File protection method and system
By hashing calculation and cyclic redundancy verification of the OTA upgrade file package and multi-layer digital signatures are generated, the security and authenticity of OTA upgrade files are solved, ensuring the security and user experience of the vehicle system upgrade.
Patent Information
- Application Number
- CN202510831977.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-20
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-06-20
AI Technical Summary
The prior art has failed to effectively hide OTA upgrade files and ensure their security and authenticity.
By hashing calculation and cyclic redundancy verification of the upgraded file package, internal and external digital signatures and implicit digital signatures are generated, and combined with preset parameters to hide and decrypt, ensuring the integrity and authenticity of the file package.
Effectively confirm whether the upgrade file package has tampered with it, ensure the security and user experience of the vehicle system upgrade, and improve security.
Smart Images

Figure CN120337310A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of encryption technology, and in particular to a file protection method and system. Background Art
[0002] OTA (Over-The-Air) refers to the technology of remotely updating software or firmware for devices such as vehicles and mobile phones. In the automotive field, OTA has become one of the core functions of intelligent connected vehicles, enabling rapid iteration, function optimization, and vulnerability repair, thus enhancing the user experience and security.
[0003] However, the related technology does not describe how to hide OTA upgrade files and how to ensure the security and authenticity of OTA upgrade files. Summary of the Invention
[0004] In view of the above-mentioned disadvantages of the prior art, the purpose of this application is to provide a file protection method and system to solve the technical problems existing in the prior art.
[0005] To achieve the above object and other related objects, this application provides a file protection method, which is applied to a file receiving end and includes the following steps: Obtain an upgrade file package transmitted in advance or in real time through a file sending end, where the upgrade file package is used to upgrade a target device, and the target device includes a vehicle; Decrypt based on the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; According to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value, confirm whether the upgrade file package has been tampered with; wherein, the target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package.
[0006] In an embodiment of this application, the process of decrypting based on the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value includes: Decrypt based on the inner digital signature of the upgrade file package to obtain an inner hash value; wherein, the inner hash value is obtained by performing a hash calculation on the encrypted upgrade file of the upgrade file package; And / or, decrypt based on the implicit digital signature of the upgrade file package to obtain an implicit hash value and an implicit cyclic redundancy check value; wherein, the implicit hash value is obtained by performing a hash calculation on the implicit data corresponding to the upgrade file package, the implicit cyclic redundancy check value is obtained by performing a cyclic redundancy check on the implicit data, and the implicit data is obtained by hiding after adding preset parameters of the target device to the encrypted upgrade file; And / or, decrypt based on the outer digital signature of the upgrade file package to obtain an outer hash value and an outer cyclic redundancy check value; wherein, the outer hash value is obtained by performing a hash calculation on the explicit file corresponding to the upgrade file package, the outer cyclic redundancy check value is obtained by performing a cyclic redundancy check on the explicit file, and the explicit file includes the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature.
[0007] In an embodiment of the present application, the process of confirming whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value includes: Compare the outer hash value with the target hash value, and under the condition that the outer hash value is equal to the target hash value, then compare the outer cyclic redundancy check value with the target check value; And, under the condition that the outer cyclic redundancy check value is equal to the target check value, then compare the inner hash value with the target hash value; And, under the condition that the inner hash value is equal to the target hash value, then compare the implicit hash value with the target hash value; And, under the condition that the implicit hash value is equal to the target hash value, then compare the implicit cyclic redundancy check value with the target check value; And, under the condition that the implicit cyclic redundancy check value is equal to the target check value, the upgrade file package has not been tampered with.
[0008] In an embodiment of the present application, the process of confirming whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value further includes: Under the condition that the outer-layer hash value is not equal to the target hash value, or under the condition that the outer-layer cyclic redundancy check value is not equal to the target check value, or under the condition that the inner-layer hash value is not equal to the target hash value, or under the condition that the implicit hash value is not equal to the target hash value, or under the condition that the implicit cyclic redundancy check value is not equal to the target check value, or under the condition that the comparison times of the outer-layer hash value and the target hash value exceed the preset times, or under the condition that the comparison times of the outer-layer cyclic redundancy check value and the target check value exceed the preset times, or under the condition that the comparison times of the inner-layer hash value and the target hash value exceed the preset times, or under the condition that the comparison times of the implicit hash value and the target hash value exceed the preset times, or under the condition that the comparison times of the implicit cyclic redundancy check value and the target check value exceed the preset times, the upgrade file package has been tampered with.
[0009] In an embodiment of the present application, the preset parameters include an electronic control unit identification code, an electronic control unit production serial number, a system-on-chip serial number, and the current physical time; Among them, the electronic control units in the vehicle communicate for message transmission and signal interaction through a controller area network bus or an Ethernet bus, and the vehicle performs data information interaction with the file sending end through a cockpit domain controller.
[0010] The present application further provides a file protection method, which is applied to a file sending end, and the method includes the following steps: Encrypt the content of the upgrade file, and obtain an inner-layer digital signature based on the encrypted upgrade file; Obtain an implicit digital signature based on the preset parameters of the target device; wherein, the target device includes a vehicle; Generate an outer-layer digital signature according to the inner-layer digital signature and the implicit digital signature, and obtain an upgrade file package for upgrading the target device based on the outer-layer digital signature.
