ECU secret key safety filling method and system

Through mTLS protocol and ECU root key encryption technology, the identity forgery, leakage and tampering problems during the ECU key filling process are solved, and the secure transmission and storage of keys are realized, and the security of automobile information is improved.

CN120238306APending Publication Date: 2025-07-01SHENZHEN ROADROVER TECH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510614770.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In the prior art, the identity legitimacy of the key filling machine (KLM) cannot be verified during the ECU key filling process. The key is exposed in plain text during the transmission process and lacks two-way identity authentication, resulting in high risks of identity forgery, key leakage and tampering, and cannot meet the security requirements of modern automobile production.

Method used

The two-way secure communication protocol mTLS protocol is used for authentication, combined with the certificate two-way verification mechanism, and the ECU root key public key is used for asymmetric encryption, so that the legality and integrity of the key is ensured through multi-signature verification, and the key is stored securely in the ECU hardware security module.

Benefits of technology

Effectively prevent forged identity attacks, ensure the confidentiality of key transmission and storage, improve the security level of automotive information, eliminate the risks of key leakage and tampering, and realize the security and integrity of the key filling process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238306A_ABST
    Figure CN120238306A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of automobile electronics, and particularly relates to an ECU secret key safety filling method and system. Bidirectional identity authentication is carried out, a secure communication channel between the KLM and the KMS is established by adopting an mTLS protocol, and identity counterfeiting attack is prevented in combination with a certificate bidirectional verification mechanism; secret key encryption transmission: carrying out asymmetric encryption on a secret key plaintext by using an ECU root secret key public key; multiple signature verification is carried out, ECU identity information is signed through a KLM working key private key, a key ciphertext is signed through the KMS working key private key, a KMS working key public key is signed through the KLM working key private key, and the ECU verifies the KLM identity legality and verifies the key integrity twice; the technical problems of identity counterfeiting and secret key leakage and tampering in the traditional secret key filling process are effectively solved, the purposes of secure transmission and secret key storage in the secret key filling process are achieved, and the automobile information security level is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of automotive electronics, and particularly relates to an ECU key security filling method and system. Background Art

[0002] In the key filling production process of an automotive electronic control unit (ECU), as a brand-new component, the ECU has no keys in its hardware security module. Therefore, the prior art usually cannot verify the identity legality of the key filling host computer (KLM). And for the same reason, the keys to be filled are exposed in plain text in the communication channel between the KLM and the ECU during transmission, and the key integrity is not verified. In addition, there is a lack of two-way identity authentication between the KLM and the key management system (KMS). Such technical defects lead to the following prominent problems:

[0003] Risk of identity forgery: An attacker can forge the KLM identity to deceive the KMS and the ECU, resulting in illegal key injection; Risk of key leakage: The keys transmitted in plain text are easily stolen, and there is a risk of leakage in the plain text storage of the keys outside the ECU hardware security module; Risk of key tampering: An attacker can intercept and tamper with the key data in the communication channel, destroying the key integrity.

[0004] The above technical defects pose a serious security threat to the ECU key filling production process and cannot meet the high standards for key filling confidentiality, integrity, and source legality in the modern automotive production process. Summary of the Invention

[0005] The purpose of the present invention is to provide an ECU key security filling method and system, which effectively eliminates the risks of identity forgery, key leakage, and tampering during the key filling process, realizes the goal of securely transmitting and storing keys during the key filling process, significantly improves the automotive information security level, and solves the problems raised in the above background art.

[0006] To achieve the above purpose, the present invention adopts the following technical solution: An ECU key security filling method, including the following steps:

[0007] The KLM and the KMS mutually verify their identities through a two-way secure communication protocol and establish a secure connection. The KLM obtains a list of keys to be filled from the KMS; the list of keys to be filled includes the types of cryptographic algorithms supported by the KMS and the ECU, the ECU identity information, and the basic information of the keys to be filled;

[0008] KLM selects an asymmetric key algorithm and a hash algorithm as the selected algorithms according to the types of algorithms supported by the KMS and the ECU in the key list to be filled, generates an asymmetric key pair as the KLM working key, and generates the KLM first authentication information based on the ECU identity information in the key list to be filled. Then, it sends a request for generating the ECU root key containing the KLM first authentication information and the selected algorithms to the ECU through the vehicle communication protocol.

[0009] After the ECU verifies the KLM first authentication information and confirms the legality of the KLM identity, it generates the ECU root key through the hardware security module, securely stores the private key, and returns the public key to the KLM.

[0010] The KLM sends the ECU root key public key and the selected algorithms to the KMS, requests to generate the KMS working key, and the KMS generates an asymmetric key pair as the KMS working key based on the selected asymmetric key algorithm.

[0011] The KLM requests the ciphertext of the key to be filled, its signature value, and the public key of the KMS working key from the KMS. The KMS encrypts the plaintext of the key to be filled with the public key of the ECU root key to generate the ciphertext and signs it with the private key of the KMS working key, and then returns them to the KLM together with the public key of the KMS working key.

