Data security protection method, device and system, electronic equipment and storage medium

By using asymmetric encryption algorithm to decrypt in vehicle OTA updates and combining symmetric encryption technology, data is ensured to be safely installed in the on-board terminal, the security issues in the data installation stage are solved, and independent information security is achieved for installation and download.

CN120372646APending Publication Date: 2025-07-25ECARX (HUBEI) TECHCO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510443440.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-09
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

In the prior art, the safety of vehicle OTA updates during the data installation stage is difficult to ensure.

Method used

The asymmetric encryption algorithm is used to decrypt the data to be installed using the first private key, and the locally stored installation key and symmetric key are encrypted to ensure the secure installation of the data in the on-board terminal.

Benefits of technology

It realizes independent information security during the data installation stage and improves the overall security of vehicle OTA updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372646A_ABST
    Figure CN120372646A_ABST
Patent Text Reader

Abstract

The invention relates to a data security protection method, device and system, electronic equipment and a storage medium, and is applied to a system-on-chip of a vehicle-mounted terminal, and the method comprises the steps: obtaining first encrypted data from a server, decrypting the first encrypted data through employing a first private key, obtaining to-be-installed data, and storing the to-be-installed data in the server; the first encrypted data is obtained by encrypting a first public key corresponding to the first private key; encrypting the to-be-installed data by using a locally stored installation key to obtain second encrypted data, and encrypting the installation key by using the first symmetric key to obtain an encrypted key; and forwarding the second encrypted data and the encryption key to the microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on an installation key obtained by decrypting the encryption key. In the data installation stage, different encryption modes independent of the data downloading stage are adopted, independent information security of installation and downloading is achieved, and then the security of the data installation stage is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and in particular, to a data security protection method, apparatus, system, electronic device, and storage medium. Background Art

[0002] OTA (Over-the-Air Technology) refers to a wireless communication technology in which data for software updates is downloaded from a server to an in-vehicle terminal, and then the data is installed on the in-vehicle terminal to achieve automatic software updates.

[0003] In the prior art, an in-vehicle terminal can download data from a server through two-way authentication or digital envelope technology to enhance the security of the data download phase, while ensuring the integrity, authenticity, and confidentiality of the data.

[0004] However, there is currently no targeted data security protection mechanism for how to securely install the downloaded data within the in-vehicle terminal domain, resulting in the difficulty of ensuring the security of vehicle OTA updates during the data installation phase. Summary of the Invention

[0005] The present disclosure provides a data security protection system, method, apparatus, system, electronic device, and storage medium to at least solve the problem that the security of vehicle OTA updates during the data installation phase is difficult to ensure in the related art. The technical solutions of the present disclosure are as follows:

[0006] According to a first aspect of an embodiment of the present disclosure, a data security protection method is provided, which is applied to a system-on-chip of an in-vehicle terminal and includes:

[0007] Obtain first encrypted data from a server, and decrypt the first encrypted data using a first private key to obtain data to be installed, where the first encrypted data is encrypted using a first public key corresponding to the first private key;

[0008] Encrypt the data to be installed using an installation key stored locally to obtain second encrypted data, and encrypt the installation key using a first symmetric key to obtain an encrypted key;

[0009] Forward the second encrypted data and the encrypted key to a microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encrypted key.

[0010] Optionally, the first encrypted data includes ciphertext information and a digital envelope. The step of decrypting the first encrypted data using the first private key to obtain the data to be installed includes:

[0011] Decrypt the digital envelope using the first private key to obtain a second symmetric key;

[0012] Decrypt the ciphertext information using the second symmetric key to obtain the data to be installed.

[0013] Optionally, before obtaining the first encrypted data from the server, it further includes:

[0014] Receive the authentication information of the server, where the authentication information includes an encrypted information digest and an encrypted signature, the encrypted signature is obtained by encrypting with a second private key, and the authentication information is obtained after the server passes the authentication of the verification center;

[0015] Decrypt the encrypted signature using the pre-obtained second public key to obtain a decrypted signature, and the second public key is obtained after the system-on-chip passes the authentication of the verification center;

[0016] Perform decryption calculation on the encrypted information digest using a preset algorithm to obtain a decrypted information digest;

[0017] Compare the decrypted signature and the decrypted information digest. If the decrypted signature and the decrypted information digest are the same, it is determined that the authentication of the server is passed, and the step of obtaining the first encrypted data from the server is executed.

[0018] Optionally, obtaining the first encrypted data from the server includes:

[0019] Obtain the first encrypted data from the server based on the Transport Layer Security protocol.

[0020] Optionally, forwarding the second encrypted data and the encryption key to the microcontroller unit includes:

[0021] Forward the second encrypted data and the encryption key to the microcontroller unit through in-domain transmission.

[0022] Optionally, before encrypting the data to be installed using the installation key stored locally to obtain the second encrypted data, it further includes:

[0023] Use one-time programming technology to burn the installation key into a preset independent partition of the system-on-chip;

[0024] Encrypting the data to be installed using the installation key stored locally to obtain the second encrypted data includes:

[0025] Read the installation key from the preset independent partition and encrypt the data to be installed using the installation key to obtain the second encrypted data.

