OTA upgrade package encryption and decryption method and device, vehicle-mounted terminal and storage medium

By directly encrypting and decrypting the OTA upgrade package between the OTA platform and the vehicle terminal, the problem of inefficiency in the existing technology is solved and efficient and secure OTA upgrade package processing is achieved.

CN120296707APending Publication Date: 2025-07-11XUZHOU XCMG AUTOMOTIVE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510259165.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

The existing OTA upgrade package encryption and decryption methods are inefficient in cars, requiring remote network requests and intensive password algorithm operations, which are difficult to meet the requirements of efficiency.

Method used

Using identification password algorithm and digital envelope technology, the OTA platform directly encrypts the OTA upgrade package without obtaining certificates and verifying the legality of the certificate. The on-board terminal directly decrypts the encrypted files.

Benefits of technology

The encryption and decryption process is simplified, the encryption and decryption efficiency and the upgrade efficiency of automobile OTA, and the security of data transmission is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296707A_ABST
    Figure CN120296707A_ABST
Patent Text Reader

Abstract

The invention discloses an OTA upgrade package encryption and decryption method and device, a vehicle-mounted terminal and a storage medium, and belongs to the technical field of automobile information security. The method comprises the following steps: a vehicle-mounted terminal sends an upgrading request to an OTA platform, wherein the upgrading request comprises a vehicle identifier; the OTA platform determines an OTA upgrade package according to the upgrade request, encrypts the OTA upgrade package by using the OTA encryption key, and generates an upgrade package ciphertext; encrypting the OTA encryption key by using the vehicle identifier to generate a key ciphertext; sending the upgrade patch ciphertext and the key ciphertext to the vehicle-mounted terminal; the vehicle-mounted terminal adopts the identification private key to decrypt the secret key ciphertext to generate a secret key plaintext, and the secret key plaintext comprises an OTA encryption secret key; and the OTA encryption key is adopted to decrypt the upgrade patch ciphertext to generate an upgrade patch plaintext, and the upgrade patch plaintext comprises an OTA upgrade patch. According to the method, encryption is directly carried out through the OTA platform by adopting the identification password algorithm and the digital envelope technology, the certificate is not required to be acquired and the legality of the certificate is not required to be verified, the encryption and decryption process is simplified, and the encryption and decryption efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of automotive information security, and particularly relates to an OTA upgrade package encryption and decryption method, device, vehicle-mounted terminal and storage medium. Background Art

[0002] With the rapid development of intelligent vehicles, Over-The-Air (OTA) technology has become an important means for the automotive industry to improve vehicle performance, repair security vulnerabilities, and introduce new functions. However, currently, digital certificate and digital envelope technologies are usually used to encrypt and decrypt OTA upgrade packages during the OTA upgrade process. Its deficiencies are as follows: 1. After the OTA platform receives the upgrade request sent by the vehicle-mounted terminal, it needs to query the vehicle certificate from the Lightweight Directory Access Protocol (LDAP) server through the vehicle identifier, and this process is a remote network request; 2. After the OTA platform obtains the vehicle certificate, it needs to verify the legality of the vehicle certificate based on the pre-set certificate chain, and this process is an intensive cryptographic algorithm operation process. Both of these operation processes consume a large amount of time. Therefore, the traditional encryption and decryption method still has deficiencies in terms of the encryption and decryption efficiency of OTA upgrade packages and is difficult to meet the high-efficiency requirements of automotive OTA upgrades. Summary of the Invention

[0003] The purpose of the present invention is to overcome the deficiencies in the prior art and provide an OTA upgrade package encryption and decryption method, device, vehicle-mounted terminal and storage medium. The OTA platform directly encrypts using the identity-based cryptographic algorithm and digital envelope technology, without the need to obtain a certificate and verify the legality of the certificate, simplifies the encryption and decryption process, and improves the encryption and decryption efficiency.

