Security authentication request method and system based on remote high-voltage power-on of pure electric vehicle

By introducing a security authentication request system in pure electric vehicles, and using the encryption technology of cloud servers and on-board terminals, the problem of insufficient vehicle communication security in the existing technology has been solved, and the security of vehicle communication and user convenience has been improved.

CN120128614APending Publication Date: 2025-06-10联友智连科技有限公司

Patent Information

Application Number
CN202311678983.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-07
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the prior art, remote control instructions fail to effectively ensure the security and confidentiality of vehicle communications, and there is a risk of vehicle theft or data leakage.

Method used

By introducing a security authentication request system in pure electric vehicles, using cloud servers, on-board terminals, IMMO anti-theft coils and vehicle controllers, using PKI negotiated communication keys and advanced encryption algorithm technology, one-time security authentication and second security authentication are carried out to ensure the encrypted transmission of remote control control instructions and the security of high-voltage power-on.

Benefits of technology

Effectively prevent the risk of vehicle theft or data leakage, ensure the security and confidentiality of vehicle communications, and improve the user's convenience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128614A_ABST
    Figure CN120128614A_ABST
Patent Text Reader

Abstract

The invention discloses a safety certification request method and system based on remote high-voltage power-on of a pure electric vehicle, and relates to the technical field of vehicle safety. The method comprises the steps that a user sends a remote control instruction to a vehicle-mounted terminal through an APP; after the vehicle-mounted terminal receives the remote control instruction, a security authentication mechanism is started; the security authentication mechanism carries out identity authentication and authorization on a user in a password authentication mode, and an advanced encryption algorithm technology is adopted in a random combination mode of a random number, a security code, a constant code and the like by means of a secret key written by a vehicle production line. Through primary safety certification and secondary safety certification of the vehicle-mounted terminal and the I MMO, the safety and confidentiality of vehicle communication are ensured, and the risk of vehicle theft or data leakage is effectively prevented. The user can operate the vehicle anytime and anywhere through the remote control instruction and does not need to go to the location of the vehicle by himself, so that the use convenience is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of automotive safety, and particularly relates to a safety authentication request method and system for remote high-voltage power-on of pure electric vehicles. Background Art

[0002] In recent years, the popularity of electric vehicle networking has been significantly improved. Many electric vehicles have been equipped with in-vehicle Internet devices, which can be connected to an information network platform through wireless communication technology, so as to obtain vehicle dynamic information and provide different functional services for the vehicle. At present, some electric vehicles can already be remotely started through a smart key and mobile phone software, and can also control the vehicle's air conditioner and check the vehicle's condition. In addition, some electric vehicles also have functions such as automatic unlocking, automatic locking, automatic window closing, automatic anti-theft, one-key start, and one-key shutdown. Among them, remotely starting the vehicle is a very comfortable and convenient function, which allows you to heat or cool the interior of the vehicle before starting the vehicle, so as to obtain a more comfortable environment when entering the vehicle. However, the popularity of electric vehicle networking is still restricted to some extent. For example, the anti-theft systems of some electric vehicles may not be perfect and are easily cracked. If communication security cannot be guaranteed, the vehicle is at risk of being stolen.

[0003] In the prior art, the remote control command only encrypts the TSP data channel. After the in-vehicle terminal obtains the command, it does not perform authentication identification and data encryption processing with the vehicle-end ECU, and directly applies to start the vehicle and succeeds. When the control command is cracked, there is a possibility of illegal intrusion of the vehicle, and there is a risk of the vehicle being stolen. For example, Chinese Patent CN202271933U provides a keyless non-contact entry and start system for an automobile, belonging to the technical field of automobiles. It solves the problem that the existing keyless entry system of an automobile cannot automatically judge the owner's intention to enter the vehicle and is not sufficiently user-friendly and intelligent. The keyless non-contact entry and start system of this automobile includes a remote control key and a keyless entry and start controller, and also includes a signal detection module and a CAN bus connected to the keyless entry and start controller, an engine control unit connected to the CAN bus, and a start button connected to the engine control unit. The signal detection module includes an external sensor detection unit for detecting the state of an object outside the vehicle and an internal sensor detection unit for detecting the state of an object inside the vehicle. The keyless non-contact entry and start system of this automobile is beneficial to the lightweight design of the vehicle body, and at the same time has accurate detection, making the automobile more intelligent and user-friendly. Summary of the Invention

[0004] The object of the present invention is to provide a security authentication request method and system for remote high-voltage power-on of pure electric vehicles. By means of in-vehicle Ethernet communication technology, when the vehicle-mounted terminal obtains an application from the cloud APP to start the vehicle, the vehicle-mounted terminal needs to pass an authentication request when applying for high-voltage power-on of the electric vehicle at the vehicle end, avoiding the possibility that other unauthenticated nodes can also successfully request high-voltage power-on, and solving the problem that there is a possibility of illegal intrusion of the vehicle when the control instruction is cracked in the prior art.

