Security authentication method and device, vehicle, equipment and storage medium
By limiting the access of the unverified debug terminal at the IO configuration information level and verifying based on the first identification information of the debug terminal, the data leakage problem caused by the disclosure of the debug port lock integrated circuit unlocking algorithm in the prior art is solved, and high data security and traceability are achieved.
Patent Information
- Application Number
- CN202510487442.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-06-13
AI Technical Summary
In the prior art, the debugging port lock integrated circuit unlocking algorithm and verification process of vehicle chips are disclosed, resulting in malicious users obtaining access rights through simple password matching or brute force cracking, resulting in data leakage and insufficient protection of intellectual property rights.
At the IO configuration information level, the unverified debug terminal access controller data is restricted, and the first identification information of the debug terminal is obtained for verification and positioning, thereby improving the security and traceability of the data.
Ensure that only the credited debugging terminal can interact with the controller through the security authentication module, prevent uncredited data access, and improve data security and traceability.
Smart Images

Figure CN120151097A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of security authentication, including but not limited to a security authentication method and device, a vehicle, a device, and a storage medium. Background Art
[0002] With the rapid development of the Internet of Vehicles, in order to better serve users and provide a high-quality driving experience, the vehicle terminal needs to continuously upgrade in terms of systems and performance. During this process, data security and intellectual property protection at the vehicle terminal become particularly important.
[0003] In related technologies, out of considerations for data security and intellectual property protection, manufacturers have embedded a debug port lock integrated circuit corresponding to the debug port circuit in the chip to achieve hardware encryption. However, the information of the hardware circuit is often publicly available to the outside world, and the unlocking method is relatively conventional and public. This results in a weak protection for information security and intellectual property. Some malicious users can break through the debug port lock integrated circuit of many controller chips through simple brute-force password matching, and then obtain the binary code inside the chip, causing data leakage through decompilation means, affecting data security. Summary of the Invention
[0004] In view of this, the security authentication method, device, vehicle, device, and storage medium provided by the embodiments of the present application can restrict unauthenticated debug terminals from accessing controller data at the IO configuration information level, and perform verification and positioning based on the first identification information of the debug terminal, improving data security and traceability. The security authentication method, device, vehicle, device, and storage medium provided by the embodiments of the present application are implemented as follows:
[0005] The first aspect of the present application provides a security authentication method, which is applied to a security authentication module of a vehicle. The vehicle further includes a controller and a debug port circuit. The method includes:
[0006] Obtain authentication data sent by a debug terminal, where the authentication data includes the first identification information of the debug terminal;
[0007] Perform verification processing on the authentication data, where the verification processing includes comparing the first identification information with pre-stored trusted data to determine whether the authentication data is successfully verified. The trusted data includes multiple trusted identification information;
[0008] When the authentication data is successfully verified, send verification data to the controller so that the controller configures the IO configuration information of the debug port circuit as target IO configuration information. The debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
[0009] As an alternative implementation, in the first aspect of the embodiments of the present application, the verification process for the authentication data includes:
[0010] Sending the authentication data to a security authentication server;
[0011] Obtaining authentication feedback data sent by the security authentication server, where the authentication feedback data includes the verification result of the security authentication server for the first identification information, and the verification result is used to indicate that the security authentication server verifies the first identification information successfully or fails;
[0012] Judging whether the authentication data is verified successfully according to the authentication feedback data.
[0013] As an alternative implementation, in the first aspect of the embodiments of the present application, the first identification information includes the software identification information of the host computer application deployed by the debugging terminal and the hardware identification information of the debugging terminal. When the security authentication server judges that the software identification information and the hardware identification information match according to a preset matching relationship table, a verification result indicating that the security authentication server verifies the first identification information successfully is generated, and the preset matching relationship table includes the matching relationship between the preset software identification information and the preset hardware identification information.
[0014] As an alternative implementation, in the first aspect of the embodiments of the present application, the authentication data further includes the second identification information of the vehicle, and the verification process for the authentication data includes:
[0015] Sending the authentication data to a security authentication server;
[0016] Obtaining a first key sent by the security authentication server, where the first key is generated by the security authentication server according to the second identification information when the security authentication server verifies the first identification information successfully;
[0017] Comparing the first key with a second key to judge whether the authentication data is verified successfully, where the second key includes a preset key or a key generated by the security authentication module according to a preset rule.
[0018] As an alternative implementation, in the first aspect of the embodiments of the present application, the authentication data further includes a target permission, and the target permission includes a read permission and / or a write permission requested by the debugging terminal. Sending the verification data to the controller includes:
[0019] Generating the verification data according to the target permission;
[0020] Send the verification data to the controller, so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information corresponding to the target permission.
[0021] A second aspect of the present application provides a security authentication method, which is applied to a controller of a vehicle. The vehicle further includes a security authentication module and a debug port circuit. The method includes:
[0022] When obtaining the verification data sent by the security authentication module, configure the IO configuration information of the debug port circuit as the target IO configuration information, where the verification data is sent by the security authentication module when the authentication data sent by the debug terminal is verified successfully. The authentication data includes the first identification information of the debug terminal, and the debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
[0023] As an optional implementation manner, in the second aspect of the embodiments of the present application, the authentication data further includes a target permission, and the target permission includes a read permission and / or a write permission requested by the debug terminal. The verification data is generated according to the target permission. Configuring the IO configuration information of the debug port circuit as the target IO configuration information includes:
[0024] Determine the target IO configuration information according to the verification data;
[0025] Configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0026] As an optional implementation manner, in the second aspect of the embodiments of the present application, the vehicle further includes a debug port lock integrated circuit, and the debug port lock integrated circuit is used to control the working state of the debug port circuit. The working state includes a locked state or an unlocked state. The debug port lock integrated circuit controls the debug port circuit to be in the unlocked state when the key sent by the debug terminal matches the preset unlocking key. The method further includes:
[0027] Obtain the target number of times the debug terminal sends the key within a preset time period;
[0028] When the target number of times is greater than a preset threshold and all the keys sent by the debug terminal do not match the preset unlocking key, perform a security processing operation, where the security processing includes configuring the IO configuration information of the debug port circuit as the preset IO configuration information. When the IO configuration information of the debug port circuit is the preset IO configuration information, the debug terminal is prohibited from communicating with the controller through the debug port circuit.
[0029] As an alternative implementation, in the second aspect of the embodiments of the present application, the security processing operation further includes, when obtaining a read instruction for the debugging terminal to read the original data of the controller, sending data modified based on the original data to the debugging terminal, so that the data read by the debugging terminal through the debugging port circuit is different from the original data of the controller; or,
[0030] The security processing operation further includes sending a security alarm message to a security authentication server, where the security alarm message includes the first identification information.
[0031] As an alternative implementation, in the second aspect of the embodiments of the present application, the vehicle further includes a debugging port lock integrated circuit, which is used to control the working state of the debugging port circuit, and the working state includes a locked state or an unlocked state. The method further includes:
[0032] When obtaining the verification data sent by the security authentication module, sending an unlock instruction to the debugging port lock integrated circuit, so that the debugging port circuit is in the unlocked state.
[0033] The third aspect of the present application provides a security authentication device, which is applied to the security authentication module of a vehicle. The vehicle further includes a controller and a debugging port circuit. The device includes:
[0034] An obtaining unit, configured to obtain authentication data sent by a debugging terminal, where the authentication data includes the first identification information of the debugging terminal;
[0035] A verification unit, configured to perform verification processing on the authentication data, where the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes multiple credit identification information;
[0036] A sending unit, configured to, when the authentication data is successfully verified, send verification data to the controller, so that the controller configures the IO configuration information of the debugging port circuit as target IO configuration information, and the debugging terminal can communicate with the controller through the debugging port circuit when the IO configuration information of the debugging port circuit is configured as the target IO configuration information.
[0037] The fourth aspect of the present application provides a security authentication device, which is applied to the controller of a vehicle. The vehicle further includes a security authentication module and a debugging port circuit. The device includes:
[0038] A configuration unit is used to configure the IO configuration information of the debug port circuit as target IO configuration information when obtaining verification data sent by the security authentication module. The verification data is sent by the security authentication module when the authentication data sent by the debug terminal is successfully verified. The authentication data includes the first identification information of the debug terminal. The debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
[0039] A vehicle is provided in the fifth aspect of the present application. The vehicle includes a security authentication module, a controller, and a debug port circuit, where:
[0040] The security authentication module is used to obtain authentication data sent by a debug terminal, where the authentication data includes the first identification information of the debug terminal; perform verification processing on the authentication data, where the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes multiple credit identification information; when the authentication data is successfully verified, send verification data to the controller so that the controller configures the IO configuration information of the debug port circuit as target IO configuration information, and the debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information;
[0041] The controller is used to configure the IO configuration information of the debug port circuit as the target IO configuration information when obtaining the verification data sent by the security authentication module.
[0042] A computer device is provided in the sixth aspect of the present application, including a memory and a processor. The memory stores a computer program that can run on the processor, and the processor implements the method described in the first aspect or the second aspect of the embodiments of the present application when executing the program.
[0043] A computer-readable storage medium is provided in the seventh aspect of the present application, on which a computer program is stored. When the computer program is executed by a processor, it implements the method provided in the first aspect or the second aspect of the embodiments of the present application.
