Automobile software remote upgrading method and system based on network security protection

The method and system use digital certificates and cryptographic algorithms to secure automobile software updates, addressing fragmented security measures and enhancing the integrity and confidentiality of the upgrade process, thus improving network security in smart connected vehicles.

CN120321045AInactive Publication Date: 2025-07-15CHINA AUTOMOTIVE TECH & RES CENT CO LTD +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510803977.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-07-15
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

While providing important update channels, automotive software upgrade technology increases information security risks, especially during remote download and firmware flashing, the number of ECUs on the vehicle is large and the computing performance is limited, resulting in tight protection resources and uneven security mechanism levels, which disperses protection risk points.

Method used

The upgrade package is signed by the digital certificate of the upgrade server and the SM3 hash algorithm. The encryption module uses the public key and SM4 symmetric algorithm in the digital certificate of the car to encrypt the upgrade package. It establishes a secure channel through the TLS communication protocol, and uses the private key of the car and the public key of the upgrade server for decryption and digest calculation during the decryption process to ensure the authenticity and integrity of the upgrade package.

Benefits of technology

It realizes the confidentiality of communication messages during the automotive software upgrade process, the authenticity and integrity of the upgrade package are protected, ensuring the protection of the secure environment and traceability of security incidents, and improving the security of remote upgrade of automotive software.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321045A_ABST
    Figure CN120321045A_ABST
Patent Text Reader

Abstract

The invention discloses an automobile software remote upgrading method and system based on network security protection, and relates to the technical field of automobile electronic systems.The method comprises the steps that a public key in a digital certificate of an automobile and an SM4 symmetric algorithm are adopted to encrypt a signed upgrading package, and an encrypted upgrading package is obtained; verifying based on the digital certificate and the digital certificate chain, and after the verification is passed, establishing a communication channel between the automobile and the upgrade server based on a TLS communication protocol; carrying out decryption and abstract calculation on the encrypted upgrade package by adopting a private key in the digital certificate of the automobile, a public key in the digital certificate of the upgrade server and an SM3 hash algorithm to obtain a first abstract value, a second abstract value and a decrypted upgrade package; and when the first digest value is consistent with the second digest value, remotely upgrading the automobile software by adopting the decrypted upgrade package. According to the invention, the security of remote upgrading of the automobile software can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of automotive electronic systems, and in particular to a method and system for remote software upgrade of automobiles based on network security protection. Background Art

[0002] A new round of scientific and technological and industrial revolutions is promoting the intelligent development of automobiles. In 2020, the sales volume of intelligent connected vehicles in China reached 3.032 million, and the market penetration rate was about 15%. World - wide, connected vehicles will account for 86% of the automotive market. The emergence of intelligent vehicles has greatly promoted the deep integration of the automotive industry with multiple industries such as the Internet, big data, and communication. However, while bringing innovation opportunities, this integration has also triggered severe network and data security problems. With the continuous increase in the vehicle networking rate, automobiles have gradually become key targets for cyber - attacks, and security risks have become increasingly prominent, while the corresponding security protection foundation is relatively weak.

[0003] With the development of the "new four modernizations" of automobiles, the technology of vehicle software upgrade has emerged. By changing the software of the electronic control units of modules such as vehicle airbags, engines, and charging systems, this technology can adjust vehicle safety, emissions, fuel consumption, and battery performance parameters, complete vehicle vulnerability repair and new function push, becoming a new ecological model in the automotive field and being widely applied. The content that can be upgraded has gradually expanded from the initial automotive audio - visual entertainment system to the automotive control system. However, while providing an important update path for intelligent connected vehicles, the vehicle software upgrade technology has also brought more information security risks. On the one hand, it provides internal and external interconnection interfaces. The upgrade process requires remote download of upgrade packages and flashing of firmware and software, which undoubtedly increases the possibility of the vehicle being invaded by information security. On the other hand, the security verification process of the vehicle - end upgrade package and other processes are carried out independently in each electronic control unit (ECU). Due to the limited computing performance of the vehicle - end ECU, the resources for remote software upgrade protection are tense. Moreover, each ECU manages the software upgrade process independently, and the levels of security mechanisms vary, resulting in scattered protection risk points and further exacerbating information security risks. Summary of the Invention

[0004] The purpose of the present application is to provide a method and system for remote software upgrade of automobiles based on network security protection, which can improve the security of remote software upgrade of automobiles.

[0005] To achieve the above - mentioned purpose, the present application provides the following solutions.