[0004] To achieve the above object, the present invention is implemented by the following technical solutions: In the first aspect, the present invention provides an OTA upgrade package encryption and decryption method, and the method includes: The vehicle-mounted terminal responds that the local software version is lower than the OTA platform software version and sends an upgrade request to the OTA platform, and the upgrade request includes a vehicle identifier; The OTA platform determines an OTA upgrade package according to the upgrade request, and encrypts the OTA upgrade package using a symmetric encryption algorithm according to an OTA encryption key to generate an encrypted upgrade package ciphertext; The OTA platform encrypts the OTA encryption key using an identity-based cryptographic algorithm according to the vehicle identifier to generate a key ciphertext; The OTA platform sends an encrypted file to the vehicle-mounted terminal, and the encrypted file includes the encrypted upgrade package ciphertext and the key ciphertext; The in-vehicle terminal decrypts the ciphertext of the key using an identity-based cryptographic algorithm according to the identity private key, and generates the plaintext of the key. The identity private key is the asymmetric key of the vehicle identity, and the plaintext of the key includes the OTA encryption key; The in-vehicle terminal decrypts the ciphertext of the upgrade package using a symmetric encryption algorithm according to the OTA encryption key, and generates the plaintext of the upgrade package. The plaintext of the upgrade package includes the OTA upgrade package.

[0005] In a second aspect, the present invention further provides an OTA upgrade package encryption method, which is applied to an OTA platform and includes: Receiving an upgrade request sent by an in-vehicle terminal, where the upgrade request includes a vehicle identity; Encrypting the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate a ciphertext of the upgrade package, where the OTA upgrade package is determined according to the upgrade request; Encrypting the OTA encryption key using an identity-based cryptographic algorithm according to the vehicle identity to generate a ciphertext of the key; Sending an encrypted file to the in-vehicle terminal, where the encrypted file includes the ciphertext of the upgrade package and the ciphertext of the key.

[0006] In a third aspect, the present invention further provides an OTA upgrade package decryption method, which is applied to an in-vehicle terminal and includes: In response to the local software version being lower than the OTA platform software version, sending an upgrade request to the OTA platform, where the upgrade request includes a vehicle identity; Receiving an encrypted file sent by the OTA platform, where the encrypted file includes a ciphertext of the upgrade package and a ciphertext of the key; Decrypting the ciphertext of the key using an identity-based cryptographic algorithm according to the identity private key, and generating the plaintext of the key. The identity private key is the asymmetric key of the vehicle identity, and the plaintext of the key includes the OTA encryption key; Decrypting the ciphertext of the upgrade package using a symmetric encryption algorithm according to the OTA encryption key, and generating the plaintext of the upgrade package. The plaintext of the upgrade package includes the OTA upgrade package, and the OTA upgrade package is determined according to the upgrade request.

[0007] In combination with the third aspect, further, before sending the upgrade request to the OTA platform, it further includes: Sending a software version query request to the OTA platform; Receiving the OTA platform software version information returned by the OTA platform.

[0008] In combination with the third aspect, further, before sending the software version query request to the OTA platform, it further includes: Applying for an identity private key from an identity key management system according to the vehicle identity; Receive the identity private key returned by the identity key management system.

[0009] Fourthly, the present invention further provides an OTA upgrade package encryption device, which is applied to an OTA platform and includes: A first receiving module: configured to receive an upgrade request sent by a vehicle terminal, where the upgrade request includes a vehicle identifier; An encryption module: configured to encrypt the OTA upgrade package using a symmetric encryption algorithm according to an OTA encryption key to generate an encrypted upgrade package ciphertext, where the OTA upgrade package is determined according to the upgrade request; encrypt the OTA encryption key using an identity cryptography algorithm according to the vehicle identifier to generate a key ciphertext; A first sending module: configured to send an encrypted file to the vehicle terminal, where the encrypted file includes the encrypted upgrade package ciphertext and the key ciphertext.

