Figure 2 shown, in step 201, the vehicle sales management platform (which can also be called the vehicle sales management system) obtains the user's ordering information. It can be understood that this vehicle sales management platform can query the VIN of the user's vehicle based on the user's information. The user's ordering information is associated with the user's vehicle, so that the ordering information related to this vehicle can be queried based on the VIN of the user's vehicle. The ordering information may include the product list or feature list ordered by the user, and the product list or feature list includes the business function items ordered by the user.
[0099] In step 202, the vehicle sales management platform may send the VIN and feature list of the vehicle to the vehicle license management platform (vehicle license management system) to apply for generating a new license file for the vehicle.
[0100] In step 203, the vehicle license management platform obtains the ESN of the controller corresponding to the VIN of the vehicle from the vehicle management platform (which may also be referred to as the vehicle management system).
[0101] In step 204, the vehicle license management platform generates a license file. For example, the vehicle license management platform may generate license control information based on the product list or feature list, and then bind the license control information with the ESN of the corresponding vehicle controller and sign it to generate a license file.
[0102] In step 205, the vehicle license management platform sends the license file to the corresponding vehicle controller.
[0103] In step 206, the vehicle controller verifies the license file and enables the service functions related to the vehicle controller. It can be understood that the vehicle controller can verify the license file, and after the verification passes, it can enable the service functions related to the vehicle controller.
[0104] For some service functions that are not executed by the vehicle controller, the vehicle controller may send the identifiers of the service functions related to certain actuators and the enabling status of the service functions to these actuators in plain text, so that these actuators can enable the corresponding service functions. For example, in step 207, the vehicle controller sends the service functions and the enabling status to the actuators related to these service functions. In step 208, the actuator can enable the service functions related to the actuator.
[0105] It can be understood that in Figure 1 or Figure 2 In the vehicle license management method shown, in the license generation stage, mainly the feature list of the service functions ordered by the user is bound to the controller of the user's vehicle, and in the license file verification stage, mainly the license file is verified for signature. The license generation stage can be completed in the cloud. For example, the above vehicle license management platform can be deployed in the cloud. The license file verification stage can be completed on the vehicle side. For example, a device (such as a vehicle controller) or module on the vehicle can complete the verification of the license file. After completing the license file verification stage, the controller can distribute corresponding execution instructions to the actuators related to the service functions ordered by the user to enable the corresponding service functions, and this process is the service function enabling stage. It can be understood that the service function enabling stage is also completed on the vehicle side.
[0106] However, during the enabling stage of the service function, when the controller sends an execution instruction to the actuator, the instruction includes the service function identifier of the service function ordered by the user, and the execution instruction is in plain text, which is easily intercepted. Moreover, the intercepted execution instruction can be reused on other vehicles through some means. For example, the intercepted instruction is encapsulated in an external physical module, and the external physical module is connected to the actuator of other vehicles to bypass the license generation stage and the license verification stage, and directly send the execution instruction to the actuator through the external physical module to enable the service function. Thus, it can be seen that there are information security risk problems in this vehicle license management process. Vehicle manufacturers will lose the order lists of many service functions without being aware of it, bringing relatively large losses to vehicle manufacturers.
[0107] In view of the above problems, the present application provides a vehicle license management method, a vehicle and related devices. By performing integrity protection on the service function identifier and authenticating the identity of the control device before sending a control message containing the service function identifier, the service function identifier cannot be easily intercepted and reused on other vehicles, thereby improving the information security of the vehicle license management process, reducing information security risks, and thus reducing the losses of vehicle manufacturers.
[0108] Before elaborating on the vehicle license management method provided by the embodiments of the present application in detail, first, in combination with Figure 3 an exemplary description of the vehicle applicable to the embodiments of the present application is given.
[0109] Figure 3 is a structural block diagram of a vehicle provided by an embodiment of the present application.
[0110] Exemplarily, as Figure 3 shown, the vehicle may include a control device and a first actuator, or the vehicle may include a control device, a processor of the central gateway, and a second actuator, or the vehicle may include a control device, a first actuator, a processor of the central gateway, and a second actuator.
[0111] The control device may be any one of at least one control device on the vehicle. By way of example and not limitation, in actual application scenarios, the control device may be a VCU, a T-BOX, a cockpit domain controller (CDC) or a central controller of the vehicle, etc., or may be a dedicated control device deployed on the vehicle for license management. The present application does not make any limitation in this regard.
[0112] Among them, a license management (Lic-M) module and a license trusted application (Lic-TA) module can be deployed on the control device.
[0113] The Lic-M module is a management module responsible for communication and license security verification. It can be used externally for information interaction with a license control center (equivalent to the Figure 2 vehicle license management platform shown, which can be deployed in the cloud), for example, obtaining a license file from the license control center; or, for example, reporting the license status of the vehicle (including but not limited to which functional features are activated and which are not, or rather, which business functions are enabled and which are not). The Lic-M module can be used internally to manage the license services of the entire vehicle. For example, the Lic-M module can pass the obtained license file to the Lic-TA module for the Lic-TA module to verify the license file. In a possible implementation, one Lic-M module can be deployed on the entire vehicle to uniformly manage the license services of the entire vehicle.
[0114] The Lic-TA module can be understood as the license security application of the entire vehicle and can be used to verify the license file. The Lic-TA module requires a dedicated hardware security module (HSM) or a trusted execution environment (TEE), etc. for guarantee. In a possible implementation, one Lic-TA module can be deployed on the entire vehicle. The Lic-TA module and the Lic-M module can cooperate to jointly complete the security control of the license file from the license control center at the vehicle end.
[0115] A license agent (Lic-A) module can be deployed in the first actuator. The Lic-A module is a module responsible for in-domain feature activation and status management. It can be understood that a certain device on the vehicle with the Lic-A module deployed can be used to respond to license services. In a possible implementation, one or more Lic-A modules can be deployed on the entire vehicle. By way of example and not limitation, the vehicle can include multiple first actuators, and one Lic-A module can be deployed in each of these multiple first actuators.
[0116] In this application, the first actuator is an actuator with the hardware and software security capabilities required for deploying the Lic-A module, and the second actuator is an actuator without the hardware and software security capabilities required for deploying the Lic-A module. It can be understood that the vehicle may include at least one first actuator or at least one second actuator.
[0117] An application (APP) related to the license service may be installed in the first actuator. For example, a seat heating APP can be used to implement corresponding service functions, such as service function 1.
[0118] The Lic-A module may also be deployed in the processor of the central gateway, so that the processor of the central gateway can proxy the second actuator to execute some license services that the second actuator cannot execute, to promote the second actuator to enable related service functions. For example, service function 2.
[0119] The license control center can be used for issuing and revoking license functions, as well as monitoring and recording the license status, etc. For example, generating a license file and sending the license file related to the vehicle to the vehicle. This application does not make any limitations in this regard. The license file may include a feature list, signature information, digital certificate, etc. This application does not make any limitations in this regard.
[0120] Figure 4 It is a schematic flowchart of a vehicle license management method provided by an embodiment of this application.
[0121] As Figure 4 shown, method 400 can be applied to a vehicle. The steps of method 400 can be executed by the vehicle, or, method 400 can also be executed by components (such as chips, chip systems, etc.) configured in the vehicle, or, can also be implemented by a logic module or software capable of implementing all or part of the vehicle functions. This application does not make any limitations in this regard. For example, the vehicle may include a control device and a processing device. The control device can execute step 410 and step 420, and the processing device can execute step 430. The following Figure 4 will elaborate on each step in
[0122] In step 410, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device to generate a control message.
