Key management system and method, medium and product
By generating and distributing encryption keys in offline mode by offline key generation and storage unit, the high cost problem caused by hardware security module dependence is solved, and the secure storage and portability of the key is realized.
Patent Information
- Application Number
- CN202510483298.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-17
- Publication Date
- 2025-07-04
AI Technical Summary
In the prior art, key generation of automotive electronic control units requires relying on hardware security modules, resulting in high additional procurement, deployment and maintenance costs, and the TLS and IPsec protocols limit chips that do not support Ethernet.
The offline key generation unit and the key storage unit are used to generate and distribute the encrypted key in the offline mode through a physical transmission medium or an internal isolation network system, and decrypt the key storage unit with the paired initial key and write it to the secure storage area, avoiding dependence on the hardware security module.
It realizes the secure generation, distribution and storage of keys, reduces system costs, and improves the portability of key management solutions, and is suitable for chips that do not support Ethernet.
Smart Images

Figure CN120263407A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of automotive technologies, and in particular, to a key management system, method, medium, and product. Background Art
[0002] To prevent the leakage of keys, usually before the production of an automotive electronic control unit (ECU), R & D personnel of automotive component suppliers will generate keys on a security server equipped with a hardware security module (HSM). The generated keys are transmitted to a secure flashing device on the production line through security protocols, such as the Transport Layer Security (TLS) protocol and the Internet Protocol Security (IPSec) protocol. The secure flashing device on the production line then flashes the keys to a secure storage area in a microcontroller unit (MCU) chip through a security protocol.
[0003] However, the above solution requires the use of a security server with a hardware HSM, so additional procurement, deployment, and maintenance costs are required. Summary of the Invention
[0004] This application provides a key management system, method, medium, and product, which can realize the generation, distribution, and storage of keys without relying on a hardware security module, thereby effectively reducing system costs.
[0005] In a first aspect of this application, a key management system is provided, including:
[0006] An offline key generation unit, which stores a first initial key and is used to generate an encrypted key based on the first initial key in an offline mode. The encrypted key is designated to be distributed to a key storage unit through a physical transmission medium or an internal isolation network system;
[0007] The key storage unit stores a second initial key paired with the first initial key, and is used to obtain the encrypted key generated by the offline key generation unit, process the encrypted key with the second initial key to obtain a decrypted key, and write the decrypted key into a preset secure storage area.
[0008] In a second aspect of this application, a key management method is provided, including:
[0009] The offline key generation unit generates an encrypted key based on a first initial key stored locally in the offline mode, where the encrypted key is designated to be distributed to the key storage unit through a physical transmission medium or an internal isolation network system;
[0010] The key storage unit obtains the encrypted key generated by the offline key generation unit, processes the encrypted key with a second initial key stored locally to obtain a decrypted key, and writes the decrypted key into a preset secure storage area, where the second initial key is paired with the first initial key.
[0011] A third aspect of the present application provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the key management method described above are implemented.
[0012] A fourth aspect of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps of the key management method described above are implemented.
[0013] One or more technical solutions proposed by the present application have at least the following technical effects:
[0014] By deploying an offline key generation unit and a key storage unit, the offline key generation unit stores a first initial key, the key storage unit stores a second initial key paired with the first initial key, and the offline key generation unit generates an encrypted key based on the first initial key in the offline mode. The key storage unit decrypts the encrypted key using the second initial key and writes the decrypted key into a preset secure storage area. Since the generation of the key is executed on the offline key generation unit, there is no need to deploy an additional hardware security module, and the encrypted key is distributed to the key storage unit through a physical transmission medium or an internal isolation network system, which can isolate the external network environment during the generation and distribution of the key. At the same time, the decrypted key is written into the internal secure storage area, making it impossible for external attackers to obtain the key through access, realizing the secure storage of the key. Therefore, this technical solution can realize the generation, distribution, and storage of the key without relying on a hardware security module, thereby effectively reducing the system cost. In addition, this technical solution does not require the chip to support the TLS protocol and the IPsec protocol, so the portability of the key management solution can be realized. Description of the Drawings
[0015] The drawings here are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0016] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0017] Figure 1 It is the structural block diagram provided by the first embodiment of the key management system of the present application;
[0018] Figure 2 It is the structural block diagram provided by the second embodiment of the key management system of the present application;
[0019] Figure 3 It is the schematic diagram of the brief process of key distribution provided by the embodiment of the present application;
[0020] Figure 4 It is the schematic diagram of the brief process of key generation provided by the embodiment of the present application;
[0021] Figure 5 It is the schematic diagram of the brief process of key distribution and storage provided by the embodiment of the present application. Detailed implementation manners
[0022] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0023] To better understand the technical solutions of the present application, the following will be described in detail in combination with the drawings of the specification and specific implementation manners.