[0010] Fifthly, the present invention further provides an OTA upgrade package decryption device, which is applied to a vehicle terminal and includes: A second sending module: configured to send an upgrade request to the OTA platform in response to the local software version being lower than the OTA platform software version, where the upgrade request includes a vehicle identifier; A second receiving module: configured to receive an encrypted file sent by the OTA platform, where the encrypted file includes an encrypted upgrade package ciphertext and a key ciphertext; A decryption module: configured to decrypt the key ciphertext using an identity cryptography algorithm according to an identity private key to generate a key plaintext, where the identity private key is an asymmetric key of the vehicle identifier, and the key plaintext includes an OTA encryption key; decrypt the encrypted upgrade package ciphertext using a symmetric encryption algorithm according to the OTA encryption key to generate an upgrade package plaintext, where the upgrade package plaintext includes an OTA upgrade package, and the OTA upgrade package is determined according to the upgrade request.

[0011] Sixthly, the present invention further provides a vehicle terminal, including a storage medium and a processor; The storage medium is used to store an OTA upgrade package decryption program; The processor is configured to operate according to the OTA upgrade package decryption program to implement the steps of the OTA upgrade package decryption method according to any one of the third aspect.

[0012] Seventhly, the present invention further provides a vehicle, including the vehicle terminal according to the sixth aspect.

[0013] In an eighth aspect, the present invention further provides a computer-readable storage medium, on which an OTA upgrade package encryption program is stored. When the program is executed by a processor, the steps of the OTA upgrade package encryption method described in the second aspect are implemented; alternatively, an OTA upgrade package decryption program is stored thereon. When the program is executed by a processor, the steps of the OTA upgrade package decryption method described in any one of the third aspects are implemented.

[0014] Compared with the prior art, the present invention can at least achieve the following beneficial effects: In the OTA upgrade package encryption and decryption method provided by the present invention, the OTA platform directly encrypts the OTA upgrade package by using an identity-based cryptographic algorithm and digital envelope technology, without the need to obtain a certificate and verify the legality of the certificate, avoiding complex certificate management problems, reducing the possibility of data transmission errors, and improving the security of data transmission; and the in-vehicle terminal directly decrypts the encrypted file to obtain the OTA upgrade package, simplifying the encryption and decryption process, and improving the encryption and decryption efficiency and the automotive OTA upgrade efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 is a flowchart of an OTA upgrade package encryption and decryption method provided by an embodiment of the present invention; Figure 2 is a flowchart of an OTA upgrade package encryption method provided by an embodiment of the present invention; Figure 3 is a flowchart of an OTA upgrade package decryption method provided by an embodiment of the present invention; Figure 4 is a schematic structural diagram of an OTA upgrade package encryption device provided by an embodiment of the present invention; Figure 5 is a schematic structural diagram of an OTA upgrade package decryption device provided by an embodiment of the present invention; Figure 6 is a schematic structural diagram of an in-vehicle terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0017] The present invention will be further described below with reference to the drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present invention and should not be used to limit the protection scope of the present invention.

[0018] Embodiment 1

[0019] This embodiment provides an OTA upgrade package encryption and decryption method. As Figure 1 shown, it is the flowchart of the encryption and decryption method provided by this embodiment, mainly including the following steps: S101: When the in-vehicle terminal responds that the local software version is lower than the OTA platform software version, it sends an upgrade request to the OTA platform. The upgrade request includes a vehicle identifier; S102: The OTA platform determines the OTA upgrade package according to the upgrade request, and encrypts the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate an encrypted upgrade package ciphertext; S103: The OTA platform encrypts the OTA encryption key using an identity-based cryptographic algorithm according to the vehicle identifier to generate a key ciphertext; S104: The OTA platform sends an encrypted file to the in-vehicle terminal. The encrypted file includes the encrypted upgrade package ciphertext and the key ciphertext; S105: The in-vehicle terminal decrypts the key ciphertext using an identity-based cryptographic algorithm according to the identity private key to generate a key plaintext. The identity private key is the asymmetric key of the vehicle identifier, and the key plaintext includes the OTA encryption key; S106: The in-vehicle terminal decrypts the encrypted upgrade package ciphertext using a symmetric encryption algorithm according to the OTA encryption key to generate an upgrade package plaintext. The upgrade package plaintext includes the OTA upgrade package.