[0123] Among them, the first service function may be one or more service functions ordered by the user. This application does not make any limitations in this regard.
[0124] In a possible implementation, the control message may include the product name of the product (or feature), the product version number, and the enabling or subscription status of each business function of the product, etc., which are not limited in this application.
[0125] In this application, the business function identifier may be the name of the business function, or the index number or identification number corresponding to the business function, etc., which are not limited in this application.
[0126] The processing device may be an actuator (such as Figure 3 the first actuator shown in
[0127] Exemplarily, the control device may use a Lic-TA module as shown in Figure 3 to perform integrity protection on the first business function identifier of the first business function subscribed by the user and authenticate the identity of the controller, and generate the control message.
[0128] In a possible implementation, the control device performs integrity protection on the first business function identifier of the first business function subscribed by the user and authenticates the identity of the control device, including: the control device performs integrity protection on the first business function identifier and authenticates the identity of the control device based on the first key, the first random number, and the device certificate of the control device. It can be understood that the first key, the first random number, and the device certificate of the control device can all be preset (i.e., pre-stored). Among them, the first random number is an anti-replay random number.
[0129] Figure 5 It is a schematic diagram of the control device generating a control message and the processing device decrypting the control message provided by the embodiments of this application.
[0130] By way of example and not limitation, the control device and the processing device may be prefabricated with public key infrastructure (PKI) certificates when leaving the factory. The control device may also be prefabricated with a device certificate and a device private key, as well as the first random number and the first key, for example, it may include but is not limited to Figure 5 the device private key, the Lic public key, and the Lic private key shown in
[0131] Exemplarily, the control device may use the Lic-TA module to verify the license file. After the verification passes, it may first sign the Lic public key with the device private key, and then sign the first business function identifier with the Lic private key to generate signature information. In addition, in order to prevent the control message from being reused by other vehicles, a random number mechanism may also be introduced in the signature content. For example, Figure 5For the first random number shown in [figure], the control device can also use the Lic-TA module to put the device certificate of the control device into the control message. So far, the control device has used the Lic-TA module to complete the security protection of the first service function identifier and authenticate the identity of the control device, and generated a control message. It can be understood that, as Figure 5 shown, the control message may include the first service function identifier, the first random number, signature information, device certificate, etc.
[0132] In step 420, the control device sends the control message to the processing device. Correspondingly, the processing device receives the control message from the control device.
[0133] Exemplarily, as Figure 3 or Figure 5 shown, after generating the control message, the control device can use the Lic-TA module to return (or transfer) the control message to the Lic-M module. Furthermore, the control device can use the Lic-M module to send the control message to the processing device. Correspondingly, the processing device can use, as Figure 3 or Figure 5 shown, the Lic-A module to receive the control message.
[0134] In some possible implementation manners, after the control device generates the control message by using the Lic-TA module, the Lic-TA module can also distribute the control message to the processing device, and this application does not limit this.
[0135] In step 430, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier.
[0136] After receiving the control message from the control device, the processing device can verify the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier.
[0137] Exemplarily, as Figure 5 shown, the processing device can use the Lic-A module to verify the device certificate in the control message based on a prefabricated PKI certificate. After the verification of the device certificate passes, the processing device can further verify the signature information and the first random number based on the device certificate. When the verification of the signature information and the first random number passes, the verification of the integrity of the first service function identifier and the identity of the control device is completed, and the first service function identifier can be obtained.
[0138] In a possible implementation, the processing device is an actuator. After obtaining the first service function identifier, method 400 further includes: the actuator enables the first service function based on the first service function identifier.
[0139] Exemplarily, as Figure 3 shown, when the processing device is the first actuator, after the first actuator obtains the first service function identifier, the first actuator can also directly enable the first service function based on the first service function identifier.
[0140] In this implementation, the control device and the first actuator have pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the authentication and verification of the identity of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the first actuator to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle permission management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be reduced.
[0141] In a possible implementation, the processing device is the processor of the central gateway, and the vehicle further includes an actuator. After obtaining the first service function identifier, method 400 further includes: the processor of the central gateway sends the first service function identifier to the actuator; the actuator enables the first service function based on the first service function identifier.
[0142] Exemplarily, as Figure 3 shown, when the processing device is the processor of the central gateway, after the processor of the central gateway obtains the first service function identifier, the processor of the central gateway can also send the first service function identifier to the second actuator. Correspondingly, the second actuator can receive the first service function identifier from the processor of the central gateway. Furthermore, the second actuator can enable the first service function based on the first service function identifier.
[0143] It can be understood that in this implementation, the control device and the processor of the central gateway have also pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the authentication and verification of the identity of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processor of the central gateway to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world between the control device and the processor of the central gateway and then reused on other vehicles. Therefore, the information security of the vehicle permission management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be reduced.
[0144] In a possible implementation, the method 400 further includes: when it is detected that there is a second service function identifier, the processor of the central gateway sends an alarm message, which is used to prompt the existence of an information security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
[0145] It can be understood that the processor of the central gateway knows what content it sends to the second actuator at what time. If the processor of the central gateway detects content that is not sent by itself to the second actuator, the processor of the central gateway can determine that there may be an external device sending a CAN instruction to the second actuator, that is, the processor of the central gateway determines that there may be an information security risk.
[0146] Exemplarily, as Figure 3 shown, the processor of the central gateway can also have a CAN instruction monitoring function. That is to say, a CAN instruction monitoring module can be deployed in the processor of the central gateway. The processor of the central gateway can detect whether there is a second service function identifier on the CAN bus between the central gateway and the second actuator based on this CAN instruction monitoring detection (including but not limited to real-time detection or periodic detection). When it is detected that there is a second service function identifier on the CAN bus between the processor of the central gateway and the second actuator, the processor of the central gateway can send an alarm message, which is used to prompt the existence of an information security risk. For example, the processor of the central gateway can send this alarm information to the license control center to remind the relevant staff of the license control center that there is an information security risk in the license management process of the vehicle, so that the relevant staff can find and determine the specific reason and implement corresponding solutions or loss prevention measures. For another example, the processor of the central gateway can also display the alarm information on the vehicle's display screen or send out the alarm information by voice or other means to alert the user (such as the vehicle owner or driver, etc.) of the information security risk. Therefore, this implementation method can timely discover the information security risk in the vehicle license management process and give a risk alarm, which can reduce the losses of vehicle manufacturers.
[0147] In a possible implementation, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device to generate a control message, including: the control device encrypts the first service function identifier of the first service function ordered by the user based on a second key; the control device performs integrity protection on the encrypted first service function identifier and authenticates the identity of the control device to generate the control message. Correspondingly, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message, and obtains the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; the processing device decrypts the encrypted first service function identifier based on the key corresponding to the second key to obtain the first service function identifier.
[0148] Among them, the second key is also pre-stored in the control device; the key corresponding to the second key is pre-stored in the processing device. In an actual application scenario, the second key and the key corresponding to the second key can be symmetric keys or asymmetric keys, and the present application does not make any limitations in this regard.
[0149] Exemplarily, Figure 5 not all are shown in. In this implementation, the control device can first use the Lic-TA module to encrypt the first service function identifier based on the second key to obtain the encrypted first service function identifier, then sign the Lic public key with the device private key, and then use the Lic private key to sign the encrypted first service function identifier to generate signature information. In addition, in order to prevent the control message from being reused by other vehicles, a random number mechanism can also be introduced in the signature content. For example, Figure 5 the first random number shown in. The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. Thus, the control device generates the control message.