[0012] The KLM calculates the KLM second authentication information and sends a key filling request containing the key ciphertext, the key ciphertext signature value, and the KLM second authentication information to the ECU.

[0013] The ECU verifies the KLM second authentication information and the key ciphertext signature value in sequence. After confirming the legality of the KLM identity and the integrity of the key ciphertext, it decrypts the key ciphertext and securely stores the plaintext.

[0014] The ECU feeds back the key filling result to the KLM. If it is successful, it marks the current key as filled, and the KLM updates the status of the key list according to the filling result.

[0015] Preferably, the two-way secure communication protocol is the mTLS protocol, which includes a two-way authentication mechanism for the server certificate and the client certificate.

[0016] Preferably, the asymmetric key algorithm is the RSA-2048 algorithm, and the hash algorithm is the SHA-256 algorithm.

[0017] Preferably, the generation of the KLM first authentication information includes:

[0018] Sign the ECU identity information with the private key of the KLM working key, and use the signature value and the public key of the KLM working key as the KLM first authentication information.

[0019] Preferably, the verification of the KLM first authentication information includes:

[0020] Using the KLM working key public key in the KLM first authentication information to verify the signature value in the KLM first authentication information.

[0021] Preferably, the generation of the ECU root key by the hardware security module, securely storing the private key, and returning the public key to KLM includes:

[0022] The hardware security module generates a true random number based on the hardware real-time temperature, time, and voltage as the entropy value, and uses this true random number as the key seed;

[0023] Performing a key generation operation based on the key seed using a selected asymmetric key algorithm to generate an asymmetric key pair as the ECU root key;

[0024] Storing the ECU root key private key in the secure storage unit of the hardware security module, and returning the ECU root key public key to KLM through the vehicle communication protocol.

[0025] Preferably, the calculation of the KLM second authentication information includes:

[0026] Using the KLM working key private key to sign the KMS working key public key, and using the signature value as the KLM second authentication information.

[0027] Preferably, the ECU sequentially verifies the KLM second authentication information and the key ciphertext signature value, including:

[0028] The ECU uses the KLM working key public key to verify the KLM second authentication information;

[0029] After the KLM second authentication information is verified, the ECU uses the KMS working key public key to verify the key ciphertext signature value.

[0030] Preferably, the decryption of the key ciphertext and the secure storage of the plaintext include:

[0031] Using the ECU root key private key to decrypt the key ciphertext, and storing the obtained key plaintext in the secure storage unit of the hardware security module.

[0032] On the other hand, the present invention proposes an ECU key secure filling system, including:

[0033] A KMS module for performing: implementing mutual authentication with KLM by exchanging certificates through the mTLS protocol; providing a list of keys to be filled to KLM; receiving the ECU root key public key; generating a KMS working key; providing the key ciphertext to be filled and its signature value, as well as the KMS working key public key to KLM;

[0034] The KLM module is used to perform the following: establish a secure connection with the KMS through the mTLS protocol; request a list of keys to be filled from the KMS; select an algorithm and generate a KLM working key; send an ECU root key generation request; provide the ECU root key public key to the KMS; request the generation of a KMS working key; send a key filling request; generate multi-factor authentication information to support ECU authentication.

[0035] The ECU module includes a hardware security module and is used to perform the following: parse the ECU root key generation request and verify the identity of the KLM, generate and securely store the ECU root key, and provide the ECU root key public key to the KLM; parse the key filling request and verify the identity of the KLM, verify the key integrity, and complete key decryption and storage; feedback the filling result to the KLM. Among them, the hardware security module has a secure storage unit, and the confidentiality of the stored keys is guaranteed through access control. The access control means that the keys written into the secure storage unit can only be accessed by the hardware security module, and the plaintext of the keys written into the secure storage unit cannot be read from outside the hardware security module.

[0036] The technical effects and advantages of the present invention: An ECU key secure filling method and system proposed by the present invention have the following advantages compared with the prior art:

[0037] In the present invention, for two-way authentication, the mTLS protocol is used to establish a secure communication channel between the KLM and the KMS, combined with a certificate two-way verification mechanism to prevent forged identity attacks; for key encrypted transmission, the ECU root key public key is used to perform asymmetric encryption on the key plaintext to ensure the confidentiality of the transmission process; for multi-signature verification, the ECU identity information is signed with the KLM working key private key, the key ciphertext is signed with the KMS working key private key, and the KMS working key public key is signed with the KLM working key private key. The ECU verifies the legitimacy of the KLM identity and the key integrity twice to ensure the key integrity and the legitimacy of the source; for key secure storage, relying on the secure storage unit of the ECU hardware security module and the root key generation mechanism based on true random numbers, the risk of key plaintext exposure is eliminated. It effectively solves the technical problems of identity forgery, key leakage and tampering in the traditional key filling process, realizes the goal of securely transmitting and storing keys in the key filling process, and significantly improves the automotive information security level. Description of the Drawings

[0038] Figure 1 It is the working flow chart of the ECU key secure filling system of the present invention;

[0039] Figure 2 It is the schematic diagram of the ECU key secure filling system of the present invention. Detailed Embodiments

[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0041] Embodiment 1

[0042] The present invention provides an ECU key security filling method, including the following steps:

[0043] KLM and KMS mutually verify their identities through a two-way secure communication protocol and establish a secure connection. KLM obtains the key list to be filled from KMS. Further, the two-way secure communication protocol is the mTLS protocol, which includes a two-way authentication mechanism for server certificates and client certificates.