[0024] To prevent the leakage of keys, usually before the production of the electronic control unit of the vehicle, the R & D personnel of the vehicle parts supplier will generate keys on the security server equipped with a hardware security module, and the generated keys are transmitted to the security flashing device on the production line through security protocols, such as the Transport Layer Security Protocol TLS and the Internet Protocol Security IPSec. The security flashing device on the production line then flashes them into the secure storage area in the MCU chip through the security protocol.
[0025] However, the above solution requires the use of a security server with a hardware security module, so additional procurement, deployment, and maintenance costs are required. In addition, the TLS protocol and the IPsec protocol usually need to be transmitted based on the Ethernet physical layer, which poses a limitation on chips that do not support Ethernet.
[0026] To solve the above problems, the embodiments of the present application provide a key management system. Please refer to Figure 1 , Figure 1 It is the structural block diagram provided by the first embodiment of the key management system of the present application.
[0027] The key management system 10 in this embodiment includes an offline key generation unit 100 and a key storage unit 101.
[0028] Among them, the offline key generation unit 100 stores a first initial key and is used to generate an encrypted key based on the first initial key in an offline mode. The encrypted key is designated to be distributed to the key storage unit 101 through a physical transmission medium or an internal isolation network system.
[0029] The key storage unit 101 stores a second initial key paired with the first initial key, and is used to obtain the encrypted key generated by the offline key generation unit 100, process the encrypted key with the second initial key to obtain a decrypted key, and write the decrypted key into a preset secure storage area.
[0030] In this embodiment, the offline key generation unit 100 generates an encrypted key in an offline environment. Therefore, it can be ensured that the key is generated in a secure environment.
[0031] In an implementation scenario, the offline key generation unit 100 may be an offline key generation server deployed by an automotive parts supplier, and the key storage unit 101 may be a secure flashing server deployed by the automotive parts supplier.
[0032] In this embodiment, the implementation scheme for distributing the encrypted key to the key storage unit 101 may include:
[0033] In one implementation manner, after the offline key generation unit 100 generates an encrypted key in the offline mode, the generated encrypted key can be copied by a R & D personnel to the key storage unit 101 through a physical transmission medium. The physical transmission medium may be a USB flash drive, an optical disc, etc.
[0034] In another implementation manner, after the offline key generation unit 100 generates an encrypted key in the offline mode, it can be connected to the internal isolation network system, and the encrypted key is transmitted to the key storage unit 101 through the internal isolation network system.
[0035] In the above two implementation manners, the encrypted key does not need to be transmitted to the key storage unit 101 through the TLS or IPsec security communication protocol. On the one hand, it can isolate the external environment, so that the key is distributed in a secure environment. On the other hand, it can be applied to chips that do not support Ethernet (for example, some ECU main control MCU chips do not support Ethernet), realizing the portability and flexibility of the key management scheme.
[0036] In some embodiments, the key storage unit 101 may be a device type with a network connection, or the key storage unit 101 may refer to a device type without a network connection.
[0037] In this embodiment, the implementation scheme for the key storage unit 101 to obtain the encrypted key generated by the offline key generation unit may include:
[0038] In one implementation, if the encrypted key is transmitted to the key storage unit 101 through a physical transmission medium, the key storage unit 101 obtains the encrypted key by accessing the storage address of the encrypted key. Among them, the physical transmission medium can be a USB flash drive or the like.