[0150] Correspondingly, the processing device can use the Lic-A module to verify the device certificate in the control message based on the prefabricated PKI certificate. After the verification of the device certificate is successful, the processing device can further verify the signature information and the first random number based on the device certificate. When the verification of the signature information and the first random number is successful, the encrypted first service function identifier can be obtained. Furthermore, the processing device can use the Lic-A module to decrypt the encrypted first service function identifier based on the key corresponding to the second key, so as to obtain the first service function identifier.
[0151] In this implementation manner, not only is the integrity protection and integrity verification of the first service function identifier performed, as well as the identity authentication and verification of the control device, but also the first service function identifier is encrypted before that, which can further improve the information security of the vehicle permission management process.
[0152] In a possible implementation manner, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and performs identity authentication on the control device to generate a control message, including: the control device performs integrity protection on the first service function identifier and performs identity authentication on the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on a third key to generate the control message. Correspondingly, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on a key corresponding to the third key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtains the first service function identifier when the integrity of the first service function identifier and the identity authentication of the control device are successful.
[0153] Among them, the third key is also pre-stored in the control device; the key corresponding to the third key is pre-stored in the processing device. In an actual application scenario, the third key and the key corresponding to the third key can be symmetric keys or asymmetric keys, and the present application does not make any limitations in this regard.
[0154] Exemplarily, Figure 5 not all are shown in. In this implementation manner, the control device can use the Lic-TA module to first sign the Lic public key with the device private key, and then sign the encrypted first service function identifier with the Lic private key to generate signature information. In addition, in order to prevent the control message from being reused by other vehicles, a random number mechanism can also be introduced in the signature content. For example, Figure 5 the first random number shown in. The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. Thus, the control device generates a preliminary control message. Furthermore, the control device can also use the Lic-TA module to encrypt the preliminary control message based on the third key to generate a control message.
[0155] Accordingly, the processing device may utilize the Lic-A module to first decrypt the control message based on the key corresponding to the third key to obtain the preliminary control message. Furthermore, the processing device may then verify the device certificate in the preliminary control message based on the prefabricated PKI certificate. After successfully verifying the device certificate, the processing device may further verify the signature information and the first random number based on the device certificate. When the signature information and the first random number are successfully verified, the first service function identifier may be obtained.
[0156] In this implementation manner, not only is the integrity protection and integrity verification of the first service function identifier, as well as the identity authentication and identity verification of the control device, carried out, but these information are further encrypted before sending, which can further improve the information security of the vehicle permission management process.
[0157] In a possible implementation manner, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and performs identity authentication on the control device to generate a control message, including: the control device encrypts the first service function identifier of the first service function ordered by the user based on the fourth key; the control device performs integrity protection on the encrypted first service function identifier and performs identity authentication on the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on the fifth key to generate the control message. Accordingly, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on the key corresponding to the fifth key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and when the integrity of the first service function identifier and the identity of the control device are successfully verified, obtains the encrypted first service function identifier; the processing device decrypts the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier.
[0158] Among them, the fourth key and the fifth key are also pre-stored by the control device; the key corresponding to the fourth key and the key corresponding to the fifth key are pre-stored by the processing device. In an actual application scenario, the fourth key and the key corresponding to the fourth key may be a symmetric key or an asymmetric key; the fifth key and the key corresponding to the fifth key may be a symmetric key or an asymmetric key. This application does not make any limitations in this regard.
[0159] Exemplarily, Figure 5Not all are shown in the figure. In this implementation, the control device can first use the Lic-TA module to encrypt the first service function identifier based on the fourth key to obtain the encrypted first service function identifier, then use the device private key to sign the Lic public key, and then use the Lic private key to sign the encrypted first service function identifier to generate signature information. In addition, in order to prevent the control message from being reused by other vehicles, a random number mechanism can also be introduced in the signature content, for example, Figure 5 The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. At this point, the control device has generated a preliminary control message. Furthermore, the control device can also use the Lic-TA module to encrypt the preliminary control message based on the fifth key to generate a control message.
[0160] Accordingly, the processing device can use the Lic-A module to first decrypt the control message based on the key corresponding to the fifth key to obtain the preliminary control message; then, verify the device certificate in the preliminary control message based on the pre-made PKI certificate. After the device certificate is successfully verified, the processing device can further verify the signature information and the first random number based on the device certificate. When the signature information and the first random number are successfully verified, the encrypted first service function identifier can be obtained. Then, the processing device can use the Lic-A module to decrypt the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier.
[0161] In this implementation, not only is the integrity protection and integrity verification performed on the first business function identifier, and the identity authentication and identity verification of the control device, but the first business function identifier is also encrypted before this, and this information is further encrypted before sending, which can further improve the information security of the vehicle licensing management process.
[0162] In a possible implementation, before the control device generates a control message, the method 400 also includes: the control device obtains a license file, the license file includes a business function identifier of a business function subscribed by a user, and the business function includes the first business function; the control device verifies the license file, and the control message is generated when the verification of the license file is successful.
[0163] Figure 6 It is a schematic diagram of information interaction between a vehicle and a license control center provided in an embodiment of the present application.
[0164] For example, Figure 6As shown, the control device can use the Lic-M module to obtain a license file from the license control center. The license file includes the service function identifier (i.e., the feature list) of the service functions ordered by the user, etc. The license file may also include signature information, digital certificates, etc., which are not limited in this application. After obtaining the license file, the control device can use the Lic-TA module to verify the license file. After successfully verifying the license file, the Lic-TA module can generate a control message and distribute the control message to the processing device.
[0165] In some possible implementation manners, after the control device uses the Lic-TA module to generate a control message, it can also be returned by the Lic-TA module to the Lic-M module, and the Lic-M module distributes the control message to the processing device, which is not limited in this application.
[0166] In one possible implementation manner, the control device verifies the license file, including: the control device verifies the license file based on the chip identifier of the control device and the VIN of the vehicle.
[0167] As Figure 6 shown, in this implementation manner, the license file may also include the VIN of the vehicle and the chip identifier of the control device on the vehicle.
[0168] Exemplarily, before generating the license file, the license control center can pre-obtain the VIN of the vehicle and the chip identifier of the control device on the vehicle from the vehicle management platform as Figure 2 shown. During the process of generating the license file of the vehicle, the license control center can bind the feature list of the vehicle with the VIN of the vehicle and the chip identifier of the control device on the vehicle, and further generate the license file of the vehicle. It can be understood that the VIN of the vehicle and the chip identifier of the control device on the vehicle in the vehicle management platform are also pre-stored.
[0169] In this implementation manner, the control device also needs to pre-store the VIN of the vehicle and the chip identifier of the control device on the vehicle. Thus, after obtaining the license file, the control device can verify the license file based on the pre-stored VIN of the vehicle and the chip identifier of the control device on the vehicle, that is, verify whether the VIN of the vehicle in the license file matches the VIN of the vehicle pre-stored by the control device, and verify whether the chip identifier of the control device in the license file matches the chip identifier of the control device pre-stored by the control device.
[0170] If either the VIN of the vehicle or the chip identification of the control device fails to match, it can be considered that the verification of the license file fails; when both the VIN of the vehicle and the chip identification of the control device match successfully, and other content to be verified (such as digital certificates) also passes the verification, it can be considered that the verification of the license file is successful. When the verification of the license file is successful, the control device can proceed with the subsequent process of generating control messages; when the verification of the license file fails, the control device does not proceed with the subsequent process of generating control messages.