[0006] In a first aspect, the present application provides a method for remote software upgrade of an automobile based on network security protection, including: calculating the digest and signing the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is an upgrade package for remote upgrade of the automobile; encrypting the signed upgrade package using the public key in the digital certificate of the automobile and the SM4 symmetric algorithm to obtain the encrypted upgrade package; verifying based on the digital certificate and the digital certificate chain, and after the verification passes, establishing a communication channel between the automobile and the upgrade server based on the TLS communication protocol; the digital certificate includes the digital certificate of the automobile and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the automobile and the digital certificate chain of the upgrade server; transmitting the encrypted upgrade package between the automobile and the upgrade server through the communication channel, and decrypting and calculating the digest of the encrypted upgrade package using the private key in the digital certificate of the automobile, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to obtain the first digest value, the second digest value, and the decrypted upgrade package; when the first digest value and the second digest value are consistent, remotely upgrading the automobile software using the decrypted upgrade package.

[0007] In a second aspect, the present application provides a system for remote software upgrade of an automobile based on network security protection, including: a signature module for calculating the digest and signing the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is an upgrade package for remote upgrade of the automobile; an encryption module for encrypting the signed upgrade package using the public key in the digital certificate of the automobile and the SM4 symmetric algorithm to obtain the encrypted upgrade package; a verification and channel construction module for verifying based on the digital certificate and the digital certificate chain, and after the verification passes, establishing a communication channel between the automobile and the upgrade server based on the TLS communication protocol; the digital certificate includes the digital certificate of the automobile and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the automobile and the digital certificate chain of the upgrade server; a decryption module for transmitting the encrypted upgrade package between the automobile and the upgrade server through the communication channel, and decrypting and calculating the digest of the encrypted upgrade package using the private key in the digital certificate of the automobile, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to obtain the first digest value, the second digest value, and the decrypted upgrade package; an upgrade module for remotely upgrading the automobile software using the decrypted upgrade package when the first digest value and the second digest value are consistent.

[0008] According to the specific embodiments provided by the present application, the present application has the following technical effects.

[0009] The present application provides a method and system for remote vehicle software upgrade based on network security protection. First, through digital certificates and digital certificate chains, the identities of the vehicle and the upgrade server are verified to ensure the legitimacy between the identities of the vehicle and the upgrade server. Then, a secure communication channel is established between the vehicle and the upgrade server through the TLS communication protocol to ensure the security of the transmission channel for the upgrade package. Finally, the upgrade package is encrypted using the public key in the vehicle's digital certificate and the SM4 symmetric algorithm, and the encrypted upgrade package is decrypted and subjected to digest calculation using the private key in the vehicle's digital certificate, the public key in the upgrade server's digital certificate, and the SM3 hashing algorithm, realizing the confidentiality of communication messages, the authenticity and integrity protection and verification of the upgrade package during the vehicle software upgrade process, ensuring the security protection of the basic environment and the traceability of security events, and improving the security of remote vehicle software upgrade. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0011] Figure 1 It is a schematic flowchart of a method for remote vehicle software upgrade based on network security protection provided by an embodiment of the present application.

[0012] Figure 2 It is a detailed flowchart of a method for remote vehicle software upgrade based on network security protection provided by an embodiment of the present application.

[0013] Figure 3 It is a detailed structural schematic diagram of a system for remote vehicle software upgrade based on network security protection provided by an embodiment of the present application.

[0014] Figure 4 It is a structural schematic diagram of a system for remote vehicle software upgrade based on network security protection provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0015] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application.

[0016] In 2015, Charlie Miller and Chris Valasek successfully hacked a Jeep remotely, being able to remotely control the car's air conditioner, windshield wipers, and even the accelerator and brakes, which could seriously affect the personal safety of drivers and passengers, resulting in the company recalling 1.4 million vehicles. In the past 10 years, the number of automotive cybersecurity incidents has been increasing rapidly. On the other hand, according to the dynamic monitoring of the vehicle networking by the Ministry of Industry and Information Technology, since 2020, more than 2.8 million malicious attacks on related enterprises and platforms such as vehicle manufacturers and vehicle networking information service providers have been discovered. Risks such as platform vulnerabilities, communication hijacking, and privacy leakage are very serious, and the harm is even more severe, easily triggering social security risks.