[0039] In another implementation, when the encrypted key is sent to the key storage unit 101 through an internal isolation network system, the key storage unit 101 obtains the encrypted key by receiving the encrypted key transmitted by the internal isolation network system.
[0040] In the above two implementation manners, the encrypted key distributes the key in isolation from the external environment. Therefore, secure transmission of the key can be achieved. At the same time, since there is no need to transmit through the TLS or IPsec security communication protocol, this key management scheme can be applied to chips that do not support Ethernet, thereby improving the portability of the key management scheme.
[0041] In some embodiments, the first initial key and the second initial key may be the same or different, which is specifically determined according to the configured encryption algorithm. For example, in the case of using a symmetric encryption algorithm, the first initial key and the second initial key are the same. In this case, the first initial key and the second initial key can be defined as the key encryption key; in the case of using an asymmetric encryption algorithm, the first initial key and the second initial key are different. In this case, the first initial key can be defined as the public key, and the second initial key can be defined as the private key. Among them, the key encryption key is a key used to encrypt other keys, including the master key, the data encryption key, or other key encryption keys themselves. The public key and the private key are the public keys in the asymmetric encryption algorithm and exist in pairs with the private key. The public key is used to encrypt data or verify signatures, and the private key is used to decrypt data or generate signatures.
[0042] In some embodiments, the first initial key and the second initial key may be provided by the key management terminal. The key management terminal can generate the first initial key and the second initial key through a random number generator, and then the R & D personnel save the first initial key to the offline key generation unit 100 and save the second initial key to the key storage unit 101.
[0043] The offline key generation unit 100 can encrypt the plaintext key using symmetric encryption algorithms such as the Advanced Encryption Standard (AES) and the Data Encryption Standard (DES), or use asymmetric encryption algorithms such as RSA and Elliptic Curve Cryptography (ECC) to encrypt the plaintext key.
[0044] In a specific embodiment, the offline key generation unit 100 is further configured to: generate a plaintext key through a random number generator; perform an exclusive OR operation on the first initial key and a pre-generated random seed to obtain a third key; use the third key to encrypt the plaintext key to obtain an encrypted key. The random seed generated by the offline key generation unit 100 is designated and distributed to the key storage unit 101. In addition, the key storage unit 101 is further configured to: obtain the random seed generated by the offline key generation unit 100; perform an exclusive OR operation on the random seed and the second initial key to obtain a third key; use the third key to decrypt the encrypted key.
[0045] That is, after the offline key generation unit 100 generates the encrypted key, it needs to provide the encrypted key and the random seed used in the encryption process to the key storage unit 101, so that the key storage unit 101 can decrypt the encrypted key based on the second initial key and the random seed. In addition, the offline key generation unit 100 can generate one or more plaintext keys according to the instructions input by the user, and encrypt each plaintext ciphertext based on the first initial key to obtain multiple encrypted keys correspondingly. After the key storage unit 101 obtains multiple encrypted keys, it decrypts the multiple encrypted keys based on the second initial key to obtain multiple decrypted keys correspondingly.
[0046] In some embodiments, the secure storage area of the key storage unit 101 can be pre-configured as an exclusive key storage area for Flash. The access to this secure storage area is restricted in terms of hardware, allowing only access from the hardware security engine and not allowing access through the CPU, thus ensuring the security of the key.
[0047] The key management system of this embodiment includes an offline key generation unit and a key storage unit. Among them, the offline key generation unit stores a first initial key, and the key storage unit stores a second initial key paired with the first initial key. The offline key generation unit generates an encrypted key based on the first initial key in an offline mode. The key storage unit decrypts the encrypted key using the second initial key and writes the decrypted key into a preset secure storage area. Since the generation of the key is executed on the offline key generation unit, there is no need to deploy an additional hardware security module, and the encrypted key is distributed to the key storage unit through a physical transmission medium or an internal isolation network system, which can isolate the external network environment during the generation and distribution of the key. At the same time, the decrypted key is written into the internal secure storage area, making it impossible for external attackers to obtain the key through access, realizing the secure storage of the key. Therefore, this technical solution can realize the generation, distribution, and storage of the key without relying on a hardware security module, thereby effectively reducing the system cost. In addition, the key storage unit does not need to support the TLS protocol and the IPsec protocol, so the portability of the key management solution can be realized.