[0171] In this implementation, different from the license file generation phase and the license file verification process in the method as Figure 2 shown, the license file is not generated based on the VIN of the vehicle and the ESN of the control device, nor is the license file verified based on the VIN of the vehicle and the ESN of the control device. Instead, the license file is generated based on the VIN of the vehicle and the chip identification of the control device, and the license file is verified based on the VIN of the vehicle and the chip identification of the control device. The ESN of the control device may be modified, while the chip identification of the control device cannot be modified. In this way, the information security risk brought by the replacement of the vehicle's control device can be avoided, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and thus the losses of vehicle manufacturers can be reduced.
[0172] In a possible implementation, the control device verifies the license file, including: the control device verifies the license file based on a preset second random number.
[0173] As Figure 6 shown, in this implementation, the license file may also include a second random number. Among them, the second random number is an anti-replay random number.
[0174] It can be understood that in actual application scenarios, the first random number and the second random number involved in this application may be the same random number or different random numbers, and this application does not make any restrictions on this.
[0175] Exemplarily, before generating the license file, the license control center may pre-store the second random number. The license control center may generate the license file of the vehicle based on the feature list and the second random number. In this implementation, the control device needs to support the local storage of the second random number in a replay protected memory block (RPMB) or a secure element (SE).
[0176] In this implementation manner, the control device also needs to pre-store the second random number. Thus, after obtaining the license file, the control device can verify the license file based on the pre-stored second random number, that is, verify whether the random number in the license file matches the random number pre-stored by the control device.
[0177] If the random number matching fails, it can be considered that the verification of the license file fails; if the random number matching is successful and other content to be verified (such as digital certificates) is also verified successfully, it can be considered that the verification of the license file is successful. When the verification of the license file is successful, the control device can proceed with the subsequent process of generating control messages; when the verification of the license file fails, the control device does not proceed with the subsequent process of generating control messages.
[0178] In this implementation manner, the verification of the license file also introduces the verification of the random number. When the random number verification is unsuccessful, the control device does not proceed with the subsequent process of generating control messages. In this way, it can prevent the license file from being reused on other vehicles, improve the information security of the vehicle licensing management process, reduce the information security risk, and thus reduce the losses of vehicle manufacturers.
[0179] In a possible implementation manner, the control device verifies the license file, including: the control device verifies the license file based on the chip identifier of the control device, the VIN of the vehicle, and a preset second random number.
[0180] As Figure 6 shown, in this implementation manner, the license file may further include the VIN of the vehicle, the chip identifier of the control device on the vehicle, and also include a second random number.
[0181] Exemplarily, before generating the license file, the license control center can pre-obtain the VIN of the vehicle and the chip identifier of the control device on the vehicle from the vehicle management platform as Figure 2 shown. And before generating the license file, the license control center can pre-store a second random number. During the process of generating the license file for the vehicle, the license control center can bind the feature list of the vehicle with the VIN of the vehicle and the chip identifier of the control device on the vehicle, and further generate the license file for the vehicle based on the second random number, etc.
[0182] In this implementation, the control device also needs to pre-store the VIN of the vehicle, the chip identification of the control device on the vehicle, and the second random number. Thus, after obtaining the license file, the control device can verify the license file based on the pre-stored VIN of the vehicle, the chip identification of the control device on the vehicle, and the second random number. That is, it verifies whether the VIN of the vehicle in the license file matches the VIN of the vehicle pre-stored by the control device, whether the chip identification of the control device in the license file matches the chip identification of the control device pre-stored by the control device, and whether the random number in the license file matches the random number pre-stored by the control device.
[0183] If any one of the VIN of the vehicle, the chip identification of the control device, or the random number fails to match, it can be considered that the verification of the license file fails; when the VIN of the vehicle, the chip identification of the control device, and the random number all match successfully, and other content to be verified (such as digital certificates) also passes the verification, it can be considered that the verification of the license file is successful. When the verification of the license file is successful, the control device can proceed with the subsequent process of generating control messages; when the verification of the license file fails, the control device does not proceed with the subsequent process of generating control messages.
[0184] In this implementation, the verification of the license file introduces the chip identification of the control device, which can avoid the security risks brought by the replacement of the control device of the vehicle; it also introduces the verification of the random number. In this way, it can better prevent the license file from being reused on other vehicles, improve the information security of the vehicle licensing management process, reduce the information security risks, and thus reduce the losses of vehicle manufacturers.
[0185] In a possible implementation, the license file may also include the expiration date of the license. In this way, when the control device verifies the license, it also needs to verify whether the license file is within the pre-set expiration date. When it is determined that the license file is within the expiration date, the control device can proceed with the subsequent process of generating control messages; when the license file is not within the expiration date, the control device does not proceed with the subsequent process of generating control messages.
[0186] In a possible implementation, when the verification of the license file fails, the control device can also send an alarm message to indicate the existence of information security risks. For example, when the verification of the license file fails, the alarm information can be sent to the license control center to remind the relevant staff of the license control center that there are information security risks in the license management process of the vehicle, so that the relevant staff can search for and determine the specific reasons and implement corresponding solutions or loss prevention measures. For example, the alarm information can also be displayed on the vehicle's display screen or sent through voice or other means to warn the user (such as the vehicle owner or driver, etc.) of the security risks.
[0187] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of integrity protection and integrity verification of the first service function identifier, as well as the authentication and verification of the identity of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be minimized. In addition, when the processing device is the processor of the central gateway, the processing device also has the CAN instruction monitoring function. When detecting the existence of information security risks, the processing device can send an alarm message, which can not only timely detect the information security risks in the vehicle license management process, but also give risk warnings, and can reduce the losses of vehicle manufacturers. Furthermore, the chip identifier of the vehicle's control device is introduced in the verification of the license file, and this identifier cannot be modified. In this way, the information security risks caused by the replacement of the vehicle's control device can be avoided, and the information security of the vehicle license management process can be further improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be minimized. Moreover, the verification of the license file also introduces the verification of random numbers. When the random number verification fails, the control device does not proceed with the subsequent process of generating control messages. In this way, the reuse of the license file on other vehicles can be prevented, the information security of the vehicle license management process can be further improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be minimized.
[0188] Figure 7 It is another schematic flowchart of the vehicle license management method provided by the embodiments of the present application.
[0189] Such as Figure 7As shown, the steps of the method 700 may be executed by a control device, or the method 700 may also be executed by components (such as chips, chip systems, etc.) configured in the control device, or may also be implemented by a logic module or software capable of implementing all or part of the functions of the control device. The embodiments of the present application do not limit this. The following will describe Figure 7 each step in detail.
[0190] In step 710, integrity protection is performed on the first service function identifier of the first service function ordered by the user, and authentication of the identity of the control device is performed to generate a control message.
[0191] For a detailed description, reference may be made to the relevant description of step 410 in the foregoing text. For the sake of brevity, it will not be repeated here. In a possible implementation manner, performing integrity protection on the first service function identifier of the first service function ordered by the user and authenticating the identity of the control device includes: the control device performing integrity protection on the first service function identifier and authenticating the identity of the control device based on a first key, a first random number, and the device certificate of the control device.
[0192] Exemplarily, the control device may use, for example, Figure 3 or Figure 5 the Lic-TA module shown, based on the first key, the first random number, and the device certificate of the control device, to perform integrity protection on the first service function identifier and authenticate the identity of the control device. For a detailed description, reference may be made to the relevant description in the foregoing text Figure 5 For the sake of brevity, it will not be repeated here.
[0193] In a possible implementation manner, performing integrity protection on the first service function identifier of the first service function ordered by the user and authenticating the identity of the control device to generate a control message includes: encrypting the first service function identifier of the first service function ordered by the user based on a second key; performing integrity protection on the encrypted first service function identifier, and authenticating the identity of the control device to generate the control message.