[0026] According to a second aspect of the embodiments of the present disclosure, there is provided a data security protection device, which is applied to a microcontroller unit of a vehicle-mounted terminal, and includes:

[0027] Receiving the second encrypted data and the encryption key sent by the system-on-chip;

[0028] Using a first symmetric key to decrypt the encryption key to obtain an installation key;

[0029] Using the installation key to decrypt the second encrypted data to obtain the data to be installed, and installing the data to be installed.

[0030] Optionally, the installing the data to be installed includes:

[0031] Performing data integrity verification on the data to be installed, and after the verification passes, installing the data to be installed.

[0032] According to a third aspect of the embodiments of the present disclosure, there is provided a data security protection device, which is applied to a system-on-chip of a vehicle-mounted terminal, and includes:

[0033] A first decryption module, configured to obtain first encrypted data from a server, and use a first private key to decrypt the first encrypted data to obtain data to be installed, where the first encrypted data is encrypted by a first public key corresponding to the first private key;

[0034] A first encryption module, configured to use an installation key stored locally to encrypt the data to be installed to obtain second encrypted data, and use a first symmetric key to encrypt the installation key to obtain an encryption key;

[0035] A forwarding module, configured to forward the second encrypted data and the encryption key to the microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encryption key.

[0036] According to a fourth aspect of the embodiments of the present disclosure, there is provided a data security protection device, which is applied to a microcontroller unit of a vehicle-mounted terminal, and includes:

[0037] A receiving module, configured to receive the second encrypted data and the encryption key sent by the system-on-chip;

[0038] A second decryption module, configured to use a first symmetric key to decrypt the encryption key to obtain an installation key;

[0039] An installation module, configured to use the installation key to decrypt the second encrypted data to obtain data to be installed, and install the data to be installed.

[0040] According to a fifth aspect of the embodiments of the present disclosure, a data security protection system is provided, which is applied to a vehicle-mounted terminal and includes:

[0041] A system-on-chip, configured to obtain first encrypted data from a server, decrypt the first encrypted data by using a first private key to obtain data to be installed, where the first encrypted data is encrypted by using a first public key corresponding to the first private key; encrypt the data to be installed by using an installation key stored locally to obtain second encrypted data, and encrypt the installation key by using a first symmetric key to obtain an encrypted key; forward the second encrypted data and the encrypted key to a microcontroller unit;

[0042] The microcontroller unit is configured to decrypt the encrypted key by using the first symmetric key to obtain the installation key; decrypt the second encrypted data by using the installation key to obtain the data to be installed, and install the data to be installed.

[0043] According to a sixth aspect of the embodiments of the present disclosure, a data security protection electronic device is provided, including:

[0044] A processor;

[0045] A memory for storing executable instructions of the processor;

[0046] Wherein, the processor is configured to execute the instructions to implement the data security protection method described in any one of the above.

[0047] According to a seventh aspect of the embodiments of the present disclosure, a computer-readable storage medium is provided. When instructions in the computer-readable storage medium are executed by a processor of a data security protection electronic device, the data security protection electronic device can execute the data security protection method described in any one of the above.

[0048] According to an eighth aspect of the embodiments of the present disclosure, a computer program product is provided, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the data security protection method described in any one of the above is implemented.

[0049] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:

[0050] During the download process of the data to be installed, the obtained first encrypted data is decrypted using the first private key pre-agreed with the server to obtain the data to be installed. Then, during the installation process, the data to be installed is first encrypted using the installation key to obtain the second encrypted data, and then, using the symmetric encryption technology and the first symmetric key, the installation key stored in the system-on-chip is encrypted again and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other in the data installation stage and the data download stage are adopted, realizing independent information security for installation and download, and further improving the security of the data installation stage.

[0051] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure, and do not constitute an improper limitation to the present disclosure.

[0053] Figure 1 is a flowchart of a data security protection method shown according to an exemplary embodiment.

[0054] Figure 2 is a schematic diagram of the system architecture of a data security protection method shown according to an exemplary embodiment.

[0055] Figure 3 is a schematic diagram of the process of a system-on-chip downloading data to be installed shown according to an exemplary embodiment.

[0056] Figure 4 is a schematic diagram of the process of a microcontroller unit decrypting and installing data to be installed shown according to an exemplary embodiment.

[0057] Figure 5 is a flowchart of a data security protection method shown according to an exemplary embodiment.

[0058] Figure 6 is a block diagram of a data security protection device shown according to an exemplary embodiment.

[0059] Figure 7 is a flowchart of a data security protection device shown according to an exemplary embodiment.

[0060] Figure 8 is a block diagram of a data security protection system shown according to an exemplary embodiment.

[0061] Figure 9It is a block diagram of an electronic device for data security protection shown according to an exemplary embodiment.

[0062] Figure 10 It is a block diagram of a device for data security protection shown according to an exemplary embodiment. Detailed implementation manners

[0063] In order to enable those of ordinary skill in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0064] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data used can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described here can be implemented in an order other than those illustrated or described here. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0065] Figure 1 It is a flowchart of a data security protection method shown according to an exemplary embodiment. As Figure 1 shown, this data security protection method is applied to a system-on-chip (SOC) of a vehicle-mounted terminal and includes:

[0066] In step S101, obtain first encrypted data from a server, and decrypt the first encrypted data using a first private key to obtain data to be installed. The first encrypted data is encrypted by a first public key corresponding to the first private key.