[0048] In a feasible implementation manner, the offline key generation unit 100 provided in the above embodiment is further configured to: write the encrypted key into a binary file to obtain a key binary file; after generating the key binary file, connect to the internal isolation network system and send the key binary file to the key storage unit 101 through the internal isolation network system, so as to send the encrypted key to the key storage unit 101 in the format of a binary ciphertext.
[0049] Specifically, the encrypted key is converted into a binary format and written into a binary file. At the same time, the header information of the binary file can also be generated based on the identifier of the encrypted key, and the header information and the encrypted key in binary format are written into the binary file to obtain a key binary file.
[0050] In this implementation manner, the encrypted key is converted into a binary format and written into a binary file, which increases the difficulty for external attackers to reverse-compile and obtain the key.
[0051] In a feasible implementation manner, the offline key generation unit 100 is further configured to: generate verification data for the encrypted key, and write the encrypted key and the verification data into a binary file to obtain a key binary file.
[0052] In this implementation manner, in order to support the key storage unit 101 to verify the correctness of the decrypted key, each generated plaintext key can also be encrypted separately through a random seed to obtain verification data corresponding to each plaintext key, and each encrypted key and the verification data corresponding to each plaintext key are written into a binary file.
[0053] Based on the first embodiment of the present application, in the second embodiment of the present application, the same or similar content as that in the above-mentioned first embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, please refer to Figure 2 , the key management system of this embodiment further includes a key management terminal 102, and the key management terminal 102 is used for: generating a first initial key and a second initial key; writing the first initial key into a pre-developed original key generation code to obtain a target key generation code file; writing the second initial key into a pre-developed original flashing code to obtain a target flashing code file; wherein, the target key generation code file is designated to be delivered to the offline key generation unit 100, and the target flashing code file is designated to be delivered to the key storage unit 101.
[0054] Specifically, after the key management terminal 102 writes the first initial key into the original key generation code, it compiles the original key generation code written with the first initial key to obtain a target key generation code file; and, after writing the second initial key into the original flashing code, it compiles the original flashing code written with the second initial key to obtain a target flashing code file, wherein both the target key generation code file and the target flashing code file are binary format files.
[0055] In this embodiment, the key management terminal 102 can generate the first initial key and the second initial key on a local security server. When the first initial key and the second initial key are the same, the key management terminal can generate a random number through a random number generator, and this random number serves as the first initial key and the second initial key.
[0056] In one implementation manner, the key management terminal 102 is further used for: deleting the first initial key and the second initial key.
[0057] Specifically, after the key management terminal 102 generates the target key generation code file and the target flashing code file, it deletes the first initial key and the second initial key. This can prevent the publisher from knowing the first initial key and the second initial key either.
[0058] In one implementation manner, the offline key generation unit 102 is further used for: in response to a first deployment instruction input by the user, deploying the target key generation code file on the offline key generation unit 100 to store the first initial key in the target key generation code file, and executing the step of generating an encrypted key based on the first initial key in the offline mode by running the target key generation code file.
[0059] In this embodiment, the target key generation code file generated by the key management terminal 102 is deployed by a user (such as a R & D personnel) to the offline key generation unit 100. Then, the offline key generation unit 100 can run the target key generation code file in response to a first execution instruction input by the user. The target generation code file is at least used to implement the function of generating a plaintext key and processing the plaintext key based on a first initial key to obtain an encrypted key.
[0060] In one implementation, the key storage unit 101 is further configured to: in response to a second deployment instruction input by the user, deploy a target rewrite code file on the key storage unit 101 to store a second initial key in the target rewrite code file, and execute the process of processing the encrypted key with the second initial key to obtain a decrypted key and write the decrypted key into a preset secure storage area by running the target rewrite code file.