[0005] To solve the above technical problems, the present invention is realized through the following technical solutions:

[0006] As a first aspect of the present invention, the present invention is a security authentication request system for remote high-voltage power-on of pure electric vehicles. The system is composed of a cloud server, a vehicle-mounted terminal, an IMMO anti-theft coil, a vehicle control unit, etc., and includes:

[0007] Cloud server: It is used for issuing remote control instructions, and the APP and TSP use HTTPS communication;

[0008] Vehicle-mounted terminal: It is used for issuing and reporting the status of actuators of remote control instructions. When the IMMO initiates a security authentication request, the IMMO cooperates with the vehicle-mounted terminal to complete the security authentication request;

[0009] The vehicle-mounted terminal and the cloud server negotiate a communication key using PKI, and the remote control instruction is encrypted by the communication key and then transmitted;

[0010] CGW: Responsible for forwarding Ethernet messages;

[0011] VCU: Also known as the vehicle control unit, it is used for vehicle power-on and power-off management. When receiving a high-voltage power-on request sent by the vehicle-mounted terminal, it executes the high-voltage power-on logic of the vehicle;

[0012] IMMO: Also known as the anti-theft coil, it is an electronic device used to prevent the vehicle from operating without the correct key (or other verification measures).

[0013] Further, to improve the wake-up success rate, when waking up the vehicle-mounted terminal, the cloud server simultaneously sends a TCP wake-up instruction and a short message for waking up the vehicle-mounted terminal each time; among them, to shorten the user waiting time of the entire vehicle control, the TCP wake-up instruction also carries a remote control instruction.

[0014] Further, after the vehicle shuts down, the vehicle-mounted terminal maintains a long connection heartbeat, and the heartbeat is maintained for 120 s; the TSP directly wakes up the vehicle-mounted terminal through the heartbeat channel, and after waking up, the vehicle-mounted terminal directly obtains and executes the remote control instruction.

[0015] As a second aspect of the present invention, the present invention provides a security authentication request method for remote high-voltage power-on of a pure electric vehicle. The method is implemented based on the system described in the first aspect, and the method includes the following steps:

[0016] Step SS1: The user sends a remote control instruction to the vehicle-mounted terminal through the mobile phone APP;

[0017] Step SS2: After receiving the instruction, the vehicle-mounted terminal starts the security authentication mechanism;

[0018] Step SS3: The security authentication mechanism authenticates and authorizes the user through password authentication;

[0019] Among them, when the vehicle-mounted terminal performs security authentication, the master key is obtained by converting the VIN code through the SHA256 algorithm, and the master key is written into the vehicle-mounted terminal and IMMO through the diagnostic 2E service; the public key is obtained through IMMO learning; when IMMO receives a request for high-voltage power-on, a multi-digit random number is generated; the random number, master key, and constant code combination are encrypted by the public key to generate the corresponding combination code; IMMO calculates the lower 4-byte of the combination code, and sends the combination of the lower 4-byte of the combination code and the random number signal to the vehicle-mounted terminal.

[0020] Further, when the vehicle-mounted terminal parses the signal sent by IMMO, the random number is encrypted synchronously with the security key; the vehicle-mounted terminal uses the public key and the combination code to compare with the parameters sent by IMMO. If they are consistent, the authentication passes.

[0021] Further, the method for writing the master key by the diagnostic 2E service includes the following steps:

[0022] Step S01: The vehicle-mounted terminal processes the request to enter the extended session;

[0023] Step S02: The vehicle-mounted terminal processes the request to unlock level1 of the security access service;

[0024] Step S03: The vehicle-mounted terminal receives the diagnostic request for writing the master key;

[0025] Step S04: The vehicle-mounted terminal stores the master key in the non-volatile memory;

[0026] Step S05: The vehicle-mounted terminal responds to the diagnostic request for writing the master key.