[0011] In an embodiment of the present application, the method further includes: Encrypt the content of the upgrade file to obtain an encrypted upgrade file; Perform a hash calculation on the encrypted upgrade file to obtain an inner-layer hash value, and encrypt the inner-layer hash value to obtain an inner-layer digital signature; Add the preset parameters of the target device to the encrypted upgrade file, and hide them according to the preset permissions to form implicit data; Perform a hash calculation on the implicit data to obtain an implicit hash value; and, perform a cyclic redundancy check on the implicit data to obtain an implicit cyclic redundancy check value; and, encrypt the implicit hash value and the implicit cyclic redundancy check value to obtain an implicit digital signature.
[0012] In an embodiment of the present application, the method further includes: Use the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature as an explicit file, and perform a hash calculation on the explicit file to obtain an outer hash value; and, perform a cyclic redundancy check on the explicit file to obtain an outer cyclic redundancy check value; and, encrypt the outer hash value and the outer cyclic redundancy check value to obtain the outer digital signature; Associate the outer digital signature with the explicit file to obtain an upgrade file package for upgrading the target device.
[0013] The present application also provides a file protection system, which is applied to a file receiving end. The system includes: A data acquisition module, configured to obtain an upgrade file package transmitted in advance or in real time through a file sending end. The upgrade file package is used to upgrade a target device, and the target device includes a vehicle; A decryption module, configured to decrypt according to the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; A comparison and protection module, configured to confirm whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value; wherein, the target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package.
[0014] The present application also provides a file protection system, which is applied to a file sending end. The system includes: An inner digital signature module, configured to encrypt the upgrade file content and obtain an inner digital signature based on the encrypted upgrade file; An implicit digital signature module, configured to obtain an implicit digital signature through preset parameters of a target device; wherein, the target device includes a vehicle; An outer digital signature module, configured to generate an outer digital signature according to the inner digital signature and the implicit digital signature; An upgrade file package module, configured to obtain an upgrade file package for upgrading the target device according to the outer digital signature.
[0015] As described above, the present application provides a file protection method and system, which have the following beneficial effects: obtaining an upgrade file package transmitted in advance or in real time through a file sender, where the upgrade file package is used to upgrade a target device, and the target device includes a vehicle; then decrypting the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; and confirming whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and a target hash value, and the comparison result between the decrypted cyclic redundancy check value and a target check value, where the target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package. It can be seen that the present application can perform security authentication and authenticity authentication on the upgrade file by confirming whether the upgrade file package has been tampered with, so as to ensure the upgrade safety requirements of the vehicle system and improve the user experience and security when upgrading the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic flowchart of the file protection method provided by an embodiment of the present application; Figure 2 It is an interactive schematic diagram of generating an inner digital signature provided by an embodiment of the present application; Figure 3 It is an interactive schematic diagram of generating an outer digital signature provided by an embodiment of the present application; Figure 4 It is a schematic flowchart of generating an outer digital signature provided by an embodiment of the present application; Figure 5 It is a schematic diagram of performing a hash calculation provided by an embodiment of the present application; Figure 6 It is a schematic flowchart of the file protection method provided by another embodiment of the present application; Figure 7 It is a schematic diagram of comparing hash values provided by an embodiment of the present application; Figure 8 It is a schematic flowchart of the file protection method provided by yet another embodiment of the present application; Figure 9 It is a schematic diagram of the hardware structure of the file protection system provided by an embodiment of the present application; Figure 10 It is a schematic diagram of the hardware structure of the file protection system provided by another embodiment of the present application; Figure 11 It is a schematic diagram of the hardware structure of a computer device suitable for implementing one or more embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The following describes the implementation manners of the present application through specific examples. Those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in this specification. The present application can also be implemented or applied through other different specific implementation manners. All details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present application. It can be understood that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. In addition, it can be understood that the drawings provided in the following embodiments only illustrate the basic concept of the present application schematically. Therefore, only the components related to the present application are shown in the drawings, rather than being drawn according to the number, shape, and size of the components in actual implementation. The types, numbers, and ratios of the components in actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0018] Figure 1 The flowchart of a file protection method is shown. Specifically, in an exemplary embodiment, as Figure 1 shown, this embodiment provides a file protection method applied to a file sending end. The method includes the following steps: S110, encrypt the content of the upgrade file, and obtain an inner digital signature based on the encrypted upgrade file; S120, obtain an implicit digital signature based on the preset parameters of the target device; where the target device includes a vehicle; S130, generate an outer digital signature according to the inner digital signature and the implicit digital signature, and obtain an upgrade file package for upgrading the target device based on the outer digital signature.
[0019] In some exemplary embodiments, the process of encrypting the content of the upgrade file and obtaining an inner digital signature based on the encrypted upgrade file may include: encrypting the content of the upgrade file to obtain an encrypted upgrade file; where the content of the upgrade file is used to form an upgrade file package; performing a hash calculation on the encrypted upgrade file to obtain an inner hash value, and encrypting the inner hash value to obtain an inner digital signature.
[0020] In some exemplary embodiments, the process of obtaining an implicit digital signature based on the preset parameters of the target device may include: adding the preset parameters of the target device to the encrypted upgrade file, and hiding them according to the preset permissions to form implicit data; performing a hash calculation on the implicit data to obtain an implicit hash value; and performing a cyclic redundancy check on the implicit data to obtain an implicit cyclic redundancy check value; and encrypting the implicit hash value and the implicit cyclic redundancy check value to obtain an implicit digital signature.
