Dual-redundancy automobile steering system software non-inductive upgrading method based on network security
By introducing external hardware security modules in the software sensingless upgrade process of dual redundant automotive steering systems, data is encrypted and decrypted, and breakpoint continuous transmission is achieved using checkpoints and non-volatile memory, information security and data integrity issues are solved, and the robustness and information security of the system are improved.
Patent Information
- Application Number
- CN202510443369.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-10
- Publication Date
- 2025-06-13
AI Technical Summary
During the software sensorless upgrade of dual redundant automotive steering systems, information security cannot be effectively guaranteed, especially when data transmission is interrupted, the integrity and security of transmitted data cannot be ensured.
By introducing an external hardware security module (HSM), the security of the controller firmware is verified during the software upgrade process, and the data is encrypted and decrypted during the data transmission process to ensure the security of the data. If transmission interruption occurs, use checkpoints and nonvolatile memory to achieve breakpoint continuous transmission to prevent data tampering.
It effectively improves the information security and data integrity in the sensorless upgrade of dual-redundant automotive steering system software, ensures that in the single node existence mode in the vehicle architecture, the upgrade process will not increase the workload of gateways, etc., simplifies the vehicle network system, and improves robustness and information security.
Smart Images

Figure CN120151333A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle software seamless upgrade, and specifically to a method for seamless upgrade of a dual-redundancy automotive steering system software based on network security. Background Technique
[0002] For a dual-redundancy automotive steering electronic control system with dual control core chips, communication, power supply and other modules, when performing software seamless upgrade (FOTA) on the electronic control system, it is necessary to upgrade the two control chips on the electronic control hardware board and upgrade the two control units respectively, which takes a long time and is difficult to ensure information security.
[0003] When performing seamless upgrade on a dual-redundancy automotive steering system, in the vehicle's electronic and electrical architecture, it is generally initiated by the body gateway unit. The gateway initiates an upgrade network message. In the dual-redundancy architecture, the main control chip receives the upgrade message and starts to trigger the software upgrade process. At the same time, it forwards the upgrade message to the auxiliary control chip until the auxiliary control chip also enters the upgrade process and replies with a positive response message to the main unit. After the main unit makes a logical judgment on the reply message, it uniformly replies to the gateway. After receiving the positive response, the gateway unit proceeds with the next upgrade process according to the defined upgrade specification process.
[0004] However, during the data transmission process, it is impossible to judge the information security of external data messages in the network, and during the upgrade process, if a transmission interruption occurs, it is impossible to ensure that the transmitted data has not been tampered with during the continued transmission. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to overcome the existing defects and provide a method for seamless upgrade of a dual-redundancy automotive steering system software based on network security, which can effectively solve the problems in the background technique.
[0006] To achieve the above object, the present invention discloses a method for seamless upgrade of a dual-redundancy automotive steering system software based on network security. The technical solution adopted is as follows: Step 1: Start the external hardware security module (HSM) and verify the security of the controller firmware. If the firmware is secure, proceed to Step 2; if the firmware is not secure, end the upgrade. Here, the hardware security module examines the security of the firmware by checking the firmware integrity and secret key; Step 2: Identify the software operation partition and report the partition information to the server side; Step 3: Judge the master-slave relationship between the two control chips of the dual-redundancy automotive steering system control unit. Since both control chips are communicatively connected to the body gateway unit, it is necessary to first judge the master-slave relationship during the upgrade; Step 4: Initialize other software and load the software configuration of the corresponding unit until the application software starts running. During the running process of the application software, the body gateway unit or the diagnostic instrument sends an upgrade request to the main control chip to activate the upgrade mode of the main control chip. The main control chip sends an upgrade instruction to the auxiliary control chip through the internal communication network to activate the upgrade mode of the auxiliary control chip. The body gateway unit encrypts the upgrade data packet through the external hardware security module and transmits it to the main control chip. The built-in hardware security module of the main control chip decrypts, verifies, and stores the upgrade data packet. The main control chip transmits the upgrade data to the auxiliary control chip. The hardware security module can prevent the upgrade data packet from being intercepted and tampered with during the transmission process. Before starting the upgrade, the original data is saved. During the upgrade process, the written data is encrypted by the hardware security module and then transmitted. If a transmission interruption occurs, the address of the written data is stored or a data checkpoint is established for storage. After re-establishing the transmission channel, the transmission continues through the stored address or checkpoint. When resuming the transmission, the stored encrypted data is first decrypted by the hardware security module and then the transmission continues. This operation can prevent the data from being tampered with during the resume of interrupted transmission. Step 5: Perform software upgrade according to the upgrade process. Step 6: After the upgrade is completed, verify the complete firmware package and store the verification value as the security root data for subsequent verification reference of the firmware package.
[0007] As a preferred technical solution of the present invention, in the step 2, the software identifies the partition where the current software is running by accessing the control chip register.