[0020] It should be noted that the systems involved in the OTA upgrade package encryption and decryption method provided by this embodiment include: an OTA platform, an in-vehicle terminal, and an identity-based cryptographic management system. Among them, the OTA platform is used to store the OTA upgrade package, and according to the vehicle identifier carried in the upgrade request sent by the in-vehicle terminal, it encrypts the OTA upgrade package using an identity-based cryptographic algorithm and digital envelope technology, and sends an encrypted file to the in-vehicle terminal; the in-vehicle terminal is installed on the vehicle, used to send an upgrade request, and perform an upgrade operation after receiving and decrypting the encrypted file; the identity-based cryptographic management system is used to generate a corresponding identity private key according to the vehicle identifier sent by the in-vehicle terminal and return the identity private key to the in-vehicle terminal.

[0021] In the OTA upgrade package encryption and decryption method provided by this embodiment, the OTA platform directly encrypts the OTA upgrade package using an identity-based cryptographic algorithm and digital envelope technology, without the need to obtain a certificate and verify the legality of the certificate, avoiding complex certificate management problems, reducing the possibility of data transmission errors, and improving the security of data transmission; and the in-vehicle terminal directly decrypts the encrypted file to obtain the OTA upgrade package, simplifying the encryption and decryption process, and improving the encryption and decryption efficiency and the automotive OTA upgrade efficiency.

[0022] Embodiment Two

[0023] This embodiment provides an OTA upgrade package encryption method, which is applied to an OTA platform, such as Figure 2 As shown, it is a flowchart of the encryption method provided in this embodiment, mainly including the following steps: S201: Receive an upgrade request sent by the in-vehicle terminal. The upgrade request includes a vehicle identifier; S202: Encrypt the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate an encrypted upgrade package ciphertext. The OTA upgrade package is determined according to the upgrade request; S203: Encrypt the OTA encryption key using an identity-based cryptography algorithm according to the vehicle identifier to generate a key ciphertext; S204: Send the encrypted file to the in-vehicle terminal. The encrypted file includes the encrypted upgrade package ciphertext and the key ciphertext.

[0024] In this embodiment, after the OTA platform executes step S201: receiving the upgrade request sent by the in-vehicle terminal, it is necessary to determine the OTA upgrade package required by the in-vehicle terminal according to the upgrade request. In addition, before executing step S202, the OTA platform also needs to generate an OTA encryption key, which is a random symmetric key, and then perform the encryption process of the OTA upgrade package based on the identity-based cryptography algorithm and the digital envelope technology.

[0025] Specifically, as shown in steps S202 and S203, the OTA platform uses the symmetric encryption algorithm corresponding to the OTA encryption key to encrypt the OTA upgrade package to obtain the encrypted upgrade package ciphertext; then uses the identity-based cryptography algorithm corresponding to the vehicle identifier (i.e., the identity public key) to encrypt the OTA encryption key to obtain the key ciphertext (i.e., the digital envelope).

[0026] It should be noted that the vehicle identifier can be a vehicle identification number (VIN), vehicle model, electronic control unit (ECU) type, electronic control unit (ECU) identification number, etc. In addition, the OTA encryption key can be an SM4 key, an AES key, or a 3DES key, and the corresponding symmetric encryption algorithms are the SM4-OFB algorithm, the AES-CBC algorithm, and the 3DES-OFB algorithm respectively. The identity-based cryptography algorithm can be the SM9 algorithm or the CPK algorithm. In practical applications, the OTA encryption key can also be other symmetric keys, and the identity-based cryptography algorithm can also be other asymmetric encryption algorithms, as long as the same effect can be achieved.