[0021] In some exemplary embodiments, the process of generating an outer digital signature based on an inner digital signature and an implicit digital signature and obtaining an upgrade file package for upgrading a target device may include: regarding the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature as explicit files, performing a hash calculation on the explicit files to obtain an outer hash value; and performing a cyclic redundancy check on the explicit files to obtain an outer cyclic redundancy check value; and encrypting the outer hash value and the outer cyclic redundancy check value to obtain an outer digital signature; associating the outer digital signature with the explicit files to obtain an upgrade file package for upgrading the target device.
[0022] In some exemplary embodiments, the hash value may also be referred to as the HASH value, and the hash calculation may also be referred to as the HASH calculation. In some examples, the HASH algorithms for performing the HASH calculation include, but are not limited to, algorithms such as MD5, SHA-128, and SHA-256. Among them, the characteristics of the HASH algorithm are: (1) Input sensitivity: Any change in the original input information should result in a significant change in the new HASH value. (2) Irreversibility: Given the plaintext and the HASH algorithm, the HASH value can be calculated within a limited time and with limited resources. However, given the HASH value, it is difficult to reverse-engineer the plaintext within a limited time. (3) Collision avoidance: It is difficult to find two pieces of plaintext with different contents such that their HASH values are the same.
[0023] In some exemplary embodiments, if the target device is a vehicle, the preset parameters of the target device include, but are not limited to, the electronic control unit (Electric Control Unit, abbreviated as ECU) identification code, the electronic control unit production serial number, the system on chip (System on Chip, abbreviated as SOC) serial number, and the current physical time. Among them, the electronic control units in the vehicle communicate and transmit signal interactions through the controller area network (Controller Area Network, abbreviated as CAN) bus or the Ethernet bus, and the vehicle exchanges data information with the file sender through the cockpit domain controller. For example, the ECUs in the cockpit domain controller communicate and transmit signal interactions through the controller area network bus or the Ethernet bus. Therefore, the ECU identification code, the ECU production serial number, the SOC serial number, and the current physical time can be saved into the encrypted upgrade file, and then the administrator permission of the encrypted upgrade file can be obtained, and the encrypted upgrade file added with the ECU identification code, the ECU production serial number, the SOC serial number, and the current physical time can be hidden to form implicit data.
[0024] In some exemplary embodiments, the file sender may be the cloud, and the file receiver may be the vehicle end.
[0025] In some exemplary embodiments, the generated HASH value can be encrypted with a private key to generate a corresponding digital signature.
[0026] In some exemplary embodiments, as Figure 2 shown, a HASH calculation can be performed on the encrypted upgrade file to obtain an inner-layer HASH value, and then the inner-layer HASH value can be encrypted to obtain an inner-layer digital signature.
[0027] In some exemplary embodiments, as Figure 2 shown, for the HASH result or HASH value obtained through HASH calculation, it can also be expressed in the form of a message digest; that is, the HASH result or HASH value can be expressed in the form of a message digest.
[0028] In some exemplary embodiments, as Figure 3 and Figure 4 shown, a HASH calculation is performed on the implicit data to obtain an implicit HASH value; and, a cyclic redundancy check (CRC) is performed on the implicit data to obtain an implicit CRC value; then the implicit HASH value and the implicit CRC value are encrypted to obtain an implicit digital signature. Then, the encrypted upgrade file, the inner-layer digital signature, the implicit data, the implicit CRC value, and the implicit digital signature are used as an explicit file, and a HASH calculation is performed on the explicit file to obtain an outer-layer HASH value; and, a CRC is performed on the explicit file to obtain an outer-layer CRC value; and, the outer-layer HASH value and the outer-layer CRC value are encrypted to obtain an outer-layer digital signature.
[0029] In some exemplary embodiments, all or part of the process of performing a hash calculation or HASH calculation can be referred to Figure 5 shown. For example, in Figure 5 , after the data content "John Smlth" undergoes a HASH calculation, the obtained HASH value is 02; after the data content "Usa Smlth" undergoes a HASH calculation, the obtained HASH value is 01; after the data content "Sam Doe" undergoes a HASH calculation, the obtained HASH value is 04; after the data content "Sandra Dee" undergoes a HASH calculation, the obtained HASH value can also be 02.
[0030] It can be seen from this that based on generating a digital signature by performing HASH calculation on the upgrade file, the ECU identification code, ECU production serial number, SOC serial number, and current physical time are saved into the encrypted upgrade file and hidden to obtain implicit data. Then, HASH calculation and CRC calculation are performed on the implicit data, and the implicit HASH value and implicit CRC value are encrypted to generate an implicit digital signature. Next, the encrypted upgrade file, inner digital signature, implicit data, implicit CRC value, and implicit digital signature are used as an explicit file, and then HASH calculation and CRC calculation are performed on the explicit file, and the outer HASH value and outer CRC value are encrypted to generate an outer digital signature. Finally, the outer digital signature and the explicit file are associated to obtain an upgrade file package for performing OTA (Over-The-Air, abbreviated as OTA) upgrade on the target device (such as a vehicle). When OTA upgrade is required for the vehicle, by performing outer digital signature verification and CRC verification, implicit digital signature verification, implicit CRC verification, and inner digital signature verification, the integrity and authenticity of the upgrade file can be ensured, thus meeting the security requirements for the upgrade of the entire vehicle system. Therefore, this method effectively reduces the probability of HASH value collision through the method of digital signature and CRC check, and at the same time, through multiple signature verifications of inner and outer digital signatures and CRC check, the upgrade file can have better anti-collision performance; and the digital signature generated by the implicit file content cannot be collided, ensuring the security of the entire vehicle system. At the same time, this method supports multiple digital signatures and signature verifications, supports explicit and implicit digital certificate signatures and signature verifications, and supports the hiding of upgrade data.