[0194] Exemplarily, Figure 5 not all are shown in. In this implementation manner, the control device may first use the Lic-TA module to encrypt the first service function identifier based on the second key to obtain the encrypted first service function identifier, then sign the Lic public key with the device private key, and then sign the encrypted first service function identifier with the Lic private key to generate signature information. In addition, in order to prevent the control message from being reused by other vehicles, a random number mechanism may also be introduced in the signature content. For example, Figure 5The first random number shown in . The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. Thus, the control device generates the control message.
[0195] In a possible implementation, integrity protection is performed on the first service function identifier of the first service function ordered by the user and authentication of the control device is performed to generate a control message, including: performing integrity protection on the first service function identifier and performing authentication of the control device to generate a preliminary control message; encrypting the preliminary control message based on a third key to generate the control message.
[0196] Exemplarily, Figure 5 not all shown in . In this implementation, the control device can use the Lic-TA module to first sign the Lic public key with the device private key, and then sign the encrypted first service function identifier with the Lic private key to generate signature information. Additionally, in order to prevent the control message from being reused by other vehicles, a random number mechanism can also be introduced in the signature content, for example, Figure 5 the first random number shown in . The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. Thus, the control device generates the preliminary control message. Further, the control device can also use the Lic-TA module to encrypt the preliminary control message based on a third key to generate the control message.
[0197] In a possible implementation, integrity protection is performed on the first service function identifier of the first service function ordered by the user and authentication of the control device is performed to generate a control message, including: encrypting the first service function identifier of the first service function ordered by the user based on a fourth key; performing integrity protection on the encrypted first service function identifier and performing authentication of the control device to generate a preliminary control message; encrypting the preliminary control message based on a fifth key to generate the control message.
[0198] Exemplarily, Figure 5 not all shown in . In this implementation, the control device can first use the Lic-TA module to encrypt the first service function identifier based on a fourth key to obtain the encrypted first service function identifier, then sign the Lic public key with the device private key, and then sign the encrypted first service function identifier with the Lic private key to generate signature information. Additionally, in order to prevent the control message from being reused by other vehicles, a random number mechanism can also be introduced in the signature content, for example, Figure 5The control device can also use the Lic-TA module to put the device certificate of the control device into the control message. At this point, the control device has generated a preliminary control message. Furthermore, the control device can also use the Lic-TA module to encrypt the preliminary control message based on the fifth key to generate a control message.
[0199] In step 720, the control message is sent to the processing device.
[0200] The processing device may be an actuator (e.g. Figure 3 The first actuator shown in ) or a processor of a central gateway.
[0201] For a detailed description, please refer to the relevant description of step 420 above, which will not be repeated here for the sake of brevity.
[0202] In one possible implementation, before generating the control message, the method 700 further includes: obtaining a license file, the license file including a business function identifier of a business function subscribed by the user, the business function including the first business function; and verifying the license file, wherein the control message is generated when the license file verification is successful.
[0203] For example, Figure 6 As shown, the control device can use the Lic-M module to obtain a license file from the license control center. The license file includes the business function identifier (i.e., the feature list) of the business function ordered by the user. The license file can also include signature information and digital certificates, etc., which are not limited in this application. After obtaining the license file, the control device can use the Lic-TA module to verify the license file. After the license file is successfully verified, the Lic-TA module can generate a control message and distribute the control message to the processing device.
[0204] In some possible implementations, after the control device generates a control message using the Lic-TA module, the Lic-TA module may return it to the Lic-M module, and the Lic-M module distributes the control message to the processing device. This application does not limit this.
[0205] In one possible implementation, verifying the license file includes: verifying the license file based on the chip identifier of the control device and the VIN of the vehicle; or, verifying the license file based on a preset second random number; or, verifying the license file based on the chip identifier of the control device and the VIN of the vehicle, and a preset second random number.
[0206] For a detailed description, see the above Figure 6For the related descriptions, for the sake of brevity, they will not be elaborated here.
[0207] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the identity authentication and verification of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle license management process can be improved, the information security risk can be reduced, and thus the losses of vehicle manufacturers can be reduced. In addition, the chip identifier of the control device of the vehicle is introduced in the verification of the license file. This identifier cannot be modified. In this way, the information security risk caused by the replacement of the control device of the vehicle can be avoided, the information security of the vehicle license management process can be further improved, the information security risk can be reduced, and thus the losses of vehicle manufacturers can be reduced. Furthermore, the verification of the license file also introduces the verification of random numbers. When the random number verification fails, the control device does not perform the subsequent process of generating control messages. In this way, the license file can be prevented from being reused on other vehicles, the information security of the vehicle license management process can be further improved, the information security risk can be reduced, and thus the losses of vehicle manufacturers can be reduced.
[0208] Figure 8 It is another schematic flowchart of the vehicle license management method provided by the embodiments of the present application.
[0209] As Figure 8 shown, the steps of the method 800 can be executed by the processing device, or the method 800 can also be executed by components (such as chips, chip systems, etc.) configured in the processing device, or can also be implemented by a logic module or software that can implement all or part of the functions of the processing device. The embodiments of the present application do not limit this. The following will Figure 8 make a detailed description of each step in
[0210] In step 810, a control message from the control device is received.
[0211] The processing device can receive a control message from the control device. The control message includes the first service function identifier of the first service function ordered by the user.
[0212] For the detailed description, reference can be made to the related description of step 420 in the above text. For the sake of brevity, it will not be elaborated here.
[0213] In step 820, based on the control message, the integrity of the first service function identifier and the identity of the control device are verified to obtain the first service function identifier.
[0214] For detailed description, reference can be made to the relevant description of step 430 above. For the sake of brevity, it will not be elaborated here.
[0215] In a possible implementation, based on the control message, verify the integrity of the first service function identifier and the identity of the control device to obtain the first service function identifier, including: based on the control message, verify the integrity of the first service function identifier and the identity of the control device, and when the verification of the integrity of the first service function identifier and the identity of the control device is successful, obtain the encrypted first service function identifier; based on the key corresponding to the second key, decrypt the encrypted first service function identifier to obtain the first service function identifier.
[0216] Exemplarily, Figure 5 Not all shown in, the processing device can use the Lic-A module to verify the device certificate in the control message based on the prefabricated PKI certificate. After the verification of the device certificate is successful, the processing device can further verify the signature information and the first random number based on the device certificate. When the verification of the signature information and the first random number is successful, the encrypted first service function identifier can be obtained. Furthermore, the processing device can use the Lic-A module to decrypt the encrypted first service function identifier based on the key corresponding to the second key to obtain the first service function identifier.
[0217] In a possible implementation, based on the control message, verify the integrity of the first service function identifier and the identity of the control device to obtain the first service function identifier, including: based on the key corresponding to the third key, decrypt the control message to obtain a preliminary control message; based on the preliminary control message, verify the integrity of the first service function identifier and the identity of the control device, and when the verification of the integrity of the first service function identifier and the identity of the control device is successful, obtain the first service function identifier.
[0218] Exemplarily, Figure 5 Not all shown in, the processing device can use the Lic-A module to first decrypt the control message based on the key corresponding to the third key to obtain the preliminary control message; then, verify the device certificate in the preliminary control message based on the prefabricated PKI certificate. After the verification of the device certificate is successful, the processing device can further verify the signature information and the first random number based on the device certificate. When the verification of the signature information and the first random number is successful, the first service function identifier can be obtained.