[0008] As a preferred technical solution of the present invention, in the step 3, the body gateway unit sends software identification information to the main control chip. The identification information is sent by the main control chip to the auxiliary control chip through the internal communication network. The main control chip verifies and collects the messages and then sends them to the gateway unit uniformly.
[0009] As a preferred technical solution of the present invention, in the step 4, when data communication and transmission are carried out among the main control chip, the auxiliary control chip, and the body gateway unit, the data source first encrypts the data through the hardware security module at the data source end and then transmits it. After reaching the data receiving end, the built-in hardware security module at the data receiving end first decrypts the data and then verifies and stores it to ensure the communication security between the main control chip and the body gateway unit.
[0010] As a preferred technical solution of the present invention, in step 4, during the software upgrade, the vehicle body gateway unit sends an upgrade network message to the main control chip. After receiving and processing the upgrade network message, the main control chip verifies the security of the upgrade network message through the hardware security module, and then forwards it to the auxiliary control chip through the internal communication network. The auxiliary control chip no longer performs security verification to improve efficiency, but both the main control chip and the auxiliary control chip need to verify the integrity and accuracy of the data.
[0011] As a preferred technical solution of the present invention, in step 4, the transmission interruption during the upgrade process is divided into normal power-off and unexpected interruption. If it is a normal power-off, the address of the written data is stored in the non-volatile memory. After the next power-on, the transmission channel is established again, and the software upgrade starts from the stored address; if it is an unexpected interruption, a checkpoint is defined, and the checkpoint is stored in the non-volatile memory. When the upgrade is re-initiated, the resume transmission address is obtained through the checkpoint.
[0012] As a preferred technical solution of the present invention, the firmware check in step 6 is verified by a hardware security module built into the main control chip and a security module built into the auxiliary control chip.
[0013] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention ensures the information security of the steering system by introducing a hardware security module during the software upgrade process of the steering system. The method of upgrading in the steering system software itself ensures the single-node existence mode in the whole vehicle architecture, and the workload of its gateway, etc., will not be increased during the upgrade, which greatly simplifies the whole vehicle network system. By sending the upgrade message from the main control chip to the auxiliary control chip, the internal upgrade logic is completely controlled by the automobile steering system itself, and other components will not be affected. The main control chip verifies the information security of the main upgrade data through the hardware security module, and the auxiliary control chip no longer verifies, reducing the hardware operation load rate of the auxiliary control chip. The network security guarantee is added to the breakpoint resumption mechanism, which greatly improves the security of the upgrade data and ensures the robustness and information security of the automobile steering gear electronic control. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 This is a schematic diagram of the startup and upgrade process of the present invention; Figure 2 This is a schematic diagram of the non-sensing upgrade interaction mode of the present invention; Figure 3 This is a schematic diagram of the message flow of the non-sensing upgrade of the present invention; Figure 4 It is a schematic diagram of the breakpoint resume transmission mechanism of the present invention. DETAILED DESCRIPTION
[0015] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Example 1
[0016] like Figures 1 to 4 As shown, the present invention discloses a method for non-sensing software upgrade of a dual-redundant automobile steering system based on network security, and the technical solution adopted is, comprising the following steps: Step 1, such as Figure 1 As shown, the external hardware security module is started to check the security of the firmware in the non-volatile memory. If the firmware is safe, proceed to step 2. If the firmware is not safe, the upgrade is terminated. Step 2: The software identifies the partition where the current software is running by accessing the register of the control chip. When the upgrade starts, the partition information is reported to the gateway, and the gateway reports it to the server through the Tbox unit. Step 3: The vehicle body gateway unit sends software identification information to the main control chip, which is then sent to the auxiliary control chip via the internal communication network. The main control chip verifies and collects the information and then sends it to the gateway unit. Step 4, initialize other software and load the software configuration of the corresponding unit until the application software starts to run. During the application software running process, Figure 2 , Figure 3 As shown, the vehicle body gateway unit or the diagnostic instrument sends an upgrade request to the main control chip to activate the main control chip upgrade mode. The main control chip sends an upgrade instruction to the auxiliary control chip through the internal communication network to activate the auxiliary control chip upgrade mode. When the main control chip and the vehicle body gateway unit are communicating and transmitting data, the vehicle body gateway unit first sends the upgrade network message to the external hardware security module to encrypt the data, and then transmits it to the built-in hardware security module at the main control chip. The built-in hardware security module at the main control chip decrypts the data and performs security verification. At the same time, the main control chip compares the received data with the cloud data. If the data is safe after verification and the data is complete and accurate after comparison with the cloud data, it will be written into the non-volatile memory of the main control unit. If at least one of the security, integrity, and accuracy of the data is abnormal, the data received in the external hardware security module at the main control chip will be erased, and a message will be sent to the vehicle body gateway unit to retransmit the upgrade network message. Before starting the upgrade, save the original data. Figure 4As shown, the data is split into multiple parts using checkpoints. The written data is encrypted by the built-in hardware security module of the control chip and stored in the secure area. Each time a checkpoint is reached, the checkpoint is stored in the non-volatile memory. During the upgrade process, if a transmission interruption occurs, it is divided into two types: normal power-off and unexpected interruption according to the cause of the interruption. If it is a normal power-off, the address of the written data is stored in the non-volatile memory. After the next power-on, the transmission channel is re-established, and the software upgrade starts from the stored address. If it is an unexpected interruption, the data from the last stored checkpoint to the current transmission position will be erased. After re-establishing the transmission channel, the resume address is obtained through the last stored checkpoint. Step 5: The main control chip forwards the upgrade network message with qualified verification to the auxiliary control chip through the internal communication network, and the auxiliary control chip does not perform security verification again. Step 6: After the upgrade is completed, the built-in hardware security module of the main control chip and the built-in security module of the auxiliary control chip perform verification, and the verification value is stored as the secure root data. Each time it is started later, the built-in hardware security module calculates the encryption of the current firmware parameters according to the key, and compares the calculation result with the secure root data. If the comparison is correct, it can be started.