[0031] Figure 6 shows a schematic flowchart of a file protection method. Specifically, in an exemplary embodiment, as Figure 6 shown, this embodiment provides a file protection method applied to a file receiving end. The method includes the following steps: S610, obtain an upgrade file package transmitted in advance or in real time through a file sending end. The upgrade file package is used to upgrade a target device, and the target device includes a vehicle; S620, decrypt based on the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; S630, confirm whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value; wherein, the target hash value is obtained by performing hash calculation on the upgrade file package, and the target check value is obtained by performing cyclic redundancy check on the upgrade file package.
[0032] In some exemplary embodiments, the process of obtaining the target hash value by performing hash calculation on the upgrade file package can be referred to Figure 7 as shown. In Figure 7 it,Figure 7 The HASH value or letter digest in the upper middle row is used as the target hash value, and Figure 7 the HASH value or letter digest in the lower middle row is used as the decrypted hash value. As Figure 7 shown, when comparing the hash values, the digital signature can be taken first, and then decrypted with the public key to obtain the corresponding decrypted HASH value. Then, calculate the HASH of the upgrade file content itself as the target hash value, and then compare the obtained decrypted HASH value with the target hash value. If the two are the same, it proves that the upgrade file has not been modified.
[0033] In some exemplary embodiments, the process of decrypting based on the upgrade file package to obtain the decrypted hash value and the cyclic redundancy check value may include: decrypting based on the inner digital signature of the upgrade file package to obtain the inner hash value; wherein, the inner hash value is obtained by calculating the hash of the encrypted upgrade file of the upgrade file package. As an example, the specific process of obtaining the inner hash value by calculating the hash of the encrypted upgrade file of the upgrade file package can be seen in the above-mentioned some embodiments, and will not be elaborated here.
[0034] In some exemplary embodiments, the process of decrypting based on the upgrade file package to obtain the decrypted hash value and the cyclic redundancy check value may include: decrypting based on the implicit digital signature of the upgrade file package to obtain the implicit hash value and the implicit cyclic redundancy check value; wherein, the implicit hash value is obtained by calculating the hash of the implicit data corresponding to the upgrade file package, the implicit cyclic redundancy check value is obtained by performing a cyclic redundancy check on the implicit data, and the implicit data is obtained by hiding after adding the preset parameters of the target device to the encrypted upgrade file. As an example, the specific process of obtaining the implicit hash value by calculating the hash of the implicit data corresponding to the upgrade file package, and / or obtaining the implicit cyclic redundancy check value by performing a cyclic redundancy check on the implicit data can be seen in the above-mentioned some embodiments, and will not be elaborated here.
[0035] In some exemplary embodiments, the process of decrypting based on the upgrade file package to obtain the decrypted hash value and the cyclic redundancy check value may include: decrypting based on the outer digital signature of the upgrade file package to obtain the outer hash value and the outer cyclic redundancy check value; wherein, the outer hash value is obtained by calculating the hash of the explicit file corresponding to the upgrade file package, the outer cyclic redundancy check value is obtained by performing a cyclic redundancy check on the explicit file, and the explicit file includes the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature. As an example, the specific process of obtaining the outer hash value by calculating the hash of the explicit file corresponding to the upgrade file package, and / or obtaining the outer cyclic redundancy check value by performing a cyclic redundancy check on the explicit file can be seen in the above-mentioned some embodiments, and will not be elaborated here.
[0036] In some exemplary embodiments, according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value, the process of confirming whether the upgrade file package has been tampered with may include: comparing the outer-layer hash value with the target hash value, and under the condition that the outer-layer hash value is equal to the target hash value, then comparing the outer-layer cyclic redundancy check value with the target check value; and, under the condition that the outer-layer cyclic redundancy check value is equal to the target check value, then comparing the inner-layer hash value with the target hash value; and, under the condition that the inner-layer hash value is equal to the target hash value, then comparing the implicit hash value with the target hash value; and, under the condition that the implicit hash value is equal to the target hash value, then comparing the implicit cyclic redundancy check value with the target check value; and, under the condition that the implicit cyclic redundancy check value is equal to the target check value, the upgrade file package has not been tampered with. Among them, the comparison process between the outer-layer hash value and the target hash value, the comparison process between the inner-layer hash value and the target hash value, and the comparison process between the implicit hash value and the target hash value can refer to Figure 7 the schematic diagram of hash value comparison shown, and details will not be repeated here.
[0037] In some exemplary embodiments, according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value, the process of confirming whether the upgrade file package has been tampered with may further include: under the condition that the outer-layer hash value is not equal to the target hash value, or, under the condition that the outer-layer cyclic redundancy check value is not equal to the target check value, or, under the condition that the inner-layer hash value is not equal to the target hash value, or, under the condition that the implicit hash value is not equal to the target hash value, or, under the condition that the implicit cyclic redundancy check value is not equal to the target check value, or, under the condition that the number of comparisons between the outer-layer hash value and the target hash value exceeds the preset number of times, or, under the condition that the number of comparisons between the outer-layer cyclic redundancy check value and the target check value exceeds the preset number of times, or, under the condition that the number of comparisons between the inner-layer hash value and the target hash value exceeds the preset number of times, or, under the condition that the number of comparisons between the implicit hash value and the target hash value exceeds the preset number of times, or, under the condition that the number of comparisons between the implicit cyclic redundancy check value and the target check value exceeds the preset number of times, the upgrade file package has been tampered with. Among them, the comparison process between the outer-layer hash value and the target hash value, the comparison process between the inner-layer hash value and the target hash value, and the comparison process between the implicit hash value and the target hash value can refer to Figure 7 the schematic diagram of hash value comparison shown, and details will not be repeated here. In some examples, the preset number of times can be set according to the actual situation, and no specific numerical limit is imposed on the preset number of times here. For example, the preset number of times can be set to 3 times.