[0219] In a possible implementation, the integrity of the first service function identifier and the identity of the control device are verified based on the control message to obtain the first service function identifier, including: decrypting the control message based on the key corresponding to the fifth key to obtain a preliminary control message; verifying the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtaining the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; decrypting the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier.
[0220] Exemplarily, Figure 5 not all shown in the figure, the processing device may utilize the Lic-A module to first decrypt the control message based on the key corresponding to the fifth key to obtain the preliminary control message; then, further verify the device certificate in the preliminary control message based on the prefabricated PKI certificate. After the verification of the device certificate is successful, the processing device may further verify the signature information and the first random number based on the device certificate. When the verification of the signature information and the first random number is successful, the encrypted first service function identifier can be obtained. Further, the processing device may utilize the Lic-A module to decrypt the encrypted first service function identifier based on the key corresponding to the fourth key, thereby obtaining the first service function identifier.
[0221] In a possible implementation, when the processing device is an actuator, after obtaining the first service function identifier, the method 800 further includes: the actuator enabling the first service function based on the first service function identifier.
[0222] Exemplarily, as Figure 3 shown, when the processing device is the first actuator, after the first actuator obtains the first service function identifier, the first actuator may also directly enable the first service function based on the first service function identifier.
[0223] In a possible implementation, when the processing device is the processor of the central gateway, after obtaining the first service function identifier, the method 800 further includes: sending the first service function identifier to the actuator.
[0224] Exemplarily, as Figure 3As shown, when the processor of the processing device is the processor of the central gateway, after obtaining the first service function identifier, the processor of the central gateway may also send the first service function identifier to the second actuator. Correspondingly, the second actuator may receive the first service function identifier from the processor of the central gateway. Further, the second actuator may enable the first service function based on the first service function identifier.
[0225] In a possible implementation, the method 800 further includes: when detecting the existence of a second service function identifier, sending an alarm message for prompting the existence of an information security risk, where the second service function identifier is not sent by the processor of the central gateway to the actuator.
[0226] It can be understood that the processor of the central gateway knows what content it sends to the second actuator at what time. If the processor of the central gateway detects content that is not sent by itself to the second actuator, the processor of the central gateway can determine that there may be an external device sending a CAN instruction to the second actuator, that is, the processor of the central gateway determines that there may be an information security risk.
[0227] Exemplarily, as Figure 3 shown, the processor of the central gateway may also have a CAN instruction monitoring function. That is to say, a CAN instruction monitoring module may be deployed in the processor of the central gateway. The processor of the central gateway may detect (including but not limited to real-time detection or periodic detection) whether there is a second service function identifier on the CAN bus between the central gateway and the second actuator based on the CAN instruction monitoring. When detecting that there is a second service function identifier on the CAN bus between the processor of the central gateway and the second actuator, the processor of the central gateway may send an alarm message for prompting the existence of an information security risk. For example, the alarm information may be sent to the license control center to remind the relevant staff of the license control center that there is an information security risk in the license management process of the vehicle, so that the relevant staff can find and determine the specific reason and implement corresponding solutions or loss prevention measures. For example, the alarm information may also be displayed on the vehicle's display screen or sent out by voice or other means to warn the user (such as the vehicle owner or driver, etc.) of the information security risk. Therefore, this implementation can timely discover the information security risk in the vehicle license management process, perform risk warning, and timely reduce the losses of vehicle manufacturers.
[0228] Based on the above technical solution, the control device and the processing device have pre-negotiated the process of integrity protection and integrity verification for the first service function identifier, as well as the identity authentication and verification of the control device. This is equivalent to establishing a secure and dedicated transmission channel between the control device and the processing device to transmit the first service function identifier. In this way, the first service function identifier will not be easily intercepted by the outside world and then reused on other vehicles. Therefore, the information security of the vehicle permission management process can be improved, the information security risk can be reduced, and the losses of vehicle manufacturers can be reduced. In addition, when the processing device is the processor of the central gateway, the processing device also has a CAN instruction monitoring function. When detecting an information security risk, the processing device can send an alarm message, which can not only timely detect the information security risk in the vehicle permission management process, but also perform risk warning, and can reduce the losses of vehicle manufacturers.
[0229] Figure 9 It is a schematic block diagram of a control device applicable to the vehicle permit management method provided in this application.
[0230] As Figure 9 shown, the control device 900 may include: a processing module 910 and a transceiver module 920. The control device 900 may be used to execute the execution steps of the control device in the vehicle permit management method proposed in the embodiments of this application.
[0231] Exemplarily, when the control device 900 is used to execute the execution steps of the control device in method 400 or method 700, wherein, the processing module 910 may be used to perform integrity protection on the first service function identifier of the first service function ordered by the user and perform identity authentication on the control device to generate a control message; the transceiver module 920 may be used to send the control message to the processing device.
[0232] Optionally, the processing module 910 is specifically used for: performing integrity protection on the first service function identifier and performing identity authentication on the control device based on the first key, the first random number, and the device certificate of the control device. Optionally, the processing module 910 is specifically used for: encrypting the first service function identifier of the first service function ordered by the user based on the second key; performing integrity protection on the encrypted first service function identifier, and performing identity authentication on the control device to generate the control message.
[0233] Optionally, the processing module 910 is specifically used for: performing integrity protection on the first service function identifier and performing identity authentication on the control device to generate a preliminary control message; encrypting the preliminary control message based on the third key to generate the control message.
[0234] Optionally, the processing module 910 is specifically configured to: encrypt the first service function identifier of the first service function ordered by the user based on the fourth key; perform integrity protection on the encrypted first service function identifier, and authenticate the identity of the control device to generate a preliminary control message; encrypt the preliminary control message based on the fifth key to generate the control message.
[0235] Optionally, the transceiver module 920 is further configured to obtain a license file, where the license file includes the service function identifiers of the service functions ordered by the user, and the service functions include the first service function; the processing module 910 is further configured to verify the license file, and the control message is generated when the verification of the license file is successful.
[0236] Optionally, the processing module 910 is specifically configured to verify the license file based on the chip identifier of the control device and the VIN of the vehicle; or verify the license file based on a preset second random number; or verify the license file based on the chip identifier of the control device and the VIN of the vehicle, and a preset second random number.
[0237] Figure 10 It is a schematic block diagram of a processing device applicable to the vehicle license management method provided in this application.
[0238] As Figure 10 shown, the processing device 1000 may include: a transceiver module 1010 and a processing module 1020. The processing device 1000 may be used to execute the execution steps of the processing device (such as the processor of the first actuator or the central gateway) or the processing device in the vehicle license management method proposed in the embodiments of this application.
[0239] Exemplarily, when the processing device 1000 is used to execute the execution steps of the processing device in method 400 or method 800, where the transceiver module 1010 may be used to receive a control message from the control device, and the control message includes the service function identifier of the first service function ordered by the user; the processing module 1020 may be used to verify the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier.
[0240] Optionally, when the processing device 1000 is an actuator, the transceiver module 1010 may further be used to: enable the first service function based on the first service function identifier. Optionally, when the processing device 1000 is the processor of the central gateway, the transceiver module 1010 may further be used to: send the first service function identifier to the actuator.
[0241] Optionally, the processing module 1020 can also be used to detect whether there is a second service function identifier; when it is detected that there is a second service function identifier, the transceiver module 1010 can also be used to send an alarm message for prompting that there is a security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
[0242] Optionally, the processing module 1020 is specifically configured to: verify the integrity of the first service function identifier and the identity of the control device based on the control message, and obtain the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; decrypt the encrypted first service function identifier based on the key corresponding to the second key, where the second key is the key for encrypting the first service function identifier, to obtain the first service function identifier.