[0017] The circuit and mechanical connections involved in the present invention are common means adopted by those skilled in the art and can obtain technical inspiration through a limited number of experiments, which belong to common general knowledge.
[0018] The components not described in detail in this article are prior art.
[0019] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A method for non-sensing software upgrade of dual-redundant automobile steering system based on network security, characterized in that: The following steps are involved: Step 1: Start the external hardware security module to verify the security of the controller firmware. If the firmware is safe, proceed to step 2. If the firmware is not safe, end the upgrade. Step 2: Identify the partition where the software is running and report the partition information to the server; Step 3, determining the master-slave relationship between two control chips of the dual-redundant automobile steering system control unit; Step 4: Initialize other software and load the software configuration of the corresponding units until the application software starts to run. During the running of the application software, the vehicle body gateway unit or the diagnostic instrument sends an upgrade request to the main control chip to activate the upgrade mode of the main control chip. The main control chip sends an upgrade instruction to the auxiliary control chip through the internal communication network to activate the upgrade mode of the auxiliary control chip. The vehicle body gateway unit encrypts the upgrade data packet through the external hardware security module and transmits it to the main control chip. The built-in hardware security module of the main control chip decrypts the upgrade data packet, verifies and stores it, and the main control chip transmits the upgrade data to the auxiliary control chip. Before starting the upgrade, the original data is saved. During the upgrade process, it is encrypted and transmitted through the hardware security module. If the transmission is interrupted, the address of the written data is stored or a data checkpoint is established for storage. After the transmission channel is established again, the data is resumed through the stored address or checkpoint. When resuming the transmission, the hardware security module is used to decrypt the stored encrypted data before resuming the transmission. Step 5: Upgrade the software according to the upgrade process; Step 6: After the upgrade is completed, the complete firmware package is verified and the verification value is stored as the security root data.
2. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 1 is characterized in that: In step 2, the software identifies the partition where the current software is running by accessing the control chip register.
3. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 1 is characterized in that: In step 3, the vehicle body gateway unit sends software identification information to the main control chip, and the identification information is sent by the main control chip to the auxiliary control chip through the internal communication network. The main control chip verifies and collects the messages and sends them to the gateway unit.
4. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 1 is characterized in that: In step 4, when data communication is being transmitted between the main control chip, the auxiliary control chip, and the vehicle body gateway unit, the data source first sends the data to the hardware security module at the data source end to encrypt the data, and then transmits the data. After reaching the data receiving end, the built-in hardware security module at the data receiving end first decrypts the data, and then verifies and saves it.
5. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 4 is characterized in that: In step 4, during the software upgrade process, the vehicle body gateway unit sends an upgrade network message to the main control chip. After receiving and processing the upgrade network message, the main control chip verifies the security of the upgrade network message through the built-in hardware security module, and then forwards it to the auxiliary control chip through the internal communication network. The auxiliary control chip no longer performs security verification, but both the main control chip and the auxiliary control chip need to verify the integrity and accuracy of the data.
6. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 1 is characterized in that: In step 4 and step 5, the transmission data is segmented, and the segmentation points are checkpoints; the transmission interruption during the upgrade process is divided into normal power-off and accidental interruption. If it is a normal power-off, the specific address of the written data is stored in the non-volatile memory. After the next power-on, the transmission channel is established again, and the software upgrade starts from the stored address; If it is an unexpected interruption, the completed checkpoint will be stored in the non-volatile memory, and the resume address will be obtained through the completed checkpoint when the upgrade is re-initiated.
7. The method for non-sensing software upgrade of dual-redundant automobile steering system based on network security according to claim 1 is characterized in that: The firmware check in step 6 is verified by the hardware security module built into the main control chip and the security module built into the auxiliary control chip.