[0061] In this embodiment, the target key generation code file generated by the key management terminal 102 is deployed by a user (such as a R & D personnel) to the key storage unit 101. Then, the key storage unit 101 can run the target rewrite code file in response to a second execution instruction input by the user. The target rewrite code file is at least used to implement the function of processing the encrypted key with the second initial key to obtain a decrypted key.
[0062] To solve the above problems, this embodiment further provides a key management method, including:
[0063] The offline key generation unit generates an encrypted key based on a first initial key stored locally in an offline mode, where the encrypted key is designated to be distributed to the key storage unit through a physical transmission system or an internal isolation network system;
[0064] The key storage unit obtains the encrypted key generated by the offline key generation unit, processes the encrypted key with a second initial key stored locally to obtain a decrypted key, and writes the decrypted key into a preset secure storage area, where the second initial key is paired with the first initial key.
[0065] In one implementation, the key management method further includes:
[0066] The key management terminal generates a first initial key and a second initial key;
[0067] The key management terminal writes the first initial key into the pre-developed original key generation code to obtain a target key generation code file, and writes the second initial key into the pre-developed original flashing code to obtain a target flashing code file; wherein, the target key generation code file is designated to be delivered to the offline key generation unit, and the target flashing code file is designated to be delivered to the key storage unit.
[0068] In one embodiment, the key management method further includes:
[0069] After generating the target key generation code file and the target flashing code file, delete the first initial key and the second initial key.
[0070] In one embodiment, the key management method further includes:
[0071] In response to a first deployment instruction input by a user, the offline key generation unit deploys the target key generation code file on the offline key generation unit to store the first initial key in the target key generation code file, and executes the step of generating an encrypted key based on the first initial key by running the target key generation code file.
[0072] In one embodiment, the key management method further includes:
[0073] In response to a second deployment instruction input by a user, the key storage unit deploys the target flashing code file on the key storage unit to store the second initial key in the target flashing code file, and executes the step of processing the encrypted key through the second initial key to obtain a decrypted key and writing the decrypted key into a preset secure storage area by running the target flashing code file.
[0074] In one embodiment, the key management method further includes:
[0075] The offline key generation unit writes the encrypted key into a binary file to obtain a key binary file;
[0076] After generating the key binary file, the offline key generation unit connects to the internal isolation network system and sends the key binary file to the key storage unit through the internal isolation network system, so as to send the encrypted key to the key storage unit in the form of a binary ciphertext.
[0077] In one embodiment, the offline key generation unit generating an encrypted key based on the first initial key stored locally includes:
[0078] The offline key generation unit generates a plaintext key through a random number generator;
[0079] The offline key generation unit performs an exclusive OR operation on the first initial key and a pre-generated random seed to obtain a third key;
[0080] The offline key generation unit uses the third key to encrypt the plaintext key to obtain an encrypted key.
[0081] In one implementation, the encrypted key is processed by the second initial key stored locally to obtain a decrypted key, including:
[0082] Obtain the random seed generated by the offline key generation unit;
[0083] Perform an exclusive OR operation on the random seed and the second initial key to obtain a third key;
[0084] Use the third key to decrypt the encrypted key.
[0085] Exemplarily, to facilitate understanding of the implementation solution of this embodiment, the following introduces this embodiment in combination with a specific scenario. Specifically, the key management end is deployed by the chip developer, and the offline key generation unit and the key storage unit are deployed by the automotive parts supplier.
[0086] Please refer to Figure 3 , Figure 3 which is a schematic diagram of the brief process of key distribution provided by the embodiment of the present application. First, the chip developer develops a key generation tool (i.e., the original key generation code in the above embodiment) and a secure flashing tool (i.e., the original flashing code in the above embodiment) at the key management end. At the same time, before the key management end of the chip developer distributes the key generation tool and the secure flashing tool to the automotive parts supplier, a random and unique key encryption key KEK is generated by a random number generator on the local secure server. This key encryption key KEK serves as the first initial key and the second initial key, and the key encryption key KEK is written into the key generation tool and the secure flashing tool to write the first initial key into the key generation tool and the second initial key into the secure flashing tool. After that, the key management end compiles the key generation tool written with the first initial key and the secure flashing tool written with the second initial key into binary files, respectively obtaining a target key generation code file and a target flashing code file. Then, the key management end deletes the key encryption key KEK. Then, the chip developer distributes the target key generation code file and the target flashing code file to the automotive supplier to deliver the target key generation code file to the offline key generation unit and the target flashing code file to the key storage unit.