[0044] The key list to be filled includes the types of cryptographic algorithms supported by KMS and ECU, ECU identity information, and basic information of the key to be filled.

[0045] KLM selects an asymmetric key algorithm (RSA-2048 algorithm) and a hash algorithm (SHA-256 algorithm) as the selected algorithms according to the types of algorithms supported by KMS and ECU in the key list to be filled, generates an asymmetric key pair as the KLM working key, and generates the KLM first authentication information based on the ECU identity information in the key list to be filled. Then, it sends an ECU root key generation request containing the KLM first authentication information and the selected algorithms to the ECU through the vehicle communication protocol. Further, generating the KLM first authentication information includes:

[0046] Sign the ECU identity information using the private key of the KLM working key, and use the signature value and the public key of the KLM working key as the KLM first authentication information.

[0047] After the ECU verifies the KLM first authentication information and confirms the legitimacy of the KLM identity, it generates the ECU root key through the hardware security module, securely stores the private key, and returns the public key to KLM. Further, verifying the KLM first authentication information includes:

[0048] Verify the signature value in the KLM first authentication information using the public key of the KLM working key in the KLM first authentication information.

[0049] Further, the process of generating the ECU root key through the hardware security module, securely storing the private key, and returning the public key to KLM includes:

[0050] The hardware security module generates true random numbers based on the real-time temperature, time, and voltage of the hardware as entropy values, and uses the true random numbers as key seeds;

[0051] Performs key generation operations based on the key seeds using a selected asymmetric key algorithm to generate an asymmetric key pair as the ECU root key;

[0052] Stores the private key of the ECU root key in the secure storage unit of the hardware security module, and returns the public key of the ECU root key to the KLM via the in-vehicle communication protocol.

[0053] The KLM sends the public key of the ECU root key and the selected algorithm to the KMS, requesting to generate a KMS working key. The KMS generates an asymmetric key pair as the KMS working key based on the selected asymmetric key algorithm;

[0054] The KLM requests the ciphertext of the key to be loaded, its signature value, and the public key of the KMS working key from the KMS. The KMS encrypts the plaintext of the key to be loaded using the public key of the ECU root key to generate the ciphertext and signs it using the private key of the KMS working key, and returns them to the KLM together with the public key of the KMS working key;

[0055] The KLM calculates the second authentication information of the KLM and sends a key loading request containing the key ciphertext, the signature value of the key ciphertext, and the second authentication information of the KLM to the ECU; Further, calculating the second authentication information of the KLM, including:

[0056] Signs the public key of the KMS working key using the private key of the KLM working key, and uses the signature value as the second authentication information of the KLM.

[0057] The ECU sequentially verifies the second authentication information of the KLM and the signature value of the key ciphertext. After confirming the legitimacy of the KLM's identity and the integrity of the key ciphertext, it decrypts the key ciphertext and securely stores the plaintext; Further, the ECU sequentially verifies the second authentication information of the KLM and the signature value of the key ciphertext, including:

[0058] The ECU verifies the second authentication information of the KLM using the public key of the KLM working key;

[0059] After the verification of the second authentication information of the KLM passes, the ECU verifies the signature value of the key ciphertext using the public key of the KMS working key.

[0060] Further, the decrypting the key ciphertext and securely storing the plaintext includes:

[0061] Decrypts the key ciphertext using the private key of the ECU root key, and stores the obtained key plaintext in the secure storage unit of the hardware security module.

[0062] The ECU feeds back the key filling result to the KLM. If successful, the current key is marked as filled, and the KLM updates the key list status according to the filling result.

[0063] Embodiment 2

[0064] In this embodiment, an ECU key security filling system is proposed, including:

[0065] The KMS module is used to perform: implementing two-way authentication by exchanging certificates with the KLM through the mTLS protocol; providing the KLM with the list of keys to be filled; receiving the ECU root key public key; generating the KMS working key; providing the KLM with the ciphertext of the key to be filled and its signature value, as well as the KMS working key public key;

[0066] The KLM module is used to perform: establishing a secure connection with the KMS through the mTLS protocol; requesting the KMS for the list of keys to be filled; selecting an algorithm and generating the KLM working key; sending a request for generating the ECU root key; providing the KMS with the ECU root key public key; requesting the generation of the KMS working key; sending a key filling request; generating multi-factor authentication information to support the ECU for authentication;

[0067] The ECU module includes a hardware security module, which is used to perform: parsing the ECU root key generation request and verifying the identity of the KLM, generating and securely storing the ECU root key, and providing the KLM with the ECU root key public key; parsing the key filling request and verifying the identity of the KLM, verifying the key integrity and completing the key decryption and storage; feeding back the filling result to the KLM; Further, the hardware security module has a secure storage unit, which ensures the confidentiality of the stored keys through access control. The access control means that the keys written into the secure storage unit can only be accessed by the hardware security module, and the plaintext of the keys written into the secure storage unit cannot be read from outside the hardware security module.

