Hash algorithm credibility improvement method of trust anchor, controller, equipment and medium
By introducing the trust anchor and summary monitoring module in the MCU, the hash algorithm credibility on the HSM side is improved, and the problem that the HSM module hardware resources do not cover the functional safety mechanism, achieving the improvement of the functional safety level.
Patent Information
- Application Number
- CN202410104388.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-24
- Publication Date
- 2025-07-25
AI Technical Summary
The hardware resources of the existing MCUs' HSM modules are not developed in accordance with functional safety standards, resulting in the digital summary calculation results of the HSM side that cannot guarantee the functional safety level and cannot be applied to critical functional safety scenarios.
The trust anchor and summary monitoring module are introduced, and the trust anchor has low credibility. The actual digital summary is generated by calculating the transmitted data, and the trust verification data is generated in combination with monitoring problems. The summary monitoring module has high credibility, and the host verification data is generated for comparison, which improves the trust anchor's hash algorithm credibility.
The functional safety level of the trust anchor's hash algorithm has been improved, so that its calculation results can be applied to functional safety critical scenarios and ensure the credibility of data integrity verification.
Smart Images

Figure CN120372693A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicles, and in particular, to a method, a controller, a device, and a medium for improving the credibility of a hash algorithm of a trust anchor. Background Art
[0002] To further improve the safety design of road vehicle-related products and evaluate the safety level of automobiles, ISO26262 "Road Vehicles - Functional Safety" assesses the safety level for different safety objectives based on the analysis of risks and hazards of the entire vehicle under various working conditions, introduces the concept of Automotive Safety Integrity Level (ASIL), and defines four different ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. Among them, ASIL D represents the highest safety integrity, while ASIL A represents the lowest safety integrity. Additionally, for risks identified as QM, there is no corresponding safety requirement. That is, the safety integrity gradually increases from QM, ASIL-A / B / C / D. Currently, functional safety has become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.
[0003] With the improvement of the vehicle networking level, there will be more and more interactions between future functional safety and information security. On the one hand, ensuring information security is the basis for realizing functional safety; on the other hand, functional safety may also need to rely on information security mechanisms. To meet the requirements for storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments, a trust anchor needs to be equipped. In MCU (Micro Controller Unit) applications, the trust anchor is implemented in ways such as HSM (Hardware Security Module).
[0004] In related technologies, some HSM firmware follows the requirements of the functional safety process for development. However, currently, there are still a large number of HSM modules in MCUs that are not developed according to the functional safety standard, that is, there is no corresponding functional safety mechanism to cover the failure of their hardware resources. In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module.
[0005] The hash algorithm is currently widely used in the field of automotive information security, such as verifying software, message integrity, etc. Common hash algorithms include SHA1, SHA2, MD5, etc. The hash algorithm can be used to ensure data integrity. First, the original content to be ensured integrity (hereinafter referred to as the original content) is used to obtain the target digital digest based on the hash algorithm, which is used as the target value for subsequent integrity verification. For example, when the actual content is tampered with, the actual digital digest calculated again for the actual content will not be equal to the original digital digest, thereby detecting that the integrity is damaged.
[0006] The current implementation of the hash algorithm based on HSM first calls the HSM driver function located at the HOST end of the HSM to transfer the actual content to be ensured integrity to the HSM firmware at the HSM end, and then triggers the calculation of the actual digital digest. The calculation result of the actual digital digest or the comparison result between it and the target digital digest is then fed back from the HSM end to the HOST end to determine the integrity of the actual data.
[0007] Since the hardware resources at the HSM end are not currently covered by a functional safety mechanism, the calculation result of the digital digest obtained on it cannot guarantee the functional safety level and can only be considered QM, and cannot be applied to functional safety critical scenarios. Therefore, it is necessary to design a scheme to improve the credibility of the hash algorithm based on HSM with a higher functional safety level. Summary of the Invention
[0008] The embodiments of the present invention provide a method, a controller, a device, and a medium for improving the credibility of the hash algorithm of the trust anchor, so as to solve the technical problem in the related art that since the HSM module hardware of the MCU is not developed according to the functional safety standard, that is, the failure of its hardware resources is not covered by the corresponding functional safety mechanism, the signature verification success flag obtained at the HSM end cannot guarantee the functional safety level and can only be considered QM, and cannot be applied to functional safety critical scenarios, and it is necessary to design a scheme to improve the credibility of the hash algorithm based on HSM with a higher functional safety level.