[0017] However, while automotive software upgrade technology provides an important update path for intelligent connected vehicles, it also brings more information security risks. Automotive software upgrade technology provides internal and external interconnection interfaces. The upgrade process requires the remote download of upgrade packages and the flashing of firmware and software, increasing the possibility of additional information security intrusion into the vehicle. There are a large number of in-vehicle ECUs, and the security verification of upgrade packages and other processes are carried out independently in each ECU. However, the computing performance of in-vehicle ECUs is limited, resulting in a shortage of resources for protecting remote software upgrades. Moreover, a large number of in-vehicle ECUs manage their own software upgrade processes independently, and the security mechanism levels of each ECU vary, leading to problems such as scattered protection risk points.

[0018] Regarding automotive software upgrade technology, automotive manufacturers at home and abroad have designed their own remote and local automotive software upgrade technology processes and system design solutions. How to deal with attacks such as illegal access and data tampering by hackers during data transmission and flashing is still a hot topic of current research. Foreign research mainly focuses on the security strength of various signature encryption algorithms (symmetric encryption and asymmetric encryption) or the adjustment and improvement for specific system requirements, as well as how to apply the improved and integrated security measures to industrial production practice. How to build a protection strategy that meets the security, functionality, and performance requirements of Chinese automotive software upgrades still requires further research.

[0019] This application designs a method for remote automotive software upgrade based on network security protection. It provides technical support for the research and verification of the information security of remote automotive software upgrades. The conclusion of the protection method formed by this application supports the formulation of the national standard "General Technical Requirements for Automotive Software Upgrade", providing information security technical guarantees for the development of the automotive remote software upgrade technology in the industry and can be widely applied in the automotive industry.

[0020] To make the above objects, features, and advantages of this application more obvious and understandable, the following further details this application in combination with the accompanying drawings and specific embodiments.

[0021] In an exemplary embodiment, asFigure 1 As shown in the figure, a method for remotely upgrading automotive software based on network security protection is provided. This method is executed by a computer device, which can be specifically executed by a computer device such as a terminal or a server alone, or jointly executed by a terminal and a server. In the embodiments of the present application, taking the application of this method to a server as an example for illustration, it includes the following steps S1 to S5.

[0022] Step S1: Calculate the digest and sign the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is an upgrade package for remote upgrade of the vehicle.

[0023] Further, step S1 specifically includes the following steps S11 - S13.

[0024] Step S11: Calculate the digest of the upgrade package using the SM3 hashing algorithm to obtain the third digest value.

[0025] Step S12: Sign the third digest value using the private key in the digital certificate of the upgrade server to obtain the first signature value.

[0026] Step S13: Package the first signature value and the upgrade package to obtain the signed upgrade package.

[0027] Step S2: Encrypt the signed upgrade package using the public key in the digital certificate of the vehicle and the SM4 symmetric algorithm to obtain the encrypted upgrade package.

[0028] Further, step S2 specifically includes the following steps S21 - S22.

[0029] Step S21: Encrypt the key of the SM4 symmetric algorithm using the public key in the digital certificate of the vehicle to obtain the encrypted key.

[0030] Step S22: Encrypt the signed upgrade package using the encrypted key to obtain the encrypted upgrade package.

[0031] Step S3: Perform verification based on the digital certificate and the digital certificate chain. After the verification passes, establish a communication channel between the vehicle and the upgrade server based on the TLS communication protocol; the digital certificate includes the digital certificate of the vehicle and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the vehicle and the digital certificate chain of the upgrade server.

[0032] Specifically, the process of generating the digital certificate for the upgrade server is as follows: First, use the SM2 asymmetric cryptographic algorithm to generate a key pair. The private key is securely stored by the server, and the public key is used for subsequent operations. Next, use the server-related information (such as the server domain name, the name of the vehicle manufacturer to which the server belongs, etc.), together with the public key, to generate a Certificate Signing Request (CSR), and use the private key to sign the CSR. Then, submit the CSR to a trusted Certificate Authority (CA). After the CA reviews the integrity of the CSR and the server identity information, use the SM3 hashing algorithm to perform a digest calculation on the certificate content, and sign the digest value with the private key of the CA, finally generating the digital certificate. After the server receives the certificate, it installs it in its own system to prove the legitimacy and security of its own identity to clients such as automobiles during the software upgrade process.

[0033] The process of generating the digital certificate for the vehicle is as follows: First, the vehicle manufacturer uses the SM2 asymmetric cryptographic algorithm to generate a key pair. The private key is stored in the vehicle, and the public key is used for subsequent operations. Next, use the vehicle-related information (such as the vehicle identification number, the name of the vehicle manufacturer, etc.), together with the public key, to generate a Certificate Signing Request (CSR), and use the private key to sign the CSR. Then, submit the CSR to a trusted Certificate Authority (CA). After the CA reviews the integrity of the CSR and the vehicle identity information, use the SM3 hashing algorithm to perform a digest calculation on the certificate content, and sign the digest value with the private key of the CA, finally generating the digital certificate. After the vehicle manufacturer receives the certificate, it installs it in the vehicle's cryptographic module to prove the legitimacy and security of its own identity to the server, etc. during the software upgrade process.