[0067] OTA technology can download data for software update from a server to a vehicle-mounted terminal, and then install the data in the vehicle-mounted terminal to achieve automatic software update. However, in the related art, there is currently no targeted data security protection mechanism for how to securely install the downloaded data within the vehicle-mounted terminal domain, resulting in the difficulty of ensuring the security of vehicle OTA updates during the data installation phase.

[0068] Based on this, the solution in this application is proposed to solve the above problems.

[0069] In this step, first, the in-vehicle terminal needs to obtain the first encrypted data from the remote server. The first encrypted data can be used for software updates, application programs, or firmware upgrades of the in-vehicle terminal, etc. The first encrypted data is the data encrypted by the server using the first public key corresponding to the first private key. The encryption of the first encrypted data by the server can ensure that the first encrypted data is not stolen or tampered with during the transmission process and can only be decrypted and used by an authorized in-vehicle terminal.

[0070] Specifically, after generating the content of the data to be installed, the server encrypts the data using a specific first public key. The first public key and the first private key used by the subsequent system-on-chip for decryption are a pair of public and private keys that exist in pairs. They are generated based on the asymmetric encryption algorithm. Among them, the asymmetric encryption algorithm includes algorithms such as RSA (Rivest-Shamir-Adleman) algorithm and ECC (Elliptic Curve Cryptography) algorithm, and specific algorithms are not limited. The characteristic of this asymmetric encryption algorithm is that the data encrypted with the public key can only be decrypted with the paired private key.

[0071] That is to say, the first private key paired with the first public key used by the server for encryption is pre-stored in the system-on-chip. Therefore, after obtaining the first encrypted data from the server, the stored first private key can be used to decrypt the received first encrypted data according to the corresponding asymmetric encryption algorithm. During the decryption process, the first private key performs specific mathematical operations on the first encrypted data to gradually restore the original data to be installed. For example, in the RSA algorithm, the decryption process involves complex mathematical calculations such as modular exponentiation, and the first encrypted data is decrypted through these calculations.

[0072] After the decryption operation, the system-on-chip successfully extracts the original data to be installed from the first encrypted data. These data to be installed can be various forms of data such as software programs, firmware update packages, and configuration files, and they will be installed and used on the in-vehicle terminal subsequently.

[0073] In one implementation, before obtaining the first encrypted data from the server, it further includes:

[0074] Receiving the identity verification information of the server. The identity verification information includes an encrypted information digest and an encrypted signature. The encrypted signature is obtained by encrypting with the second private key, and the identity verification information is obtained after the server passes the identity verification of the verification center;

[0075] Using the pre-obtained second public key to decrypt the encrypted signature to obtain the decrypted signature. The second public key is obtained after the system-on-chip passes the identity verification of the verification center;

[0076] Using a preset algorithm to decrypt and calculate the encrypted information digest to obtain the decrypted information digest;

[0077] Compare the decrypted signature and the decrypted message digest. If they are the same, it is determined that the authentication of the server is passed, and the step of obtaining the first encrypted data from the server is executed.

[0078] That is to say, the system-on-chip of the vehicle-mounted terminal can receive the authentication information sent by the server. Among them, the authentication information includes two key parts, namely the encrypted message digest and the encrypted signature. The encrypted message digest is the digest value obtained by performing a specific algorithm calculation on the server identity-related data, and this digest value can reflect the characteristics of the server identity information. The encrypted signature is the encrypted result obtained by encrypting the message digest (or related data containing the message digest) with the second private key, and is used to verify the integrity and authenticity of the message digest.

[0079] The authentication information is obtained by the server after passing the authentication of the authentication center to ensure the legality of its own identity before establishing a communication connection with the vehicle-mounted terminal. Moreover, before obtaining the second public key, the system-on-chip will also perform an authentication interaction with the authentication center first. The authentication center is an authoritative third-party institution responsible for verifying and authenticating the identities of the server and the vehicle-mounted terminal.

[0080] When the system-on-chip passes the authentication of the authentication center, the authentication center will issue the second public key to the system-on-chip. The second public key is the public key paired with the second private key used by the server to generate the encrypted signature, and is generated based on the asymmetric encryption algorithm.

[0081] Furthermore, after receiving the authentication information of the server, the system-on-chip can use the previously obtained second public key to decrypt the encrypted signature in the authentication information according to the corresponding asymmetric encryption algorithm. During the decryption process, the second public key will perform specific mathematical operations on the encrypted signature to gradually restore the original signature value of the message digest, that is, the decrypted signature.

[0082] The characteristics of the asymmetric encryption algorithm determine that the data encrypted with the private key can only be decrypted with the paired public key. Therefore, only when the second public key is paired with the second private key used by the server to generate the encrypted signature can the correct decrypted signature be successfully obtained through decryption.

[0083] At the same time, the system-on-chip selects the same preset algorithm as that used by the server to generate the encrypted message digest, such as the hash algorithm, to perform decryption calculation on the encrypted message digest to obtain the decrypted message digest. The hash algorithm is an algorithm that can map data of any length to a fixed-length digest value, and has characteristics such as irreversibility and collision resistance.