[0009] An embodiment of the present invention provides a method for improving the credibility of a hash algorithm of a trust anchor, which is applied to a controller. The controller includes a trust anchor and a host, and the host includes a digest monitoring module. The credibility of the digest monitoring module is higher than that of the trust anchor. The method includes: the host obtains data to be transmitted, a target digital digest, and a monitoring question, and sends the data to be transmitted and the monitoring question to the trust anchor. The target digital digest is obtained by calculating the data to be transmitted based on a hash algorithm; the trust anchor calculates an actual digital digest for the data to be transmitted through the hash algorithm, and during the process of calculating the actual digital digest for the data to be transmitted, determines an answer according to the monitoring question, generates trust verification data based on the answer and the actual digital digest, and sends the trust verification data to the digest monitoring module; the digest monitoring module generates host verification data according to the target digital digest and a preset answer to the monitoring question, and performs a first comparison between the host verification data and the trust verification data to obtain a first comparison result, so as to improve the credibility of the hash algorithm of the trust anchor.
[0010] In an embodiment of the present invention, the method further includes: the host sends the target digital digest to the trust anchor; the trust anchor performs a second comparison between the target digital digest and the actual digital digest, determines a trust anchor verification result based on the second comparison result, and sends the trust anchor verification result to the digest monitoring module; the digest monitoring module performs a third comparison between the trust anchor verification result and the first comparison result to obtain a third comparison result, so as to improve the credibility of the hash algorithm of the trust anchor.
[0011] In an embodiment of the present invention, after obtaining the third comparison result, the method further includes: if the third comparison result shows that the trust anchor verification result is the same as the first comparison result, determining that the trust status of the trust anchor verification result is trustworthy; if the third comparison result shows that the trust anchor verification result is different from the first comparison result, determining that the trust status of the trust anchor signature verification result is doubtful.
[0012] In an embodiment of the present invention, before the host obtains the data to be transmitted and the target digital digest, the method includes: the data sender calculates an original digital digest according to the original content data; the data sender sends the original content data and the original digital digest to the host, so that the host receives the original content data as the actual transmitted content data, uses the original digital digest as the target digital digest of the actual transmitted content data, and determines the actual transmitted content data as the data to be transmitted.
[0013] In an embodiment of the present invention, before the host obtains the data to be transmitted and the target digital digest, the method includes: the data sender sends the original content data to the host; determining the preset verification data as the data to be transmitted, and determining the preset digital digest of the preset verification data as the target digital digest, where the preset digital digest is obtained by calculating the preset verification data.
[0014] In an embodiment of the present invention, after obtaining the first comparison result, the method further includes: the host sends the received original content data as the actual transmission content data to the trust anchor, so that the trust anchor calculates a content digital digest for the actual transmission content data, where the credibility of the content digital digest is higher than that of the trust anchor, and the credibility of the content digital digest is lower than or equal to the credibility of the digest monitoring module.
[0015] In an embodiment of the present invention, the host obtains a monitoring problem, including any one of the following: obtaining a preset problem and determining the preset problem as the monitoring problem; obtaining multiple preset problems and determining one or more selected preset problems as the monitoring problem; obtaining the sent monitoring problem and multiple preset problems, screening out the sent monitoring problem from the multiple preset problems, and determining one or more preset problems after screening as the monitoring problem; obtaining the sent monitoring problem and multiple preset problems, determining multiple randomly selected preset problems as preselected problems, if the problem content of the preselected problems is the same as the problem content of the sent monitoring problem, adjusting the problem order of the multiple preset problems in the preselected problems so that the problem order of the preselected problems is different from the problem order of the sent monitoring problem, and determining the adjusted preselected problems as the monitoring problem.
[0016] In an embodiment of the present invention, determining an answer according to the monitoring problem includes: the trust anchor matches the monitoring problem with multiple preset local problems in a preset problem answer table. If it matches a preset local problem successfully, determining the preset local answer corresponding to the preset local problem as the first answer sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem, and the trust anchor stores the preset problem answer table; the trust anchor triggers a preset function module based on the monitoring problem to output a function answer, and determines the function answer as the second answer sub-answer. The trust anchor is provided with the preset function module; the trust anchor collects one or more self-owned security mechanism monitoring results based on the monitoring problem, and determines the one or more self-owned security mechanism monitoring results as the third answer sub-answer; the trust anchor generates the answer according to at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.