[0044] Compared with the related art, the embodiments of the present application have the following beneficial effects:
[0045] The security authentication method provided by this application, when applied to the security authentication module of a vehicle, first obtains the authentication data sent by the debugging terminal. The authentication data includes the first identification information of the debugging terminal, which enables different debugging terminals to be distinguished and identified, providing support for subsequent verification processing and traceability. Then, the authentication data is subjected to verification processing, which includes comparing the first identification information with the pre-stored trusted data to determine whether the authentication data is successfully verified. The trusted data includes multiple trusted identification information. In this way, it can be ensured that only the trusted debugging terminals can pass the verification, enhancing the system's control ability over the debugging terminals and improving the security of the data. Finally, when the security authentication module successfully verifies the authentication data, it sends the verification data to the controller so that the controller configures the IO configuration information of the debugging port circuit as the target IO configuration information, enabling the debugging terminal to communicate with the controller through the debugging port circuit when the IO configuration information of the debugging port circuit is configured as the target IO configuration information.
[0046] In this way, it is ensured that the trusted debugging terminal can smoothly communicate with the controller, ensuring that the normal debugging work can be carried out. At the IO configuration information level, un-verified debugging terminals are restricted from accessing the controller data, and verification can be performed based on the first identification information of the debugging terminal, further improving the security and traceability of the data. Description of the Drawings
[0047] The drawings here are incorporated into the specification and form a part of this specification. These drawings show embodiments consistent with this application and are used together with the specification to illustrate the technical solutions of this application.
[0048] Figure 1A It is a schematic diagram of an application scenario of the security authentication method provided by an embodiment of this application;
[0049] Figure 1B It is another schematic diagram of an application scenario of the security authentication method provided by an embodiment of this application;
[0050] Figure 2A It is a schematic diagram of a framework of a vehicle provided by an embodiment of this application;
[0051] Figure 2B It is another schematic diagram of a framework of a vehicle provided by an embodiment of this application;
[0052] Figure 2C It is yet another schematic diagram of a framework of a vehicle provided by an embodiment of this application;
[0053] Figure 3 It is a schematic flowchart of the security authentication method provided by an embodiment of this application when applied to the security authentication module of a vehicle;
[0054] Figure 4 A schematic flow chart of the security authentication method provided by the embodiments of the present application applied to the controller of a vehicle;
[0055] Figure 5 A schematic flow chart of the security authentication method provided by the embodiments of the present application;
[0056] Figure 6 Another schematic flow chart of the security authentication method provided by the embodiments of the present application applied to the security authentication module of a vehicle;
[0057] Figure 7 Another schematic flow chart of the security authentication method provided by the embodiments of the present application applied to the security authentication module of a vehicle;
[0058] Figure 8 Another schematic flow chart of the security authentication method provided by the embodiments of the present application applied to the controller of a vehicle;
[0059] Figure 9 Another schematic flow chart of the security authentication method provided by the embodiments of the present application;
[0060] Figure 10 A schematic structural diagram of the security authentication device provided by the embodiments of the present application applied to the security authentication module of a vehicle;
[0061] Figure 11 A schematic structural diagram of the security authentication device provided by the embodiments of the present application applied to the controller of a vehicle;
[0062] Figure 12 A schematic structural diagram of the computer device provided in the embodiments of the present application. Detailed implementation manners
[0063] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will further describe the specific technical solutions of the present application in detail with reference to the accompanying drawings in the embodiments of the present application. The following embodiments are used to illustrate the present application but are not intended to limit the scope of the present application.
[0064] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0065] In the following descriptions, reference is made to "some embodiments", which describe a subset of all possible embodiments. However, it can be understood that "some embodiments" can be the same subset or different subsets of all possible embodiments and can be combined with each other without conflict.
[0066] It should be noted that the terms "first / second / third" involved in the embodiments of the present application are used to distinguish similar or different objects, and do not represent a specific order for the objects. Understandably, "first / second / third" can be interchanged with a specific order or sequence under allowable circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein.
[0067] In the electronic system of an automobile, the debug port circuit, as an important interface for development and maintenance, its security is directly related to the overall security of the vehicle and the intellectual property protection of the manufacturer. Traditional debug port circuit protection measures mainly rely on the encryption of hardware circuits. However, this hardware encryption method appears to be relatively weak in terms of protection ability in the face of increasingly complex attack means and may not be able to provide sufficient security guarantees.
[0068] Exemplarily, the unlocking algorithms and verification processes of the debug port lock integrated circuits of many controller chips are public, which enables attackers to obtain access rights through simple password guessing or brute force cracking. Once the debug port lock integrated circuit is cracked, the attacker can read the sensitive data inside the chip through the debug port circuit, including but not limited to firmware code, configuration parameters, and user information, etc. The leakage of these data may not only damage the intellectual property rights of the manufacturer but also cause other security risks, such as the vehicle being remotely controlled and user privacy being violated.
[0069] In addition, the existing debug port security mechanism lacks the ability to identify and verify the access source. After the attacker cracks the hardware debug port lock and obtains the internal data of the chip, it is difficult for the manufacturer to trace back to the infringer based on the cracking behavior, which brings obstacles to subsequent incident investigation and rights protection.
[0070] In view of this, the embodiments of the present application provide a security authentication method, device, vehicle, equipment, and storage medium. This method can restrict unauthenticated debug terminals from accessing controller data at the IO configuration information level and perform verification and positioning based on the first identification information of the debug terminal, improving the security and traceability of the data.
[0071] Next, the actual scenario to which the security authentication method provided in the embodiments of the present application is applied will be introduced.
[0072] Please refer to Figure 1A , Figure 1A which is a schematic diagram of an application scenario of the security authentication method provided in the embodiments of the present application. As Figure 1A shown, the application scenario schematic diagram includes a vehicle 10 and a debug terminal 20.
[0073] The vehicle 10 in the embodiments of the present application may include a security authentication module, a controller, and a debug port circuit.
[0074] The security authentication module is used to verify the debugging terminal 20 and determine whether it is trusted. When the debugging terminal 20 sends authentication data, the security authentication module will receive and process this data, and only after passing the verification is the debugging terminal allowed to interact with other modules or systems of the vehicle.
[0075] The controller is one of the core components of the vehicle and can be a microcontroller unit (MCU) or a system on chip (SOC). It is responsible for receiving the verification results and related instructions from the security authentication module. In the case of successful verification, the controller will make corresponding adjustments and configurations to the IO configuration information of the debugging port circuit according to the received verification data.
[0076] The debugging port circuit includes an interface for connecting the vehicle to an external debugging device, and the correct setting of its IO configuration information is crucial. During normal operation, the IO configuration information of the debugging port circuit may be set to restrict or prohibit access by external devices to protect the security and stability of the vehicle system. Only after passing the security authentication will the IO configuration information of the debugging port circuit be configured by the controller as the target IO configuration information, enabling the debugging terminal to establish a communication connection with the controller through this circuit for legal debugging and data interaction operations.
[0077] The debugging terminal 20 in the embodiments of this application can be a terminal device integrating data transmission and debugging functions, with a variety of functions and application scenarios. The debugging terminal 20 can include, but is not limited to, mobile phones, tablets, laptop computers, and fixed debugging workstations, etc., which are not limited here.
[0078] Optionally, the debugging terminal 20 can be deployed with a host computer application. Through this host computer application, the user can, in the case of successful verification of the terminal device, use the host computer application to send various commands or requests to the controller of the vehicle 10. For example, during the vehicle development or system upgrade stage, engineers can physically connect the debugging terminal 20 to the debugging port circuit of the vehicle 10 using a cable to send authentication data for security authentication through the host computer application, and then they can debug and test the controller after passing the authentication; during the vehicle production stage, technicians on the production line can use the debugging terminal 20 to quickly verify the software version and configuration information of the vehicle 10 to ensure production quality; during the after-sales maintenance stage, maintenance personnel can connect to the vehicle 10 with the debugging terminal 20 and obtain the fault information of the vehicle after passing the security authentication for precise maintenance. In addition, the debugging terminal 20 can also be connected to external test equipment or sensors to further expand its debugging and testing capabilities to meet the vehicle debugging requirements in complex scenarios.
[0079] Optionally, the debugging terminal 20 may be provided with a cable interface of the debugger, such as a USB interface, an Ethernet interface, etc., so as to establish a physical connection with the debugging port circuit of the vehicle 10. In this way, the user can send debugging commands and authentication requests in a wired manner to ensure the stability and security of communication.
[0080] Optionally, the debugging terminal 20 may be provided with a communication module to support wireless communication methods such as Wi-Fi or Bluetooth, so that debugging and authentication operations can still be conveniently carried out in cases where physical connection is impossible or inconvenient. This flexible connection method enables the debugging terminal 20 to adapt to different actual application scenarios and improve work efficiency and convenience.
[0081] In the application scenario as Figure 1A shown, the debugging terminal 20 can establish a wireless connection with the vehicle 10 to perform security authentication through the security authentication module of the vehicle 10. After successful verification, the security authentication module will send verification data to the controller, instructing the controller to adjust the IO configuration information of the debugging port circuit to the target IO configuration information. In this way, the debugging terminal 20 can establish a wired connection with the vehicle 10 through the debugging port circuit of the vehicle 10 to perform debugging and data interaction operations.
[0082] Please refer to Figure 1B , Figure 1B which is another application scenario schematic diagram of the security authentication method provided by the embodiment of the present application. The application scenario schematic diagram as Figure 1B shown includes a vehicle 10, a debugging terminal 20, and a security authentication server 30.
[0083] It can be understood that after the security authentication module of the vehicle 10 receives the authentication data sent by the debugging terminal 20, it can be processed through modules inside the vehicle 10, such as the security authentication module itself or other security chips, or the authentication data can be sent to the security authentication server 30 by establishing a communication connection with the vehicle 10 to utilize the powerful computing power and security policies of the server for more complex authentication processing. After receiving the authentication data, the security authentication server 30 will analyze and verify the authentication data according to preset security policies and credit rules, such as digital certificate verification, encryption key exchange, etc., to ensure the reliability and security of the authentication process. If the authentication is passed, the security authentication server 30 will send authentication feedback data indicating successful verification to the security authentication module of the vehicle 10, and the security authentication module will then perform operations similar to those in the Figure 1A scenario shown, that is, send verification data to the controller, instructing the controller to adjust the IO configuration information of the debugging port circuit to the target IO configuration information.