[0034] Generation of the certificate chain: First, a trusted Root Certificate Authority (CA) generates the root certificate. The root CA self-signs the root certificate using its own private key. The root certificate contains the public key and related information of the root CA. The root CA can issue one or more intermediate certificates to the intermediate CAs. The intermediate CAs are responsible for generating and managing digital certificates within a specific scope. The intermediate CAs use the public key of the root CA to verify the root certificate and sign the intermediate certificates using their own private keys. The intermediate CAs generate digital certificates for specific entities (such as software upgrade servers or automobiles). The entity generates a key pair and creates a Certificate Signing Request (CSR). After receiving the CSR, the intermediate CA conducts a review. After passing the review, the intermediate CA generates the entity certificate using the entity's public key and related information, and signs the entity certificate using its own private key. The digital certificate chain consists of the entity certificate, the intermediate certificate, and the root certificate. The entity certificate is at the top of the chain, the intermediate certificate is in the middle layer, and the root certificate is at the end of the chain. The certificate chain ensures that each certificate can be verified by the upper-level certificate, and ultimately the trust chain traces back to the root certificate.

[0035] Further, the digital certificate is generated using the SM2 asymmetric cryptographic algorithm and the SM3 hashing algorithm.

[0036] Further, step S3 specifically includes the following steps S31 - S33.

[0037] Step S31: Based on the asymmetric cryptographic algorithm and the hashing algorithm, generate a digital certificate and a digital certificate chain.

[0038] Step S32: Based on the digital certificate, use the digital certificate chain for verification to obtain a first verification result.

[0039] Further, step S32 specifically includes the following steps S321 - S322.

[0040] Step S321: Use the digital certificate chain of the vehicle to verify the digital certificate of the upgrade server to obtain a second verification result.

[0041] Step S322: Determine whether the second verification result is passed; if so, use the digital certificate chain of the upgrade server to verify the digital certificate of the vehicle to obtain a first verification result; if not, end the communication between the vehicle and the upgrade server.

[0042] Step S33: Determine whether the first verification result is passed; if so, establish a communication channel between the vehicle and the upgrade server based on the TLS communication protocol; if not, end the communication between the vehicle and the upgrade server.

[0043] Step S4: Transmit the encrypted upgrade package between the vehicle and the upgrade server through the communication channel, and use the private key in the digital certificate of the vehicle, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to decrypt and calculate the digest of the encrypted upgrade package to obtain a first digest value, a second digest value, and the decrypted upgrade package.

[0044] Further, step S4 specifically includes the following steps S41 - S44.

[0045] Step S41: Use the private key in the digital certificate of the vehicle to decrypt the encrypted upgrade package to obtain the key of the SM4 symmetric algorithm.

[0046] Step S42: Use the key of the SM4 symmetric algorithm to decrypt the encrypted upgrade package to obtain the decrypted upgrade package.

[0047] Step S43: Use the SM3 hashing algorithm to calculate the digest of the decrypted upgrade package to obtain a first digest value.

[0048] Step S44: Calculate the digest of the first signature value using the public key in the digital certificate of the upgrade server to obtain a second digest value.

[0049] Step S5: When the first digest value and the second digest value are consistent, remotely upgrade the vehicle software using the decrypted upgrade package.

[0050] Regarding the process of the above Steps S1 - S5, as Figure 2 shown, an embodiment is provided for the interaction process between the vehicle and the upgrade server. As Figure 3 shown, the vehicle includes: a vehicle-end system A for vehicle software upgrade, a communication security module B, a cryptographic module C, and an upgrade security module D. a and b are the interaction data between the vehicle and the upgrade server, where a represents secure upgrade upstream data (including connection requests, upload of digital certificates, etc.), and b represents secure upgrade downstream data (including issuance of digital certificates, issuance of upgrade packages, etc.).

