Vehicle OTA upgrading method and device, electronic equipment and storage medium

By using a dual security verification method of hash verification value and encrypted signature information in intelligent connected vehicles, the security risks of the OTA upgrade solution are solved and the security of the upgrade process is improved.

CN120342659AActive Publication Date: 2025-07-18FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Patent Information

Application Number
CN202510316501.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-07-18
Estimated Expiration
2045-03-18

AI Technical Summary

Technical Problem

The existing OTA upgrade solution has security risks in intelligent connected vehicles. Attackers can attack the OTA upgrade link through hijacking, tampering, replacement, etc., resulting in unsafe upgrade process.

Method used

The dual security verification method of hash check value and encrypted signature information is adopted, and the plain text hash check value is encrypted by the vehicle-side public key to generate the cipher text hash check value, and the cloud platform private key is encrypted by the plain text signature information to generate the cipher text signature information, and the upgrade package, cipher text hash check value and cipher text signature information are transmitted to the vehicle-side for upgrading.

Benefits of technology

It realizes dual security verification of the OTA upgrade process, reduces the risk of being attacked and tampered, and improves the security of OTA upgrades.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342659A_ABST
    Figure CN120342659A_ABST
Patent Text Reader

Abstract

The invention discloses an in-vehicle OTA upgrading method and device, electronic equipment and a storage medium, and relates to the technical field of computers, the method comprises the following steps: calculating a plaintext hash check value of an upgrade package; encrypting the plaintext hash check value by using a public key of the vehicle end to generate a ciphertext hash check value; encrypting plaintext signature information of the cloud platform by using a private key of the cloud platform to generate ciphertext signature information; wherein the plaintext signature information comprises a plaintext hash check value and the information of the upgrade package; and transmitting the upgrade package, the ciphertext hash check value and the ciphertext signature information to the vehicle end, so that the vehicle end can upgrade by using the upgrade package. According to the method and the device, the hash check value and the encrypted signature information are adopted, so that dual security verification is realized, the risk that the OTA process is attacked and tampered can be reduced, and the security of OTA upgrading is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular, to a method, device, electronic device and storage medium for OTA upgrade of a vehicle-mounted computer. Background Art

[0002] With the development of intelligent connected vehicles, more and more vehicle manufacturers have integrated the OTA upgrade function into vehicle products, and realize system upgrade, application update, vulnerability repair and function activation through OTA. OTA, that is, over-the-air update, refers to software upgrade that performs data transmission wirelessly instead of using cables or other local connections. As an important function of intelligent connected vehicles, the OTA function has also become a key target for attackers, who launch attacks on the OTA upgrade link of intelligent connected vehicles through attack methods such as hijacking, tampering, and replacement. Therefore, existing OTA upgrade solutions have security risks. Summary of the Invention

[0003] The main purpose of the embodiments of the present application is to propose a method, device, electronic device and storage medium for OTA upgrade of a vehicle-mounted computer, so as to improve the security of OTA upgrade of intelligent connected vehicles.

[0004] To achieve the above object, on the one hand, an embodiment of the present application proposes a method for OTA upgrade of a vehicle-mounted computer, which is applied to a cloud platform, and the method includes the following steps:

[0005] Calculate the plaintext hash check value of the upgrade package;

[0006] Encrypt the plaintext hash check value with the public key of the vehicle terminal to generate a ciphertext hash check value;

[0007] Encrypt the plaintext signature information of the cloud platform with the private key of the cloud platform to generate ciphertext signature information; wherein, the plaintext signature information includes the plaintext hash check value and the information of the upgrade package;

[0008] Transmit the upgrade package, the ciphertext hash check value and the ciphertext signature information to the vehicle terminal for the vehicle terminal to perform an upgrade using the upgrade package.

[0009] In some embodiments, the step of encrypting the plaintext hash check value with the public key of the vehicle terminal to generate a ciphertext hash check value includes the following steps:

[0010] If the length of the public key of the vehicle terminal exceeds the information block length of the information digest algorithm, calculate the digest of the public key of the vehicle terminal as the target public key using the information digest algorithm;

[0011] Encrypt the plaintext hash check value with the target public key to generate the ciphertext hash check value.