[0084] It can be understood that the decrypted message digest should be essentially the same as the encrypted message digest generated by the server. Therefore, the system-on-chip compares the decrypted signature obtained by decryption with the decrypted message digest obtained by decryption calculation. The comparison process is to compare the binary data of the two bit by bit to check whether they are exactly the same.

[0085] If the decrypted signature and the decrypted message digest are the same, it indicates that the server's authentication information is complete and authentic, the server identity is legal, and the system-on-chip determines that the authentication of the server passes. At this time, the system-on-chip will execute the step of obtaining the first encrypted data from the server and continue the subsequent data interaction and processing process. If the two are different, it indicates that the server's authentication information may be tampered with or the server identity is illegal. The system-on-chip will refuse to perform further data interaction with the server and may take corresponding security measures, such as alarm, logging, etc.

[0086] In this way, through the strict verification of the server identity, it is ensured that the in-vehicle terminal only interacts with legal servers, preventing attacks and data theft on the in-vehicle terminal by illegal servers. Moreover, the use of the encrypted message digest and the encrypted signature ensures the integrity and authenticity of the server authentication information during transmission, preventing the information from being tampered with or forged.

[0087] Such as Figure 2 shown, is a schematic diagram of the system architecture of the data security protection method in this application. Among them, the system consists of a cloud server and the ADCU (Automatic Drive Control Unit) of the in-vehicle terminal. The ADCU includes an SOC and an MCU (Microcontroller Unit). Two "keys" are stored in the SOC. One is used for OTA data download when the SOC is an OTA slave device, that is, the first private key, and the other is used for OTA data installation, that is, the installation key and the first symmetric key.

[0088] In one implementation, obtaining the first encrypted data from the server includes:

[0089] Obtaining the first encrypted data from the server based on the Transport Layer Security protocol.

[0090] That is to say, between the in-vehicle terminal and the server, the TLS (Transport Layer Security) protocol can be used for data transmission. TLS is a security protocol used to provide communication security on the Internet, ensuring that the data transmitted between two communication applications remains private and integral.

[0091] Among them, the establishment of a TLS connection begins with a "handshake" process, in which the system-on-chip of the vehicle-mounted terminal and the server negotiate encryption algorithms, exchange keys, and verify each other's identities. This process generally includes the following steps: The system-on-chip sends a greeting message containing the supported TLS versions and encryption algorithms to the server; the server responds to the client's greeting, selects an encryption algorithm, and sends its own certificate; the system-on-chip verifies whether the server's certificate is issued by a trusted certificate authority; the system-on-chip and the server exchange keys through public-key encryption technology for session encryption; the system-on-chip and the server use the exchanged keys to encrypt further communications.

[0092] In this way, the Transport Layer Security Protocol ensures the confidentiality of the first encrypted data during transmission through encryption technology, preventing the data from being stolen or eavesdropped. Even if the first encrypted data is intercepted during transmission, the attacker cannot decrypt it to obtain the data to be installed without the correct key.

[0093] In step S102, the data to be installed is encrypted using the locally stored installation key to obtain the second encrypted data, and the installation key is encrypted using the first symmetric key to obtain the encrypted key.

[0094] The installation key is pre-stored locally in the system-on-chip of the vehicle-mounted terminal. A suitable encryption algorithm can be selected, such as a symmetric encryption algorithm like AES (Advanced Encryption Standard), etc., to encrypt the data to be installed using the installation key. The characteristic of the symmetric encryption algorithm is that the encryption and decryption processes use the same key, which has the advantages of fast encryption speed and high efficiency.

[0095] Specifically, the system-on-chip takes the data to be installed as input, combines it with the installation key, and performs an encryption operation according to the rules of the selected encryption algorithm to obtain the second encrypted data. The second encrypted data is the data to be installed encrypted with the installation key, and its content is unreadable to entities that do not hold the correct installation key.

[0096] Furthermore, the system-on-chip selects another symmetric encryption algorithm (which can be the same as or different from the algorithm used to encrypt the data to be installed), and encrypts the installation key using the first symmetric key to obtain the encrypted key. The encrypted key is the result of encrypting the installation key, and it is used to protect the security of the installation key when transmitting the second encrypted data and the installation key to the microcontroller unit, preventing the installation key from being stolen during transmission.

[0097] Among them, the first symmetric key is a key pre-negotiated when establishing a secure communication channel between the system-on-chip and the microcontroller unit. This key is usually generated through a secure key negotiation protocol, and both parties securely store this key for subsequent data encryption and decryption operations.

[0098] In one implementation, before encrypting the data to be installed using the locally stored installation key to obtain the second encrypted data, it further includes:

[0099] Using one-time programmable technology, burn the installation key into a preset independent partition of the system-on-chip;

[0100] Encrypting the data to be installed using the locally stored installation key to obtain the second encrypted data includes:

[0101] Read the installation key from the preset independent partition and encrypt the data to be installed using the installation key to obtain the second encrypted data.

[0102] Among them, OTP (One-Time Programmable) technology is a special storage technology, and its characteristic is that once data is written into the storage unit, it cannot be modified or erased again. That is to say, in the production or initialization stage of the system-on-chip, through a dedicated burning device, the installation key is written into a preset independent partition of the chip in the form of binary data. This independent partition is specially divided in the storage space of the chip and isolated from other functional areas to ensure the security and independence of the installation key.