[0051] Figure 2Among them, 0 means that the upgrade server uses the digital signature technology based on the SM2 asymmetric cryptographic algorithm and the SM3 hash cryptographic algorithm to sign the upgrade package. The specific steps are as follows: First, use the SM3 hash algorithm to calculate the digest of the upgrade package to obtain the third digest value. Then, use the private key in the SM2 digital certificate to sign the digest value to obtain the first signature value, and package the first signature value together with the upgrade package, waiting for the vehicle to request to download the upgrade package; 1 means that the communication security module of the vehicle sends a connection request to the upgrade server; 2 means that the upgrade server issues the digital certificate based on the SM2 algorithm used to prove the identity of the upgrade server to the vehicle, and the communication security module of the vehicle forwards the digital certificate to the password module; 3 means that the password module of the vehicle verifies the identity of the upgrade server using the digital certificate chain (the digital certificate chain is pre-loaded in the vehicle password module of this application); 4 means that after the upgrade service identity verification is passed, the communication security module sends the digital certificate used to prove the identity of the vehicle to the upgrade server; 5 means that the upgrade server verifies the identity of the vehicle; 6 means that the upgrade server issues the verification result. After the verification is passed, a secure connection based on the TLS communication protocol is established with the vehicle to carry out subsequent communications; 7 means that the upgrade server uses the public key in the digital certificate of the vehicle to encrypt and protect the password of the SM4 algorithm, and uses the SM4 algorithm to encrypt and protect the upgrade package; 8 means that the upgrade server transmits the encrypted key and the upgrade package to the vehicle through the TLS secure communication protocol, and the vehicle communication security module forwards the data to the password module; 9 The vehicle uses the private key in the digital certificate of the vehicle to decrypt the encrypted upgrade package to obtain the key of the SM4 symmetric algorithm, and uses the SM4 key to decrypt the encrypted upgrade package to obtain the decrypted upgrade package and the first signature value; 9-1 means that if the decryption fails, a failure message is sent to the upgrade security module, and the security log is recorded through the upgrade security module; 10 means that the vehicle password module uses the SM3 hash algorithm to calculate the digest of the upgrade package to obtain the first digest value, and uses the public key in the digital certificate of the upgrade service to decrypt the first signature value to obtain the second digest value, and compares the second digest value with the first digest value to verify the integrity of the upgrade package; 10-1 means that if the verification fails, a failure message is sent to the upgrade security module, and the security log is recorded through the upgrade security module; 11 means that after the verification is successful, the verified upgrade package is sent to the upgrade security module and distributed to the upgrade ECU for upgrade; 12 means that the upgrade security module reports the upgrade result to the communication security module in real time; 13 means that the communication security module uploads the upgrade result to the upgrade server.

[0052] Such as Figure 3As shown in the figure, the software upgrade process of the vehicle includes two parts: the upgrade server and the vehicle. The vehicle communicates with the upgrade server through the communication security module, manages the operation of the cryptographic algorithm and the key through the password module, and schedules and records the software upgrade process of each ECU of the vehicle through the upgrade security module. The vehicle and the upgrade server communicate through communication channels such as General Packet Radio Service (GPRS), cellular network, and Wi-Fi wireless network. The vehicle software upgrade host of the vehicle and all ECUs that need to be upgraded are connected (directly or indirectly) using Controller Area Network (CAN) or in-vehicle Ethernet.

[0053] This application takes domestic commercial cryptography technology as the core and provides a method for remote software upgrade of vehicles based on network security protection. This method is applied to the vehicle end of the vehicle, integrated with the vehicle-mounted terminal, and includes a password module, a communication security module, and an upgrade security module, providing functions such as software upgrade key management, certificate management, signature verification, symmetric decryption, and secure communication. The digital certificates based on the SM2 (asymmetric cryptographic algorithm) algorithm are used to uniformly represent the identities of entities such as the vehicle and the upgrade server. The vehicle password module uses the digital certificates of the upgrade server and the upgrade package obtained through the secure communication channel to provide authentication of the upgrade server and the upgrade package, ensuring the integrity and source authenticity of the upgrade package during the transmission process; through the SM4 symmetric encryption technology, the confidentiality of the upgrade package during transmission and storage is ensured, realizing the secure authentication of the communication identities of the vehicle end and the upgrade server end, and preventing information leakage caused by illegal access of external entities; the communication channel between the vehicle and the upgrade server is based on the TLS secure communication protocol to ensure the security of the upgrade package transmission channel; the signature verification, encryption, and decryption processes involved in this application are all completed in the password module.

[0054] The password module of this application is prefabricated with a certificate chain issued by the upgrade server. The digital certificate chain is used to realize the authentication of the authenticity of the identity of the upgrade server and the signature authentication of the upgrade package issued by the upgrade server to the vehicle.