[0038] In some exemplary embodiments, the preset parameters include the electronic control unit identification code, the electronic control unit production serial number, the system-on-chip serial number, and the current physical time; wherein, communication messages are transmitted and signals are interacted between the electronic control units in the vehicle through a controller area network bus or an Ethernet bus, and the vehicle performs data information interaction with the file sender through a cockpit domain controller (CDC).
[0039] Figure 8 The flowchart of a file protection method is shown. Specifically, in an exemplary embodiment, as Figure 8 shown, this embodiment provides a file protection method, which includes the following steps: Start an upgrade thread through the ECU in the vehicle, obtain the upgrade text version from the file sender, and download the upgrade file package. Perform HASH calculation and CRC check on the upgrade file package to obtain the corresponding HASH value and CRC value; and decrypt the digital signature on the outer layer of the upgrade file package to obtain the outer layer HASH value and the outer layer CRC value; Compare the outer layer HASH value with the HASH value obtained in the previous step. If the outer layer HASH value is equal to the HASH value obtained in the previous step, then proceed to the next step; if the outer layer HASH value is not equal to the HASH value obtained in the previous step, then directly exit the comparison and confirm that the upgrade file package has been tampered with; if the number of comparison times exceeds 3 times, also directly exit the comparison and confirm that the upgrade file package has been tampered with. And compare the outer layer CRC value with the CRC value obtained in the previous step. If the outer layer CRC value is equal to the CRC value obtained in the previous step, then proceed to the next step; if the outer layer CRC value is not equal to the CRC value obtained in the previous step, then directly exit the comparison and confirm that the upgrade file package has been tampered with; Perform HASH calculation on the explicit file of the upgrade file package to obtain the corresponding HASH value, and decrypt the digital signature of the explicit file to obtain the inner layer HASH value; Compare the inner layer HASH value with the HASH value obtained in the previous step. If the inner layer HASH value is equal to the HASH value obtained in the previous step, then proceed to the next step; if the inner layer HASH value is not equal to the HASH value obtained in the previous step, then directly exit the comparison and confirm that the upgrade file package has been tampered with; if the number of comparison times exceeds 3 times, also directly exit the comparison and confirm that the upgrade file package has been tampered with.
[0040] Obtain the management permission of the upgrade file package, read the hidden file, and perform HAHS calculation and CRC check on the implicit data of the upgrade file package to obtain the corresponding HASH value and CRC value; and decrypt the implicit digital signature of the upgrade file package to obtain the implicit HASH value and the implicit CRC value.
[0041] Compare the implicit HASH value with the HASH value obtained in the previous step. If the implicit HASH value is equal to the HASH value obtained in the previous step, proceed to the next step; if the implicit HASH value is not equal to the HASH value obtained in the previous step, directly exit the comparison and confirm that the upgrade file package has been tampered with; if the number of comparison times exceeds 3 times, also directly exit the comparison and confirm that the upgrade file package has been tampered with. Also, compare the implicit CRC value with the CRC value obtained in the previous step. If the implicit CRC value is equal to the CRC value obtained in the previous step, proceed to the next step; if the implicit CRC value is not equal to the CRC value obtained in the previous step, directly exit the comparison and confirm that the upgrade file package has been tampered with.
[0042] It can be seen that when OTA upgrade is required for a target device (such as a vehicle), this method can ensure the integrity and authenticity of the upgrade file by performing outer-layer digital signature verification and CRC verification, implicit digital signature verification, implicit CRC verification, and inner-layer digital signature verification, thereby meeting the security requirements for the upgrade of the vehicle system. Therefore, this method can effectively reduce the probability of HASH value collision through digital signature and CRC verification, and at the same time, through multi-layer digital signature and CRC verification, the upgrade file can have better anti-collision performance; and the digital signature generated by the implicit file content cannot be collided, ensuring the security of the vehicle system. At the same time, this method supports multi-signature and verification, supports explicit and implicit digital certificate signature and verification, and supports the hiding of upgrade data.
[0043] In another exemplary embodiment of the present application, as Figure 9 shown, this embodiment provides a file protection system applied to a file sender, including: An inner-layer digital signature module 101, configured to encrypt the content of the upgrade file and obtain an inner-layer digital signature based on the encrypted upgrade file; An implicit digital signature module 102, configured to obtain an implicit digital signature through preset parameters of the target device; wherein the target device includes a vehicle; An outer-layer digital signature module 103, configured to generate an outer-layer digital signature according to the inner-layer digital signature and the implicit digital signature; An upgrade file package module 104, configured to obtain an upgrade file package for upgrading the target device according to the outer-layer digital signature.