[0103] Due to the non-modifiability of OTP technology, once the installation key is burned into the chip, it cannot be illegally obtained or tampered with. This provides a reliable security foundation for subsequent data encryption operations. At the same time, the isolation design of the preset independent partition prevents the installation key from being easily accessed by other programs inside the chip or external attackers.

[0104] As Figure 3 shown, it is a schematic flowchart of the system-on-chip downloading the data to be installed in a specific embodiment.

[0105] Among them, the server first conducts identity authentication and applies for a certificate from the authentication center. Here, the authentication center can be a CA (Certificate Authority) certificate center. The CA center verifies whether the server information is forged based on the stored certificate information. If it is not forged, it issues a certificate after successful authentication. The certificate contains an encrypted information digest and an encrypted signature. After the CA certificate is given to the server, it is returned to the system-on-chip of the in-vehicle terminal. The system-on-chip verifies the CA certificate according to the client certificate stored by itself, including decrypting the signature with the local public key to obtain the information digest, and calculating the information digest by using the hash algorithm on the plaintext in the certificate. If the two are the same after comparison, the verification passes.

[0106] Furthermore, the server can generate a second symmetric key, and based on the second symmetric key, encrypt the original data to be installed through the AES encryption algorithm to obtain ciphertext information, and then encrypt the second symmetric key by using the first public key authenticated by the CA to obtain a digital envelope. Then, the ciphertext information and the digital envelope can be used as the first encrypted information and transmitted to the system-on-chip.

[0107] The system-on-chip then decrypts the digital envelope with its own first private key to obtain the second symmetric key, and then decrypts the ciphertext information with the second symmetric key to obtain the data to be installed, realizing data parsing.

[0108] In step S103, the second encrypted data and the encryption key are forwarded to the microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encryption key.

[0109] There is a pre-established secure communication channel between the system-on-chip and the microcontroller unit. The system-on-chip forwards the second encrypted data and the encryption key to the microcontroller unit through this channel. Among them, some verification information, data identifiers, etc. may be added during the data forwarding process to ensure the integrity and identifiability of the data during transmission.

[0110] The first symmetric key negotiated with the system-on-chip is pre-stored in the microcontroller unit. The first symmetric key is usually stored in the secure storage area of the microcontroller unit, such as a hardware encryption module or a specific secure storage chip, to prevent illegal access and tampering.

[0111] Then, the microcontroller unit selects the same symmetric encryption algorithm as when encrypting the installation key with the system-on-chip, takes the encryption key as the input, combines it with the first symmetric key, and performs a decryption operation according to the rules of the selected encryption algorithm to obtain the installation key.

[0112] Furthermore, the microcontroller unit uses the just-decrypted installation key to select an appropriate encryption algorithm (the same algorithm as used by the system-on-chip to encrypt the data to be installed), and decrypts the second encrypted data to restore the second encrypted data to the original data to be installed.

[0113] The decrypted data to be installed may be in various forms such as software programs, firmware update packages, configuration files, etc. The microcontroller unit installs it into the corresponding storage area or performs specific installation operations according to the type and use of the data to be installed. For example, if it is a software program, it is installed in the program storage area and the relevant program startup information is updated; if it is a configuration file, it is stored in the specified configuration storage area and applied to the system running configuration.

[0114] As Figure 4 shown, it is a schematic flow diagram of the microcontroller unit decrypting and installing the data to be installed in a specific embodiment. Among them, the installation key is stored in an independent partition of the SOC and burned in through a diagnostic instrument, and can only be burned once by default; in order for the MCU to obtain the key, symmetric encryption is used for verification within the domain, and the same encryption and decryption algorithms are stored in both the SOC and the MCU; the installation key of the SOC uses an encryption algorithm based on the first symmetric key to achieve data security protection; after the MCU receives the encryption key sent by the SOC, it decrypts the encryption key through the first symmetric key stored locally in the MCU to obtain the installation key, and verifies the obtained installation key. If the verification passes, it means that the data has not been tampered with, and the content inside, that is, the installation key, is obtained.

[0115] In one implementation, forwarding the second encrypted data and the encryption key to the microcontroller unit includes:

[0116] Forwarding the second encrypted data and the encryption key to the microcontroller unit through in-domain transmission.

[0117] In an automotive electronic system, in-domain usually refers to a relatively independent area divided according to function or location. This area contains multiple interconnected electronic control units, sensors and other devices, which are connected and communicate through a specific network topology (such as a bus network). An appropriate communication protocol can be selected for data transmission according to the characteristics and requirements of the in-domain network.

[0118] For example, the in-domain communication protocols of in-vehicle terminals include, but are not limited to, CAN (Controller Area Network), LIN (Local Interconnect Network), FlexRay (Flexible Time-Triggered Communication), etc. Different protocols have different characteristics and applicable scenarios. For example, the CAN protocol has characteristics such as high reliability and strong real-time performance, and is applicable to scenarios such as the power domain with high requirements for data transmission real-time performance; the LIN protocol has a lower cost and is applicable to scenarios such as the body domain with low requirements for data transmission rate.

[0119] In this way, in-domain transmission utilizes the existing network infrastructure within the domain, without the need for an additional complex network architecture, and can achieve fast and stable transmission of the second encrypted data and the encryption key, ensuring that the data can reach the microcontroller unit in a timely manner.