[0243] Optionally, the processing module 1020 is specifically configured to: decrypt the control message based on the key corresponding to the third key to obtain a preliminary control message, where the third key is the key for encrypting the control message; verify the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtain the first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful.
[0244] Optionally, the processing module 1020 is specifically configured to: decrypt the control message based on the key corresponding to the fifth key to obtain a preliminary control message, where the fifth key is the key for encrypting the preliminary control message; verify the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtain the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; decrypt the encrypted first service function identifier based on the key corresponding to the fourth key, where the fourth key is the key for encrypting the first service function identifier, to obtain the first service function identifier.
[0245] Figure 11 It is a schematic block diagram of a device applicable to the vehicle license management method provided in this application.
[0246] The device 1100 can be used to implement the functions of the control device or the processing device in the above method. The device 1100 can be a chip system. In the embodiments of this application, the chip system can be composed of chips or can include chips and other discrete devices.
[0247] Such as Figure 11As shown, the device 1100 may include at least one processor 1110, which is used to implement the functions of the control device or the processing device in the method provided by the embodiments of the present application.
[0248] For example, when the device 1100 is used to implement the function of the control device in the method 700 provided by the embodiments of the present application, the processor 1110 can be used to perform integrity protection on the first service function identifier of the first service function ordered by the user and authenticate the identity of the control device to generate a control message; and send the control message to the processing device. For specific details, please refer to the detailed description in the method example, which will not be elaborated here.
[0249] For example, when the device 1100 is used to implement the function of the processing device in the method 800 provided by the embodiments of the present application, the processor 1110 can be used to receive a control message from the control device, and the control message includes the service function identifier of the first service function ordered by the user; and verify the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier. For specific details, please refer to the detailed description in the method example, which will not be elaborated here.
[0250] The device 1100 may further include at least one memory 1120, which is used to store program instructions and / or data. The memory 1120 is coupled to the processor 1110. The coupling in the embodiments of the present application is an indirect coupling or communication connection between devices, units or modules, which can be electrical, mechanical or other forms, and is used for information interaction between devices, units or modules. The processor 1110 may cooperate with the memory 1120. The processor 1110 may execute the program instructions stored in the memory 1120. At least one of the at least one memory may be included in the processor.
[0251] The device 1100 may further include a communication interface 1130, which is used to communicate with other devices through a transmission medium, so that the device 1100 can communicate with other devices. Exemplarily, when the device 1100 is used to implement the function of the control device in the method provided by the embodiments of the present application, the other device may be a processing device; when the device 1100 is used to implement the function of the processing device in the method provided by the embodiments of the present application, the other device may be a control device. The communication interface 1130 may be, for example, a transceiver, an interface, a bus, a circuit or a device capable of implementing transceiver functions. The processor 1110 may use the communication interface 1130 to send and receive data and / or information, and is used to implement Figure 4 the methods performed by the control device or the processing device described in the corresponding embodiments in
[0252] In the embodiments of the present application, the specific connection medium between the above-mentioned processor 1110, memory 1120 and communication interface 1130 is not limited. The embodiments of the present application are inFigure 11 In the [system], the processor 1110, the memory 1120, and the communication interface 1130 are connected via a bus 1140. The bus 1140 is shown as a thick line in the [system]. The connection manners between other components are only for illustrative purposes and are not limiting. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity in representation, Figure 11 it is shown as only one thick line in the [system], but it does not mean that there is only one bus or one type of bus. Figure 11
[0253] This application also provides a vehicle, which includes a control device and a processing device. The control device is used to execute the functions of the control device in the method embodiments as Figure 4 shown, and the processing device is used to execute the functions of the processing device in the method embodiments as Figure 4 shown.
[0254] This application also provides a vehicle, which includes a control device and a processing device. The control device is used to execute the functions of the control device in the method embodiments as Figure 7 shown, and the processing device is used to execute the functions of the processing device in the method embodiments as Figure 8 shown.
[0255] This application also provides a chip system, which includes at least one processor for implementing the functions involved in the methods executed by the control device or the processing device in the above Figure 4 shown embodiments, or for implementing the functions involved in the methods executed by the control device in the above Figure 7 shown embodiments, or for implementing the functions involved in the methods executed by the processing device in the above Figure 8 shown embodiments. For example, receiving and / or processing the data and / or information involved in the above methods.
[0256] In a possible design, the chip system further includes a memory for storing program instructions and data, and the memory is located inside or outside the processor.
[0257] The chip system can be composed of chips or can include chips and other discrete devices.
[0258] This application embodiment also provides a readable storage medium, on which a program is stored. When the program is run, Figure 4 the methods executed by the control device in the Figure 7 shown embodiments are executed, or the methods executed by the processing device are executed; or Figure 8 the methods executed by the control device in the
[0259] The embodiments of the present application further provide a program product, including a program which, when run, Figure 4 executes the method executed by the control device in the illustrated embodiment, or executes the method executed by the processing device; or, Figure 7 executes the method executed by the control device in the illustrated embodiment; or, Figure 8 executes the method executed by the processing device in the illustrated embodiment.
[0260] It should be understood that the processor in the embodiments of the present application may be an integrated circuit chip with the ability to process signals. During implementation, the steps of the above method embodiments may be completed by the integrated logic circuit in the hardware of the processor or by instructions in the form of software. The above processor may be a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by the hardware decoding processor, or executed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as random access memory, flash memory, read-only memory, programmable read-only memory or electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above method.
[0261] It should also be understood that the memory in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable programmable ROM (EPROM), an electrically erasable programmable ROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include but not be limited to these and any other suitable types of memory.
[0262] As used in this specification, terms such as "unit" and "module" can be used to represent an entity, hardware, firmware, a combination of hardware and software, software, or software in execution related to a device or apparatus.
[0263] Those of ordinary skill in the art will appreciate that the various illustrative logical blocks and steps described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application. In several embodiments provided in this application, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed among each other can be through some interfaces, and the indirect couplings or communication connections of the devices or modules can be in electrical, mechanical, or other forms.
[0264] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place, or may be distributed over multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0265] In addition, in each embodiment of this application, the functional modules can be integrated in one processing module, or each module can exist physically alone, or two or more units can be integrated in one module.
[0266] In the above embodiments, the functions of each functional module can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a program product. The program product includes one or more instructions (programs). When the program instructions (programs) are loaded and executed on a device or apparatus, the processes or functions described in the embodiments of the present application are generated in whole or in part. The instructions can be stored in a readable storage medium or transmitted from one readable storage medium to another readable storage medium. For example, the instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The readable storage medium can be any available medium that can be accessed by the device or apparatus, or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a digital videodisc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.
[0267] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for causing a device or apparatus (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs that can store program codes.
[0268] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A vehicle license management method, characterized in that, the method is applied to a vehicle, the vehicle includes a control device and a processing device, and the method includes: the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device to generate a control message; the control device sends the control message to the processing device; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier; wherein, the processing device is a processor of an actuator or a central gateway.
2. The method according to claim 1, characterized in that, the processing device is the actuator, and after obtaining the first service function identifier, the method further includes: the actuator enables the first service function based on the first service function identifier.
3. The method according to claim 1, characterized in that, the processing device is a processor of the central gateway, and the vehicle further includes an actuator. After obtaining the first service function identifier, the method further includes: the processor of the central gateway sends the first service function identifier to the actuator; the actuator enables the first service function based on the first service function identifier.