[0084] It should be noted that as Figure 1A or Figure 1BThe application scenarios shown are only examples and can be flexibly adjusted and extended according to actual needs. For example, in some application scenarios, more intermediate devices or servers can be introduced to participate in the authentication process, or different communication protocols and data transmission methods can be adopted to adapt to specific network environments and security requirements. In addition, the specific implementation of security authentication can also be customized according to different security levels and application requirements to meet the security authentication needs in various complex scenarios, which are not limited herein.
[0085] The framework of the vehicle will be introduced below in conjunction with the accompanying drawings to facilitate understanding of the architecture inside the vehicle and the relationships between various components.
[0086] Please refer to Figure 2A , Figure 2A which is a schematic diagram of a framework of a vehicle provided by an embodiment of the present application. As Figure 2A shown, the vehicle 10 may include a security authentication module 11, a controller 12, and a debug port circuit 13.
[0087] As Figure 2A shown, the security authentication module 11 may be communicatively connected to the controller 12. For example, the security authentication module 11 communicates with the controller 12 through the system bus of the vehicle 10, the vehicle communication gateway, and the communication transceiver, etc. And the controller 12 may be communicatively connected to the debug port circuit 13 for configuring the IO configuration information of the debug port circuit 13.
[0088] In the embodiment of the present application, after the security authentication module 11 obtains the authentication data sent by the debug terminal, it can verify the authentication data. When the verification of the authentication data is successful, it sends the verification data to the controller 12 so that the controller 12 configures the IO configuration information of the debug port circuit 13 as the target IO configuration information, enabling the debug terminal to communicate with the controller 12 through the physical connection with the debug port circuit 13.
[0089] Optionally, when the security authentication module 11 verifies the authentication data through a security authentication server, the security authentication module 11 may include a communication unit, or uses the system bus, vehicle communication gateway, etc. included in the vehicle 10 to establish a communication connection with the security authentication server. This is not limited herein.
[0090] Exemplarily, when the security authentication module 11 needs to verify authentication data with the help of an external security authentication server, it can establish a direct communication link with the security authentication server through the built-in communication unit. The communication unit can support multiple communication protocols, such as TCP / IP, UDP, etc., to adapt to different network environments and security requirements. In addition, the security authentication module 11 can also utilize the existing communication infrastructure inside the vehicle 10, such as the system bus or the vehicle communication gateway, to transmit the authentication data to the security authentication server.
[0091] In some possible embodiments, the vehicle may further include a debug port lock integrated circuit to encrypt and lock the debug port circuit at the hardware level to ensure the data security of the controller. The debug port lock integrated circuit restricts access to the debug port circuit through a hardware encryption algorithm and a verification mechanism. Only when the debug terminal passes the verification of the security authentication module and the debug port lock integrated circuit is unlocked, is the debug terminal allowed to access the data of the controller through the debug port circuit.
[0092] Please refer to Figure 2B , Figure 2B Another framework schematic diagram of the vehicle provided by the embodiment of the present application, as Figure 2B shown, the vehicle 10 may include a security authentication module 11, a controller 12, a debug port circuit 13, and a debug port lock integrated circuit 14.
[0093] As Figure 2B shown, the vehicle 10 further includes a debug port lock integrated circuit 14, which can be used to control the working state of the debug port circuit 13. The working state includes a locked state or an unlocked state. In the locked state, even if the IO configuration information of the debug port circuit 13 is configured as the target IO configuration, an external device, such as a debug terminal, cannot access or operate the data in the controller 12 through the debug port circuit 13. Only when the debug port circuit 13 is in the unlocked state and the IO configuration is configured as the target IO configuration, is an external device, such as a debug terminal, allowed to establish a communication connection with the controller 12 through the debug port circuit 13, thus effectively preventing unauthorized access and data leakage and improving the overall security of the vehicle.
[0094] Please refer to Figure 2C , Figure 2C Another framework schematic diagram of the vehicle provided by the embodiment of the present application, as Figure 2C shown, the vehicle 10 may include a security authentication module 11, a controller 12, a debug port circuit 13, a debug port lock integrated circuit 14, a vehicle communication gateway 15, and a communication transceiver 16.
[0095] As Figure 2CFor the vehicle 10 shown, the security authentication module 11 can communicate with the controller 12 through the vehicle communication gateway 15 and the communication transceiver 16.
[0096] The vehicle communication gateway 15 serves as a bridge between different modules inside the vehicle 10 and is responsible for data forwarding and protocol conversion between various modules. The vehicle communication gateway 15 can receive authentication data and instructions from the security authentication module 11, convert them into a format suitable for transmission inside the vehicle, and send them to the controller 12 through the communication transceiver 16. This communication method not only improves the efficiency of data transmission but also ensures that information between different modules can be transmitted accurately. The communication transceiver 16 is responsible for signal transmission and reception, supporting multiple communication protocols such as CAN bus, LIN bus, Ethernet, etc., to adapt to the complex communication environment inside the vehicle.
[0097] Optionally, the communication transceiver 16 can be used to convert the data sent from the vehicle communication gateway 15, such as converting digital signals into a format that the controller 12 can read. For example, the communication transceiver 16 can receive signals from the vehicle communication gateway 15 and convert them into a signal type compatible with the controller 12 to ensure accurate data transmission and identification. This conversion process can include signal modulation and demodulation, voltage level adjustment, and communication protocol adaptation, etc. In this way, modules such as the security authentication module 11, the vehicle communication gateway 15, and the controller 12 can perform data interaction efficiently and stably, thus supporting the collaborative work of various modules inside the vehicle and ensuring the reliability and response speed of the entire security authentication process.
[0098] Next, the application of the security authentication method to the security authentication module of the vehicle will be introduced in conjunction with the accompanying drawings to better understand the implementation process of the security authentication method.
[0099] Please refer to Figure 3 , Figure 3 which is a schematic flowchart of a process for applying the security authentication method provided by the embodiment of the present application to the security authentication module of the vehicle. The security authentication method can be applied to the security authentication module of the vehicle. As Figure 3 shown, the method can include the following steps:
[0100] S301, Obtain the authentication data sent by the debugging terminal.
[0101] In the embodiment of the present application, the authentication data includes the first identification information of the debugging terminal.
[0102] It should be noted that the first identification information of the debugging terminal is used to identify and verify the identity of the debugging terminal, ensuring that only the trusted debugging terminal can interact with the vehicle's controller through the security authentication module. The first identification information can have various forms. For example, the first identification information includes but is not limited to the following: such as the software identification information of the host computer application deployed on the debugging terminal, the hardware identification information of the debugging terminal, etc.
[0103] Exemplarily, the software identification information of the host computer application refers to the unique identifier of the host computer application deployed on the debugging terminal, which is used to distinguish different application programs. For example, the software identification information can be the account information of the currently logged-in user of the host computer application, such as a string that uniquely identifies a user like a mobile phone number, an email address, etc., or it can be the unique identification code of the host computer application itself, such as a self-designed login account.
[0104] The hardware identification of the debugging terminal refers to the hardware characteristic information that can uniquely identify the debugging terminal device. For example, the hardware identification can be the unique serial number of the debugging terminal, usually assigned by the device manufacturer during the production process to distinguish different devices of the same model; it can also be the MAC address of the debugging terminal, that is, the unique identification code of the network interface controller (NIC), which is used to distinguish different network devices in a local area network. This is not limited here.
[0105] Optionally, in addition to the software identification information of the host computer application and the hardware identification information of the debugging terminal, the first identification information of the debugging terminal can also be biometric information obtained by the debugging terminal, such as fingerprint, face recognition, etc., which is used to confirm the user's identity and enhance the security of authentication.
[0106] In the embodiments of the present application, the security authentication module can obtain the authentication data sent by the debugging terminal through a wireless communication connection method, such as WiFi, Bluetooth, etc.
[0107] Optionally, the debugging terminal can directly communicate with the security authentication module through methods such as WiFi, Bluetooth, etc., or the debugging terminal can also communicate with the communication network module inside the vehicle to achieve data interaction with the security authentication module. For example, the debugging terminal can establish a direct connection with the vehicle's security authentication module through Bluetooth to quickly send authentication data. It can also be connected to communication modules such as the vehicle's in-vehicle communication gateway, WiFi module, or Bluetooth module through methods such as WiFi, Bluetooth, etc., and then the communication module forwards the data to the security authentication module.
[0108] Optionally, the security authentication module can establish a physical connection with the debugging terminal through a wired connection method, such as a USB interface, an Ethernet interface, etc., so as to receive the authentication data. This method is applicable to the vehicle development stage or debugging scenarios that require a stable connection to ensure the reliability and security of data transmission.
[0109] It should be noted that when the authentication data sent by the debugging terminal fails to pass the verification, the debugging terminal cannot transmit or read data to / from the controller through the debugging port circuit. At this time, through other interfaces, such as USB interfaces, Ethernet interfaces, etc., the security authentication module can obtain the authentication data sent by the debugging terminal in a wired connection manner. At the same time, by restricting the functions of the interfaces, such as through technical means such as interface permission management, protocol restriction, or data filtering, only the debugging terminal is allowed to send authentication data to the vehicle's security authentication module, while restricting its access rights to other modules (such as the controller).
[0110] Exemplarily, when the debugging terminal is connected to the vehicle through a vehicle interface, such as a USB interface, the interface can be configured to only allow specific types of communication, such as protocols and endpoints that are only used by the security authentication module. In this way, even if the authentication data fails to pass the verification, the debugging terminal cannot use this interface to communicate with the controller or other sensitive modules. In addition, a data filtering mechanism can be implemented at the interface to ensure that only data packets that meet the requirements of the security authentication module can pass, thereby further restricting the access scope of the debugging terminal.