[0120] Figure 5 It is a flowchart of a data security protection method shown according to an exemplary embodiment. As Figure 5 shown, this data security protection method is applied to the microcontroller unit of an in-vehicle terminal and includes:

[0121] In step S201, receive the second encrypted data and the encryption key sent by the system-on-chip.

[0122] In step S202, decrypt the encryption key using the first symmetric key to obtain the installation key.

[0123] In step S203, decrypt the second encrypted data using the installation key to obtain the data to be installed, and install the data to be installed.

[0124] Among them, the processes of steps S201 to S203 are similar to the processes in step S103 of the foregoing embodiment, and will not be elaborated here.

[0125] In one implementation manner, installing the data to be installed includes:

[0126] Perform data integrity verification on the data to be installed, and after the verification passes, install the data to be installed.

[0127] In this embodiment, an appropriate data integrity verification algorithm can be selected according to the characteristics and security requirements of the data to be installed, such as the Cyclic Redundancy Check (CRC) algorithm, hash algorithms (such as MD5, SHA-1, SHA-256, etc.). Among them, the CRC algorithm is simple and fast to calculate and is suitable for scenarios where the requirement for data integrity is not extremely high; the verification values generated by hash algorithms are unique and irreversible, providing a higher level of data integrity guarantee, especially suitable for data verification with strict security requirements.

[0128] Taking the CRC algorithm as an example, the data to be installed is processed bit by bit by byte, and a fixed-length verification value is generated through specific polynomial operations. The hash algorithm takes the data to be installed as input and outputs a fixed-length hash value after a series of complex mathematical operations. The calculation process is usually completed by the internal hardware encryption module or software algorithm library of the system to ensure the accuracy and efficiency of the calculation results.

[0129] Furthermore, the calculated verification value can be compared with the pre-stored correct verification value. The pre-stored verification value can be calculated and stored in a secure location during the data generation or distribution stage. Only when the calculated verification value is exactly the same as the pre-stored verification value is it determined that the data integrity verification passes.

[0130] As can be seen from the above, in the technical solution provided by the embodiment of the present disclosure, during the download process of the data to be installed, the first encrypted data obtained is decrypted using the first private key pre-agreed with the server to obtain the data to be installed. Then, during the installation process, the data to be installed is first encrypted using the installation key to obtain the second encrypted data, and then, using symmetric encryption technology, the installation key stored in the system-on-chip is encrypted again using the first symmetric key and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other are adopted in the data installation stage and the data download stage, realizing independent information security for installation and download, and further improving the security of the data installation stage.

[0131] Figure 6 FIG. is a block diagram of a data security protection device shown according to an exemplary embodiment, applied to the system-on-chip of a vehicle-mounted terminal, including:

[0132] A first decryption module 301, configured to obtain the first encrypted data from the server and decrypt the first encrypted data using the first private key to obtain the data to be installed, where the first encrypted data is encrypted using the first public key corresponding to the first private key;

[0133] The first encryption module 302 is configured to encrypt the to-be-installed data by using an installation key stored locally, obtain second encrypted data, and encrypt the installation key by using a first symmetric key to obtain an encrypted key;

[0134] The forwarding module 303 is configured to forward the second encrypted data and the encrypted key to the microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encrypted key.

[0135] Figure 7 It is a block diagram of a data security protection device shown according to an exemplary embodiment, which is applied to the microcontroller unit of a vehicle-mounted terminal and includes:

[0136] The receiving module 401 is configured to receive the second encrypted data and the encrypted key sent by the system-on-chip;

[0137] The second decryption module 402 is configured to decrypt the encrypted key by using the first symmetric key to obtain an installation key;

[0138] The installation module 403 is configured to decrypt the second encrypted data by using the installation key to obtain the to-be-installed data, and install the to-be-installed data.

[0139] As can be seen from the above, in the technical solution provided by the embodiments of the present disclosure, during the download process of the to-be-installed data, the first encrypted data obtained is decrypted by using a first private key pre-agreed with the server to obtain the to-be-installed data. Then, during the installation process, the to-be-installed data is first encrypted by using the installation key to obtain second encrypted data, and then, by using symmetric encryption technology and the first symmetric key, the installation key stored in the system-on-chip is encrypted again and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other in the data download stage are adopted in the data installation stage, realizing independent information security for installation and download, and thus improving the security of the data installation stage.

[0140] Figure 8 It is a flowchart of a data security protection system shown according to an exemplary embodiment, which is applied to a vehicle-mounted terminal and includes:

[0141] The system-on-chip is configured to obtain first encrypted data from the server, decrypt the first encrypted data by using the first private key to obtain the to-be-installed data, where the first encrypted data is encrypted by the first public key corresponding to the first private key; encrypt the to-be-installed data by using the installation key stored locally to obtain second encrypted data, and encrypt the installation key by using the first symmetric key to obtain an encrypted key; forward the second encrypted data and the encrypted key to the microcontroller unit;

[0142] A microcontroller unit is configured to decrypt the encryption key by using the first symmetric key to obtain the installation key; decrypt the second encrypted data by using the installation key to obtain the data to be installed, and install the data to be installed.