[0027] Furthermore, after the user sends a remote high-voltage power-on request through the APP, the cloud server forwards the high-voltage power-on request instruction to the vehicle terminal after receiving it. If the vehicle terminal is in sleep state, the TCP protocol connection is disconnected, and TSP will send a "UDP data packet" and text message at the same time to wake up the vehicle terminal. After waking up, the vehicle terminal connects to the cloud server and receives remote control instructions.

[0028] Furthermore, after the on-board terminal is awakened, the entire vehicle is awakened through CANFD; when awakened by "UDP data packet" or SMS, the MCU listens to the control instructions sent by NAD, and starts sending network management messages according to the function of the control instructions. If there is no new request within 5 minutes, the management message will be stopped; if a new control instruction is received within 5 minutes, the timer will be reset to 5 minutes.

[0029] Furthermore, the IMMO sends an "identity authentication challenge" message to the vehicle terminal after completing the initialization. If the vehicle terminal does not respond, the IMMO will send the same message every 100ms within xxs. If there is still no response within xxs, the authentication is considered to have failed, and the authorization failure result is returned to the vehicle terminal. At the same time, the vehicle terminal stops the high-voltage power-on request to the vehicle controller; if the authentication is successful, the vehicle terminal notifies the vehicle controller to execute the corresponding high-voltage power-on instruction, the vehicle controller transmits the execution result to the vehicle terminal, and the vehicle terminal uploads the execution result to the TSP. After obtaining the information, the TSP sends it to the mobile phone APP to prompt the user.

[0030] Furthermore, when the security authentication is passed, the vehicle terminal obtains the current vehicle status, defense status, low-voltage battery status, vehicle speed status, gear status, etc. If the vehicle status meets the requirements, the vehicle terminal sends a high-voltage power-on request to the vehicle controller and completes the high-voltage power-on.

[0031] The present invention has the following beneficial effects:

[0032] The present invention uses advanced encryption algorithm technology by using the key written by the vehicle production line through random numbers, security codes, constant codes and other random combinations. When the vehicle terminal receives the remote control command issued by the cloud, the vehicle terminal and IMMO perform a primary security authentication and a secondary security authentication to ensure the security and confidentiality of vehicle communications, effectively preventing the risk of vehicle theft or data leakage. Users can operate the vehicle anytime and anywhere through remote control commands without having to go to the location of the vehicle in person, which greatly improves the convenience of use.

[0033] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0035] Figure 1 It is a structural diagram of the security authentication request system for remote high-voltage power-on of a pure electric vehicle based on the present invention;

[0036] Figure 2 It is a schematic diagram of obtaining the master key from the VIN code through the SHA256 algorithm based on the present invention;

[0037] Figure 3 It is a schematic diagram of the in-vehicle terminal of the present invention comparing the public key and the combined code with the parameters sent by the IMMO;

[0038] Figure 4 It is a schematic diagram of the identity authentication challenge based on the present invention;

[0039] Figure 5 It is a timing diagram of PIN writing based on the present invention;

[0040] Figure 6 It is a timing diagram of security key writing based on the present invention;

[0041] Figure 7 It is a schematic diagram of security authentication based on the present invention. Detailed implementation manners

[0042] In the following description, for the purpose of illustration rather than limitation, specific details such as specific system architectures and technologies are presented to thoroughly understand the embodiments of the present application. However, those skilled in the art should clearly understand that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present application.

[0043] It should be understood that when used in the specification and claims of the present application, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0044] It should also be understood that the term "and / or" used in the specification and claims of the present application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0045] As used in the specification of this application and the appended claims, the term "if" may be construed, depending on the context, as "when", "once", "in response to determining", or "in response to detecting". Similarly, the phrases "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, to mean "once determined", "in response to determining", "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".

[0046] In addition, in the description of the specification of this application and the appended claims, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0047] Reference to "one embodiment" or "some embodiments" or the like described in the specification of this application means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of this application. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0048] Embodiment 1:

[0049] As Figure 1 shown, as the first embodiment of the present invention, the present invention is a security authentication request system for remote high-voltage power-on of a pure electric vehicle. The system consists of a cloud server, an in-vehicle terminal, an IMMO anti-theft coil, a vehicle controller, etc., and includes:

[0050] Cloud server: It is used for issuing remote control instructions, and the APP and TSP communicate using HTTPS;