[0012] In some embodiments, encrypting the plaintext signature information of the cloud platform with the private key of the cloud platform to generate ciphertext signature information includes the following steps:

[0013] Combining the plaintext hash check value, the identity information of the cloud platform, and the version information of the upgrade package in a target format to form the plaintext signature information;

[0014] Encrypting the plaintext signature information with the private key of the cloud platform to generate the ciphertext signature information.

[0015] To achieve the above object, another aspect of the embodiments of the present application proposes a vehicle head unit OTA upgrade method, which is applied to the vehicle end in a vehicle head unit OTA upgrade method as described in the present application. The method includes the following steps:

[0016] Receiving an upgrade package sent by the cloud platform, the ciphertext hash check value of the upgrade package, and the ciphertext signature information of the cloud platform;

[0017] Decrypting the ciphertext signature information with the public key of the cloud platform to obtain decrypted signature information;

[0018] If the decrypted signature information matches the plaintext signature information of the cloud platform, calculate the plaintext hash check value of the upgrade package;

[0019] Decrypting the ciphertext hash check value with the private key of the vehicle end to obtain a decrypted hash check code;

[0020] If the decrypted hash check code matches the plaintext hash check value, perform an upgrade using the upgrade package.

[0021] In some embodiments, calculating the plaintext hash check value of the upgrade package includes the following steps:

[0022] Sequentially read the bytes of the upgrade package in chunks;

[0023] Using a hash algorithm to generate sub-hash values of corresponding lengths based on the bytes read in chunks;

[0024] Combining each of the sub-hash values to form the plaintext hash check value.

[0025] In some embodiments, the method further includes the following steps:

[0026] If it is detected that the upgrade of the upgrade package fails, roll back the software corresponding to the upgrade package to the version before the upgrade.

[0027] To achieve the above object, on the other hand, an embodiment of the present application provides a vehicle-mounted OTA upgrade device, which is applied to a cloud platform and includes:

[0028] A first hash value calculation unit for calculating a plaintext hash check value of the upgrade package;

[0029] A hash value encryption unit for encrypting the plaintext hash check value with the public key of the vehicle terminal to generate a ciphertext hash check value;

[0030] A signature encryption unit for encrypting the plaintext signature information of the cloud platform with the private key of the cloud platform to generate ciphertext signature information; wherein, the plaintext signature information includes the plaintext hash check value and the information of the upgrade package;

[0031] An information transmission unit for transmitting the upgrade package, the ciphertext hash check value and the ciphertext signature information to the vehicle terminal for the vehicle terminal to perform an upgrade using the upgrade package.

[0032] To achieve the above object, on the other hand, an embodiment of the present application provides a vehicle-mounted OTA upgrade device, which is applied to the vehicle terminal in a vehicle-mounted OTA upgrade method as described in the present application and includes:

[0033] An information receiving unit for receiving the upgrade package, the ciphertext hash check value of the upgrade package and the ciphertext signature information of the cloud platform sent by the cloud platform;

[0034] A signature decryption unit for decrypting the ciphertext signature information with the public key of the cloud platform to obtain decrypted signature information;

[0035] A second hash value calculation unit for calculating the plaintext hash check value of the upgrade package if the decrypted signature information matches the plaintext signature information of the cloud platform;

[0036] A hash value decryption unit for decrypting the ciphertext hash check value with the private key of the vehicle terminal to obtain a decrypted hash check code;

[0037] A software upgrade unit for performing an upgrade using the upgrade package if the decrypted hash check code matches the plaintext hash check value.

[0038] To achieve the above object, on the other hand, an embodiment of the present application provides an electronic device, which includes a memory and a processor, the memory stores a computer program, and the processor implements the above method when executing the computer program.

[0039] To achieve the above object, on the other hand, an embodiment of the present application provides a computer-readable storage medium storing a computer program, which when executed by a processor implements the above method.