[0143] As can be seen from the above, in the technical solution provided by the embodiments of the present disclosure, during the download process of the data to be installed, the first encrypted data obtained is decrypted by using the first private key pre-agreed with the server to obtain the data to be installed. Then, during the installation process, the data to be installed is first encrypted by using the installation key to obtain the second encrypted data, and then, by using symmetric encryption technology and the first symmetric key, the installation key stored in the system-on-chip is encrypted again and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other in the data download stage are adopted in the data installation stage, realizing independent information security for installation and download, and thus improving the security of the data installation stage.

[0144] Figure 9 It is a block diagram of an electronic device for data security protection shown according to an exemplary embodiment.

[0145] In an exemplary embodiment, there is also provided a computer-readable storage medium including instructions, such as a memory including instructions, and the instructions can be executed by a processor of an electronic device to complete the method. Optionally, the computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0146] In an exemplary embodiment, there is also provided a computer program product, which when running on a computer, enables the computer to implement the method for data security protection.

[0147] As can be seen from the above, in the technical solution provided by the embodiments of the present disclosure, during the download process of the data to be installed, the first encrypted data obtained is decrypted by using the first private key pre-agreed with the server to obtain the data to be installed. Then, during the installation process, the data to be installed is first encrypted by using the installation key to obtain the second encrypted data, and then, by using symmetric encryption technology and the first symmetric key, the installation key stored in the system-on-chip is encrypted again and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other in the data download stage are adopted in the data installation stage, realizing independent information security for installation and download, and thus improving the security of the data installation stage.

[0148] Figure 10 It is a block diagram of a device 800 for data security protection shown according to an exemplary embodiment.

[0149] For example, device 800 may be a mobile phone, a computer, a digital broadcast electronic device, a messaging device, a gaming console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.

[0150] Referring Figure 10 to, device 800 may include one or more of the following components: a processing component 802, a memory 804, a power component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.

[0151] The processing component 802 generally controls the overall operation of device 800, such as operations associated with display, telephone calls, data communications, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the described method. In addition, the processing component 802 may include one or more modules to facilitate interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate interaction between the multimedia component 808 and the processing component 802.

[0152] The memory 804 is configured to store various types of data to support the operation of device 800. Examples of such data include instructions for any application or method operating on device 800, contact data, phone book data, messages, pictures, videos, etc. The memory 804 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disk.

[0153] The power component 807 provides power to the various components of device 800. The power component 807 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for device 800.

[0154] The multimedia component 808 includes a screen that provides an output interface between the device 800 and the account. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen can be implemented as a touch screen to receive input signals from the account. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors can sense not only the boundaries of the touch or swipe actions, but also detect the duration and pressure associated with the touch or swipe operations. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each of the front camera and the rear camera can be a fixed optical lens system or have a focal length and optical zoom capabilities.

[0155] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC) that is configured to receive external audio signals when the device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 further includes a speaker for outputting audio signals.

[0156] The I / O interface 812 provides an interface between the processing component 802 and a peripheral interface module, which can be a keyboard, a click wheel, buttons, etc. These buttons can include, but are not limited to: a home button, a volume button, a power button, and a lock button.

[0157] The sensor component 814 includes one or more sensors for providing an assessment of the various aspects of the state of the device 800. For example, the sensor component 814 can detect the on / off state of the device 800, the relative positioning of components, such as the display and keypad of the device 800, the sensor component 814 can also detect a change in the position of the device 800 or a component of the device 800, the presence or absence of contact between the account and the device 800, the orientation or acceleration / deceleration of the device 800, and the temperature change of the device 800. The sensor component 814 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 814 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 814 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.

[0158] The communication component 816 is configured to facilitate communication, either wired or wirelessly, between the device 800 and other devices. The device 800 may access a wireless network based on a communication standard, such as WiFi, a carrier network (such as 2G, 3G, 4G, or 5G), or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 further includes a Near Field Communication (NFC) module to facilitate short-range communication. For example, the NFC module may be implemented based on Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra-Wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.

[0159] In an exemplary embodiment, the device 800 may be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the methods described in the first and second aspects.

[0160] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions that may be executed by a processor 820 of the device 800 to complete the method. Optionally, for example, the storage medium may be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium may be a ROM, Random Access Memory (RAM), CD-ROM, magnetic tape, floppy disk, and optical data storage device, among others.

[0161] In an exemplary embodiment, a computer program product including instructions is also provided, which, when running on a computer, causes the computer to execute the data security protection method described in any of the embodiments.

[0162] As can be seen from the above, in the technical solution provided by the embodiments of the present disclosure, during the download process of the data to be installed, the first encrypted data obtained is decrypted using a first private key pre-agreed with the server to obtain the data to be installed. Then, during the installation process, the data to be installed is first encrypted using an installation key to obtain second encrypted data, and then, using symmetric encryption technology and a first symmetric key, the installation key stored in the system-on-chip is encrypted again and transmitted to the microcontroller unit. That is to say, different encryption methods independent of each other in the data download stage are adopted in the data installation stage, realizing independent information security for installation and download, and thus improving the security of the data installation stage.