4. The method according to claim 3, characterized in that, the method further includes: when it is detected that there is a second service function identifier, the processor of the central gateway sends an alarm message, and the alarm message is used to prompt an information security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
5. The method according to any one of claims 1 to 4, characterized in that, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device, including: the control device performs integrity protection on the first service function identifier and authenticates the identity of the control device based on a first key, a first random number, and a device certificate based on the control device.
6. The method according to any one of claims 1 to 5, characterized in that, the control device performs integrity protection on the first service function identifier of the first service function ordered by the user and authenticates the identity of the control device to generate a control message, including: the control device encrypts the first service function identifier of the first service function ordered by the user based on a second key; the control device performs integrity protection on the encrypted first service function identifier and authenticates the identity of the control device to generate the control message.
7. The method according to claim 6, characterized in that, the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: The processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message, and obtains the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful. The processing device decrypts the encrypted first service function identifier based on the key corresponding to the second key to obtain the first service function identifier.
8. The method according to any one of claims 1 to 5, characterized in that the control device performs integrity protection on the first service function identifier of the first service function subscribed by the user and authenticates the identity of the control device, and generates a control message, including: the control device performs integrity protection on the first service function identifier and authenticates the identity of the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on a third key to generate the control message.
9. The method according to claim 8, characterized in that the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on the key corresponding to the third key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtains the first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful.
10. The method according to any one of claims 1 to 5, characterized in that the control device performs integrity protection on the first service function identifier of the first service function subscribed by the user and authenticates the identity of the control device, and generates a control message, including: the control device encrypts the first service function identifier of the first service function subscribed by the user based on a fourth key; the control device performs integrity protection on the encrypted first service function identifier and authenticates the identity of the control device to generate a preliminary control message; the control device encrypts the preliminary control message based on a fifth key to generate the control message.
11. The method according to claim 10, characterized in that the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier, including: the processing device decrypts the control message based on the key corresponding to the fifth key to obtain the preliminary control message; the processing device verifies the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtains the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful. The processing device decrypts the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier.
12. The method according to any one of claims 1 to 11, wherein, before generating the control message, the method further includes: the control device obtains a license file, the license file includes service function identifiers of services subscribed by the user, and the services include the first service; the control device verifies the license file, and the control message is generated when the verification of the license file is successful.
13. The method according to claim 12, wherein, the control device verifies the license file, including: the control device verifies the license file based on the chip identifier of the control device and the vehicle identification number VIN of the vehicle; or, the control device verifies the license file based on a preset second random number; or, the control device verifies the license file based on the chip identifier of the control device and the VIN of the vehicle, and a preset second random number.
14. A vehicle license management method, wherein, applied to a control device, the method includes: performing integrity protection on the first service function identifier of the first service subscribed by the user and authenticating the identity of the control device to generate a control message; sending the control message to a processing device.
15. The method according to claim 14, wherein, the performing integrity protection on the first service function identifier of the first service subscribed by the user and authenticating the identity of the control device includes: performing integrity protection on the first service function identifier and authenticating the identity of the control device based on a first key, a first random number, and the device certificate of the control device.
16. The method according to claim 14 or 15, wherein, the performing integrity protection on the first service function identifier of the first service subscribed by the user and authenticating the identity of the control device to generate a control message includes: encrypting the first service function identifier of the first service subscribed by the user based on a second key; performing integrity protection on the encrypted first service function identifier and authenticating the identity of the control device to generate the control message.
17. The method according to claim 14 or 15, wherein, the performing integrity protection on the first service function identifier of the first service subscribed by the user and authenticating the identity of the control device to generate a control message includes: performing integrity protection on the first service function identifier and authenticating the identity of the control device to generate a preliminary control message; encrypting the preliminary control message based on a third key to generate the control message.
18. The method according to claim 14 or 15, wherein, Performing integrity protection on the first service function identifier of the first service function ordered by the user and authenticating the identity of the control device to generate a control message, including: Encrypting the first service function identifier of the first service function ordered by the user based on a fourth key; Performing integrity protection on the encrypted first service function identifier and authenticating the identity of the control device to generate a preliminary control message; Encrypting the preliminary control message based on a fifth key to generate the control message.
19. The method according to any one of claims 14 to 18, wherein, before generating the control message, the method further includes: Obtaining a license file, the license file including the service function identifier of the service function ordered by the user, and the service function including the first service function; Verifying the license file, and the control message is generated when the verification of the license file is successful.
20. The method according to claim 19, wherein, the verifying the license file includes: Verifying the license file based on the chip identifier of the control device and the vehicle identification number VIN of the vehicle; or, Verifying the license file based on a preset second random number; or, Verifying the license file based on the chip identifier of the control device and the VIN of the vehicle, and a preset second random number.
21. A vehicle license management method, wherein, applied to a processing device, the method includes: Receiving a control message from a control device, the control message including the service function identifier of the first service function ordered by the user; Verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier.
22. The method according to claim 21, wherein, when the processing device is an actuator, after obtaining the first service function identifier, the method further includes: The actuator enabling the first service function based on the first service function identifier.
23. The method according to claim 21, wherein, when the processing device is a processor of a central gateway, after obtaining the first service function identifier, the method further includes: Sending the first service function identifier to an actuator.
24. The method according to claim 23, wherein, the method further includes: When detecting the existence of a second service function identifier, sending an alarm message, the alarm message being used to prompt the existence of an information security risk, and the second service function identifier is not sent by the processor of the central gateway to the actuator.
25. The method according to any one of claims 21 to 24, wherein, the verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: Verify the integrity of the first service function identifier and the identity of the control device based on the control message, and obtain the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful. Decrypt the encrypted first service function identifier based on the key corresponding to the second key to obtain the first service function identifier, where the second key is the key used to encrypt the first service function identifier.
26. The method according to any one of claims 21 to 24, characterized in that The verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: Decrypt the control message based on the key corresponding to the third key to obtain a preliminary control message, where the third key is the key used to encrypt the control message; Verify the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtain the first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful.
27. The method according to any one of claims 21 to 24, characterized in that The verifying the integrity of the first service function identifier and the identity of the control device based on the control message to obtain the first service function identifier includes: Decrypt the control message based on the key corresponding to the fifth key to obtain a preliminary control message, where the fifth key is the key used to encrypt the preliminary control message; Verify the integrity of the first service function identifier and the identity of the control device based on the preliminary control message, and obtain the encrypted first service function identifier when the verification of the integrity of the first service function identifier and the identity of the control device is successful; The processing device decrypts the encrypted first service function identifier based on the key corresponding to the fourth key to obtain the first service function identifier, where the fourth key is the key used to encrypt the first service function identifier.
28. A control device for vehicle permit management, characterized in that The control device includes a module for executing the method according to any one of claims 14 to 20.
29. A control device for vehicle permit management, characterized in that It includes a processor and a memory, wherein The memory is used to store programs; The processor is used to call the program so that the control device executes the method according to any one of claims 14 to 20.
30. A processing device for vehicle permit management, characterized in that The processing device includes a module for executing the method according to any one of claims 21 to 27.
31. A processing device for vehicle permit management, characterized in that It includes a processor and a memory, wherein The memory is used to store programs; The processor is used to call the program so that the processing device executes the method according to any one of claims 21 to 27.
32. A vehicle, characterized in that the vehicle includes a control device and a processing device, the control device is used to execute the method according to any one of claims 14 to 20, and the processing device is used to execute the method according to any one of claims 21 to 27.
33. A readable storage medium, on which a program is stored, characterized in that when the program is executed, the method according to any one of claims 1 to 27 is executed.
34. A program product, characterized in that it includes a program, and when the program is run, the method according to any one of claims 1 to 27 is executed.