[0040] The embodiments of the present application at least include the following beneficial effects:

[0041] The present application can calculate the plaintext hash check value of the upgrade package; encrypt the plaintext hash check value with the public key of the vehicle end to generate a ciphertext hash check value; encrypt the plaintext signature information of the cloud platform with the private key of the cloud platform to generate a ciphertext signature information, where the plaintext signature information includes the plaintext hash check value and the information of the upgrade package; transmit the upgrade package, the ciphertext hash check value and the ciphertext signature information to the vehicle end for the vehicle end to perform an upgrade using the upgrade package. The present application adopts the hash check value and the encrypted signature information, realizes double security verification, can reduce the risk of being attacked and tampered during the OTA process, and improves the security of the OTA upgrade. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0043] Figure 1 It is a schematic flowchart of a vehicle head unit OTA upgrade method provided by an embodiment of the present application;

[0044] Figure 2 It is a schematic flowchart of another vehicle head unit OTA upgrade method provided by an embodiment of the present application;

[0045] Figure 3 It is an example flowchart of a vehicle head unit OTA upgrade method provided by an embodiment of the present application;

[0046] Figure 4 It is a schematic structural diagram of a vehicle head unit OTA upgrade device provided by an embodiment of the present application;

[0047] Figure 5 It is a schematic structural diagram of another vehicle head unit OTA upgrade device provided by an embodiment of the present application;

[0048] Figure 6 It is a schematic hardware structure diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present application. They are only examples of devices and methods consistent with some aspects of the embodiments of the present application as detailed in the appended claims.

[0050] It can be understood that the terms "first", "second", etc. used in the present application can be used herein to describe various concepts, but unless otherwise specified, these concepts are not limited by these terms. These terms are only used to distinguish one concept from another. For example, without departing from the scope of the embodiments of the present application, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the words "if", "in case" used herein can be interpreted as "when...", "while...", or "in response to determining".

[0051] The terms "at least one", "a plurality of", "each", "any one", etc. used in the present application, at least one includes one, two or more than two, a plurality of includes two or more than two, each refers to each of the corresponding plurality, and any one refers to any one of the plurality.

[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present application belongs. The terms used herein are only for the purpose of describing the embodiments of the present application and are not intended to limit the present application.

[0053] Before describing the embodiments of the present application in detail, some related technologies involved in the embodiments of the present application will be described first, as follows:

[0054] The related OTA upgrade verification modes include:

[0055] (1) Integrity verification based on the HASH algorithm: The cloud uses the HASH algorithm such as MD5, SHA-1, etc. to calculate the HASH value of the upgrade file, and the vehicle end uses the same algorithm to calculate the HASH value of the upgrade file. By comparing the HASH values, the integrity verification of the upgrade file is realized, and the OTA upgrade verification is completed. However, attackers can usually bypass this verification method by tampering with the HASH value and the verification logic. This verification method has low security and the attack methods against this method are relatively mature.

[0056] (2) Signature verification based on the signature algorithm: By using the PKI system to generate public and private keys, the cloud uses the private key to encrypt the checksum of the upgrade package data or other variables related to the data content to complete the legal "signature" of the data. The vehicle side then uses the public key of the cloud to interpret the received "digital signature" and uses the interpretation result for the verification of data integrity to confirm the legality of the signature. This method confirms the source of the upgrade package, but it lacks consideration for the integrity of the upgrade package content and the rollback mechanism after an upgrade failure.

[0057] Related OTA upgrade methods include HASH integrity verification, signature algorithm verification, etc.

[0058] The integrity verification method based on the HASH algorithm is simple to deploy. However, if the HASH value is tampered with by an attacker during the transmission process or the verification logic is tampered with, this verification method will be bypassed. The signature verification based on the signature algorithm can basically confirm the legality of the signature and prove that the upgrade package indeed comes from a legitimate source, but it lacks consideration for the integrity of the upgrade package content and the rollback mechanism after an upgrade failure.

[0059] The purpose of this application is to provide a secure OTA upgrade method for intelligent connected vehicles. This method comprehensively utilizes technologies such as public key infrastructure (PKI), digital signature, hash verification, and failure rollback to ensure the data security during the upgrade process.