[0017] In an embodiment of the present invention, before the abstract monitoring module generates host verification data based on the target digital abstract and the preset answer to the monitoring question, the method includes: the abstract monitoring module matches the monitoring question with a plurality of preset local questions in a preset question answer table. If a match is successful with a preset local question, the preset local answer corresponding to the preset local question is determined as the first preset sub-answer. The preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question. The abstract monitoring module stores the question answer table; the abstract monitoring module triggers a preset function module to output a function answer based on the monitoring question, and determines the function answer as the second preset sub-answer. The abstract monitoring module is provided with the preset function module; the abstract monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as the third preset sub-answer based on the monitoring question; the abstract monitoring module generates the preset answer according to at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; the abstract monitoring module determines the host verification data according to the target digital abstract and the preset answer.
[0018] In an embodiment of the present invention, before sending the data to be transmitted and the monitoring question to the trust anchor, the method includes: the host receives the original content data sent by the data sender and uses it as the actual transmission content data; determines the estimated actual digest calculation time of the actual transmission content data; if the estimated actual digest calculation time is less than a preset duration threshold, the actual digital digest of the data to be transmitted is calculated through the abstract monitoring module.
[0019] In an embodiment of the present invention, the method further includes: counting the number of events in which the first comparison result and / or the third comparison result are different within a preset statistical period; if the number of events is greater than a preset number threshold, controlling the controller to enter a preset security state.
[0020] An embodiment of the present invention further provides a controller, which includes a trust anchor and a host. The host includes a digest monitoring module, where the credibility of the digest monitoring module is higher than that of the trust anchor. The host is used to obtain data to be transmitted, a target digital digest, and a monitoring question, and send the data to be transmitted and the monitoring question to the trust anchor. The target digital digest is obtained by calculating the data to be transmitted based on a hashing algorithm. The trust anchor is used to calculate an actual digital digest for the data to be transmitted through the hashing algorithm, and during the process of calculating the actual digital digest for the data to be transmitted, determine an answer according to the monitoring question, generate trust verification data based on the answer and the actual digital digest, and send the trust verification data to the digest monitoring module. The digest monitoring module is used to generate host verification data according to the target digital digest and a preset answer to the monitoring question, and perform a first comparison between the host verification data and the trust verification data to obtain a first comparison result, so as to improve the credibility of the hashing algorithm of the trust anchor.
[0021] In an embodiment of the present invention, the host further includes a trust anchor driver function module, which is used to obtain data to be transmitted and a target digital digest, receive the monitoring question sent by the digest monitoring module, send the monitoring question, the data to be transmitted, and the target digital digest to the trust anchor, and receive the trust verification data and send the trust verification data to the digest monitoring module.
[0022] In an embodiment of the present invention, the digest monitoring module is arranged in the trust anchor driver function module.
[0023] In an embodiment of the present invention, the host further includes a mode switching module, which is used to, after the host receives the original content data sent by the data sender and uses it as the actual transmission content data, if the host does not receive the original digital digest of the original content data, determine the estimated actual digest calculation time of the actual transmission content data, and if the estimated actual digest calculation time is less than a preset duration threshold, calculate the actual digital digest for the data to be transmitted through the digest monitoring module.
[0024] In an embodiment of the present invention, the host is further used to, if the host only receives the original content data and does not receive the original digital digest, determine the preset verification data as the data to be transmitted, and determine the preset digital digest of the preset verification data as the target digital digest, where the preset digital digest is obtained by calculating the preset verification data.
[0025] In an embodiment of the present invention, after the host obtains the first comparison result of the abstract monitoring module, the host is further configured to use the received original content data as the actual transmitted content data and send it to the trust anchor, so that the trust anchor calculates a content digital digest for the actual transmitted content data. The credibility of the content digital digest is higher than that of the trust anchor, and the credibility of the content digital digest is lower than or equal to that of the abstract monitoring module.
[0026] In an embodiment of the present invention, the abstract monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.
[0027] An embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any of the above embodiments is implemented.
[0028] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the method described in any of the above embodiments is implemented.