[0111] S302, perform verification processing on the authentication data.
[0112] In the embodiment of the present application, after obtaining the authentication data, the security authentication module performs verification processing on the authentication data. Among them, the verification processing includes comparing the first identification information with the pre-stored trusted data to determine whether the authentication data is successfully verified, and the trusted data includes multiple trusted identification information.
[0113] It should be noted that after receiving the authentication data, the security authentication module can extract the first identification information therein, and compare the first identification information with the trusted data pre-stored in the security authentication module or the vehicle internal memory to determine whether the debugging terminal is trustworthy.
[0114] Optionally, perform verification processing on the authentication data.
[0115] In the embodiment of the present application, after obtaining the authentication data, the security authentication module performs verification processing on the authentication data. Among them, the verification processing includes comparing the first identification information with the pre-stored trusted data to determine whether the authentication data is successfully verified, and the trusted data includes multiple trusted identification information.
[0116] It should be noted that after receiving the authentication data, the security authentication module can extract the first identification information therein, and compare the first identification information with the trusted data pre-stored in the security authentication module or the vehicle internal memory to determine whether the debugging terminal is trustworthy.
[0117] Optionally, the credit data exists in the form of a database or a list and includes multiple credit identification information. The credit information can be data of the same type or format as the first identification information. For example, when the first identification information is the MAC address of a debugging terminal or the account information corresponding to software, the multiple credit information is the MAC address corresponding to different credit debugging terminals or the account information corresponding to software. It can be understood that these credit debugging terminals can be produced or purchased by the vehicle manufacturer and are devices with pre-recorded credit, ensuring that only the credited debugging terminals can access the vehicle controller, enhancing security.
[0118] In some possible embodiments, comparing the first identification information with the pre-stored credit data to determine whether the authentication data is successfully verified includes:
[0119] Comparing the first identification information with the pre-stored credit data. If the first identification information exists among the multiple credit identification information, it is determined that the authentication data is successfully verified; if the first identification information does not exist among the multiple credit identification information, it is determined that the authentication data is verified failed.
[0120] In some possible embodiments, when the security authentication module performs verification processing, other verification factors such as timestamps and verification times can also be combined to enhance the stability and reliability of security authentication.
[0121] For example, in addition to comparing the first identification information with the credit data, the timestamps corresponding to each credit identification information in the credit data can also be verified to determine whether the current time when the security authentication module obtains the authentication data exceeds the timestamp of the credit identification information corresponding to the debugging terminal, that is, to determine whether the credit period of the debugging terminal is within the valid period. If the current time exceeds the timestamp, the security authentication module will confirm that the authentication data sent by the debugging terminal fails to be verified and will not send the verification data to the controller.
[0122] In addition, the number of times the security authentication module obtains the authentication data sent by the same debugging terminal within a preset time can also be obtained. If the number of times exceeds the preset number of times, it is determined that the authentication data verification fails, and the authentication attempt of this terminal is restricted. This can prevent attackers from brute-forcing the security authentication module by frequently trying different authentication data. For example, the security authentication module can record the number of authentication attempts of each debugging terminal within a preset time, such as the maximum number of attempts allowed per hour is 3 times. Once the number of attempts of a certain terminal exceeds this limit, the security authentication module will temporarily prohibit further authentication attempts of this terminal and can send an alert to the security authentication server or the administrator to notify of a possible security threat.
[0123] By combining these additional verification factors, the security authentication module can more comprehensively evaluate the validity and credibility of the authentication data, further enhancing the security and reliability of the entire authentication process.
[0124] S303, when the authentication data is verified successfully, send the verification data to the controller so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information.
[0125] In the embodiment of the present application, when the security authentication module verifies the authentication data successfully, it sends the verification data to the controller, so that after the debug port circuit is configured as the target IO configuration information, the debug terminal can access the controller through the debug port circuit.
[0126] It should be noted that the IO configuration information of the debug port circuit can be the configuration parameters of each pin included in the debug port circuit, and these parameters define the functions and working states of the pins. For example, the debug port circuit can include multiple pins, and each pin can be configured with different functions, such as input, output, interrupt trigger, etc. It can also interact with different modules by modifying the configuration information, such as voltage level, data transfer rate, communication protocol type, etc. In the case where the controller does not receive the verification data, the configuration of these pins can be set to restrict access by external devices to protect the security and stability of the vehicle system. Only after passing the security authentication, the controller will adjust the IO configuration information of the debug port circuit to the target IO configuration information according to the received verification data. For example, the controller can configure some pins with specific functions in the debug mode, such as data transfer, command reception, etc., so that the debug terminal can communicate with the controller through these pins.
[0127] In the embodiment of the present application, when the security authentication module verifies the authentication data failed, since the controller does not receive the verification data, it will not configure the IO configuration information of the debug port circuit, preventing unauthorized debug operations and potential data leakage risks, and ensuring data security.
[0128] The security authentication method provided by the embodiment of the present application can be applied to the security authentication module of a vehicle to ensure that only an authorized debug terminal can establish a communication connection with the controller through the debug port circuit, thus ensuring the normal development of the debug work and preventing unauthorized data access. Restricting access to controller data by unauthenticated debug terminals at the IO configuration information level and being able to verify based on the first identification information of the debug terminal improves the security and traceability of the data.
[0129] Next, the application of the security authentication method to the controller of a vehicle will be introduced in combination with the accompanying drawings to better understand the implementation process of the security authentication method.
[0130] Please refer to Figure 4 , Figure 4 which is a schematic flowchart of applying the security authentication method provided by the embodiment of the present application to the controller of a vehicle. The security authentication method can be applied to the controller of a vehicle. As Figure 4 shown, the method may include the following steps:
[0131] S401, when obtaining the verification data sent by the security authentication module, configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0132] In the embodiment of the present application, the verification data is sent by the security authentication module when the authentication data sent by the debug terminal is successfully verified. The authentication data includes the first identification information of the debug terminal. The debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
[0133] Optionally, after the controller configures the IO configuration information of the debug port circuit as the target IO configuration information, it is necessary to control the debug port circuit to restart, so that the debug port circuit can apply the target IO configuration in the next power-on cycle after restart and communicate with the debug terminal.
[0134] It should be noted that the verification data can instruct the controller to configure the IO configuration information of the debug port circuit as the target IO configuration information to allow the verified debug terminal to access the controller.
[0135] Optionally, the verification data can be information with a preset content, such as a verification code, so that after the controller obtains the verification data, it can recognize that the debug terminal has passed the security authentication and adjust the IO configuration information of the debug port circuit to the target configuration according to the preset rules.
[0136] Optionally, the verification data can also include information such as a timestamp, a configuration instruction, etc. to enhance the security and flexibility of the security verification.
[0137] When the verification data further includes a timestamp, the controller can, according to the timestamp, reconfigure the IO configuration information of the debug port circuit as the initial IO configuration information after a preset time period after configuring the IO configuration information of the debug port circuit as the target IO configuration information, so as to ensure the security of the vehicle system by restricting the access time of the debug terminal. For example, in the after-sales maintenance scenario of a vehicle, when a maintenance personnel connects to the vehicle for fault diagnosis. After the security authentication module verifies the debug terminal of the maintenance personnel, it sends verification data including a timestamp. The controller, according to the timestamp, automatically restores the initial configuration of the debug port circuit after a preset time period, such as 1 hour, to prevent the maintenance terminal from being accidentally or maliciously used by other people after the task is completed without physical separation, thereby protecting the security and integrity of the vehicle data.
[0138] The verification data may also include configuration instructions for instructing the controller to adjust the IO configuration information of the debug port circuit to different target IO configuration information. The configuration instructions may be generated by the security authentication module after successful verification, and may include the target IO configuration information that the debug port circuit needs to use, or may include configuration numbers corresponding to different target IO configuration information, etc., which are not limited herein.
[0139] The security authentication method provided by the embodiments of the present application can be applied to the controller of a vehicle. Since the verification data is sent by the security authentication module when the authentication data sent by the debug terminal is successfully verified, it can prevent an untrusted terminal from establishing a connection with the controller and ensure data security. By restricting access to controller data by unauthenticated debug terminals at the IO configuration information level and verifying based on the first identification information of the debug terminal, the data security and traceability are further improved. In addition, by combining additional verification factors such as timestamps and configuration instructions, not only the security of the authentication process is enhanced, but also the system can flexibly adapt to different debug requirements and scenarios, improving the overall reliability and practicality.
[0140] Please refer to Figure 5 , Figure 5 which is a schematic flowchart of a security authentication method provided by an embodiment of the present application. As Figure 5 shown, the method may include the following steps:
[0141] S501, the security authentication module obtains the authentication data sent by the debug terminal.
[0142] S502, the security authentication module performs verification processing on the authentication data.
[0143] S503, when the authentication data is successfully verified, the security authentication module sends verification data to the controller.
[0144] It should be noted that the implementation processes of S501 to S503 are similar to those of S301 to S303, and will not be repeated here.
[0145] S504, when the controller obtains the verification data sent by the security authentication module, it configures the IO configuration information of the debug port circuit as the target IO configuration information.
[0146] It should be noted that the implementation process of S504 is similar to that of S401, and will not be repeated here.
[0147] In the security authentication method provided by the embodiments of the present application, the security authentication module and the controller can work together to achieve efficient and reliable security authentication and data access control. The security authentication module can focus on verifying whether the debugging terminal is trusted, and based on the successful verification by the security authentication module, the controller adjusts the IO configuration of the debugging port circuit so that the trusted terminal can be successfully connected and perform debugging operations. By handing over the verification work to a dedicated security authentication module, the risk that may be brought about by the controller directly obtaining the data sent by the debugging terminal for verification is avoided, and the data protection ability is improved.