[0068] Specifically, the KMS is used to mutually verify the identity with the KLM and establish a secure communication connection, provide the KLM with the list of keys to be filled; and receive the ECU root key public key, the selected asymmetric key algorithm and hash algorithm sent by the KLM, and generate the KMS working key using the selected asymmetric key algorithm; and calculate the ciphertext of the key to be filled and its signature value using the ECU root key public key and the KMS working key private key in cooperation with the selected asymmetric key algorithm and hash algorithm; and send the ciphertext of the key to be filled and its signature value and the KMS working key public key to the KLM.

[0069] Specifically, the KMS is a computer system held and managed by the vehicle manufacturer, which stores the KMS database. The KMS database records the types of cryptographic algorithms supported by the KMS, the types of cryptographic algorithms supported by the ECU, the ECU identity information, the basic information of all keys to be loaded into the ECU, etc. The identity information of the ECU refers to the information that can be used to identify and determine the uniqueness of the ECU identity, such as the supplier code, part number, and serial number SN, etc. The basic information of the key to be loaded refers to the information that can be used to identify and find the key to be loaded, such as the key ID, key name, etc.

[0070] Specifically, the KMS can be connected to the Internet and has a server root certificate and a server certificate to support mutual authentication of identity legality with the KLM through the mTLS protocol and establish a secure communication connection.

[0071] Specifically, the KLM is used to mutually verify the identity with the KMS and establish a secure communication connection, obtain the list of keys to be loaded from the KMS; and select a symmetric key algorithm and a hash algorithm to generate the first KLM authentication information, send an ECU root key generation request to the ECU; and send the ECU root key public key and the selected asymmetric key algorithm and hash algorithm to the KMS, request to generate the KMS working key; and request the ciphertext of the key to be loaded and its signature value and the KMS working key public key from the KMS; and calculate the second KLM authentication information, send a key loading request to the ECU; and decide whether to continue the key loading.

[0072] Specifically, the KLM is a production control computer located at the production line station. The KLM is connected to the KMS through the Internet. The KLM has a server root certificate and a client certificate issued by the KMS to support mutual authentication of identity legality with the KMS through the mTLS protocol and establish a secure communication connection.

[0073] Specifically, the KLM is connected to the ECU through the in-vehicle Ethernet bus.

[0074] Specifically, the ECU is an intelligent cockpit domain controller, which is used to receive the ECU root key generation request sent by the KLM and verify the identity of the KLM; and send the ECU root key public key to the KLM; and receive the key loading request sent by the KLM, verify the identity of the KLM again, and verify the ciphertext of the key to be loaded; and send the key loading result to the KLM.

[0075] Specifically, the ECU includes a hardware security module, which is used to generate the ECU root key and decrypt the ciphertext of the key to be loaded. The hardware security module does not provide an external interface for reading the clear text of the key, and the clear text of the key cannot be read outside the hardware security module.

[0076] Specifically, the hardware security module has a secure storage unit for securely storing the ECU root key private key and the loaded key. The keys stored in the secure storage unit can only be accessed by the hardware security module, and the clear text of the keys cannot be read outside the hardware security module.

[0077] In addition, each of the above modules is also used to implement other steps of an ECU key secure loading method as described above when executed, specifically as follows, such as Figure 1 and Figure 2 shown:

[0078] Referring to the accompanying Figure 1 of the specification of the present invention, the present invention provides a preferred embodiment of an ECU key secure loading method, including:

[0079] Step S1: The KLM and the KMS mutually verify their identities and establish a secure communication connection, and the KLM obtains the list of keys to be loaded from the KMS.

[0080] Specifically, the step S1 includes:

[0081] S1.1: The KLM establishes a secure communication connection with the KMS through the mTLS protocol.

[0082] The mTLS two-way transport layer security protocol is an extension of the TLS protocol, which realizes two-way authentication between the client and the server, and is especially suitable for usage scenarios with a limited number of clients and a closed environment.

[0083] Specifically, the step of establishing the secure communication connection includes: The KLM sends an mTLS handshake request to the KMS; after receiving the handshake request from the KLM, the KMS sends its server certificate to the KLM and at the same time requests the KLM to provide its client certificate; after receiving the server certificate, the KLM uses the public key in the server root certificate to verify the validity of the server certificate; after the KLM verifies the server certificate, it sends its client certificate to the KMS; after receiving the client certificate, the KMS uses the public key in the server root certificate to verify the validity of the client certificate; after the KMS verifies the client certificate, the handshake is completed and the secure communication connection is established.

[0084] S1.2: The KLM obtains the list of keys to be loaded from the KMS through the mTLS protocol.