[0027] Further, in step S204: When sending the encrypted file to the vehicle terminal, the ciphertext of the upgrade package can be synchronized with the Content Delivery Network (CDN) connected to the OTA platform and sent to the vehicle terminal, and the ciphertext of the key can be returned to the vehicle terminal through the response message of the HyperText Transfer Protocol (HTTP).

[0028] As an embodiment, before the OTA platform executes step S201, it can also perform operations: receiving a software version query request sent by the vehicle terminal; according to the software version query request, sending the OTA platform software version information to the vehicle terminal; which helps the vehicle terminal determine whether the local software version is consistent with the OTA platform software version and whether it needs to send an upgrade request to the OTA platform.

[0029] For the OTA upgrade package encryption method provided in this embodiment, compared with the traditional Public Key Infrastructure (PKI), the OTA platform makes full use of the advantages of identity-based cryptography technology, without the need to obtain digital certificates and verify the legality of digital certificates, simplifies the encryption process, improves the encryption efficiency of the OTA upgrade package, and enables the vehicle to obtain the OTA upgrade package more efficiently and quickly when performing OTA upgrades.

[0030] The flowchart of this embodiment only shows the logical order of the method described in this embodiment. On the premise of no conflict, in other possible embodiments of the present invention, the steps shown or described can be completed in a different order than Figure 2 shown. The OTA upgrade package encryption method provided in this embodiment can be applied to terminals and can be executed by an OTA upgrade package encryption device, which can be implemented in software and / or hardware, and this device can be integrated in the terminal, for example: any smart phone, tablet computer or computer device with communication functions.

[0031] Embodiment III

[0032] This embodiment provides an OTA upgrade package decryption method, which is applied to the vehicle terminal. Referring to Figure 3 , which is the flowchart of the decryption method provided in this embodiment, mainly includes the following steps: S305: In response to the local software version being lower than the OTA platform software version, send an upgrade request to the OTA platform, and the upgrade request includes the vehicle identifier; S306: Receive the encrypted file sent by the OTA platform, and the encrypted file includes the ciphertext of the upgrade package and the ciphertext of the key; S307: Decrypt the key ciphertext using the identity cipher algorithm according to the identity private key to generate the key plaintext. The identity private key is the asymmetric key of the vehicle identity, and the key plaintext includes the OTA encryption key; S308: Decrypt the upgrade package ciphertext using the symmetric encryption algorithm according to the OTA encryption key to generate the upgrade package plaintext. The upgrade package plaintext includes the OTA upgrade package, and the OTA upgrade package is determined according to the upgrade request.

[0033] As an optional embodiment, before the vehicle-mounted terminal executes step S305: sending an upgrade request to the OTA platform, the following steps may also be executed: S303: Send a software version query request to the OTA platform; S304: Receive the OTA platform software version information returned by the OTA platform.

[0034] Specifically, the vehicle-mounted terminal may regularly send a software version query request to the OTA platform at a set time interval. After querying the database, the OTA platform sends the latest software version information to the vehicle-mounted terminal. By comparing the local current software version information with the software version information returned by the OTA platform, if the local software version is lower than the OTA platform software version, then step S305: sending an upgrade request to the OTA platform is executed.

[0035] Furthermore, before the vehicle-mounted terminal executes step S303, the following steps may also be executed: S301: Apply for an identity private key from the identity key management system according to the vehicle identity; S302: Receive the identity private key returned by the identity key management system.