[0148] Next, the application of the security authentication method to the security authentication module of a vehicle will be described in conjunction with the accompanying drawings, so as to better understand how the security authentication module verifies and processes the authentication data through the server.
[0149] Please refer to Figure 6 , Figure 6 which is another schematic flowchart of the application of the security authentication method provided by the embodiments of the present application to the security authentication module of a vehicle. As Figure 6 shown, the method may include the following steps:
[0150] S601, Obtain the authentication data sent by the debugging terminal.
[0151] S602, Send the authentication data to the security authentication server.
[0152] In some possible embodiments, the security authentication module may send the authentication data to the security authentication server for verification processing of the authentication data.
[0153] It should be noted that by sending the authentication data including the first identification information to the security authentication server, the powerful computing power and data storage capacity of the security authentication server can be utilized to enhance the security and reliability of the entire authentication process.
[0154] At the same time, the security authentication module sending the authentication data to the security authentication server can enable the security authentication server to record the relevant information of the debugging terminal that attempts to access the controller of the vehicle, which helps to investigate potential security risks, and when a security event is detected, quickly locate the source of the risk, providing strong support for rights protection and intellectual property protection.
[0155] Optionally, the authentication data can be sent to the security authentication server, and the authentication feedback data sent by the security authentication server subsequently can be received through the communication unit built in the security authentication module, or communication modules such as the vehicle's overall vehicle security authentication gateway and system bus, which is not limited herein.
[0156] S603, Obtain the authentication feedback data sent by the security authentication server.
[0157] In some possible embodiments, the authentication feedback data includes the verification result of the security authentication server for the first identification information, and the verification result is used to indicate whether the security authentication server verifies the first identification information successfully or fails.
[0158] It can be understood that the security authentication server may store credit data including multiple authorized identification information to verify the first identification information.
[0159] S604, according to the authentication feedback data, determine whether the authentication data is verified successfully.
[0160] Optionally, the security authentication module can determine whether the authentication data is verified successfully according to the verification result included in the authentication feedback data sent by the security authentication server.
[0161] In the case where the verification result indicates that the security authentication server verifies the first identification information successfully, the security authentication module determines that the authentication data is verified successfully; while in the case where the verification result indicates that the security authentication server verifies the first identification information fails, the security authentication module determines that the authentication data is verified failed.
[0162] In some possible embodiments, the first identification information includes the software identification information of the host computer application deployed on the debugging terminal and the hardware identification information of the debugging terminal. When the security authentication server determines that the software identification information and the hardware identification information match according to the preset matching relationship table, a verification result indicating that the security authentication server verifies the first identification information successfully is generated. The preset matching relationship table includes the matching relationship between the preset software identification information and the preset hardware identification information.
[0163] It should be noted that for the same debugging terminal, different accounts can be logged in to the host computer application deployed on it, that is, corresponding to different software identification information. For the same software identification information, it can be used on different hardware devices, that is, corresponding to different hardware identification information. To avoid the risks brought by account leakage or loss of the debugging terminal. The preset matching relationship table will store the combinations between different preset software identification information and preset hardware identification information in the security authentication server. After the security authentication server obtains the authentication data, only the pre-authorized combinations can be verified successfully.
[0164] Optionally, when any account logs in to a new debugging terminal, a verification process is required, such as registering the combination of the software identification information and the hardware identification information on the specified authorized device and storing it in the preset matching relationship table of the security authentication server to protect the data security of the vehicle.
[0165] Exemplarily, when a technician attempts to log in to an account on a new debugging terminal, a verification step will be triggered. For example, receiving a SMS verification code, an email verification link, or using a hardware key, etc. for verification. After the verification is completed, the software identification information and hardware identification information of the debugging terminal will be registered by the security authentication server and added to the preset matching relationship table stored in the security authentication server.
[0166] S605, in the case where the authentication data is verified successfully, send the verification data to the controller so that the controller configures the IO configuration information of the debugging port circuit as the target IO configuration information.
[0167] In some possible embodiments, the authentication data further includes a target permission, and the target permission includes the read permission and / or write permission requested by the debugging terminal. Sending the verification data to the controller includes:
[0168] Generate verification data according to the target permission;
[0169] Send the verification data to the controller so that the controller configures the IO configuration information of the debugging port circuit as the target IO configuration information corresponding to the target permission.
[0170] It should be noted that when the debugging terminal sends the authentication data, in addition to including the first identification information for identifying the identity, it can also carry the target permission, which is used to indicate the access permission required for this debugging.
[0171] Optionally, the target permission may include the read permission and / or write permission requested by the debugging terminal, that is, the debugging terminal can request the read permission alone, or the write permission alone, or both the read and write permissions at the same time. In this way, the authentication data generates verification data according to the target permission, enabling the controller to configure the IO configuration information of the debugging port circuit as the target IO configuration information corresponding to the target permission, meeting the specific access requirements of the debugging terminal while ensuring data security.
[0172] Optionally, the target permission may also include the read permission and / or write permission for the debugging terminal to access the target data. By generating verification data according to the target permission, the controller configures the IO configuration information of the debugging port circuit as the target IO configuration information corresponding to the target permission, such as by adjusting the configuration parameters or working states of each pin, to achieve fine management of data access permissions.
[0173] Exemplarily, if the debugging terminal requests the read permission to access the navigation data, the controller can adjust the configuration of a specific pin so that it can only send signals related to the navigation data to the debugging terminal and cannot perform write operations. This precise adjustment of the pin configuration can achieve fine management of data access and ensure that the debugging terminal can only perform authorized operations.
[0174] In some possible embodiments, when the authentication data further includes a target permission, the security authentication method applied to the security authentication module further includes: obtaining the trusted permission of the debugging terminal according to the first identification information; comparing the target permission with the trusted permission to determine whether the target permission is within the scope of the trusted permission; and when the target permission is within the scope of the trusted permission and the first identification information is successfully verified, determining that the authentication data is successfully verified.
[0175] It should be noted that after receiving the authentication data containing the target permission, the security authentication module can perform subsequent verification steps through itself, other security chips of the vehicle, or a security authentication server.
[0176] Exemplarily, the security authentication module or the security authentication server can obtain the trusted permission of the debugging terminal from a preset permission database or permission list according to the first identification information of the debugging terminal. The trusted permission is the access permission pre-assigned to the debugging terminal, which can include read permission, write permission, and access permission to specific data types, etc. Compare the target permission in the authentication data with the obtained trusted permission to determine whether the target permission is within the scope of the trusted permission. If the target permission is completely included in the scope of the trusted permission, it is determined that the target permission is trusted; if the target permission exceeds the scope of the trusted permission, it is determined that the target permission is not trusted. When the target permission is within the scope of the trusted permission and the first identification information is successfully verified, the security authentication module or the security authentication server will determine that the authentication data is successfully verified.
[0177] In this way, the security authentication module or the security authentication server can ensure that the permissions requested by the debugging terminal are within the scope of its trusted permissions, thereby preventing unauthorized operations of the debugging terminal. Only when the target permission matches the trusted permission, the security authentication server will generate corresponding verification data and send it to the controller, instructing it to configure the IO configuration information of the debug port circuit as the target IO configuration information corresponding to the target permission. This not only meets the specific access requirements of the debugging terminal but also ensures the security and compliance of data access.
[0178] In some possible embodiments, when receiving a debug instruction sent by the security authentication server, the security authentication module can send verification data to the controller to enable the controller to configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0179] It can be understood that for some scenarios where the data of the vehicle's controller is adjusted in batches, such as when the manufacturer conducts a batch recall of its vehicles or pushes system upgrade firmware on a large scale, the security authentication module can obtain the debugging instructions sent by the security authentication server without interacting with the adjustment terminal, and send verification data to the controller based on this, so that the controller configures the IO configuration information of the debugging port circuit as the target IO configuration information. This mechanism enables the manufacturer to perform batch operations efficiently without physically connecting each vehicle, while ensuring the security and reliability of the entire process.
[0180] In the above technical solution, the security authentication module of the vehicle can work in cooperation with the security authentication server to achieve security authentication and permission management of the debugging terminal. The security authentication module first obtains the authentication data sent by the debugging terminal and sends this data to the security authentication server for verification. The security authentication server can verify the first identification information in the authentication data and return authentication feedback data to the security authentication module. The security authentication module determines whether the authentication is successful based on the feedback. In the case of success, it further generates verification data according to the target permissions and sends it to the controller. The controller then adjusts the IO configuration information of the debugging port circuit, ensuring that only authorized debugging terminals can access the data of the vehicle controller, and also preventing unauthorized debugging operations of authorized debugging terminals through meticulous management of the target permissions.
[0181] Next, the application of the security authentication method to the security authentication module of the vehicle will be introduced in conjunction with the accompanying drawings, so as to better understand how to verify and process the authentication data through the server when the authentication data also includes the second identification information of the vehicle.
[0182] Please refer to Figure 7 , Figure 7 which is another schematic flowchart of the application of the security authentication method provided by the embodiment of the present application to the security authentication module of the vehicle. As Figure 7 shown, the method may include the following steps:
[0183] S701, Obtain the authentication data sent by the debugging terminal.
[0184] S702, Send the authentication data to the security authentication server.
[0185] In some possible embodiments, the authentication data further includes the second identification information of the vehicle.
[0186] It should be noted that the second identification information is information that can uniquely identify the vehicle, and can be a license plate number, vehicle identification number (VIN), frame number, etc. By combining the second identification information of the vehicle with the first identification information of the debugging terminal, the accuracy and security of the security authentication method can be improved.
[0187] S703. Obtain the first key sent by the security authentication server.