[0085] The list of keys to be filled refers to a set of data collected by the KMS from its KMS database and jointly determined by the vehicle manufacturer and the ECU supplier during the ECU R & D stage, including the types of cryptographic algorithms supported by the KMS, the types of cryptographic algorithms supported by the ECU, the identity information of the ECU, the basic information of all keys to be filled in the ECU, etc. The identity information of the ECU refers to the information that can be used to identify and determine the uniqueness of the ECU identity, such as the supplier code, part number, and serial number SN, etc. The basic information of the key to be filled refers to the information that can be used to identify and find the key to be filled, such as the key ID, key name, etc.

[0086] Step S2: The KLM selects a key algorithm, generates the first authentication information of the KLM, and sends an ECU root key generation request to the ECU.

[0087] Specifically, the step S2 includes:

[0088] S2.1: The KLM determines the ECU that needs to perform the key filling process according to the identity information of the ECU in the list of keys to be filled.

[0089] S2.2: The KLM selects an asymmetric key algorithm and a hash algorithm from the intersection of the types of cryptographic algorithms supported by the KMS, the ECU, and the KLM itself according to the types of cryptographic algorithms supported by the KMS and the ECU in the list of keys to be filled. Specifically, the RSA - 2048 algorithm is selected as the asymmetric key algorithm, and the SHA - 256 is selected as the hash algorithm.

[0090] S2.3: The KLM performs cryptographic key generation operations using the RSA - 2048 algorithm to obtain the KLM working key public key pK_klm and the KLM working key private key sK_klm.

[0091] S2.4: The KLM performs cryptographic hash operations on the identity information of the ECU in the list of keys to be filled using the SHA - 256 algorithm to obtain the hash value H_ecu, and then performs cryptographic signature operations on the hash value H_ecu using the KLM working key private key sK_klm and the RSA - 2048 algorithm to obtain the ECU identity information signature value S_ecu. The ECU identity information signature value S_ecu and the KLM working key public key pK_klm are used as the first authentication information of the KLM.

[0092] S2.5: The KLM sends an ECU root key generation request message to the ECU through the in - vehicle Ethernet bus UDS protocol Ox31 service, including but not limited to the ECU root key generation routine identifier, the selected RSA - 2048 algorithm and SHA - 256 algorithm, the first authentication information of the KLM, etc.

[0093] Step S3: The ECU verifies the identity of the KLM.

[0094] Specifically, the step S3 includes:

[0095] S3.1: The ECU monitors the in-vehicle Ethernet bus, receives and parses the UDS protocol ECU root key generation request message, determines that the asymmetric key algorithm selected by the KLM is RSA-2048 and the hash algorithm is SHA-256, and obtains the signature value S_ecu of the ECU identity information in the first identity authentication information of the KLM and the public key pK_klm of the KLM working key.

[0096] S3.2: The ECU calls the OpenSSL software cryptographic library hash interface EVP_Digest, performs a cryptographic hash operation on the ECU identity information held by the ECU itself using the SHA-256 algorithm to obtain the hash value H_ecu', and then calls the OpenSSL software cryptographic library signature verification interface RSA_verify, uses the RSA-2048 algorithm, the public key pK_klm of the KLM working key, and the hash value H_ecu' to perform a cryptographic signature verification operation on the ECU identity information signature value S_ecu. The ECU identity information held by the ECU itself is not obtained from the KLM, but is written into the ECU by the ECU supplier prior to the key capping process during the ECU production process, and is exactly the same as the ECU identity information held by the KMS.

[0097] It can be understood that the ECU identity information is not transmitted between the KLM and the ECU, avoiding the possibility of the ECU identity information being stolen by an attacker.

[0098] It can be understood that according to step S1, the KLM can obtain the ECU identity information only after passing the identity authentication of the KMS. Therefore, if the result of the cryptographic signature verification operation on the ECU identity information signature value S_ecu is correct, it can be inferred that the KLM has the ECU identity information, and then the ECU can be sure that the KLM has a legal identity.

[0099] S3.3: The ECU confirms the identity of the KLM according to the verification result of the ECU identity information signature value S_ecu. If the verification result of the ECU identity information signature value is correct, the identity of the KLM is legal, and step S4 is continued; otherwise, an ECU root key generation negative response message is sent to the KLM through the UDS protocol Ox7F response code of the in-vehicle Ethernet bus, notifying the KLM that the signature verification fails.

[0100] Step S4: The ECU generates the ECU root key through the ECU hardware security module and securely stores the ECU root key private key, and sends the ECU root key public key to the KLM.

[0101] Specifically, step S4 includes:

[0102] S4.1: The ECU uses the RSA-2048 algorithm through the ECU hardware security module to perform cryptographic key generation operations, randomly generating the ECU root key public key pK and the ECU root key private key sK.

[0103] Specifically, the random generation means that the ECU hardware security module uses its current entropy value as a seed for key generation. The entropy value is a true random value related to random signal noises such as the temperature, time, voltage, and current of the ECU hardware security module at that time, which can ensure the true randomness of the generated ECU root key.

[0104] S4.2: The ECU hardware security module stores the ECU root key private key sK in the secure storage unit of the ECU hardware security module.

[0105] S4.3: The ECU sends a positive response message for ECU root key generation to the KLM through the in-vehicle Ethernet bus UDS protocol Ox71 response code, which contains the ECU root key public key pK.