[0036] It should be noted that the vehicle-mounted terminal uses the vehicle identity as the identity public key to apply for the corresponding identity private key from the identity key management system (KeyGenerate Center, KGC). The identity key management system will calculate the identity private key based on the system master key (known only to the identity key management system and strictly kept) and the identity public key, and return the identity private key to the vehicle-mounted terminal. Among them, the identity key management system may be an SM9 identity key management system or a CPK identity key management system. The identity private key can be calculated through the SM9 algorithm or the CPK algorithm, and the symmetric encryption algorithm and the identity cipher algorithm are the same as those in the foregoing Embodiment 2. In practical applications, the identity key management system may also be other key generation systems as long as the same effect can be achieved.

[0037] The OTA upgrade package decryption method provided in this embodiment enables the in-vehicle terminal to directly use the vehicle identifier as the public key for identity to apply for the private key for identity from the identity key management system without obtaining and managing certificates, and directly decrypt the encrypted file according to the private key for identity to quickly obtain the OTA upgrade package, improving the decryption efficiency and making the vehicle more efficient during OTA upgrade, bringing a better upgrade experience to users.

[0038] The flowchart of this embodiment only shows the logical sequence of the method described in this embodiment. On the premise of no conflict, in other possible embodiments of the present invention, the steps shown or described can be completed in a different order from Figure 3 the order shown. The OTA upgrade package decryption method provided in this embodiment can be applied to a terminal and can be executed by an OTA upgrade package decryption device. This device can be implemented in a software and / or hardware manner and can be integrated into the terminal, such as: any smart phone, tablet computer or computer device with communication functions.

[0039] Embodiment 4

[0040] This embodiment provides an OTA upgrade package encryption device, which is applied to an OTA platform. As Figure 4 shown, it is a schematic structural diagram of the device provided in this embodiment, mainly including: The first receiving module S401: used to receive the upgrade request sent by the in-vehicle terminal, and the upgrade request includes the vehicle identifier; The encryption module S402: used to encrypt the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate the encrypted upgrade package ciphertext, and the OTA upgrade package is determined according to the upgrade request; encrypt the OTA encryption key using an identity cryptographic algorithm according to the vehicle identifier to generate the key ciphertext; The first sending module S403: used to send the encrypted file to the in-vehicle terminal, and the encrypted file includes the encrypted upgrade package ciphertext and the key ciphertext.

[0041] The OTA upgrade package encryption device provided in this embodiment can execute the OTA upgrade package encryption method provided in the foregoing Embodiment 2, and has the corresponding functional modules and beneficial effects for executing the method.

[0042] Embodiment 5

[0043] This embodiment provides an OTA upgrade package decryption device, which is applied to an in-vehicle terminal. As Figure 5 shown, it is a schematic structural diagram of the device provided in this embodiment, mainly including: The second sending module S501: used to send an upgrade request to the OTA platform in response to the local software version being lower than the OTA platform software version, and the upgrade request includes the vehicle identifier; Second receiving module S502: It is used to receive the encrypted file sent by the OTA platform. The encrypted file includes the ciphertext of the upgrade package and the ciphertext of the key. Decryption module S503: It is used to decrypt the ciphertext of the key by using the identification cipher algorithm according to the identification private key to generate the plaintext of the key. The identification private key is the asymmetric key of the vehicle identification. The plaintext of the key includes the OTA encryption key. According to the OTA encryption key, the ciphertext of the upgrade package is decrypted by using the symmetric encryption algorithm to generate the plaintext of the upgrade package. The plaintext of the upgrade package includes the OTA upgrade package, and the OTA upgrade package is determined according to the upgrade request.

[0044] The OTA upgrade package decryption device provided in this embodiment can execute the OTA upgrade package decryption method provided in the foregoing Embodiment 3, and has the corresponding functional modules and beneficial effects for executing the method.

[0045] Embodiment Six

[0046] This embodiment also provides a vehicle-mounted terminal. The vehicle-mounted terminal can be a server, and its internal structure diagram can be as Figure 6 shown. The vehicle-mounted terminal includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface.