[0060] The purpose of using digital signatures is to confirm that a certain piece of information is indeed sent by a certain sender. It is impossible for anyone to forge the message, and the sender cannot deny it either. Through the use of digital signatures, OTA can prevent forgery, prevent denial, detect tampering, verify data integrity, etc., to ensure the legality of the software package during the OTA upgrade process. Common digital signature algorithms include: MD5withRSA / SHA1 withRSA / SHA256withRSA / SHA1withDSA / SHA 256withDSA / SHA512withDSA / ECDSA, etc.

[0061] HASH (Hash-based Message Authentication Code, abbreviated as HMAC, is a message authentication code algorithm based on hash functions, mainly used to ensure data integrity and verify the source of messages) algorithm is an algorithm based on message digests. Currently, it mainly incorporates two major series of message digest algorithms, MD and SHA. Among them, there are three algorithms in the MD series: HmacMD2, HmacMD4, and HmacMD5; there are five algorithms in the SHA series: HmacSHA1, HmacSHA224, HmacSHA256, HmacSHA384, and HmacSHA512. In addition to the message digest algorithm, the HMAC algorithm also requires a key. The key of HMAC can be of any length. If the length of the key exceeds the length of the message block of the digest algorithm, then the digest of the key is first calculated using the digest algorithm as the new key. Generally, it is not recommended to use a too short key because the length of the key is related to the security strength. In this application, the key length can be selected to be not less than the length of the message digest output by the selected digest algorithm.

[0062] Referring to Figure 1 , the embodiment of this application provides a method for vehicle-mounted OTA upgrade. The method is applied to a cloud platform and may include, but is not limited to, steps S100 to S130 as follows:

[0063] S100: Calculate the plaintext hash check value of the upgrade package.

[0064] S110: Encrypt the plaintext hash check value using the public key of the vehicle terminal to generate a ciphertext hash check value.

[0065] Further, S110 may include the following steps S111 to S112:

[0066] S111: If the length of the public key of the vehicle terminal exceeds the length of the message block of the digest algorithm, then calculate the digest of the public key of the vehicle terminal using the digest algorithm as the target public key;

[0067] S112: Encrypt the plaintext hash check value using the target public key to generate the ciphertext hash check value.

[0068] S120: Encrypt the plaintext signature information of the cloud platform using the private key of the cloud platform to generate ciphertext signature information; where the plaintext signature information includes the plaintext hash check value and the information of the upgrade package.

[0069] Further, S120 may include the following steps S121 to S122:

[0070] S121: Combine the plaintext hash check value, the identity information of the cloud platform, and the version information of the upgrade package into the plaintext signature information in a target format;

[0071] S122: Encrypt the plaintext signature information with the private key of the cloud platform to generate the ciphertext signature information.

[0072] S130: Transmit the upgrade package, the ciphertext hash check value, and the ciphertext signature information to the vehicle terminal for the vehicle terminal to perform an upgrade using the upgrade package.

[0073] Refer to Figure 2 , the embodiment of the present application provides a vehicle head unit OTA upgrade method, and the method is applied to Figure 1 the vehicle terminal in the method shown in

[0074] S200: Receive the upgrade package sent by the cloud platform, the ciphertext hash check value of the upgrade package, and the ciphertext signature information of the cloud platform.

[0075] S210: Decrypt the ciphertext signature information with the public key of the cloud platform to obtain the decrypted signature information.

[0076] S220: If the decrypted signature information matches the plaintext signature information of the cloud platform, calculate the plaintext hash check value of the upgrade package.

[0077] Further, S220 may include the following steps S221 to S223:

[0078] S221: Read the bytes of the upgrade package in blocks in sequence;

[0079] S222: Use a hash algorithm to generate sub-hash values of corresponding lengths based on the bytes obtained by block reading;

[0080] S223: Combine each of the sub-hash values into the plaintext hash check value.

[0081] S230: Decrypt the ciphertext hash check value with the private key of the vehicle terminal to obtain the decrypted hash check code.

[0082] S240: If the decrypted hash check code matches the plaintext hash check value, perform an upgrade using the upgrade package.

[0083] Further, the embodiment of the present application may further include a step of upgrade rollback:

[0084] S250: If it is detected that the upgrade of the upgrade package fails, roll back the software corresponding to the upgrade package to the version before the upgrade.