[0051] TBOX: Also known as the in-vehicle terminal: It is used for issuing remote control instructions and reporting the status of the actuator. When the IMMO initiates a security authentication request, the IMMO cooperates with the in-vehicle terminal to complete the security authentication request; the in-vehicle terminal and the cloud server negotiate a communication key using PKI, and relevant vehicle control instructions are encrypted and transmitted through the communication key; to improve the wake-up success rate, the background sends both TCP and SMS to wake up the in-vehicle terminal each time; to shorten the user waiting time for the entire vehicle control, the TCP wake-up instruction carries the vehicle control instruction at the same time; after the vehicle shuts off, the in-vehicle terminal module will maintain a long connection heartbeat, and the heartbeat is maintained every 120s; the TSP directly wakes up the in-vehicle terminal through this channel, and after waking up, the in-vehicle terminal directly obtains and executes the instruction;

[0052] The vehicle-mounted terminal and the cloud server negotiate a communication key using PKI, and the remote control instruction is encrypted with the communication key before transmission.

[0053] CGW: Responsible for forwarding Ethernet packets.

[0054] VCU: Also known as the vehicle controller, it is used for vehicle power-on and power-off management. When receiving a high-voltage power-on request sent by the vehicle-mounted terminal, it executes the vehicle high-voltage power-on logic.

[0055] IMMO: Also known as the anti-theft coil, it is an electronic device used to prevent the vehicle from operating without the correct key (or other verification measures).

[0056] As an embodiment provided by the present invention, preferably, to improve the wake-up success rate, when waking up the vehicle-mounted terminal, the cloud server simultaneously sends a TCP wake-up instruction and a short message each time to wake up the vehicle-mounted terminal; wherein, to shorten the user waiting time for the entire vehicle control, the TCP wake-up instruction carries the remote control instruction at the same time.

[0057] As an embodiment provided by the present invention, preferably, after the vehicle shuts off, the vehicle-mounted terminal maintains a long connection heartbeat for 120s; the TSP directly wakes up the vehicle-mounted terminal through the heartbeat channel, and after waking up, the vehicle-mounted terminal directly obtains the remote control instruction and executes it.

[0058] Embodiment 2:

[0059] As the second embodiment of the present invention, the present invention is a security authentication request method for remote high-voltage power-on of a pure electric vehicle. The method is implemented based on the system described in the first embodiment. The purpose of this embodiment is to establish a full-link communication anti-theft authentication mechanism based on remote control instructions, which can greatly improve the security of the vehicle and prevent the vehicle from being stolen or illegally invaded.

[0060] The implementation method of this anti-theft authentication mechanism may include the following steps:

[0061] 1) The user sends a remote control instruction to the vehicle through the mobile phone software.

[0062] 2) After the vehicle receives the instruction, it starts the security authentication mechanism.

[0063] 3) The security authentication mechanism authenticates and authorizes the user through a password authentication method (primary authentication, secondary authentication).

[0064] If the user passes the identity authentication and authorization, the vehicle starts and executes the corresponding remote control instruction. If the user fails to pass the identity authentication and authorization, the security authentication mechanism refuses to execute the instruction and issues an alarm or takes other security measures.

[0065] This full-link communication security authentication mechanism based on remote control instructions can not only prevent vehicle theft, but also improve the safety and reliability of the vehicle. At the same time, this mechanism can also realize the remote control and management of the vehicle, improving the user experience and convenience.

[0066] As an embodiment provided by the present invention, preferably, the method includes the following steps:

[0067] Step SS1: The user sends a remote control instruction to the in-vehicle terminal through the mobile phone APP;

[0068] Step SS2: After receiving the instruction, the in-vehicle terminal activates the security authentication mechanism;

[0069] Step SS3: The security authentication mechanism authenticates and authorizes the user through the password authentication method;

[0070] When the in-vehicle terminal applies for high-voltage power-on, it needs to pass an authentication request to prevent other unauthenticated nodes from successfully requesting high-voltage power-on; among them, when the in-vehicle terminal performs security authentication, the master key is obtained by converting the VIN code through the SHA256 algorithm, and the master key is written into the in-vehicle terminal and IMMO through the diagnostic 2E service; the public key is obtained through IMMO learning; when IMMO receives a high-voltage power-on request, a multi-digit random number is generated; the random number, master key, and constant code combination are encrypted by the public key to generate a corresponding combination code; IMMO calculates the lower 4-byte of the combination code, and sends the lower 4-byte of the combination code and the random number combination signal to the in-vehicle terminal.

[0071] As an embodiment provided by the present invention, preferably, the master key is converted from the VIN code through the SHA256 algorithm and written by the diagnostic 2E service. The tester writes the security code into the in-vehicle terminal through the diagnostic service. Considering that the master key must be secure, the diagnostic instrument writing needs to pass a secure access.