[0047] Among them, the processor of the vehicle-mounted terminal is used to provide computing and control capabilities. The memory of the vehicle-mounted terminal includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, an OTA upgrade package decryption program, and a database. The internal memory provides an environment for the operation of the operating system and the OTA upgrade package decryption program in the non-volatile storage medium. The database of the vehicle-mounted terminal is used to store the data obtained and generated in the method for the robot to autonomously enter the packaging container. The input / output interface of the vehicle-mounted terminal is used to exchange information between the processor and external devices. The communication interface of the vehicle-mounted terminal is used to communicate with external terminals through a network connection. When the OTA upgrade package decryption program is executed by the processor, the method of the foregoing Embodiment 3 is implemented.

[0048] Those skilled in the art can understand that Figure 6 the structure shown in

[0049] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the vehicle-mounted terminal to which the solution of the present application is applied. The specific vehicle-mounted terminal may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0050] Embodiment VII

[0051] This embodiment also provides a vehicle, including the on-vehicle terminal provided in the foregoing Embodiment VI.

[0052] Embodiment VIII

[0053] This embodiment also provides a computer-readable storage medium, on which an OTA upgrade package encryption program is stored. When the program is executed by a processor, the steps of the method described in the foregoing Embodiment II are implemented, and corresponding functional modules and beneficial effects for executing the method are provided; or, an OTA upgrade package decryption program is stored thereon. When the program is executed by a processor, the steps of the method described in the foregoing Embodiment III are implemented, and corresponding functional modules and beneficial effects for executing the method are provided.

[0054] The computer-readable storage medium provided in this embodiment can execute the OTA upgrade package encryption method provided in the foregoing Embodiment II or can execute the OTA upgrade package decryption method provided in the foregoing Embodiment III, and has corresponding functional modules and beneficial effects for executing the method.

[0055] In the description of the present invention, it should be understood that the terms "first", "second", etc. are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first", "second", etc. may explicitly or implicitly include one or more of such features. In the description of the present invention, unless otherwise stated, the meaning of "a plurality" is two or more.

[0056] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0057] The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate for implementing in the process Figure 1 one process or multiple processes and / or blocksFigure 1 means for functions specified in one or more blocks.

[0058] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to operate in a particular manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction means that implements the functions specified in one Figure 1 or more processes and / or blocks Figure 1 means for functions specified in one or more blocks.

[0059] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 or more processes and / or blocks Figure 1 means for functions specified in one or more blocks.

[0060] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the spirit and scope protected by the claims of the present invention. All of these are within the protection scope of the present invention.

Claims

1. An OTA upgrade package encryption and decryption method, characterized in that, The method includes: When the local software version of the vehicle terminal is lower than the OTA platform software version, the vehicle terminal sends an upgrade request to the OTA platform, and the upgrade request includes a vehicle identifier; The OTA platform determines an OTA upgrade package according to the upgrade request, and encrypts the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate an encrypted upgrade package ciphertext; The OTA platform encrypts the OTA encryption key using an identity-based cryptography algorithm according to the vehicle identifier to generate an encrypted key ciphertext; The OTA platform sends an encrypted file to the vehicle terminal, and the encrypted file includes the encrypted upgrade package ciphertext and the encrypted key ciphertext; The vehicle terminal decrypts the encrypted key ciphertext using an identity-based cryptography algorithm according to the identity private key to generate a clear key, and the identity private key is the asymmetric key of the vehicle identifier, and the clear key includes the OTA encryption key; The vehicle terminal decrypts the encrypted upgrade package ciphertext using a symmetric encryption algorithm according to the OTA encryption key to generate a clear upgrade package, and the clear upgrade package includes the OTA upgrade package.

2. An OTA upgrade package encryption method, characterized in that, The method applied to the OTA platform includes: Receiving an upgrade request sent by the vehicle terminal, where the upgrade request includes a vehicle identifier; Encrypting the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate an encrypted upgrade package ciphertext, and the OTA upgrade package is determined according to the upgrade request; Encrypting the OTA encryption key using an identity-based cryptography algorithm according to the vehicle identifier to generate an encrypted key ciphertext; Sending an encrypted file to the vehicle terminal, where the encrypted file includes the encrypted upgrade package ciphertext and the encrypted key ciphertext.