[0085] Next, specific application examples will be combined to introduce and explain the solution of the embodiment of the present application in detail.

[0086] Refer to Figure 3 , this embodiment provides an example flowchart of a vehicle head unit OTA upgrade method.

[0087] Specifically, this embodiment may include the following steps:

[0088] The first step: The OTA cloud platform establishes a secure link with the vehicle terminal TBOX.

[0089] The second step: The OTA cloud platform calculates the hash check value (H) of the upgrade package and encrypts H with the public key of the vehicle terminal to generate an encrypted hash check value (SH). The identity information of the cloud platform, the version information of the upgrade package, etc. are integrated into signature information (N) in a specific format and encrypted with the private key of the cloud platform to generate platform signature information (SN).

[0090] The third step: The OTA cloud platform transmits the upgrade package, signature information (SN), and encrypted check value (SH) to the vehicle terminal TBOX.

[0091] The fourth step: The vehicle terminal TBOX decrypts the signature information N1 through the public key of the cloud platform.

[0092] The fifth step: If N = N1, it means the signature information is valid, proving that the data source of the upgrade package is reliable; otherwise, enter the first step to re - establish the link.

[0093] The sixth step: The vehicle terminal TBOX calculates the hash check value H of the received data packet and decrypts the hash check value H1 through the private key of the vehicle terminal.

[0094] The seventh step: If H = H1, it means the check is valid and the content of the upgrade package is complete; otherwise, enter the second step.

[0095] The eighth step: The vehicle terminal TBOX distributes the upgrade package to the ECU, and the ECU performs a secondary check on the received upgrade package using digital signature or hash check technology according to its own software and hardware architecture. After the check is successful, the upgrade is flashed and installed.

[0096] The ninth step: The vehicle terminal checks the software or firmware version information. If the upgrade fails, it rolls back to the initial version.

[0097] More specifically, the solution of this embodiment can be implemented through the following implementation methods:

[0098] In the cloud platform, the following steps can be included:

[0099] 1. Calculate the hash check value of the upgrade package:

[0100] First, select a suitable hashing algorithm, such as SHA-256, and then calculate the hash of the file to be upgraded (e.g., "firmware_update.bin"). This step is carried out by reading each byte of the file and inputting it into the hash function, ultimately generating a unique hash value (H). This hash value represents the digital fingerprint of the file content and is used for subsequent integrity verification.

[0101] 2. Encrypt the hash check value:

[0102] Next, encrypt the calculated hash value H using the public key of the in-vehicle TBOX. This process ensures that only the in-vehicle device with the corresponding private key can decrypt it. The result of encryption is called the encrypted hash check value (SH). This step uses an asymmetric encryption algorithm and combines an encryption padding scheme such as PKCS5Padding or PKCS1Padding to ensure the security of the encryption process.

[0103] 3. Combine the obtained signature information:

[0104] In this step, the OTA cloud platform needs to prepare the signature information (N). The signature information usually includes the identity information of the cloud platform (e.g., "OTA_PLATFORM_001"), the version information of the upgrade package (e.g., "1.0.0"), and the previously calculated hash value H. These information can be combined in a specific format, for example, separated by the vertical bar "|". The final formed string N is the content to be signed.

[0105] 4. Generate the signature information:

[0106] Finally, encrypt the above-generated signature information N using the private key of the OTA cloud platform. This process generates the signature information (SN). Similarly, asymmetric encryption is also used here to ensure that only the recipient with the corresponding public key can verify the validity of this signature. After completion, the cloud platform will send the upgrade data packet, the encrypted hash check value SH, and the signature information SN to the in-vehicle TBOX together.

[0107] In the in-vehicle device, the following steps can be included:

[0108] 1. Calculate the hash check value H:

[0109] Receive the upgrade data packet: The in-vehicle TBOX first receives the upgrade data packet sent by the OTA cloud platform. This data packet contains the update content of the software or firmware.

[0110] Select the hash algorithm: Usually, SHA-256 or other secure hash algorithms are used. Selecting a suitable hash algorithm is very important as it can effectively generate the hash value of the data packet.

[0111] Read the content of the data packet: The TBOX reads the content of the entire upgrade data packet into memory. For larger files, it can be read in chunks to avoid excessive memory consumption.