[0044] It can be understood that the file protection system provided in the above embodiments and the file protection method provided in the above embodiments belong to the same concept. The specific manner in which the file protection method performs operations has been described in detail in the above embodiments and will not be elaborated here. In actual application, the file protection system provided in the above embodiments can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the file protection system into different functional modules, and then implement all or part of the functions of the corresponding functional modules through the file protection method described in the above embodiments. This will not be specifically limited here either. For example, the inner layer digital signature module 101 can be used to execute step S110 and the steps associated therewith, the implicit digital signature module 102 can be used to execute step S120 and the steps associated therewith, and the outer layer digital signature module 103 and the upgrade file package module 104 can be used to execute step S130 and the steps associated therewith. For the specific execution process, refer to the above embodiments and will not be elaborated here.
[0045] It can be seen from this that based on generating a digital signature by performing HASH calculation on the upgrade file, the ECU identification code, ECU production serial number, SOC serial number, and current physical time are saved to the encrypted upgrade file and hidden to obtain implicit data; then HASH calculation and CRC calculation are performed on the implicit data, and the implicit HASH value and implicit CRC value are encrypted to generate an implicit digital signature; then the encrypted upgrade file, inner layer digital signature, implicit data, implicit CRC value, and implicit digital signature are used as an explicit file, and then HASH calculation and CRC calculation are performed on the explicit file, and the outer layer HASH value and outer layer CRC value are encrypted to generate an outer layer digital signature. Finally, the outer layer digital signature is associated with the explicit file to obtain an upgrade file package for performing OTA (Over-The-Air, abbreviated as OTA) upgrade on the target device (such as a vehicle). When an OTA upgrade is required for the vehicle, by performing outer layer digital signature verification and CRC verification, implicit digital signature verification, implicit CRC verification, and inner layer digital signature verification, the integrity and authenticity of the upgrade file can be ensured, thereby meeting the security requirements for the vehicle system upgrade. Therefore, through the method of digital signature and CRC check, the probability of HASH value collision can be effectively reduced. At the same time, through multiple signature verifications of the inner and outer layer digital signatures and CRC checks, the upgrade file can have better anti-collision performance; and the digital signature generated by the implicit file content cannot be collided, ensuring the safety of the vehicle system. At the same time, this system supports multiple digital signatures and signature verifications, supports explicit and implicit digital certificate signatures and signature verifications, and supports hiding upgrade data.
[0046] In another exemplary embodiment of the present application, as Figure 10 shown, this embodiment provides a file protection system applied to a file receiving end, including: The data acquisition module 111 is used to obtain the upgrade file package transmitted in advance or in real time through the file sender. The upgrade file package is used to upgrade the target device, and the target device includes vehicles. The decryption module 112 is used to decrypt according to the upgrade file package to obtain the decrypted hash value and cyclic redundancy check value. The comparison and protection module 113 is used to confirm whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value. The target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package.
[0047] It can be understood that the file protection system provided in the above embodiment and the file protection method provided in the above embodiment belong to the same concept. The specific manner of performing operations in the file protection method has been described in detail in the above embodiment and will not be repeated here. In practical applications, the file protection system provided in the above embodiment can allocate the above functions to different functional modules as needed, that is, divide the internal structure of the file protection system into different functional modules, and then implement all or part of the functions of the corresponding functional modules through the file protection method described in the above embodiment. This is not specifically limited here. For example, the data acquisition module 111 can be used to execute step S610 and related steps, the decryption module 112 can be used to execute step S620 and related steps, and the comparison and protection module 113 can be used to execute step S630 and related steps. For the specific execution process, refer to the above embodiment and will not be repeated here.
[0048] It can be seen that when OTA upgrading of the target device (such as a vehicle) is required, the system can ensure the integrity and authenticity of the upgrade file by performing outer digital signature verification and CRC verification, implicit digital signature verification, implicit CRC verification, and inner digital signature verification, thereby meeting the security requirements for the upgrade of the vehicle system. Therefore, the system effectively reduces the probability of HASH value collision through the method of digital signature and CRC check. At the same time, through multiple signature verifications of inner and outer layer digital signatures and CRC checks, the upgrade file can have better anti-collision performance; and the digital signature generated by the implicit file content cannot be collided, ensuring the safety of the vehicle system. At the same time, the system supports multiple digital signatures and signature verifications, supports explicit and implicit digital certificate signatures and signature verifications, and supports the hiding of upgrade data.
[0049] The embodiment of the present application also provides a computer device, which may include a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to cause the computer device to execute Figure 1 、Figure 6 and / or Figure 8 the steps of the file protection method described above Figure 11 FIG. shows a schematic structural diagram of a computer device 1000. Refer to Figure 11 As shown, the computer device 1000 includes: a processor 1010, a memory 1020, a power supply 1030, a display unit 1040, and an input unit 1060.
[0050] The processor 1010 is the control center of the computer device 1000, connecting various components through various interfaces and circuits, and executing various functions of the computer device 1000 by running or executing computer programs / instructions stored in the memory 1020, thereby monitoring the computer device 1000 as a whole. In the embodiments of the present application, when the processor 1010 calls the computer program stored in the memory 1020, it executes as Figure 1 , Figure 6 and / or Figure 8 the steps of the file protection method described above. Optionally, the processor 1010 may include one or more processing units; preferably, the processor 1010 may integrate an application processor and a modem processor, where the application processor mainly processes the operating system, user interface, applications, etc., and the modem processor mainly processes wireless communication. In some embodiments, the processor and the memory can be implemented on a single chip, and in some embodiments, they can also be implemented separately on independent chips.