3. A method for decrypting an OTA upgrade package, characterized in that, The method applied to the vehicle terminal includes: When the local software version is lower than the OTA platform software version, sending an upgrade request to the OTA platform, and the upgrade request includes a vehicle identifier; Receiving an encrypted file sent by the OTA platform, where the encrypted file includes an encrypted upgrade package ciphertext and an encrypted key ciphertext; Decrypting the encrypted key ciphertext using an identity-based cryptography algorithm according to the identity private key to generate a clear key, and the identity private key is the asymmetric key of the vehicle identifier, and the clear key includes the OTA encryption key; Decrypting the encrypted upgrade package ciphertext using a symmetric encryption algorithm according to the OTA encryption key to generate a clear upgrade package, and the clear upgrade package includes the OTA upgrade package determined according to the upgrade request.

4. The OTA upgrade package decryption method according to claim 3, wherein Before sending the upgrade request to the OTA platform, it further includes: Sending a software version query request to the OTA platform; Receiving the OTA platform software version information returned by the OTA platform.

5. The OTA upgrade package decryption method according to claim 4, wherein Before sending the software version query request to the OTA platform, it further includes: Applying for an identity private key from the identity key management system according to the vehicle identifier; Receiving the identity private key returned by the identity key management system.

6. An OTA upgrade package encryption device, characterized in that, The device applied to the OTA platform includes: A first receiving module: used to receive an upgrade request sent by the vehicle terminal, where the upgrade request includes a vehicle identifier; Encryption module: used to encrypt the OTA upgrade package using a symmetric encryption algorithm according to the OTA encryption key to generate the encrypted upgrade package ciphertext, where the OTA upgrade package is determined according to the upgrade request; encrypt the OTA encryption key using an identity-based cryptography algorithm according to the vehicle identifier to generate the encrypted key ciphertext; First sending module: used to send the encrypted file to the in-vehicle terminal, where the encrypted file includes the encrypted upgrade package ciphertext and the encrypted key ciphertext.

7. An OTA upgrade package decryption device, characterized in that, The device is applied to the in-vehicle terminal and includes: Second sending module: used to send an upgrade request to the OTA platform in response to the local software version being lower than the OTA platform software version, where the upgrade request includes the vehicle identifier; Second receiving module: used to receive the encrypted file sent by the OTA platform, where the encrypted file includes the encrypted upgrade package ciphertext and the encrypted key ciphertext; Decryption module: used to decrypt the encrypted key ciphertext using an identity-based cryptography algorithm according to the identity private key to generate the key plaintext, where the identity private key is the asymmetric key of the vehicle identifier, and the key plaintext includes the OTA encryption key; decrypt the encrypted upgrade package ciphertext using a symmetric encryption algorithm according to the OTA encryption key to generate the upgrade package plaintext, where the upgrade package plaintext includes the OTA upgrade package, and the OTA upgrade package is determined according to the upgrade request.

8. A vehicle-mounted terminal, characterized in that, It includes a storage medium and a processor; The storage medium is used to store the OTA upgrade package decryption program; The processor is used to operate according to the OTA upgrade package decryption program to implement the steps of the OTA upgrade package decryption method according to any one of claims 3 to 5.

9. A vehicle, characterized in that, It includes the in-vehicle terminal according to claim 8.

10. A computer-readable storage medium, characterized in that, It stores an OTA upgrade package encryption program thereon, and when the program is executed by the processor, it implements the steps of the OTA upgrade package encryption method according to claim 2; or, it stores an OTA upgrade package decryption program thereon, and when the program is executed by the processor, it implements the steps of the OTA upgrade package decryption method according to any one of claims 3 to 5.