[0112] Calculate the hash value: Pass each byte read to the hash algorithm. The hash algorithm processes these bytes to generate a hash value H of a fixed length. This hash value represents the content of the data packet. The process of calculating the hash value includes processing the read data in chunks until the entire data packet is processed.

[0113] Obtain the hash verification value H: After the calculation is completed, the TBOX will obtain the hash verification value H of the upgrade data packet. This value is used for subsequent integrity verification.

[0114] 2. Decrypt the hash verification value H1:

[0115] Receive the encrypted hash verification value: During the upgrade process, the cloud platform sends the encrypted hash verification value SH. The in-vehicle TBOX receives this encrypted value simultaneously.

[0116] Obtain the private key: The in-vehicle TBOX has its own private key. This private key is unique and only the in-vehicle side has it, which is used to decrypt encrypted information.

[0117] Select the decryption algorithm: Usually, an asymmetric encryption algorithm such as RSA is used, combined with an appropriate padding method (such as PKCS#1 v1.5 or OAEP) to ensure a secure decryption process.

[0118] Decrypt using the private key: The TBOX uses its own private key to decrypt the received encrypted hash verification value SH. This process involves passing the encrypted data to the decryption algorithm, and the algorithm uses the private key to process the data to restore the original hash value H1.

[0119] Obtain the hash verification value H1: After the decryption is completed, the TBOX will obtain the decrypted hash value H1. This value should be compared with the previously calculated hash value H to verify whether the data packet has been tampered with or damaged during transmission.

[0120] In summary, the technical features of this embodiment include:

[0121] 1) The OTA cloud platform calculates the hash verification value (H) of the upgrade package and encrypts H with the public key of the in-vehicle side to generate the encrypted hash verification value (SH), and fuses the content such as the identity information of the cloud platform and the version information of the upgrade package into the signature information (N) and encrypts it with the private key of the cloud platform to generate the platform signature information (SN).

[0122] 2) The in-vehicle TBOX distributes the upgrade package to the ECU. The ECU, based on its own software and hardware architecture, performs secondary verification on the received upgrade package using digital signature or hash verification technology. After successful verification, the upgrade is flashed and installed.

[0123] 3) The in-vehicle terminal checks the software or firmware version information. If the upgrade fails, it rolls back to the initial version.

[0124] This embodiment has at least the following beneficial effects:

[0125] 1. By using the Public Key Infrastructure (PKI) and digital signature technology, the legitimacy of the source signature of the upgrade package and the anti-tampering ability are enhanced.

[0126] 2. By using the asymmetric encryption algorithm and hash verification technology, the security of data during transmission is protected.

[0127] 3. Through the secondary verification mechanism, the security of the ECU upgrade package is improved.

[0128] 4. Through the rollback mechanism, the negative impact caused by upgrade failure is reduced.

[0129] Referring to Figure 4 , the embodiment of the present application also provides a vehicle head unit OTA upgrade device, which can implement Figure 1 a vehicle head unit OTA upgrade method. The device includes:

[0130] The first hash value calculation unit is used to calculate the plaintext hash verification value of the upgrade package;

[0131] The hash value encryption unit is used to encrypt the plaintext hash verification value with the public key of the in-vehicle terminal to generate a ciphertext hash verification value;

[0132] The signature encryption unit is used to encrypt the plaintext signature information of the cloud platform with the private key of the cloud platform to generate ciphertext signature information; wherein, the plaintext signature information includes the plaintext hash verification value and the information of the upgrade package;

[0133] The information transmission unit is used to transmit the upgrade package, the ciphertext hash verification value and the ciphertext signature information to the in-vehicle terminal for the in-vehicle terminal to use the upgrade package for upgrading.