[0072] The method for writing the master key by the diagnostic 2E service is as follows:

[0073] 1) Enter the extended session 10 03;

[0074] 2) The diagnostic instrument requests through the 27 01 service, and the controller completes the positive response;

[0075] 3) Define the master key DID: 0x00, 0x02;

[0076] 4) The in-vehicle terminal receives the diagnostic request for writing the master key (0x2E, 0x00, 0x02, 0xXX…), and the controller completes the positive response and the writing is successful.

[0077] As an embodiment provided by the present invention, preferably, the public key is learned from the IMMO. The tester sends a routine control request message to the vehicle-mounted terminal. After receiving the routine control request message, the vehicle-mounted terminal prepares to learn from the IMMO and will open a timing window of xxs to receive the message with the key from the IMMO, and then send a positive response to the tester. Otherwise, the vehicle-mounted terminal should resume normal operation and send a negative response to the tester.

[0078] When the IMMO receives a request for high-voltage power-on, it generates a multi-digit random number. The combination of the random number, the master key, and the constant code is encrypted by the public key to generate the corresponding encrypted result. The IMMO sends the combination signal of the low 4 bytes derived from the low bits of the calculated encrypted result and the random number to the TBOX, specifically as Figure 2 shown.

[0079] As an embodiment provided by the present invention, preferably, when the vehicle-mounted terminal analyzes the signal sent by the IMMO, it synchronously encrypts the random number with the security key; the vehicle-mounted terminal uses the public key and the combination code to compare with the parameters sent by the IMMO. If they are consistent, the authentication passes.

[0080] As Figure 3 shown, as an embodiment provided by the present invention, more preferably, the vehicle-mounted terminal analyzes the signal sent by the IMMO (where the high four bits are the random number generated by the IMMO and the low four bits are the authentication code), and synchronously encrypts this number with its own key. The vehicle-mounted terminal will use the public key and the combination code (the encrypted result calculated by the encryption algorithm of the random number, the security code, and the constant code) to compare with the parameters sent by the IMMO to check if they are consistent. If they are consistent, the authentication passes once and enters the next process.

[0081] As an embodiment provided by the present invention, preferably, the method for writing the master key in the diagnostic 2E service includes the following steps:

[0082] Step S01: The vehicle-mounted terminal processes the request to enter the extended session;

[0083] Step S02: The vehicle-mounted terminal processes the request to unlock level 1 of the security access service;

[0084] Step S03: The vehicle-mounted terminal receives the diagnostic request for writing the master key (0x2E, 0x00, 0x02, 0xXX…);

[0085] Step S04: The vehicle-mounted terminal stores the master key in the non-volatile memory;

[0086] Step S05: The vehicle-mounted terminal responds to the diagnostic request for writing the master key (0x6E, 0x00, 0x02);

[0087] Timing diagram Figure 5 shown.

[0088] As an embodiment provided by the present invention, preferably, after the user sends a remote high-voltage power-on request through the APP, the cloud server forwards the high-voltage power-on request instruction to the vehicle terminal after receiving it. If the vehicle terminal is in a sleep state, the TCP protocol connection is disconnected, and the TSP will simultaneously send a "UDP data packet" and a text message to wake up the vehicle terminal. After waking up, the vehicle terminal connects to the cloud server and receives remote control instructions.

[0089] As an embodiment provided by the present invention, preferably, after the on-board terminal is awakened, the entire vehicle is awakened through CANFD; when awakened through "UDP data packet" or text message, the MCU monitors the control instructions sent by NAD, and starts sending network management messages according to the function of the control instructions. If there is no new request for 5 minutes, the management message is stopped; if a new control instruction is received within 5 minutes, the time is reset to 5 minutes.

[0090] As an embodiment provided by the present invention, preferably, the IMMO sends an "identity authentication challenge" message to the vehicle terminal after completing the initialization. If the vehicle terminal does not respond, the IMMO will send the same message every 100ms within xxs. If there is still no response within xxs, it is considered that the authentication has failed, and the authorization failure result is returned to the vehicle terminal. At the same time, the vehicle terminal stops the high-voltage power-on request to the vehicle controller; if the authentication is successful, the vehicle terminal notifies the vehicle controller to execute the corresponding high-voltage power-on instruction, the vehicle controller transmits the execution result to the vehicle terminal, and the vehicle terminal uploads the execution result to the TSP. After obtaining the information, the TSP sends it to the mobile phone APP to prompt the user.