[0087] Please refer to Figure 4 , Figure 4It is a schematic diagram of the brief process of key generation provided by an embodiment of the present application. After an automotive parts supplier obtains the target key generation code file released by the chip manufacturer, it will deploy it on the offline key generation unit. Before mass production of a certain automotive controller (ECU) product, R & D personnel will run the target key generation code file. During the running process of the target key generation code file, an inquiry message about the number of plaintext keys to be generated will be pushed to the user, so that the user can input the number of plaintext keys to be generated according to actual needs. Then, during the running process of the target key generation code file, in response to the instruction input by the user indicating the number of plaintext key generations, a random number generator is used to generate the corresponding number of plaintext keys, and then the first initial key is XORed with the dynamically generated random seed "seed" to obtain the dynamic key encryption key KEK_D (i.e., the third key in the above embodiment). Then, each plaintext key is encrypted using the dynamic encryption key KEK_D to obtain each encrypted key. Then, the encrypted keys, random seed "seed" and header information generated this time are written into a binary file, where the header information can be generated according to the identifier of each key. In addition, in order to support the key storage unit to verify the correctness of the decrypted key, each generated plaintext key is encrypted using the random seed "seed" to generate the verification data corresponding to each plaintext key, and each verification data, each encrypted key and its corresponding header information format are written into the binary file to obtain the key binary file.
[0088] Please refer to Figure 5 , Figure 5It is a schematic diagram of the brief process of key distribution and storage provided by an embodiment of this application. After the production line staff of an auto parts supplier obtains the target flashing code file released by the chip manufacturer, they will deploy it on the offline secure flashing server on the production line (i.e., the key storage unit in the above embodiment). Since the key already exists in the key binary file in ciphertext form during key generation, the distribution method of the encrypted key can follow the original internal software distribution method (such as being sent from the R & D department to the production line through the internal local area network or internal release system). After the key storage unit obtains the key binary file generated by the offline key generation unit, it runs the target flashing code file. During the execution of the target flashing code file, first, the key binary file is imported into the target flashing code file. During the execution process, the target flashing code file will parse the key binary file according to the header file format information to obtain the random seed seed and the encrypted key, and write the encrypted key into the area to be flashed visible to the CPU. Then, the random seed seed is used to perform an exclusive OR operation with the key encryption key KEK to obtain the dynamic key encryption key (KEK_D), which is then written into the RAM area of the MCU. After that, the hardware security engine in the MCU is configured (such as CSE or HSM). The address of the area to be flashed where the encrypted key is stored is used as the data address to be decrypted, and the address of the RAM area where the dynamic key encryption key KEK_D is stored is used as the key address. Then, the decrypted data address is configured as the address of the Flash key storage area exclusive to the hardware security engine, and the above configurations are all written into the configuration register of the hardware security engine. Then, the decryption operation is started to obtain the decrypted key. After the operation is completed, the decrypted key is written into the exclusive key storage area of Flash (i.e., the secure storage area in the above embodiment) through the key storage instruction for operating Flash. Access to the key storage area of Flash and the key storage area to be stored in RAM is restricted in terms of hardware, and only access from the hardware security engine is allowed, and access through the CPU is not permitted, thus ensuring the security of the key. After the key writing is completed, the random seed is written into the RAM area of the MCU and the address is configured as the encrypted original value of the hardware security engine, and the previously written key encryption key KEK is respectively configured as the encryption key of the hardware security engine. After the configuration is completed, encryption is started. After the encryption is completed, the encryption result is compared with the check data in the binary file one by one for verification to obtain the verification result.
[0089] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the key management method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0090] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the key management method in the above embodiments.