[0051] The memory 1020 may mainly include a program storage area and a data storage area. Among them, the program storage area may store the operating system, various applications, etc.; the data storage area may store instruction data created according to the use of the computer device 1000, etc. In addition, the memory 1020 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other non-volatile solid-state storage devices, etc.
[0052] The computer device 1000 further includes a power supply 1030 (such as a battery) for powering each component. The power supply can be logically connected to the processor 1010 through a power management system, thereby implementing functions such as management of charging, discharging, and power consumption through the power management system.
[0053] The display unit 1040 can be used to display information input by the user or information provided to the user, as well as various menus of the computer device 1000. In the embodiments of this application, it is mainly used to display the display interfaces of various applications in the computer device 1000 and objects such as text and pictures displayed in the display interfaces. The display unit 1040 may include a display panel 1050. The display panel 1050 can be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc.
[0054] The input unit 1060 can be used to receive information such as numbers or characters input by the user. The input unit 1060 may include a touch panel 1070 and other input devices 1080. Among them, the touch panel 1070, also known as a touch screen, can collect touch operations of the user on or near it (such as operations of the user using any suitable object or accessory such as a finger or a stylus on or near the touch panel 1070).
[0055] Specifically, the touch panel 1070 can detect the user's touch operation, detect the signals brought by the touch operation, convert these signals into contact coordinates, send them to the processor 1010, and receive and execute the commands sent by the processor 1010. In addition, the touch panel 1070 can be implemented in multiple types such as resistive, capacitive, infrared, and surface acoustic wave. Other input devices 1080 may include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power on / off keys, etc.), a trackball, a mouse, a joystick, etc.
[0056] Of course, the touch panel 1070 can cover the display panel 1050. After the touch panel 1070 detects a touch operation on or near it, it transmits it to the processor 1010 to determine the type of touch event. Subsequently, the processor 1010 provides a corresponding visual output on the display panel 1050 according to the type of touch event. Although in Figure 11 the touch panel 1070 and the display panel 1050 are implemented as two independent components to realize the input and output functions of the computer device 1000, in some embodiments, the touch panel 1070 and the display panel 1050 can be integrated to realize the input and output functions of the computer device 1000.
[0057] The computer device 1000 may also include one or more sensors, such as a pressure sensor, a gravitational acceleration sensor, a proximity light sensor, etc. Of course, according to the needs in specific applications, the above computer device 1000 may also include other components such as a camera.
[0058] The embodiments of the present application also provide a computer-readable storage medium. When the computer program / instructions stored in the storage medium are executed by a processor, the above-mentioned device can execute the steps of the file protection method as described in the present application, such as Figure 1 , Figure 6 and / or Figure 8 the steps of the file protection method described above.
[0059] Those skilled in the art can understand that Figure 11 merely examples of computer devices are provided, which do not constitute a limitation on the device. The device may include more or fewer components than shown in the figure, or combine some components, or different components. For the convenience of description, the above parts are divided into various modules (or units) according to their functions and described separately. Of course, when implementing the present application, the functions of each module (or unit) can be implemented in the same or multiple software or hardware.
[0060] Those skilled in the art can understand that the present application can be implemented in the form of a computer program product on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be applied to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, so that the instructions executed by the processors of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks. These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Therefore, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0061] It is understandable that when the above embodiments collect, store, use, process, transmit, provide, disclose, delete, etc. relevant data (such as file upgrade packages, preset parameters of vehicles, etc.), it is completed with the consent of the user or after obtaining the consent of the user. For example, file upgrade packages, preset parameters of vehicles, etc. are obtained through authorization with the knowledge and consent of the user; or are actively provided by the user after reading the relevant instructions, or are actively authorized / provided / uploaded by the user when using some or all of the functions described in the above embodiments, or are obtained through other means / ways with the consent of the user or after obtaining the consent of the user.
[0062] The above embodiments are only illustrative of the principles and effects of the present application, rather than limiting the present application. Any person familiar with this technology can modify or change the above embodiments without departing from the spirit and scope of the present application. Therefore, all equivalent modifications or changes made by those with ordinary knowledge in the technical field without departing from the spirit and technical idea disclosed in the present application should still be covered by the claims of the present application.
Claims
1. A file protection method, characterized in that, Applied to the file receiving end, the method includes the following steps: Obtain an upgrade file package transmitted in advance or in real time by a file sending end, where the upgrade file package is used to upgrade a target device, and the target device includes a vehicle; Decrypt based on the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; Based on the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value, confirm whether the upgrade file package has been tampered with; where the target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package.
2. The file protection method according to claim 1, characterized in that The process of decrypting based on the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value includes: Decrypt based on the inner digital signature of the upgrade file package to obtain an inner hash value; where the inner hash value is obtained by performing a hash calculation on the encrypted upgrade file of the upgrade file package; And / or, decrypt based on the implicit digital signature of the upgrade file package to obtain an implicit hash value and an implicit cyclic redundancy check value; where the implicit hash value is obtained by performing a hash calculation on the implicit data corresponding to the upgrade file package, the implicit cyclic redundancy check value is obtained by performing a cyclic redundancy check on the implicit data, and the implicit data is obtained by hiding after adding preset parameters of the target device to the encrypted upgrade file; And / or, decrypt based on the outer digital signature of the upgrade file package to obtain an outer hash value and an outer cyclic redundancy check value; where the outer hash value is obtained by performing a hash calculation on the explicit file corresponding to the upgrade file package, the outer cyclic redundancy check value is obtained by performing a cyclic redundancy check on the explicit file, and the explicit file includes the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature.