[0091] like Figure 4 As shown in FIG. 1 , as an embodiment of the present invention, more preferably, IMMO sends an "authentication challenge" message to the vehicle terminal after completing its own initialization. If the vehicle terminal does not respond, IMMO will send the same message every 100ms within xxs. If there is no response within 2s, it is considered that the authentication has failed. At the same time, IMMO stops the high-voltage power-on request to VCU. See Figure 4 .

[0092] As an embodiment provided by the present invention, preferably, after the security authentication is passed, the vehicle-mounted terminal obtains the current vehicle status, defense status, low-voltage battery status, vehicle speed status, gear status, etc. If the vehicle status meets the requirements, the vehicle-mounted terminal sends a high-voltage power-on request to the vehicle controller and completes the high-voltage power-on.

[0093] Embodiment three:

[0094] As the third embodiment of the present invention, the present invention is a security authentication request method based on remote high-voltage power-on of a pure electric vehicle. The method for learning the security key includes the following steps:

[0095] The tester sends a routine request message to the vehicle-mounted terminal. After receiving the routine request message, the vehicle-mounted terminal prepares to learn from the IMMO and will open a timing window of xxs to receive the message with the key from the IMMO, and then send a positive response to the tester. Otherwise, the vehicle-mounted terminal shall resume normal operation and send a negative response to the tester.

[0096] On the other hand, if the tester receives a positive response from the vehicle-mounted terminal, it will also send a routine request to the IMMO, asking the IMMO to transfer the key to the vehicle-mounted terminal. After the vehicle-mounted terminal receives the message containing the key, the vehicle-mounted terminal shall store the key in its EEROM.

[0097] Basic event flow:

[0098] The vehicle-mounted terminal processes the request to enter the extended session;

[0099] The vehicle-mounted terminal processes the request to unlock level 2 of the security access service;

[0100] The vehicle-mounted terminal receives the diagnostic request (0x31, 0x01, 0x00, 0x01) for learning the key SK;

[0101] The vehicle-mounted terminal responds to the diagnostic request (0x71, 0x01, 0x00, 0x01) for learning the key SK;

[0102] The vehicle-mounted terminal sets up a timer of xxs seconds and waits for the IMMO to send an event message to notify the vehicle-mounted terminal;

[0103] (0x71, 0x02, 0x00, 0x01, 0x04);

[0104] The timing diagram is as Figure 6 shown.

[0105] Embodiment Four:

[0106] As the fourth embodiment of the present invention, the present invention is a security authentication request method based on remote high-voltage power-on of a pure electric vehicle. The method for remotely controlling the application for high-voltage power-on includes the following steps:

[0107] 1) Remote wake-up

[0108] The user sends a remote high-voltage power-on command through the mobile phone APP. After receiving the opening instruction, the cloud server forwards it to the vehicle terminal. If the vehicle terminal is in the sleep state, the TCP protocol connection is disconnected, and TSP will wake up the vehicle terminal by sending both "UDP data packets" and "text messages" simultaneously. After waking up, the vehicle terminal connects to the platform and receives remote control instructions.

[0109] After the vehicle terminal is woken up, it wakes up the entire vehicle through CANFD. After being woken up by remote text message or UDP, the MCU listens for control instructions sent by NAD and starts sending network management messages according to specific functions. If there are no new requests within 5 minutes, it stops sending management messages. If new control instructions are received within 5 minutes, it restarts the 5-minute timer until 5 minutes after there are no request instructions and then stops sending management messages.

[0110] 2) Security authentication

[0111] After receiving the remote control instruction, the vehicle terminal completes signature verification and gives a general response to the server to confirm that the instruction has been received. The vehicle terminal synchronously sends a security authentication request to IMMO.

[0112] When IMMO receives the authentication request sent by the vehicle terminal, it generates a 32-bit random number. The combination of the 32-bit random number, 32-bit master key, and 64-bit constant code is encrypted by a 56-bit public key to generate a 128-bit encrypted result.

[0113] The vehicle terminal will encrypt this number with its own secret key. The vehicle terminal will use the 32-bit public key and the 128-bit combination code (the encryption result is calculated by the encryption algorithm of the 32-bit random number, 32-bit security code, and 64-bit constant code; the encrypted number of the "IMMO authentication challenge" is derived from the encrypted result calculated by the vehicle terminal).