[0188] In some possible embodiments, the first key is generated according to the second identification information when the security authentication server successfully verifies the first identification information.
[0189] Optionally, after successfully verifying the first identification information, the security authentication server can use a preset key generation rule or algorithm, such as a symmetric encryption algorithm, an asymmetric encryption algorithm, a hash algorithm, etc., and use the first identification information as the input condition of the encryption algorithm to obtain the first key.
[0190] Exemplarily, when the second identification information is the vehicle identification number (VIN), the security authentication server can perform a hash operation on the VIN and a preset key seed to generate the first key.
[0191] Optionally, the security authentication server can combine the first identification information and the second identification information as the input condition of the encryption algorithm to obtain the first key. For example, splice the MAC address of the debugging terminal (the first identification information) and the VIN code of the vehicle (the second identification information), and then generate the first key through a hash algorithm. In this way, the generation of the key depends not only on a single identification information, but combines two independent identifications, further improving the security of the key.
[0192] S704. Compare the first key and the second key to determine whether the authentication data is successfully verified.
[0193] In some possible embodiments, the second key includes a preset key or a key generated by the security authentication module according to a preset rule. After receiving the first key sent by the security authentication server, the security authentication module can compare the first key and the second key to determine whether the authentication data is successfully verified.
[0194] Optionally, the second key can be a fixed key pre-stored by the security authentication module during vehicle production or initialization, or a key dynamically generated by the security authentication module according to a rule agreed with the security authentication server.
[0195] Exemplarily, in the case where the second key is a key generated by the security authentication module according to a preset rule, the security authentication module can use the same encryption algorithm as the security authentication server, such as the same hash algorithm and a preset key seed, and combine the VIN code of the vehicle to generate the second key.
[0196] In some possible embodiments, comparing the first key and the second key to determine whether the authentication data is successfully verified may include: comparing the received first key with the second key bit by bit; if the first key and the second key are the same, it is determined that the authentication data is successfully verified; otherwise, it is determined that the authentication data is not successfully verified.
[0197] In some possible embodiments, comparing the first key and the second key to determine whether the authentication data is successfully verified may further include: concatenating the first key and the second key to obtain a combined key; performing a hash operation on the combined key to obtain a target hash value; comparing the target hash value with a preset hash value; if the target hash value and the preset hash value are the same, it is determined that the authentication data is successfully verified; otherwise, it is determined that the authentication data is not successfully verified.
[0198] It should be noted that the above key verification method is only an example. In actual applications, different encryption and decryption algorithms can be selected according to specific security requirements, system architectures, and performance requirements, or a combination of multiple algorithms can be used to achieve the best security and efficiency. This is not limited here.
[0199] S705, in the case where the authentication data is successfully verified, send verification data to the controller so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information.
[0200] In the above technical solution, the authentication data may further include the second identification information of the vehicle. The security authentication module compares the first key sent by the security authentication server with the second key generated or stored by the module itself to determine whether the debug terminal is trusted, improving the accuracy and security of the authentication.
[0201] Next, the application of the security authentication method to the vehicle controller will be introduced in conjunction with the drawings, so as to better understand how the controller configures the debug port circuit and the debug port lock integrated circuit when the vehicle further includes a debug port lock integrated circuit.
[0202] Please refer to Figure 8 , Figure 8 which is another schematic flowchart of the application of the security authentication method provided by the embodiment of the present application to the vehicle controller. As Figure 8 shown, the method may include the following steps:
[0203] S801, in the case of obtaining the verification data sent by the security authentication module, configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0204] In some possible embodiments, the authentication data further includes a target permission, and the target permission includes a read permission and / or a write permission requested by the debugging terminal. The verification data is generated according to the target permission. Configuring the IO configuration information of the debug port circuit as the target IO configuration information includes:
[0205] Determine the target IO configuration information according to the verification data;
[0206] Configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0207] Optionally, the storage unit of the controller or the storage module of the vehicle may pre-store the target IO configuration information corresponding to different target permissions. In this way, after the controller receives the verification data generated by the security authentication module according to the target permission, it can conveniently find the corresponding target IO configuration information and perform corresponding configuration.
[0208] Optionally, the controller may determine the target IO configuration information according to a preset mapping relationship of IO configuration information, where the preset mapping relationship of IO configuration information includes the corresponding relationship between the preset permission and the preset IO configuration information.
[0209] It should be noted that the preset mapping relationship of IO configuration information may be pre-stored in the storage unit of the controller or the storage module of the vehicle when the vehicle leaves the factory, or may be updated and adjusted as needed during the use of the vehicle, which is not limited herein.
[0210] Exemplarily, when the vehicle leaves the factory, the storage unit of the controller or the storage module of the vehicle has pre-stored the target IO configuration information corresponding to different permissions. These configuration information define the functions and working states of each pin of the debug port circuit under different permissions. For example, the read permission may correspond to configuration information 1, the write permission corresponds to configuration information 2, the read-write permission corresponds to configuration information 3, etc., to meet the access requirements of the debugging terminal and ensure data security.
[0211] S802, obtain the target number of times the debugging terminal sends a key within a preset time period.
[0212] In some possible embodiments, the vehicle further includes a debug port lock integrated circuit, and the debug port lock integrated circuit is used to control the working state of the debug port circuit. The working state includes a locked state or an unlocked state. The debug port lock integrated circuit controls the debug port circuit to be in the unlocked state when the key sent by the debugging terminal matches the preset unlocking key. The security authentication method further includes:
[0213] Obtain the target number of times the debugging terminal sends a key within a preset time period.
[0214] It can be understood that when the vehicle further includes a debugging port lock integrated circuit, even if the IO configuration information of the debugging port circuit is configured as the target IO configuration information, due to the existence of the debugging port lock integrated circuit, the debugging terminal still cannot access the data of the controller through the debugging port circuit.
[0215] Since the unlocking method of the debugging port lock integrated circuit is relatively conventional and public, in order to prevent malicious users from obtaining access rights by continuously trying passwords or brute-forcing, the controller can obtain the target number of times the debugging terminal sends a key within a preset time period, determine whether the debugging terminal has a malicious attack behavior based on the target number of times, and take corresponding security processing operations.
[0216] S803, when the target number of times is greater than a preset threshold and all the keys sent by the debugging terminal do not match the preset unlocking key, perform a security processing operation.
[0217] In some possible embodiments, when the target number of times is greater than a preset threshold and all the keys sent by the debugging terminal do not match the preset unlocking key, perform a security processing operation.
[0218] It can be understood that when the number of times the debugging terminal sends a key is relatively large, greater than the preset threshold, and all the keys sent do not match the preset unlocking key, there may be a security risk for the debugging terminal. Therefore, security processing operations need to be taken to protect data security.
[0219] Optionally, the security processing includes configuring the IO configuration information of the debugging port circuit as preset IO configuration information. Among them, when the IO configuration information of the debugging port circuit is the preset IO configuration information, the debugging terminal is prohibited from communicating with the controller through the debugging port circuit.
[0220] It should be noted that the preset IO configuration information can be the initial IO configuration information of the debugging port circuit before it is configured as the target IO configuration information by the controller. Or, the preset IO configuration information can also be specific configuration information specifically used by the controller to lock the debugging port circuit when detecting a security threat, so as to prohibit the debugging terminal from communicating with the controller through the debugging port circuit. This is not limited here.
[0221] Exemplarily, when the debugging port circuit is configured as the preset IO configuration information, all its pins can be configured as the default locked state, or all configured as high level, low level or high impedance state, so that the debugging terminal cannot establish a communication connection with the controller through the debugging port circuit.
[0222] In some possible embodiments, the security processing operation further includes, when obtaining a read instruction for the debugging terminal to read the original data of the controller, sending data modified based on the original data to the debugging terminal, so that the data read by the debugging terminal through the debugging port circuit is different from the original data of the controller; or, the security processing operation further includes sending a security alarm message to the security authentication server, where the security alarm message includes first identification information.
[0223] By obtaining a read instruction for the debugging terminal to read the original data of the controller and sending the modified data to the debugging terminal, the controller can effectively prevent the debugging terminal from obtaining the real data of the controller, further protecting the data security of the vehicle system.
[0224] Exemplarily, when the target number of times of sending the key within a preset time period by the debugging terminal is greater than a preset threshold, the controller determines that there is a security risk for the debugging terminal, and can send data modified based on the original data to the debugging terminal, so that the user of the debugging terminal mistakenly believes that accurate data has been obtained, reduces vigilance, and will not further attempt illegal access.
[0225] Optionally, the controller can end the security processing in the next power-on cycle of the debugging port circuit or when receiving a recovery instruction sent by the security authentication server, enabling the debugging terminal to resend the key and unlock the debugging port lock integrated circuit. Among them, the recovery instruction can be sent by the security authentication server after verifying that the debugging terminal is a trusted device through methods such as manual review and verification of multiple pieces of information (such as the positioning information of the debugging terminal or the identity information of relevant technicians, etc.).
[0226] The security processing operation can also include sending a security alarm message to the security authentication server. Since the security alarm message includes first identification information, it helps to identify and locate the debugging terminal with security risks, providing a basis for subsequent security audits, rights protection, risk assessment, and other processes.
[0227] Optionally, the security alarm message can also include the time and the second identification information of the vehicle, providing a detailed event record for the security authentication server and facilitating quick positioning and identification of the problem source.
[0228] In some possible embodiments, the vehicle further includes a debugging port lock integrated circuit, which is used to control the working state of the debugging port circuit. The working state includes a locked state or an unlocked state. The method further includes:
[0229] When obtaining the verification data sent by the security authentication module, sending an unlock instruction to the debugging port lock integrated circuit, so that the debugging port circuit is in the unlocked state.