[0055] Optionally, the password module uses a Trusted Execution Environment (TEE) or a security chip to realize the storage protection of the digital certificate chain, and the storage area of the digital certificate chain meets the security capabilities of the second level of national cryptography specified in GM / T008.

[0056] Preferably, the password module uses the SM2 asymmetric cryptographic algorithm and the SM3 hashing algorithm that meet GM / T0008 to realize the signature verification function.

[0057] Preferably, the SM4 symmetric cryptography algorithm is used to decrypt the upgrade package, and the symmetric key for decrypting the upgrade package is protected by the SM2 asymmetric cryptography algorithm before decryption.

[0058] Preferably, the key should be destroyed after the decryption process of symmetric encryption is completed.

[0059] Preferably, after the signature verification or decryption fails, an error message should be sent to the upgrade security module, and relevant log records should be generated.

[0060] The communication security module of this application protects communication information by establishing a secure communication channel with the upgrade server. For the communication data sent by the vehicle, the communication security module uses the TLS secure communication protocol for security protection. For the data other than the upgrade package sent from the server to the vehicle, the communication security module uses the TLS secure communication protocol for protection. For the upgrade package sent from the server to the vehicle, the communication module uses the TLS secure communication protocol to encrypt the channel, and the symmetric cryptography algorithm is used to encrypt the upgrade package at the application layer of the upgrade server. When the upgrade server sends the upgrade package, the asymmetric cryptography algorithm is used to encrypt the key of the symmetric cryptography algorithm and then send it to the vehicle together.

[0061] Preferably, the communication protocol of the communication module adopts the TLS1.2 or higher version or the GMSSL version.

[0062] The upgrade security module of this application receives the success or failure messages returned from the cryptographic module and the communication security module, and generates software upgrade security logs. When the vehicle is powered on and started, security detections of the cryptographic module and the communication security module are carried out, including the key storage situation, cached data of the upgrade, etc. The upgrade security module is equipped with a security event monitoring module, which can identify and record security logs when the cryptographic module and the communication module are under attacks such as DOS attacks, replay attacks, and key blasting attacks.

[0063] Preferably, the HSM or dedicated storage area technology is adopted for the storage protection of security logs.

[0064] Preferably, the upgrade security module has a secure boot function, which can realize the security check of the vehicle end.

[0065] Preferably, the security event monitoring function of the upgrade security module accesses a periodically updated feature library.

[0066] The beneficial effects of the vehicle software remote upgrade method based on network security protection proposed by this application are mainly manifested in the following aspects.

[0067] (1) By adopting three levels of security protection, namely the communication channel security protocol, communication message / upgrade package encryption, and upgrade environment, the confidentiality of communication messages, the authenticity and integrity protection and verification of upgrade packages are achieved, ensuring the security protection of the basic environment and the traceability of security events. In this application, digital certificates based on the SM2 algorithm are used to uniformly represent the identities of entities such as vehicles and upgrade servers. The vehicle uses the digital certificate obtained through the secure communication channel to complete the signature verification of the upgrade package, ensuring the integrity and source authenticity of the upgrade package data during transmission; through the SM4 symmetric cryptography algorithm, the confidentiality of upgrade package transmission and storage is ensured, preventing information leakage caused by illegal access by external entities; the invention implements a TLS secure communication protocol to ensure the security of the upgrade package transmission channel; the signature verification, encryption, and decryption processes involved in this application are all completed in the cryptographic module. This method protects the security of vehicle remote upgrades and provides good network security protection for vehicles.

[0068] (2) Realize the hierarchical decoupling of network security, establish in-depth defense measures, and achieve protection from the communication channel, communication messages, and basic security. The remote communication link is solely responsible for by the communication security module. The operation processes of upgrade server identity authentication and upgrade package verification are centralized in the cryptographic module, and the upgrade security module distributes the upgrade package. The keys involved in the process are centrally managed by the cryptographic module, solving problems such as high resource consumption and scattered protection risk points in vehicle remote software upgrade protection; by applying domestic commercial cryptography at the vehicle end, a protection strategy that meets the security, functionality, and performance requirements of Chinese vehicle software upgrades is constructed, realizing fast, efficient, and secure remote upgrades at the vehicle end, protecting the network security of vehicle upgrades from the bottom layer.

[0069] Based on the same inventive concept, the embodiment of this application also provides a vehicle software remote upgrade system based on network security protection. The implementation solutions provided by this system to solve problems are similar to the implementation solutions described in the above method. Therefore, the specific limitations in one or more embodiments of the vehicle software remote upgrade system based on network security protection provided below can refer to the limitations on the vehicle software remote upgrade method based on network security protection in the above text, and will not be repeated here.