[0114] After IMMO completes its initialization, it sends an "authentication challenge" message to the vehicle terminal. If the vehicle terminal does not respond, IMMO will send the same message every 100 ms within 2 s. If there is no response within this 2-s period, it is considered that the authentication fails and an authorization failure result is returned to the vehicle terminal. At the same time, the vehicle terminal stops the high-voltage power-on request to the VCU. If the authentication is successful, the vehicle terminal notifies the VCU to execute the corresponding high-voltage power-on instruction, transmits the execution result to the vehicle terminal, and the vehicle terminal uploads the result to TSP. After TSP obtains the information, it sends it to the mobile phone APP to prompt the user.

[0115] The schematic diagram of security authentication is as Figure 7 shown;

[0116] 3) Remote high-voltage power-on request

[0117] After the security authentication is passed, the in-vehicle terminal obtains the current vehicle anti-theft state, low-voltage battery state, vehicle speed state, gear state, etc. If the conditions are met, the in-vehicle terminal sends a high-voltage power-on request to the VCU and the high-voltage power-on is completed. The specific execution of the high-voltage power-on request instruction is as follows:

[0118] Basic_strt_OnOffReq = 0x1:HVON

[0119] Basic_enum_SourceID = 0xE:SourceID_Remote

[0120] When the status feedback of successful high-voltage power-on is not received for the command sent to someip within the specified time, it is judged as a timeout. The general timeout time is 2s. When the timeout policy is triggered, the in-vehicle terminal calls the get method to actively obtain the current execution status of the controller. If it still cannot be obtained, the value reported by the last frame cached by the in-vehicle terminal, TSP, is reported.

[0121] a) Timing setting

[0122] The user is supported to set the high-voltage on duration through the APP, and the duration is Amin / Bmin / Cmin.

[0123] b) Timing control

[0124] After the high-voltage power-on is successful, the in-vehicle terminal starts timing for Amin / Bmin / Cmin according to the user setting. (Support independent setting on the user APP side); when the set timing time arrives, a remote low-voltage request Basic_strt_OnOffReq = 0x0:HVOFF is sent to the VCU. After the VCU powers off successfully, the network management message is stopped being sent synchronously until the whole vehicle goes to sleep.

[0125] The associated communication signals are shown in the following table:

[0126]

[0127] 4) The cloud server returns the remote control execution result to the mobile phone and updates the status synchronously.

[0128] In the present invention, by means of the key written by the vehicle production line, through random numbers, security codes, constant codes and other random combination methods, an advanced encryption algorithm technology is adopted. When the in-vehicle terminal receives the remote control instruction sent by the cloud, through the first and second security authentications between the in-vehicle terminal and the IMMO, the security and confidentiality of vehicle communication are ensured, and the risk of vehicle theft or data leakage is effectively prevented. The user can operate the vehicle at any time and place through the remote control instruction without having to go to the vehicle location in person, which greatly improves the use convenience.

[0129] In the description of this specification, the descriptions referring to terms such as "one embodiment", "example", "specific example", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.

[0130] The preferred embodiments of the present invention disclosed above are only used to help explain the present invention. The preferred embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described. Obviously, many modifications and variations can be made according to the content of this specification. These embodiments are selected and specifically described in this specification in order to better explain the principles and practical applications of the present invention, so that those skilled in the art can well understand and utilize the present invention. The present invention is only limited by the claims and their full scope and equivalents.

Claims

1. A security authentication request system for remote high-voltage power-on of pure electric vehicles, characterized in that, it includes: Cloud server: It is used for issuing remote control instructions, and the APP communicates with the cloud server using HTTPS; In-vehicle terminal: It is used for issuing remote control instructions and reporting the status of actuators. When the IMMO initiates a security authentication request, the IMMO cooperates with the in-vehicle terminal to complete the security authentication request; The in-vehicle terminal and the cloud server negotiate a communication key using PKI, and the remote control instruction is encrypted with the communication key before transmission; Vehicle controller, which is used for vehicle power-on and power-off management. When receiving a high-voltage power-on request sent by the in-vehicle terminal, it executes the vehicle high-voltage power-on logic.

2. The security authentication request system for remote high-voltage power-on of pure electric vehicles according to claim 1, characterized in that, When waking up the in-vehicle terminal, the cloud server simultaneously sends a TCP wake-up instruction and a short message to wake up the in-vehicle terminal each time; among them, the TCP wake-up instruction carries the remote control instruction at the same time.