[0106] Step S5: The KLM sends the ECU root key public key and the selected key algorithm to the KMS, requesting the generation of the KMS working key.

[0107] Specifically, step S5 includes:

[0108] S5.1: The KLM monitors the in-vehicle Ethernet bus, receives and parses the positive response message for ECU root key generation of the UDS protocol, and obtains the ECU root key public key pK.

[0109] S5.2: The KLM sends the ECU root key public key pK, the selected RSA-2048 algorithm, and the SHA-256 algorithm to the KMS through the mTLS protocol, requesting the KMS to generate a pair of asymmetric keys as the KMS working key.

[0110] Step S6: The KMS generates the KMS working key.

[0111] Specifically, step S6 includes:

[0112] S6.1: The KMS receives the ECU root key public key pK from the KLM through the mTLS protocol, determines that the selected asymmetric key algorithm is RSA-2048, and the hash algorithm is SHA-256.

[0113] S6.2: The KMS uses the RSA-2048 algorithm to perform cryptographic key generation operations, obtaining the KMS working key public key pK_kms and the KMS working key private key sK_kms.

[0114] Step S7: KLM requests the ciphertext of the key to be filled, its signature value, and the public key of the KMS working key from the KMS.

[0115] Specifically, the step S7 includes:

[0116] S7.1: KLM, based on the current key filling progress, searches for the basic information of the next key to be filled from the list of keys to be filled.

[0117] S7.2: KLM sends the basic information of the next key to be filled to the KMS via the mTLS protocol, requesting to obtain the ciphertext CT of the key to be filled, its signature value S, and the public key pK_kms of the KMS working key.

[0118] Step S8: The KMS calculates the ciphertext of the key to be filled and its signature value, and sends them together with the public key of the KMS working key to the KLM.

[0119] Specifically, the step S8 includes:

[0120] S8.1: The KMS, according to the basic information of the key to be filled sent by the KLM, searches for the plaintext PT of the key to be filled from the KMS database.

[0121] S8.2: The KMS performs a cryptographic encryption operation on the plaintext PT of the key to be filled using the public key pK of the ECU root key and the RSA-2048 algorithm to obtain the ciphertext CT of the key to be filled.

[0122] S8.3: The KMS performs a cryptographic hash operation on the ciphertext CT of the key to be filled using the SHA-256 algorithm to obtain a hash value H, and then performs a cryptographic signature operation on the hash value H using the private key sK_kms of the KMS working key and the RSA-2048 algorithm to obtain the signature value S of the ciphertext of the key to be filled.

[0123] S8.4: The KMS sends the ciphertext CT of the key to be filled, the signature value S of the ciphertext of the key to be filled, and the public key pK_kms of the KMS working key to the KLM via the mTLS protocol.

[0124] Step S9: KLM calculates the second authentication information of KLM and sends a key filling request to the ECU.

[0125] Specifically, the step S9 includes:

[0126] S9.1: KLM receives the ciphertext CT of the key to be filled, the signature value S of the ciphertext of the key to be filled, and the public key pK_kms of the KMS working key via the mTLS protocol.

[0127] S9.2: KLM performs a cryptographic hashing operation on the KMS working key public key pK_kms using the SHA-256 algorithm to obtain the hash value H_kmspk. Then, it performs a cryptographic signature operation on the hash value H_kmspk using the KLM working key private key sK_klm and the RSA-2048 algorithm to obtain the signature value S_kmspk of the KMS working key public key. The signature value S_kmspk of the KMS working key public key is used as the KLM secondary authentication information.

[0128] S9.3: KLM sends a key filling request message to the ECU through the in-vehicle Ethernet bus UDS protocol 0x31 service, including but not limited to the key filling routine identifier, the ciphertext CT of the key to be filled, the signature value S of the ciphertext of the key to be filled, the KMS working key public key pK_kms, and the KLM secondary authentication information, etc.

[0129] Step S10: The ECU verifies the identity of KLM again and verifies the ciphertext of the key to be filled.

[0130] Specifically, the step S10 includes:

[0131] S10.1: The ECU function module listens to the in-vehicle Ethernet bus, receives and parses the UDS protocol key filling request message to obtain the signature value S_kmspk of the KMS working key public key in the ciphertext CT of the key to be filled, the signature value S of the ciphertext of the key to be filled, the KMS working key public key pK_kms, and the KLM secondary authentication information.

[0132] S10.2: The ECU calls the OpenSSL software cryptographic library hash interface EVP_Digest to perform a cryptographic hashing operation on the KMS working key public key pK_kms using the SHA-256 algorithm to obtain the hash value H_kmspk'. Then, it calls the OpenSSL software cryptographic library signature verification interface RSA_verify to perform a cryptographic signature verification operation on the signature value S_kmspk of the KMS working key public key using the RSA-2048 algorithm, the KLM working key public key pK_klm, and the hash value H_kmspk'.

[0133] It can be understood that in step S2, it has been determined that the KLM working key public key pK_klm comes from KLM with a legal identity. Therefore, if the verification result of the signature value S_kmspk of the KMS working key public key is correct, it can be inferred that the KMS working key public key is sent by the legal KLM, and then the ECU can be convinced that KLM has a legal identity.