[0029] In the solution implemented by the above-provided method, controller, device, and medium for improving the credibility of the hash algorithm of the trust anchor, the method calculates an actual digital digest for the data to be transmitted through a trust anchor with relatively low credibility. In this process, the trust anchor determines an answer according to the monitoring problem, and then generates trust verification data according to the answer and the actual digital digest. The relatively high-credibility abstract monitoring module generates host verification data according to the target digital digest and the preset answer, and obtains the first comparison result between the host verification data and the trust verification data. Through the above verification process, the credibility of the hash algorithm of the trust anchor can be improved, so that the functional safety level of the calculation and verification of the hash algorithm of the trust anchor is improved, and the obtained hash function calculation result or integrity verification success flag can be applied to functional safety critical scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts.
[0031] Figure 1 It is a schematic flowchart of a method for improving the credibility of the hash algorithm of the trust anchor provided by an embodiment of the present invention;
[0032] Figure 2 A specific flowchart of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0033] Figure 3 A specific flowchart of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0034] Figure 4 For Figure 2 The data transmission diagram of the method for improving the credibility of the hash algorithm of the trust anchor shown;
[0035] Figure 5 Another specific flowchart of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0036] Figure 6 Another specific flowchart of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0037] Figure 7 For Figure 5 The data transmission diagram of the method for improving the credibility of the hash algorithm of the trust anchor shown;
[0038] Figure 8 Another specific flowchart of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0039] Figure 9 Another specific flowchart of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention;
[0040] Figure 10 For Figure 8 The data transmission diagram of the method for improving the credibility of the hash algorithm of the trust anchor shown;
[0041] Figure 11 A structural diagram of a controller provided by the embodiment of the present invention;
[0042] Figure 12 A structural diagram of an electronic device in an embodiment of the present invention;
[0043] Figure 13 Another structural diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0044] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.
[0045] To enable those skilled in the art to better understand the improvements in the technical solutions provided by the present disclosure, the present disclosure briefly introduces the implementation method of the hash algorithm based on HSM and related information in the related art.
[0046] A trust anchor is a module required to meet the requirements of storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments. The implementation methods of trust anchors in MCU applications include Secure Hardware Extension (SHE), Hardware Security Module (HSM), Secure Element (SE), etc. Among them, HSM is a specification proposed by the E-safety Vehicle Intrusion protected Applications (EVITA, 2008-2011), that is, a research project of the European Union for vehicle communication security of Vehicle to Everything (V2X), which is divided into three levels: Light, Medium, and Full. Currently, the mainstream automotive-grade MCUs are configured with a Hardware Security Module (HSM), and the Full level has become a trend to meet the information security requirements of vehicle controllers.
[0047] The hash (HASH) algorithm is currently widely used in the field of automotive information security, such as verifying the integrity of software and messages. Common hash algorithms include SHA1, SHA2, MD5, etc.
[0048] The hash algorithm has the following characteristics:
[0049] 1. Fixed length: The hash function can accept data of any size and output a hash value of a fixed length;
[0050] 2. Avalanche effect: Even if only one byte of the original data is modified, the resulting HASH value (i.e., the digital digest) will change significantly;
[0051] 3. One-way: The HASH value can only be calculated from the original data, and the original data cannot be calculated from the HASH value;
[0052] 4. Avoidance of conflicts: The probability that different data calculates the same HASH value is extremely low. Therefore, the hash function can ensure the uniqueness of the data.
[0053] Based on the above characteristics, the hash algorithm can be used to ensure the integrity of data. First, the original content to be ensured integrity (hereinafter referred to as the original content) is used to obtain the target digital digest based on the hash algorithm as the target value for subsequent integrity verification. For example, when the actual content is tampered with, the actual digital digest calculated again for the actual content will not be equal to the original digital digest, thereby detecting that the integrity is damaged.
[0054] In addition, with the increasing complexity of automotive electronic control systems and the introduction of a large number of electrical and electronic components, while bringing control convenience and diversity, due to inevitable systematic failures and random hardware failures, it also brings certain risks to the safety of the whole vehicle. To further improve the safety design of road vehicle-related products, the ISO26262 road vehicle functional safety standard has been introduced. Based on the analysis of the risks and hazards of the whole vehicle under various working conditions, it evaluates the safety levels for different safety objectives (Automotive Safety Integrity Level, ASIL), gradually increasing from QM, ASIL-A / B / C / D. Currently, functional safety has become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.