3. The security authentication request system for remote high-voltage power-on of pure electric vehicles according to claim 2, characterized in that, After the vehicle shuts down, the in-vehicle terminal maintains a long connection heartbeat, and the heartbeat lasts for 120s; the TSP directly wakes up the in-vehicle terminal through the heartbeat channel, and after waking up, the in-vehicle terminal directly obtains the remote control instruction and executes it.

4. A security authentication request method for remote high-voltage power-on of pure electric vehicles, characterized in that, The method is implemented based on the system described in any one of claims 1-3, and the method includes the following steps: Step SS1: The user sends a remote control instruction to the in-vehicle terminal through the APP; Step SS2: After receiving the remote control instruction, the in-vehicle terminal starts the security authentication mechanism; Step SS3: The security authentication mechanism authenticates and authorizes the user through password authentication; Among them, when the in-vehicle terminal performs security authentication, the master key is obtained by converting from the VIN code through the SHA256 algorithm, and the master key is written into the in-vehicle terminal and the IMMO through the diagnostic 2E service; the public key is obtained through IMMO learning; when the IMMO receives a high-voltage power-on request, a multi-digit random number is generated; the random number, the master key and the constant code combination are encrypted by the public key to generate the corresponding combination code; the IMMO calculates the lower 4-byte of the combination code, and sends the lower 4-byte of the combination code and the random number combination signal to the in-vehicle terminal.

5. The security authentication request method for remote high-voltage power-on of pure electric vehicles according to claim 4, characterized in that, When the in-vehicle terminal parses the signal sent by the IMMO, it synchronously encrypts the random number with the security key; the in-vehicle terminal compares the public key and the combination code with the parameters sent by the IMMO, and if they are consistent, the authentication passes.

6. The security authentication request method for remote high-voltage power-on of pure electric vehicles according to claim 4, characterized in that, The method for writing the master key by the diagnostic 2E service includes the following steps: Step S01: The in-vehicle terminal processes the request to enter the extended session; Step S02: The in-vehicle terminal processes the request to unlock the security access service at level 1; Step S03: The in-vehicle terminal receives the diagnostic request to write the master key; Step S04: The in-vehicle terminal stores the master key in the non-volatile memory; Step S05: The in-vehicle terminal responds to the diagnostic request to write the master key.

7. The method for a security authentication request based on remote high-voltage power-on of a pure electric vehicle according to claim 4, wherein, The user sends a remote high-voltage power-on request through the APP. After receiving the high-voltage power-on request instruction, the cloud server forwards it to the in-vehicle terminal. If the in-vehicle terminal is in the sleep state, the TCP protocol connection is disconnected. TSP will simultaneously send a "UDP data packet" and a short message to wake up the in-vehicle terminal. After waking up, the in-vehicle terminal connects to the cloud server and receives the remote control instruction.

8. The method for a security authentication request based on remote high-voltage power-on of a pure electric vehicle according to claim 7, wherein, After the in-vehicle terminal is woken up, it wakes up the entire vehicle through CANFD; when the in-vehicle terminal is woken up by a "UDP data packet" or a short message, the MCU listens for the control instruction sent by NAD, and starts sending network management messages according to the function of the control instruction. If there is no new request within 5 minutes, the management message sending stops; if a new control instruction is received within 5 minutes, the 5-minute timer restarts.

9. The method for a security authentication request based on remote high-voltage power-on of a pure electric vehicle according to claim 4, wherein, After the IMMO completes initialization, it sends an "authentication challenge" message to the in-vehicle terminal. If the in-vehicle terminal does not respond, the IMMO will send the same message every 100 ms within xxs. If there is still no response within the xxs time, it is considered that the authentication fails, and an authorization failure result is returned to the in-vehicle terminal, and at the same time, the in-vehicle terminal is stopped from sending a high-voltage power-on request to the vehicle controller; If the authentication is successful, the in-vehicle terminal notifies the vehicle controller to execute the high-voltage power-on instruction. The vehicle controller transmits the execution result to the in-vehicle terminal, and the in-vehicle terminal uploads the execution result to the TSP. After the TSP obtains the information, it sends it to the mobile APP to prompt the user.

10. The method for a security authentication request based on remote high-voltage power-on of a pure electric vehicle according to claim 9, wherein, After the security authentication is successful, the in-vehicle terminal obtains the current vehicle state. If the vehicle state is satisfied, the in-vehicle terminal sends a high-voltage power-on request to the vehicle controller and completes the high-voltage power-on.

Citation Information

Patent Citations

  • Key-free non-contact type access start-up system of automobile

    CN202271933U

Cited By

  • Digital key fusion positioning system and method

    CN121486789A