[0230] It can be understood that the controller sends an unlocking instruction to the debugging port lock integrated circuit when obtaining the verification data sent by the security authentication module, eliminating the need for the user to actively input the key using the debugging terminal, thereby improving the security authentication efficiency and convenience.
[0231] Optionally, to ensure the security of the security authentication, it can be restricted that the controller can send an unlocking instruction to the debugging port lock integrated circuit only when the debugging terminal meets the preset conditions. For example, the preset conditions can include the permission level of the debugging terminal, the user group it belongs to, the network type it is connected to, etc. In this way, while ensuring efficient operation, it is ensured that only the debugging terminals that meet the security requirements can trigger the automatic unlocking of the debugging port lock integrated circuit, enhancing the reliability of the security authentication.
[0232] In the above technical solution, the vehicle can also include a debugging port lock integrated circuit. The debugging port lock integrated circuit encrypts the debugging port circuit, and the security authentication module and the controller cooperate to manage the IO configuration information of the debugging port circuit, forming a multi-layer protection mechanism, effectively preventing untrusted debugging terminals from accessing the data of the controller and reducing the risk of data leakage.
[0233] Please refer to Figure 9 , Figure 9 which is another process schematic diagram of the security authentication method provided by the embodiment of this application. As Figure 9 shown, the method can include the following steps:
[0234] S901, the security authentication module obtains the authentication data sent by the debugging terminal.
[0235] S902, the security authentication module sends the authentication data to the security authentication server.
[0236] S903, the security authentication module obtains the authentication feedback data sent by the security authentication server.
[0237] S904, according to the authentication feedback data, determine whether the authentication data is verified successfully.
[0238] S905, when the security authentication module verifies the authentication data successfully, it sends the verification data to the controller.
[0239] It should be noted that the implementation processes of S901 to S905 are similar to those of S601 to S605, and will not be elaborated here.
[0240] S906, when the controller obtains the verification data sent by the security authentication module, it configures the IO configuration information of the debugging port circuit as the target IO configuration information.
[0241] It should be noted that the implementation processes of S906 and S401 are similar and will not be elaborated here.
[0242] In some possible embodiments, the vehicle further includes a debug port lock integrated circuit, which is used to control the working state of the debug port circuit. The working state includes a locked state or an unlocked state. When the key sent by the debug terminal matches the preset unlocking key, the debug port lock integrated circuit controls the debug port circuit to be in the unlocked state. The security authentication method applied to the controller further includes:
[0243] Obtain the target number of keys sent by the debug terminal within a preset time period.
[0244] It can be understood that in the case where the vehicle further includes a debug port lock integrated circuit, even if the IO configuration information of the debug port circuit is configured as the target IO configuration information, due to the existence of the debug port lock integrated circuit, the debug terminal still cannot access the data of the controller through the debug port circuit.
[0245] In the above technical solution, the security authentication module can send the authentication data to the security authentication server, and the security authentication server verifies the authentication data, effectively preventing an untrusted debug terminal from accessing the data of the vehicle controller and protecting the data security of the vehicle.
[0246] It should be understood that although the steps in the above flowcharts are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the above flowcharts may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.
[0247] Based on the foregoing embodiments, an embodiment of the present application provides a security authentication device, which includes each module or unit included and can be implemented by a processor; of course, it can also be implemented by specific logic circuits; in the implementation process, the processor can be a central processing unit (CPU), a microprocessor (MPU), a digital signal processor (DSP), or a field programmable gate array (FPGA), etc.
[0248] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of the security authentication device provided by the embodiment of the present application applied to the security authentication module of a vehicle, as Figure 10As shown in the figure, the security authentication device applied to the security authentication module of a vehicle includes an acquisition unit 1001, a verification unit 1002, and a sending unit 1003, where:
[0249] The acquisition unit 1001 is configured to acquire authentication data sent by a debugging terminal, where the authentication data includes first identification information of the debugging terminal.
[0250] The verification unit 1002 is configured to perform verification processing on the authentication data, where the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes multiple credit identification information.
[0251] The sending unit 1003 is configured to send verification data to a controller when the authentication data is successfully verified, so that the controller configures the IO configuration information of the debugging port circuit as target IO configuration information, and the debugging terminal can communicate with the controller through the debugging port circuit when the IO configuration information of the debugging port circuit is configured as the target IO configuration information.
[0252] In some possible embodiments, the verification unit 1002 is further configured to send the authentication data to a security authentication server; acquire authentication feedback data sent by the security authentication server, where the authentication feedback data includes a verification result of the security authentication server on the first identification information, and the verification result is used to indicate that the security authentication server successfully verifies or fails to verify the first identification information;
[0253] Judge whether the authentication data is successfully verified according to the authentication feedback data.
[0254] In some possible embodiments, the first identification information includes software identification information of a host computer application deployed by the debugging terminal and hardware identification information of the debugging terminal. The security authentication server generates a verification result indicating that the security authentication server successfully verifies the first identification information when it determines that the software identification information and the hardware identification information match according to a preset matching relationship table, and the preset matching relationship table includes the matching relationship between preset software identification information and preset hardware identification information.
[0255] In some possible embodiments, the authentication data further includes second identification information of the vehicle. The verification unit 1002 is further configured to send the authentication data to a security authentication server; acquire a first key sent by the security authentication server, where the first key is generated according to the second identification information when the security authentication server successfully verifies the first identification information; compare the first key with a second key to determine whether the authentication data is successfully verified, and the second key includes a preset key or a key generated by the security authentication module according to a preset rule.
[0256] In some possible embodiments, the authentication data further includes a target permission, and the target permission includes a read permission and / or a write permission requested by the debugging terminal. The sending unit 1003 is further configured to generate verification data according to the target permission; and send the verification data to the controller, so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information corresponding to the target permission.
[0257] Please refer to Figure 11 , Figure 11 FIG. is a schematic structural diagram of a security authentication device provided by an embodiment of the present application applied to a controller of a vehicle. As Figure 11 shown, the security authentication device applied to the controller of the vehicle includes a configuration unit 1101, where:
[0258] The configuration unit 1101 is configured to, when obtaining the verification data sent by the security authentication module, configure the IO configuration information of the debug port circuit as the target IO configuration information, where the verification data is sent by the security authentication module when the authentication data sent by the debugging terminal is successfully verified. The authentication data includes the first identification information of the debugging terminal, and the debugging terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
[0259] In some possible embodiments, the authentication data further includes a target permission, and the target permission includes a read permission and / or a write permission requested by the debugging terminal. The verification data is generated according to the target permission. The configuration unit 1101 is further configured to determine the target IO configuration information according to the verification data; and configure the IO configuration information of the debug port circuit as the target IO configuration information.
[0260] In some possible embodiments, the vehicle further includes a debug port lock integrated circuit, and the debug port lock integrated circuit is used to control the working state of the debug port circuit. The working state includes a locked state or an unlocked state. The debug port lock integrated circuit controls the debug port circuit to be in the unlocked state when the key sent by the debugging terminal matches the preset unlocking key. The security authentication device applied to the controller of the vehicle further includes a security processing unit, configured to obtain the target number of times the debugging terminal sends a key within a preset time period; and perform a security processing operation when the target number of times is greater than a preset threshold and all the keys sent by the debugging terminal do not match the preset unlocking key, where the security processing includes configuring the IO configuration information of the debug port circuit as the preset IO configuration information. When the IO configuration information of the debug port circuit is the preset IO configuration information, the debugging terminal is prohibited from communicating with the controller through the debug port circuit.
[0261] In some possible embodiments, the security processing operation further includes, when obtaining a read instruction for the debug terminal to read the original data of the controller, sending data modified based on the original data to the debug terminal, so that the data read by the debug terminal through the debug port circuit is different from the original data of the controller; or, the security processing operation further includes sending a security alarm message to the security authentication server, where the security alarm message includes first identification information.
[0262] In some possible embodiments, the vehicle further includes a debug port lock integrated circuit, which is used to control the working state of the debug port circuit. The working state includes a locked state or an unlocked state. The security processing unit is further configured to send an unlock instruction to the debug port lock integrated circuit when obtaining the verification data sent by the security authentication module, so that the debug port circuit is in an unlocked state.
[0263] The description of the above device embodiments is similar to the description of the above method embodiments and has similar beneficial effects to the method embodiments. For the technical details not disclosed in the device embodiments of the present application, please refer to the description of the method embodiments of the present application for understanding.
[0264] It should be noted that in the embodiments of the present application Figure 10 or Figure 11 The division of modules of the security authentication device shown is illustrative, and is only a logical function division. In actual implementation, there may be other division methods. In addition, each functional unit in the various embodiments of the present application may be integrated in one processing unit, may exist physically alone, or two or more units may be integrated in one unit. The above integrated unit may be implemented in the form of hardware, or in the form of a software functional unit. It may also be implemented in the form of a combination of software and hardware.
[0265] It should be noted that in the embodiments of the present application, if the above method is implemented in the form of a software functional module and sold or used as an independent product, it may also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the related technology, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing an electronic device to execute all or part of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disc that can store program codes. In this way, the embodiments of the present application are not limited to any specific combination of hardware and software.
[0266] The embodiments of the present application provide a vehicle, which includes a security authentication module, a controller, and a debug port circuit, where:
[0267] A security authentication module, configured to obtain authentication data sent by a debugging terminal, where the authentication data includes first identification information of the debugging terminal; perform verification processing on the authentication data, where the verification processing includes comparing the first identification information with pre-stored trusted data to determine whether the authentication data is successfully verified, and the trusted data includes multiple trusted identification information; in the case that the authentication data is successfully verified, send verification data to a controller, so that the controller configures the IO configuration information of a debugging port circuit as target IO configuration information, and the debugging terminal can communicate with the controller through the debugging port circuit when the IO configuration information of the debugging port circuit is configured as the target IO configuration information;
[0268] The controller is configured to configure the IO configuration information of the debugging port circuit as target IO configuration information when obtaining the verification data sent by the security authentication module.