[0163] Other embodiments of the present disclosure will be readily apparent to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include known common general knowledge or conventional technical means in the technical field not disclosed herein. The specification and examples are only to be considered as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0164] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A data security protection method, characterized in that A system-on-chip applied to a vehicle-mounted terminal, comprising: Obtain the first encrypted data from the server, and decrypt the first encrypted data using the first private key to obtain the data to be installed, where the first encrypted data is encrypted using the first public key corresponding to the first private key; Encrypt the data to be installed using the installation key stored locally to obtain the second encrypted data, and encrypt the installation key using the first symmetric key to obtain the encrypted key; Forward the second encrypted data and the encrypted key to the microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encrypted key.

2. The data security protection method according to claim 1, wherein The first encrypted data includes ciphertext information and a digital envelope. The step of decrypting the first encrypted data using the first private key to obtain the data to be installed includes: Decrypt the digital envelope using the first private key to obtain the second symmetric key; Decrypt the ciphertext information using the second symmetric key to obtain the data to be installed.

3. The data security protection method according to claim 1, characterized in that, Before obtaining the first encrypted data from the server, it further includes: Receive the identity authentication information of the server, where the identity authentication information includes an encrypted information digest and an encrypted signature, and the encrypted signature is encrypted using the second private key, and the identity authentication information is obtained after the server passes the identity authentication of the authentication center; Decrypt the encrypted signature using the pre-obtained second public key to obtain the decrypted signature, and the second public key is obtained after the system-on-chip passes the identity authentication of the authentication center; Perform decryption calculation on the encrypted information digest using a preset algorithm to obtain the decrypted information digest; Compare the decrypted signature with the decrypted information digest. If the decrypted signature is the same as the decrypted information digest, it is determined that the identity authentication of the server is passed, and the step of obtaining the first encrypted data from the server is executed.

4. The data security protection method according to claim 1, characterized in that The step of obtaining the first encrypted data from the server includes: Obtain the first encrypted data from the server based on the Transport Layer Security protocol.

5. The data security protection method according to claim 1, wherein The step of forwarding the second encrypted data and the encrypted key to the microcontroller unit includes: Forward the second encrypted data and the encrypted key to the microcontroller unit through in-domain transmission.

6. The data security protection method according to claim 1, wherein Before encrypting the data to be installed using the installation key stored locally to obtain the second encrypted data, it further includes: Use one-time programming technology to burn the installation key into a preset independent partition of the system-on-chip; The step of encrypting the data to be installed using the installation key stored locally to obtain the second encrypted data includes: Read the installation key from the preset independent partition, and encrypt the data to be installed using the installation key to obtain the second encrypted data.

7. A data security protection method, characterized in that, A microcontroller unit applied to a vehicle-mounted terminal, comprising: Receive the second encrypted data and the encrypted key sent by the system-on-chip; Decrypt the encrypted key using the first symmetric key to obtain the installation key; Decrypt the second encrypted data using the installation key to obtain the data to be installed, and install the data to be installed.

8. The data security protection method according to claim 7, characterized in that The step of installing the data to be installed includes: Perform data integrity verification on the data to be installed, and after the verification passes, install the data to be installed.

9. A data security protection device, characterized in that, A system-on-chip applied to a vehicle terminal, comprising: A first decryption module, configured to obtain first encrypted data from a server, and decrypt the first encrypted data by using a first private key to obtain data to be installed, where the first encrypted data is encrypted by a first public key corresponding to the first private key; A first encryption module, configured to encrypt the data to be installed by using an installation key stored locally to obtain second encrypted data, and encrypt the installation key by using a first symmetric key to obtain an encrypted key; A forwarding module, configured to forward the second encrypted data and the encrypted key to a microcontroller unit, so that the microcontroller unit decrypts and installs the second encrypted data based on the installation key obtained by decrypting the encrypted key.

10. A data security protection device, characterized in that, A microcontroller unit applied to a vehicle terminal, comprising: A receiving module, configured to receive the second encrypted data and the encrypted key sent by the system-on-chip; A second decryption module, configured to decrypt the encrypted key by using the first symmetric key to obtain an installation key; An installation module, configured to decrypt the second encrypted data by using the installation key to obtain data to be installed, and install the data to be installed.

11. A data security protection system, characterized in that, Applied to a vehicle terminal, comprising: A system-on-chip, configured to obtain first encrypted data from a server, and decrypt the first encrypted data by using a first private key to obtain data to be installed, where the first encrypted data is encrypted by a first public key corresponding to the first private key; encrypt the data to be installed by using an installation key stored locally to obtain second encrypted data, and encrypt the installation key by using a first symmetric key to obtain an encrypted key; forward the second encrypted data and the encrypted key to the microcontroller unit; A microcontroller unit, configured to decrypt the encrypted key by using the first symmetric key to obtain the installation key; decrypt the second encrypted data by using the installation key to obtain the data to be installed, and install the data to be installed.

12. An electronic device, characterized in that, Comprising: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the instructions to implement the data security protection method according to any one of claims 1 to 8.

13. A computer-readable storage medium, characterized in that, When the instructions in the computer-readable storage medium are executed by the processor of the data security protection electronic device, the data security protection electronic device can execute the data security protection method according to any one of claims 1 to 8.

14. A computer program product, comprising a computer program, characterized in that, The computer program, when executed by a processor, implements the data security protection method according to any one of claims 1 to 8.