[0134] S10.3: The ECU confirms the identity of the KLM based on the verification result of the signature value S_kmspk of the KMS working key public key. If the verification result of the signature value S_kmspk of the KMS working key public key is correct, the identity of the KLM is legal and the process continues; otherwise, an ECU key filling negative response message is sent to the KLM via the in-vehicle Ethernet bus UDS protocol 0x7F response code, notifying the KLM that the signature verification has failed.

[0135] S10.4: The ECU calls the OpenSSL software cryptographic library hash interface EVP_Digest, performs a cryptographic hash operation on the key ciphertext CT to be filled using the SHA-256 algorithm to obtain the hash value H', and then calls the OpenSSL software cryptographic library signature verification interface RSA_verify, using the selected RSA-2048 algorithm, the KMS working key public key pK_kms, and the hash value H', to perform a cryptographic signature verification operation on the signature value S of the key ciphertext to be filled.

[0136] S10.5: If the verification result of the signature value S of the key ciphertext to be filled is correct, the ECU can be confident in the integrity of the key ciphertext CT to be filled and continue with step S11; otherwise, an ECU key filling negative response message is sent to the KLM via the in-vehicle Ethernet bus UDS protocol 0x7F response code, notifying the KMS that the signature verification has failed.

[0137] Step S11: The ECU decrypts the key ciphertext to be filled through the ECU hardware security module and securely stores the plaintext.

[0138] Specifically, the step S11 includes:

[0139] S11.1: The ECU decrypts the key ciphertext CT to be filled using the ECU root key private key sK and the RSA-2048 algorithm through the ECU hardware security module to obtain the key plaintext PT to be filled, and securely stores the key plaintext PT to be filled in the secure storage unit of the ECU hardware security module.

[0140] Step S12: The ECU sends the key filling result to the KLM.

[0141] Specifically, the step S12 includes:

[0142] S12.1: If the ECU hardware security module successfully stores the key plaintext PT to be filled, it is determined that the key filling is successful, and the ECU sends a key filling positive response message to the KLM via the in-vehicle Ethernet bus UDS protocol 0x71 response code.

[0143] S12.2: If the ECU hardware security module fails to successfully store the plaintext of the key to be filled, it is determined that the key filling fails, and the ECU sends a negative response message for key filling to the KLM through the in-vehicle Ethernet bus UDS protocol 0x7F response code.

[0144] Step S13: The KLM decides whether to continue key filling.

[0145] Specifically, the step S13 includes:

[0146] S13.1: The KLM monitors the in-vehicle Ethernet bus, receives and parses the UDS protocol key filling response message, and obtains the execution result of the key filling request.

[0147] S13.2: If the key filling fails, jump to step S7 to continue execution.

[0148] S13.3: If the key filling is successful, the KLM marks the key filled in this filling in the list of keys to be filled, and then checks whether there are other keys to be filled in the list of keys to be filled. If there are other keys to be filled, jump to step S7 to continue execution, otherwise end the key filling process.

[0149] This method ensures the legality and integrity of key filling: through the two-way security communication protocol, the KMS also verifies the identity of the KLM, ensuring the identity legality of the KLM relative to the KMS; and cleverly using the KMS's authentication of the KLM to help the ECU achieve the authentication of the KLM, ensuring the identity legality of the KLM relative to the ECU; and for each key filling request from the KLM, the identity legality of the KLM is verified again; and the KMS signs the ciphertext of the key to be filled, and the ECU verifies the signature, ensuring the integrity of the key to be filled.

[0150] It also ensures the confidentiality of key filling: the key to be filled is encrypted and transmitted using the ECU root key, and the ECU root key is an asymmetric key, which solves the confidentiality risk of key distribution caused by the same key for symmetric key encryption and decryption; and the ECU root key is randomly generated by the ECU hardware security module and does not need to be pre-set in advance, avoiding the key confidentiality risk brought by pre-setting keys through other means; and each ECU has theoretically different ECU root keys, that is, "one machine, one key", so that even if an attacker accidentally cracks the private key of the ECU root key of a certain ECU, it cannot threaten the confidentiality of the key filling process of other ECUs; and the generation and storage of the private key of the ECU root key are all independently completed by the ECU hardware security module, minimizing the possibility of accidental exposure of the private key of the ECU root key; and KLM does not come into contact with the plaintext of the key to be filled, ensuring the confidentiality of the key to be filled; and other parts of the ECU except the ECU hardware security module do not come into contact with the plaintext of the key to be filled, ensuring the confidentiality of the key to be filled.