[0070] In an exemplary embodiment, as Figure 4 shown, a vehicle software remote upgrade system based on network security protection is provided, including the following modules.

[0071] A signature module, which is used to perform digest calculation and signature on the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is an upgrade package for vehicle remote upgrade.

[0072] An encryption module, which is used to encrypt the signed upgrade package by using the public key in the digital certificate of the vehicle and the SM4 symmetric algorithm to obtain the encrypted upgrade package.

[0073] A verification and channel construction module, which is used to perform verification based on the digital certificate and the digital certificate chain. After the verification is passed, a communication channel between the vehicle and the upgrade server is established based on the TLS communication protocol; the digital certificate includes the digital certificate of the vehicle and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the vehicle and the digital certificate chain of the upgrade server.

[0074] A decryption module, which is used to transmit the encrypted upgrade package between the vehicle and the upgrade server through the communication channel, and decrypt and calculate the digest of the encrypted upgrade package by using the private key in the digital certificate of the vehicle, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to obtain the first digest value, the second digest value, and the decrypted upgrade package.

[0075] An upgrade module, which is used to remotely upgrade the vehicle software by using the decrypted upgrade package when the first digest value and the second digest value are the same.

[0076] Further, the encryption module includes: a first encryption unit, which is used to encrypt the key of the SM4 symmetric algorithm by using the public key in the digital certificate of the vehicle to obtain the encrypted key; a second encryption unit, which is used to encrypt the signed upgrade package by using the encrypted key to obtain the encrypted upgrade package.

[0077] Further, the decryption module includes: a first decryption unit, which is used to decrypt the encrypted upgrade package by using the private key in the digital certificate of the vehicle to obtain the key of the SM4 symmetric algorithm; a second decryption unit, which is used to decrypt the encrypted upgrade package by using the key of the SM4 symmetric algorithm to obtain the decrypted upgrade package; a first digest calculation unit, which is used to calculate the digest of the decrypted upgrade package by using the SM3 hashing algorithm to obtain the first digest value; a second digest calculation unit, which is used to calculate the digest of the first signature value by using the public key in the digital certificate of the upgrade server to obtain the second digest value.

[0078] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0079] In this text, specific examples are used to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method of this application and its core idea; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. To sum up, the content of this specification should not be construed as a limitation on this application.

Claims

1. A method for remotely upgrading automotive software based on network security protection, characterized in that, The vehicle software remote upgrade method based on network security protection includes: Calculating the digest and signing the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is an upgrade package for vehicle remote upgrade; Encrypting the signed upgrade package using the public key in the digital certificate of the vehicle and the SM4 symmetric algorithm to obtain the encrypted upgrade package; Verifying based on the digital certificate and the digital certificate chain. After the verification passes, establishing a communication channel between the vehicle and the upgrade server based on the TLS communication protocol; the digital certificate includes the digital certificate of the vehicle and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the vehicle and the digital certificate chain of the upgrade server; Transmitting the encrypted upgrade package between the vehicle and the upgrade server through the communication channel, and decrypting and calculating the digest of the encrypted upgrade package using the private key in the digital certificate of the vehicle, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to obtain the first digest value, the second digest value, and the decrypted upgrade package; When the first digest value and the second digest value are the same, remotely upgrading the vehicle software using the decrypted upgrade package.

2. The method for remotely upgrading automotive software based on network security protection according to claim 1, characterized in that The digital certificate is generated using the SM2 asymmetric cryptographic algorithm and the SM3 hashing algorithm.

3. The method for remotely upgrading automotive software based on network security protection according to claim 1, wherein Calculating the digest and signing the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package, specifically including: Calculating the digest of the upgrade package using the SM3 hashing algorithm to obtain the third digest value; Signing the third digest value using the private key in the digital certificate of the upgrade server to obtain the first signature value; Packaging the first signature value and the upgrade package to obtain the signed upgrade package.

4. The method for remotely upgrading an automotive software based on network security protection according to claim 1, wherein, Verifying based on the digital certificate and the digital certificate chain. After the verification passes, establishing a communication channel between the vehicle and the upgrade server based on the TLS communication protocol, specifically including: Generating the digital certificate and the digital certificate chain based on the asymmetric cryptographic algorithm and the hashing algorithm; Verifying using the digital certificate chain based on the digital certificate to obtain the first verification result; Judging whether the first verification result is passed; If so, establishing a communication channel between the vehicle and the upgrade server based on the TLS communication protocol; If not, ending the communication between the vehicle and the upgrade server.