[0091] The computer-readable storage medium provided by the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0092] The computer program code for performing the operations of the present application can be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages - such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0093] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0094] The components / modules involved in the embodiments described in the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0095] The present application also provides a computer program product, including a computer program, which when executed by a processor implements the steps of the key management method as described above.
[0096] The computer program product provided by the present application can solve the technical problem that the generation, distribution, and storage of keys need to rely on a hardware security module, resulting in a high system cost. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the key management method provided by the above embodiments, and will not be elaborated here.
[0097] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. All equivalent structural transformations made under the technical concept of the present application by using the content of the specification and drawings of the present application, or directly / indirectly applied in other related technical fields, are included in the patent protection scope of the present application.
Claims
1. A key management system, characterized in that, Including: An offline key generation unit that stores a first initial key and is used to generate an encrypted key based on the first initial key in an offline mode. The encrypted key is designated to be distributed to a key storage unit through a physical transmission medium or an internal isolation network system. The key storage unit stores a second initial key paired with the first initial key and is used to obtain the encrypted key generated by the offline key generation unit, process the encrypted key with the second initial key to obtain a decrypted key, and write the decrypted key into a preset secure storage area.
2. The key management system according to claim 1, wherein The key management system further includes a key management terminal, and the key management terminal is used for: Generating the first initial key and the second initial key; Writing the first initial key into a pre-developed original key generation code to obtain a target key code file; Writing the second initial key into a pre-developed original flashing code to obtain a target flashing code file; Wherein, the target key generation code file is designated to be delivered to the offline key generation unit, and the target flashing code file is designated to be delivered to the key storage unit.
3. The key management system according to claim 2, characterized in that, The key management terminal is further used for: After generating the target key generation code file and the target flashing code file, deleting the first initial key and the second initial key.
4. The key management system according to claim 2, characterized in that, The offline key generation unit is further used for: In response to a first deployment instruction input by a user, deploying the target key generation code file on the offline key generation unit to store the first initial key in the target key generation code file, and executing the step of generating an encrypted key based on the first initial key in an offline environment by running the target key generation code file.
5. The key management system according to claim 2, characterized in that, The key storage unit is further used for: In response to a second deployment instruction input by a user, deploying the target flashing code file on the key storage unit to store the second initial key in the target flashing code file, and executing the step of processing the encrypted key with the second initial key to obtain a decrypted key and writing the decrypted key into a preset secure storage area by running the target flashing code file.
6. The key management system according to claim 1, characterized in that, The offline key generation unit is further used for: Writing the encrypted key into a binary file to obtain a key binary file; After generating the key binary file, connecting to the internal isolation network system and sending the key binary file to the key storage unit through the internal isolation network system to send the encrypted key to the key storage unit in the format of a binary ciphertext.
7. The key management system according to claim 1, characterized in that, The offline key generation unit is further used for: Generating a plaintext key through a random number generator; Performing an exclusive OR operation on the first initial key and a pre-generated random seed to obtain a third key; Using the third key to encrypt the plaintext key to obtain the encrypted key.
8. The key management system according to claim 7, wherein The random seed generated by the offline key generation unit is designated to be distributed to the key storage unit, and the key storage unit is further used for: Obtain the random seed generated by the offline key generation unit; Perform an exclusive OR operation on the random seed and the second initial key to obtain the third key; Use the third key to decrypt the encrypted key.
9. A key management method, characterized in that, Comprising: The offline key generation unit generates an encrypted key based on a first initial key stored locally in an offline mode, wherein the encrypted key is designated to be distributed to the key storage unit through a physical transmission medium or an internal isolation network system; The key storage unit obtains the encrypted key generated by the offline key generation unit, processes the encrypted key with a second initial key stored locally to obtain a decrypted key, and writes the decrypted key into a preset secure storage area, wherein the second initial key is paired with the first initial key.
10. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the key management method as claimed in claim 9 are implemented.
11. A computer program product, characterized in that, The computer program product includes a computer program. When the computer program is executed by a processor, the steps of the key management method as claimed in claim 9 are implemented.
Citation Information
Cited By
Key management method, electronic control unit and vehicle
CN121530667A