3. The file protection method according to claim 2, wherein The process of confirming whether the upgrade file package has been tampered with based on the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value includes: Compare the outer hash value with the target hash value, and under the condition that the outer hash value is equal to the target hash value, then compare the outer cyclic redundancy check value with the target check value; And, under the condition that the outer cyclic redundancy check value is equal to the target check value, then compare the inner hash value with the target hash value; And, under the condition that the inner hash value is equal to the target hash value, then compare the implicit hash value with the target hash value; And, under the condition that the implicit hash value is equal to the target hash value, then compare the implicit cyclic redundancy check value with the target check value; And, under the condition that the implicit cyclic redundancy check value is equal to the target check value, the upgrade file package has not been tampered with.
4. The document protection method according to claim 3, characterized in that, The process of confirming whether the upgrade file package has been tampered with according to the comparison results between the decrypted hash value and the target hash value, and between the decrypted cyclic redundancy check value and the target check value further includes: Under the condition that the outer-layer hash value is not equal to the target hash value, or under the condition that the outer-layer cyclic redundancy check value is not equal to the target check value, or under the condition that the inner-layer hash value is not equal to the target hash value, or under the condition that the implicit hash value is not equal to the target hash value, or under the condition that the implicit cyclic redundancy check value is not equal to the target check value, or under the condition that the comparison times between the outer-layer hash value and the target hash value exceed the preset times, or under the condition that the comparison times between the outer-layer cyclic redundancy check value and the target check value exceed the preset times, or under the condition that the comparison times between the inner-layer hash value and the target hash value exceed the preset times, or under the condition that the comparison times between the implicit hash value and the target hash value exceed the preset times, or under the condition that the comparison times between the implicit cyclic redundancy check value and the target check value exceed the preset times, the upgrade file package has been tampered with.
5. The file protection method according to any one of claims 2 to 4, characterized in that The preset parameters include the electronic control unit identification code, the electronic control unit production serial number, the system-on-chip serial number, and the current physical time; Among them, communication message transmission and signal interaction are carried out between the electronic control units in the vehicle through the controller area network bus or the Ethernet bus, and the vehicle performs data information interaction with the file sender through the cockpit domain controller.
6. A file protection method, characterized in that, Applied to the file sender, the method includes the following steps: Encrypt the upgrade file content and obtain an inner-layer digital signature based on the encrypted upgrade file; Obtain an implicit digital signature based on the preset parameters of the target device; where the target device includes a vehicle; Generate an outer-layer digital signature according to the inner-layer digital signature and the implicit digital signature, and obtain an upgrade file package for upgrading the target device based on the outer-layer digital signature.
7. The document protection method according to claim 6, wherein The method further includes: Encrypt the upgrade file content to obtain an encrypted upgrade file; Perform a hash calculation on the encrypted upgrade file to obtain an inner-layer hash value, and encrypt the inner-layer hash value to obtain an inner-layer digital signature; and, Add the preset parameters of the target device to the encrypted upgrade file and hide them according to the preset permissions to form implicit data; Perform a hash calculation on the implicit data to obtain an implicit hash value; perform a cyclic redundancy check on the implicit data to obtain an implicit cyclic redundancy check value; and encrypt the implicit hash value and the implicit cyclic redundancy check value to obtain an implicit digital signature.
8. The file protection method according to claim 7, characterized in that The method further includes: Take the encrypted upgrade file, the inner digital signature, the implicit data, the implicit cyclic redundancy check value, and the implicit digital signature as an explicit file, perform a hash calculation on the explicit file to obtain an outer hash value; and, perform a cyclic redundancy check on the explicit file to obtain an outer cyclic redundancy check value; and, encrypt the outer hash value and the outer cyclic redundancy check value to obtain the outer digital signature; Associate the outer digital signature with the explicit file to obtain an upgrade file package for upgrading the target device, where the target device includes a vehicle.
9. A file protection system, characterized in that, Applied to a file receiving end, the system includes: A data acquisition module for obtaining an upgrade file package transmitted in advance or in real time through a file sending end, where the upgrade file package is used to upgrade a target device, and the target device includes a vehicle; A decryption module for decrypting according to the upgrade file package to obtain a decrypted hash value and a cyclic redundancy check value; A comparison protection module for confirming whether the upgrade file package has been tampered with according to the comparison result between the decrypted hash value and the target hash value, and the comparison result between the decrypted cyclic redundancy check value and the target check value; where the target hash value is obtained by performing a hash calculation on the upgrade file package, and the target check value is obtained by performing a cyclic redundancy check on the upgrade file package.
10. A file protection system, characterized in that, Applied to a file sending end, the system includes: An inner digital signature module for encrypting the upgrade file content and obtaining an inner digital signature based on the encrypted upgrade file; An implicit digital signature module for obtaining an implicit digital signature through preset parameters of a target device; where the target device includes a vehicle; An outer digital signature module for generating an outer digital signature according to the inner digital signature and the implicit digital signature; An upgrade file package module for obtaining an upgrade file package for upgrading the target device according to the outer digital signature.
Citation Information
Patent Citations
Information upgrading and backup method and system suitable for embedded equipment of power system
CN111131246A
Vehicle verification method, related device and system
CN117195216A
Firmware upgrade package verification method and device, terminal and storage medium
CN119128887A
Digitally signing documents using digital signatures
US11538122B1
Time Based Personal Communication
US20150156150A1