[0134] Referring to Figure 5 , the embodiment of the present application also provides a vehicle head unit OTA upgrade device, which can implement Figure 2 a vehicle head unit OTA upgrade method. The device includes:

[0135] The information receiving unit is used to receive the upgrade package, the ciphertext hash verification value of the upgrade package and the ciphertext signature information of the cloud platform sent by the cloud platform;

[0136] A signature decryption unit, configured to decrypt the ciphertext signature information by using the public key of the cloud platform to obtain decrypted signature information;

[0137] A second hash value calculation unit, configured to calculate a plaintext hash check value of the upgrade package if the decrypted signature information matches the plaintext signature information of the cloud platform;

[0138] A hash value decryption unit, configured to decrypt the ciphertext hash check value by using the private key of the vehicle terminal to obtain a decrypted hash check code;

[0139] A software upgrade unit, configured to perform an upgrade by using the upgrade package if the decrypted hash check code matches the plaintext hash check value.

[0140] It can be understood that the content in the above method embodiments is applicable to the device embodiments. The functions specifically implemented by the device embodiments are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0141] An embodiment of the present application further provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the above vehicle-mounted OTA upgrade method. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.

[0142] It can be understood that the content in the above method embodiments is applicable to the device embodiments. The functions specifically implemented by the device embodiments are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0143] Please refer to Figure 6 , Figure 6 , which schematically shows the hardware structure of an electronic device in another embodiment. The electronic device includes:

[0144] A processor 601, which can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is configured to execute relevant programs to implement the technical solutions provided by the embodiments of the present application;

[0145] The memory 602 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM), etc. The memory 602 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 602 and are called by the processor 601 to execute a vehicle-mounted OTA upgrade method according to an embodiment of the present application;

[0146] The input / output interface 603 is used to implement information input and output;

[0147] The communication interface 604 is used to implement communication interaction between this device and other devices. Communication can be achieved through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.);

[0148] The bus 605 transmits information between the various components of the device (such as the processor 601, the memory 602, the input / output interface 603, and the communication interface 604);

[0149] Among them, the processor 601, the memory 602, the input / output interface 603, and the communication interface 604 are communicatively connected to each other inside the device through the bus 605.

[0150] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned vehicle-mounted OTA upgrade method.

[0151] It can be understood that the content in the above method embodiments is applicable to this storage medium embodiment. The functions specifically implemented by this storage medium embodiment are the same as those in the above method embodiments, and the beneficial effects achieved are also the same as those in the above method embodiments.

[0152] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely provided relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above networks include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0153] The embodiments described in the embodiments of the present application are for more clearly illustrating the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art will know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0154] Those skilled in the art can understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figures, or combine certain steps, or different steps.

[0155] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0156] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations.

[0157] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0158] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (one) of the following" or its similar expressions refer to any combination of these items, including any combination of single item (one) or plural items (ones). For example, at least one (one) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0159] In several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the above-mentioned unit division is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.

[0160] The units described above as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0161] In addition, each functional unit in various embodiments of this application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.

[0162] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods of various embodiments of this application. The aforementioned storage medium includes: various media that can store programs, such as USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs.

[0163] The preferred embodiments of the embodiments of this application have been described above with reference to the accompanying drawings, and thus do not limit the scope of the rights of the embodiments of this application. Any modifications, equivalent replacements, and improvements made by those skilled in the art without departing from the scope and essence of the embodiments of this application shall be within the scope of the rights of the embodiments of this application.

Claims

1. A method for OTA upgrade of a vehicle head unit, characterized in that, The method is applied to a cloud platform, and the method includes the following steps: Calculate the plaintext hash check value of the upgrade package; Use the public key of the vehicle terminal to encrypt the plaintext hash check value to generate a ciphertext hash check value; Use the private key of the cloud platform to encrypt the plaintext signature information of the cloud platform to generate ciphertext signature information; wherein, the plaintext signature information includes the plaintext hash check value and the information of the upgrade package; Transmit the upgrade package, the ciphertext hash check value, and the ciphertext signature information to the vehicle terminal for the vehicle terminal to perform an upgrade using the upgrade package.

2. The vehicle-mounted OTA upgrade method according to claim 1, wherein, The step of using the public key of the vehicle terminal to encrypt the plaintext hash check value to generate a ciphertext hash check value includes the following steps: If the length of the public key of the vehicle terminal exceeds the information block length of the information digest algorithm, then use the information digest algorithm to calculate the digest of the public key of the vehicle terminal as the target public key; Use the target public key to encrypt the plaintext hash check value to generate the ciphertext hash check value.