5. The method for remotely upgrading automotive software based on network security protection according to claim 4, characterized in that, Verifying using the digital certificate chain based on the digital certificate to obtain the first verification result, specifically including: Verifying the digital certificate of the upgrade server using the digital certificate chain of the vehicle to obtain the second verification result; Judging whether the second verification result is passed; If so, verifying the digital certificate of the vehicle using the digital certificate chain of the upgrade server to obtain the first verification result; If not, ending the communication between the vehicle and the upgrade server.

6. The method for remotely upgrading automotive software based on network security protection according to claim 3, wherein Encrypting the signed upgrade package using the public key in the digital certificate of the vehicle and the SM4 symmetric algorithm to obtain the encrypted upgrade package, specifically including: Encrypting the key of the SM4 symmetric algorithm using the public key in the digital certificate of the vehicle to obtain the encrypted key; Encrypt the signed upgrade package with the encrypted key to obtain the encrypted upgrade package.

7. The method for remotely upgrading automotive software based on network security protection according to claim 6, characterized in that Use the private key in the digital certificate of the vehicle, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to decrypt the encrypted upgrade package and calculate the digest, obtaining the first digest value, the second digest value, and the upgrade package. Specifically, it includes: Use the private key in the digital certificate of the vehicle to decrypt the encrypted upgrade package to obtain the key of the SM4 symmetric algorithm. Use the key of the SM4 symmetric algorithm to decrypt the encrypted upgrade package to obtain the decrypted upgrade package. Use the SM3 hashing algorithm to calculate the digest of the decrypted upgrade package to obtain the first digest value. Use the public key in the digital certificate of the upgrade server to calculate the digest of the first signature value to obtain the second digest value.

8. An automotive software remote upgrade system based on network security protection, characterized in that, The vehicle software remote upgrade system based on network security protection includes: A signature module for calculating the digest and signing the upgrade package using the digital certificate of the upgrade server and the SM3 hashing algorithm to obtain the signed upgrade package; the upgrade package is set in the upgrade server; the upgrade package is the upgrade package for vehicle remote upgrade. An encryption module for encrypting the signed upgrade package using the public key in the digital certificate of the vehicle and the SM4 symmetric algorithm to obtain the encrypted upgrade package. A verification and channel construction module for verifying based on the digital certificate and the digital certificate chain. After the verification passes, establish a communication channel between the vehicle and the upgrade server based on the TLS communication protocol; the digital certificate includes the digital certificate of the vehicle and the digital certificate of the upgrade server; the digital certificate chain includes the digital certificate chain of the vehicle and the digital certificate chain of the upgrade server. A decryption module for transmitting the encrypted upgrade package between the vehicle and the upgrade server through the communication channel, and using the private key in the digital certificate of the vehicle, the public key in the digital certificate of the upgrade server, and the SM3 hashing algorithm to decrypt the encrypted upgrade package and calculate the digest, obtaining the first digest value, the second digest value, and the decrypted upgrade package. An upgrade module for remotely upgrading the vehicle software with the decrypted upgrade package when the first digest value and the second digest value are consistent.

9. The automotive software remote upgrade system based on network security protection according to claim 8, wherein The encryption module includes: A first encryption unit for encrypting the key of the SM4 symmetric algorithm using the public key in the digital certificate of the vehicle to obtain the encrypted key. A second encryption unit for encrypting the signed upgrade package with the encrypted key to obtain the encrypted upgrade package.

10. The automotive software remote upgrade system based on network security protection according to claim 9, wherein, The decryption module includes: A first decryption unit for decrypting the encrypted upgrade package using the private key in the digital certificate of the vehicle to obtain the key of the SM4 symmetric algorithm. A second decryption unit for decrypting the encrypted upgrade package using the key of the SM4 symmetric algorithm to obtain the decrypted upgrade package. A first digest calculation unit for calculating the digest of the decrypted upgrade package using the SM3 hashing algorithm to obtain the first digest value. A second digest calculation unit for calculating the digest of the first signature value using the public key in the digital certificate of the upgrade server to obtain the second digest value.

Citation Information

Patent Citations

  • Evidence storage method for solidifying data message by using digital certificate

    CN111628873A

  • Vehicle software upgrading method and device and storage medium

    CN115022092A

  • National and cryptographic hybrid encryption algorithm and device suitable for automobile ECU OTA upgrading and storage medium

    CN115883174A

  • Automobile remote control system based on PKI

    CN117560169A

  • Method, apparatus, and storage medium for updating vehicle software

    EP4318217A1