[0269] An embodiment of the present application provides a computer device, which may be a server, and its internal structure diagram may be as Figure 12 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements the above method.
[0270] An embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the method provided in the above embodiment are implemented.
[0271] An embodiment of the present application provides a computer program product containing instructions, and when it runs on a computer, it causes the computer to execute the steps in the method provided in the above method embodiment.
[0272] Those skilled in the art can understand that Figure 12 the structure shown in
[0273] In one embodiment, the security authentication device provided by the present application can be implemented in the form of a computer program, and the computer program can run on a computer device as shown in Figure 12 . Each program module constituting the above device can be stored in the memory of the computer device. The computer program constituted by each program module enables the processor to execute the steps in the methods of the various embodiments of the present application described in this specification.
[0274] It should be noted here that the descriptions of the above storage medium and device embodiments are similar to those of the above method embodiments and have beneficial effects similar to those of the method embodiments. For the technical details not disclosed in the storage medium, storage medium and device embodiments of the present application, please refer to the descriptions of the method embodiments of the present application for understanding.
[0275] It should be understood that the term "one embodiment" or "an embodiment" or "some embodiments" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, the appearances of "in one embodiment" or "in an embodiment" or "in some embodiments" throughout the specification do not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in the various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution, and the order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application. The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages and disadvantages of the embodiments. The above descriptions of the various embodiments tend to emphasize the differences between the various embodiments, and the same or similar parts can be referred to each other. For the sake of brevity, they will not be repeated herein.
[0276] The term "and / or" in this article is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, object A and / or object B can represent: object A exists alone, object A and object B exist simultaneously, and object B exists alone. These three situations.
[0277] It should be noted that in this article, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of another identical element in the process, method, article or device comprising the element.
[0278] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple modules or components can be combined, or can be integrated into another system, or some features can be ignored, or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed with each other can be through some interfaces. The indirect coupling or communication connection of devices or modules can be electrical, mechanical, or other forms.
[0279] The modules described above as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules; they can be located in one place or distributed to multiple network units; some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0280] In addition, each functional module in the embodiments of this application can be all integrated in a processing unit, or each module can be separately used as a unit, or two or more modules can be integrated in a unit; the above-mentioned integrated modules can be implemented in the form of hardware, or in the form of a combination of hardware and software functional units.
[0281] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM), magnetic disks, or optical disks and other various media that can store program codes.
[0282] Alternatively, if the above-mentioned integrated unit of this application is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application essentially or the part that contributes to the related technology can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable an electronic device to execute all or part of the methods described in the various embodiments of this application. And the foregoing storage medium includes: removable storage devices, ROM, magnetic disks, or optical disks and other various media that can store program codes.
[0283] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0284] The features disclosed in several product embodiments provided by this application can be combined arbitrarily without conflict to obtain new product embodiments.
[0285] The features disclosed in several method or device embodiments provided by this application can be combined arbitrarily without conflict to obtain new method embodiments or device embodiments.
[0286] As described above, it is only the implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered within the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims.
Claims
1. A security authentication method, characterized in that: A safety authentication module applied to a vehicle, the vehicle further comprising a controller and a debug port circuit, the method comprising: Acquire authentication data sent by the debugging terminal, wherein the authentication data includes first identification information of the debugging terminal; Performing verification processing on the authentication data, wherein the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes multiple credit identification information; When the authentication data is successfully verified, verification data is sent to the controller so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information, wherein the debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
2. The method according to claim 1, characterized in that The verifying process of the authentication data includes: Sending the authentication data to a security authentication server; Acquire authentication feedback data sent by the security authentication server, wherein the authentication feedback data includes a verification result of the security authentication server on the first identification information, and the verification result is used to indicate whether the security authentication server successfully or failed to verify the first identification information; According to the authentication feedback data, it is determined whether the authentication data is successfully verified.
3. The method according to claim 2, characterized in that The first identification information includes the software identification information of the upper computer application deployed by the debugging terminal and the hardware identification information of the debugging terminal. When the security authentication server determines that the software identification information and the hardware identification information match according to a preset matching relationship table, it generates a verification result indicating that the security authentication server has successfully verified the first identification information. The preset matching relationship table includes the matching relationship between the preset software identification information and the preset hardware identification information.
4. The method according to claim 1, characterized in that: The authentication data also includes second identification information of the vehicle, and the verification process of the authentication data includes: Sending the authentication data to a security authentication server; Acquire a first key sent by the security authentication server, wherein the first key is generated according to the second identification information when the security authentication server successfully verifies the first identification information; The first key and the second key are compared to determine whether the authentication data is successfully verified, wherein the second key includes a preset key or a key generated by the security authentication module according to a preset rule.
5. The method according to claim 1, characterized in that The authentication data further includes target permissions, and the target permissions include read permissions and / or write permissions requested by the debugging terminal. The sending of the verification data to the controller includes: generating the verification data according to the target authority; The verification data is sent to the controller so that the controller configures the IO configuration information of the debug port circuit to be the target IO configuration information corresponding to the target authority.
6. A security authentication method, characterized in that: A controller applied to a vehicle, the vehicle further comprising a safety authentication module and a debug port circuit, the method comprising: In the case of obtaining the verification data sent by the security authentication module, the IO configuration information of the debug port circuit is configured as the target IO configuration information, wherein the verification data is sent by the security authentication module when the authentication data sent by the debug terminal is successfully verified, and the authentication data includes the first identification information of the debug terminal. The debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
7. The method according to claim 6, characterized in that The authentication data also includes target permissions, the target permissions include read permissions and / or write permissions requested by the debug terminal, the verification data is generated according to the target permissions, and the IO configuration information for configuring the debug port circuit is target IO configuration information, including: Determining the target IO configuration information according to the verification data; The IO configuration information for configuring the debug port circuit is the target IO configuration information.
8. The method according to claim 6, characterized in that The vehicle further includes a debug port lock integrated circuit, the debug port lock integrated circuit is used to control the working state of the debug port circuit, the working state includes a locked state or an unlocked state, the debug port lock integrated circuit controls the debug port circuit to be in the unlocked state when the key sent by the debug terminal matches the preset unlocking key, and the method further includes: Obtaining a target number of times that the debugging terminal sends a key within a preset time period; When the target number of times is greater than a preset threshold and all keys sent by the debug terminal do not match the preset unlocking key, a security processing operation is performed, wherein the security processing includes configuring the IO configuration information of the debug port circuit to be preset IO configuration information, wherein when the IO configuration information of the debug port circuit is the preset IO configuration information, the debug terminal is prohibited from communicating with the controller through the debug port circuit.
9. The method according to claim 8, characterized in that The security processing operation further includes, when obtaining a read instruction for the debug terminal to read the original data of the controller, sending data modified according to the original data to the debug terminal, so that the data read by the debug terminal through the debug port circuit is different from the original data of the controller; or, The security processing operation also includes sending security alarm information to a security authentication server, where the security alarm information includes the first identification information.
10. The method according to claim 6, characterized in that The vehicle further includes a debug port lock integrated circuit, the debug port lock integrated circuit is used to control the working state of the debug port circuit, the working state includes a locked state or an unlocked state, and the method further includes: In the case of acquiring the verification data sent by the security authentication module, an unlocking instruction is sent to the debug port lock integrated circuit to put the debug port circuit in the unlocked state.
11. A security authentication device, characterized in that: The device is applied to a safety authentication module of a vehicle, the vehicle further comprising a controller and a debugging port circuit, and the device comprises: An acquiring unit, configured to acquire authentication data sent by a debugging terminal, wherein the authentication data includes first identification information of the debugging terminal; a verification unit, configured to perform verification processing on the authentication data, wherein the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes a plurality of credit identification information; A sending unit is used to send verification data to the controller when the authentication data is successfully verified, so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information, and the debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information.
12. A security authentication device, characterized in that: The device is applied to a controller of a vehicle, the vehicle further comprising a safety authentication module and a debug port circuit, and the device comprises: a configuration unit, configured to configure the IO configuration information of the debug port circuit to the target IO configuration information when the verification data sent by the security authentication module is obtained, wherein the verification data is sent by the security authentication module when the authentication data sent by the debug terminal is successfully verified, and the authentication data includes the first identification information of the debug terminal, and the debug terminal can be communicated with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured to the target IO configuration information.
13. A vehicle, characterized in that: The vehicle comprises a safety authentication module, a controller and a debug port circuit, wherein: The security authentication module is used to obtain authentication data sent by the debug terminal, wherein the authentication data includes first identification information of the debug terminal; perform verification processing on the authentication data, wherein the verification processing includes comparing the first identification information with pre-stored credit data to determine whether the authentication data is successfully verified, and the credit data includes multiple credit identification information; if the authentication data is successfully verified, send the verification data to the controller so that the controller configures the IO configuration information of the debug port circuit as the target IO configuration information, and the debug terminal can communicate with the controller through the debug port circuit when the IO configuration information of the debug port circuit is configured as the target IO configuration information; The controller is used to configure the IO configuration information of the debug port circuit to the target IO configuration information when the verification data sent by the security authentication module is obtained.
14. A computer device comprising a memory and a processor, wherein the memory stores a computer program executable on the processor, wherein: When the processor executes the program, the steps of the method according to any one of claims 1 to 5 or 6 to 10 are implemented.
15. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 5 or 6 to 10 is implemented.
Citation Information
Cited By
Debugging method and device, electronic equipment and vehicle
CN120915610A
Debugging method and device, electronic equipment and vehicle
CN120915610B