3. The vehicle-mounted OTA upgrade method according to claim 1, wherein The step of using the private key of the cloud platform to encrypt the plaintext signature information of the cloud platform to generate ciphertext signature information includes the following steps: Combine the plaintext hash check value, the identity information of the cloud platform, and the version information of the upgrade package in a target format to form the plaintext signature information; Use the private key of the cloud platform to encrypt the plaintext signature information to generate the ciphertext signature information.

4. A vehicle-mounted OTA upgrade method, characterized in that, The method is applied to the vehicle terminal in a vehicle OTA upgrade method as described in claim 1, and the method includes the following steps: Receive the upgrade package, the ciphertext hash check value of the upgrade package, and the ciphertext signature information of the cloud platform sent by the cloud platform; Use the public key of the cloud platform to decrypt the ciphertext signature information to obtain decrypted signature information; If the decrypted signature information matches the plaintext signature information of the cloud platform, then calculate the plaintext hash check value of the upgrade package; Use the private key of the vehicle terminal to decrypt the ciphertext hash check value to obtain a decrypted hash check code; If the decrypted hash check code matches the plaintext hash check value, then use the upgrade package to perform an upgrade.

5. The vehicle head unit OTA upgrade method according to claim 4, characterized in that The step of calculating the plaintext hash check value of the upgrade package includes the following steps: Read the bytes of the upgrade package in blocks sequentially; Use a hash algorithm to generate sub-hash values of corresponding lengths based on the bytes obtained by block reading; Combine the sub-hash values to form the plaintext hash check value.

6. A vehicle infotainment system OTA upgrade method according to any one of claims 4 to 5, characterized in that The method further includes the following steps: If it is detected that the upgrade of the upgrade package fails, then roll back the software corresponding to the upgrade package to the version before the upgrade.

7. A vehicle-mounted OTA upgrade device, characterized in that, The device is applied to a cloud platform, and the device includes: A first hash value calculation unit for calculating the plaintext hash check value of the upgrade package; A hash value encryption unit for using the public key of the vehicle terminal to encrypt the plaintext hash check value to generate a ciphertext hash check value; A signature encryption unit for using the private key of the cloud platform to encrypt the plaintext signature information of the cloud platform to generate ciphertext signature information; wherein, the plaintext signature information includes the plaintext hash check value and the information of the upgrade package; An information transmission unit, configured to transmit the upgrade package, the ciphertext hash check value, and the ciphertext signature information to the vehicle terminal for the vehicle terminal to perform an upgrade using the upgrade package.

8. A vehicle-mounted OTA upgrade device, characterized in that, The device is applied to the vehicle terminal in a vehicle-mounted OTA upgrade method as claimed in claim 1, and the device includes: An information receiving unit, configured to receive the upgrade package sent by the cloud platform, the ciphertext hash check value of the upgrade package, and the ciphertext signature information of the cloud platform; A signature decryption unit, configured to decrypt the ciphertext signature information using the public key of the cloud platform to obtain decrypted signature information; A second hash value calculation unit, configured to calculate the plaintext hash check value of the upgrade package if the decrypted signature information matches the plaintext signature information of the cloud platform; A hash value decryption unit, configured to decrypt the ciphertext hash check value using the private key of the vehicle terminal to obtain a decrypted hash check code; A software upgrade unit, configured to perform an upgrade using the upgrade package if the decrypted hash check code matches the plaintext hash check value.

9. An electronic device, characterized in that, The electronic device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the method as claimed in any one of claims 1 to 6 is implemented.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method as claimed in any one of claims 1 to 6 is implemented.

Citation Information

Patent Citations

  • Import and export system of virtual machine image in cloud computing

    CN102025744A

  • OTA upgrade package processing method and device and electronic equipment

    CN112882750A

  • OTA file security processing method, device and system

    CN113055181A

  • Automobile OTA upgrading system and method

    CN115665138A

  • Encryption method and device of in-vehicle machine log, medium and electronic equipment

    CN117176355A

Cited By

  • Software upgrading method and device and related equipment

    CN120751366A

  • Software upgrading method, device and related equipment

    CN120751366B