[0151] Finally, it should be noted that the above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for securely filling an ECU key, characterized in that: The following steps are involved: KLM and KMS mutually authenticate each other through a two-way secure communication protocol and establish a secure connection. KLM obtains a list of keys to be filled from KMS; the list of keys to be filled includes the types of cryptographic algorithms supported by KMS and ECU, ECU identity information, and basic information of the keys to be filled; The KLM selects an asymmetric key algorithm and a hash algorithm as the selected algorithm according to the algorithm types supported by the KMS and the ECU in the list of keys to be filled, generates an asymmetric key pair as a KLM working key, and uses the key to generate the KLM first identity authentication information based on the ECU identity information in the list of keys to be filled, and sends an ECU root key generation request including the KLM first identity authentication information and the selected algorithm to the ECU through the vehicle communication protocol; ECU verifies KLM's first identity authentication information. After confirming the legitimacy of KLM's identity, it generates the ECU root key through the hardware security module, stores the private key securely and returns the public key to KLM; KLM sends the ECU root key public key and the selected algorithm to KMS, requesting the generation of a KMS working key. KMS generates an asymmetric key pair as the KMS working key based on the selected asymmetric key algorithm. KLM requests the ciphertext of the key to be filled and its signature value and the KMS working key public key from KMS. KMS uses the ECU root key public key to encrypt the plaintext of the key to be filled to generate ciphertext and uses the KMS working key private key to sign it, and returns it to KLM together with the KMS working key public key; KLM calculates KLM second identity authentication information, and sends a key filling request including key ciphertext, key ciphertext signature value and KLM second identity authentication information to ECU; ECU verifies the KLM second identity authentication information and the key ciphertext signature value in turn. After confirming the legitimacy of the KLM identity and the integrity of the key ciphertext, it decrypts the key ciphertext and stores the plaintext securely. ECU feeds back the key filling result to KLM. If successful, the current key is marked as filled. KLM updates the key list status according to the filling result.

2. The method for securely filling an ECU key according to claim 1, characterized in that: The two-way secure communication protocol is the mTLS protocol, which includes a two-way authentication mechanism of a server certificate and a client certificate.

3. The method for securely filling an ECU key according to claim 1, characterized in that: The asymmetric key algorithm is the RSA-2048 algorithm, and the hash algorithm is the SHA-256 algorithm.

4. The method for securely filling an ECU key according to claim 1, characterized in that: The generating of the KLM first identity verification information comprises: Use the KLM working key private key to sign the ECU identity information, and use the signature value and the KLM working key public key as the KLM first identity authentication information.

5. The method for securely filling an ECU key according to claim 1, characterized in that: The verification of the KLM first identity verification information comprises: The signature value in the KLM first identity verification information is verified using the KLM working key public key in the KLM first identity verification information.

6. The method for securely filling an ECU key according to claim 1, characterized in that: The method of generating the ECU root key through the hardware security module, securely storing the private key and returning the public key to the KLM includes: The hardware security module generates a true random number based on the hardware real-time temperature, time, and voltage as entropy values, and uses the true random number as a key seed; Use the selected asymmetric key algorithm to perform key generation operation based on the key seed to generate an asymmetric key pair as the ECU root key; The ECU root key private key is stored in the secure storage unit of the hardware security module, and the ECU root key public key is returned to the KLM through the vehicle communication protocol.

7. The method for securely filling an ECU key according to claim 1, characterized in that: The calculating of the KLM second identity verification information comprises: Use the KLM working key private key to sign the KMS working key public key, and use the signature value as the KLM second identity authentication information.

8. The method for securely filling an ECU key according to claim 1, characterized in that: The ECU verifies the KLM second identity authentication information and the key ciphertext signature value in sequence, including: ECU verifies KLM second identity authentication information using KLM working key public key; After the KLM second identity authentication information is verified, the ECU uses the KMS working key public key to verify the key ciphertext signature value.

9. The method for securely filling an ECU key according to claim 1, characterized in that: The decryption key ciphertext and the secure storage of the plaintext include: The ECU root key private key is used to decrypt the key ciphertext, and the obtained key plaintext is stored in the secure storage unit of the hardware security module.

10. An ECU key security filling system for implementing the method according to any one of claims 1 to 9, characterized in that: include: The KMS module is used to perform: exchanging certificates with KLM through the mTLS protocol to achieve two-way authentication; providing KLM with a list of keys to be filled; Receive ECU root key public key; Generate KMS working key; provide KLM with the key ciphertext to be filled and its signature value as well as KMS working key public key; The KLM module is used to: establish a secure connection with KMS through the mTLS protocol; request a list of pending key filling from KMS; select an algorithm and generate a KLM working key; send an ECU root key generation request; and provide the ECU root key public key to KMS. Request to generate KMS working key; send key filling request; Generate multi-factor authentication information to support ECU authentication; The ECU module includes a hardware security module, which is used to execute: parsing the ECU root key generation request and verifying the KLM identity, generating and securely storing the ECU root key, and providing the ECU root key public key to the KLM; parsing the key filling request and verifying the KLM identity, verifying the key integrity and completing the key decryption and storage; and feeding back the filling result to the KLM; wherein the hardware security module includes a secure storage unit for ensuring the confidentiality of the stored key through access control; the access control includes: the key written into the secure storage unit can only be accessed by the hardware security module, and the key plaintext written into the secure storage unit cannot be read from outside the hardware security module.

Citation Information

Cited By

  • Automobile bus safety detection system and method based on commercial password technology

    CN121077711A