[0055] In the design of an MCU with a trust anchor, taking the trust anchor as an HSM as an example, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module. To accelerate the calculation speed of the hash algorithm, a hash algorithm hardware acceleration unit can be equipped on the HSM side. The current implementation of the hash algorithm based on the HSM first calls the HSM driver function located on the HOST side of the HSM to transfer the actual content to be ensured integrity to the HSM firmware on the HSM side, and then triggers the actual digital digest calculation. The result of the actual digital digest calculation or its comparison result with the target digital digest is then fed back from the HSM side to the HOST side to determine the integrity of the actual data.
[0056] Since the hardware resources on the HSM side are currently not covered by a functional safety mechanism, the digital digest calculation result obtained on it cannot guarantee the functional safety level and can only be considered as QM, and cannot be applied to functional safety critical scenarios. Therefore, it is very meaningful and forward-looking to design a solution for improving the functional safety level of the hash algorithm based on the HSM.
[0057] For current mainstream MCUs, the HOST side has a perfect functional safety mechanism to ensure that the diagnostic coverage rate of its hardware failures can meet the requirements of the highest ASIL-D; moreover, it has at least one safety core with a Lockstep mechanism, and the Lockstep mechanism can make the diagnostic coverage rate of the MCU core meet the requirements of ASIL-D.
[0058] If directly calculated through the safety core on the HOST side, although the correctness of the hash algorithm calculation can be ensured, since the hash algorithm has high requirements for computing power, it will occupy a large amount of computing power on the HOST side and affect the normal function; based on this, the embodiment of this application designs a solution for improving the functional safety level of the hash algorithm calculation based on HSM.
[0059] The MCU hardware resources used to implement the hash algorithm calculation from the HSM side mainly include: the CPU, storage, bus, clock, power supply on the HSM side, and the HASH algorithm hardware acceleration unit. Among them, the clock, power supply are the same as those on the HOST side and can be covered by the HOST side, but other resources need to design additional functional safety mechanisms to cover their failures.
[0060] To solve the above problems, the embodiment of the present invention proposes a method, a controller, a device and a medium for improving the credibility of the hash algorithm of the trust anchor. The solution provided by the present invention will be described in detail through specific embodiments below.
[0061] The method provided by the embodiment of this application can be applied to the controller MCU, which includes a trust anchor TrustAnchor and a host HOST. The host includes a digest monitoring module, and the credibility of the digest monitoring module is higher than that of the trust anchor TrustAnchor. This method can be applied to application scenarios such as verifying the software of the vehicle controller and the integrity of the message. According to the needs of those skilled in the art, this method can be applied in the process of improving the credibility of the hash algorithm of the trust anchor for the actual digital digest calculated by the trust anchor for each controller, or applied randomly, or triggered once under conditions such as at intervals of a preset detection duration or at intervals of a preset number of data transmissions, to verify the actual digital digest calculated by the trust anchor. The digest monitoring module can be a hardware unit with computing power that meets the requirements of the functional safety level, such as: a hardware acceleration unit, at least one safety core with a Lockstep mechanism, etc.
[0062] The implementation methods of the trust anchor include but are not limited to SHE, HSM or SE and other methods known to those skilled in the art. In the design of an MCU with a trust anchor, the MCU can be divided into a trust anchor side (hereinafter referred to as the trust anchor) and a host side (hereinafter referred to as the host). The host is other parts except modules such as the trust anchor like HSM, and the trust anchor is part of modules such as HSM.
[0063] The confidence level in this embodiment can be evaluated by the above-mentioned Automotive Safety Integrity Level (ASIL), or can also be achieved by other trust rules for the field of functional safety set by those skilled in the art. Functional safety can be understood as the absence of unreasonable risks caused by hazards resulting from abnormal functional behaviors of electronic / electrical systems. For example, as exemplified in the above embodiment, the confidence level of the trust anchor is QM, and the confidence level of the host is ASIL D.
[0064] Please refer to Figure 1 as shown in Figure 1 which is a schematic flowchart of a method for improving the hash algorithm confidence level of a trust anchor provided by an embodiment of the present invention. The method includes the following steps:
[0065] Step S110, the host obtains the data to be transmitted, the target digital digest, and the monitoring problem, and sends the data to be transmitted and the monitoring problem to the trust anchor.
[0066] Among them, the target digital digest is obtained by calculating the data to be transmitted based on the hash algorithm.
[0067] The data to be transmitted can be the actual transmission content data that those skilled in the art select according to needs for actual transmission or the preset verification data set in advance. When the data to be transmitted is the actual transmission content data, the actual transmission content data can be the data sent by the data sender to the MCU and received by the host side. When the data to be transmitted is the preset verification data, it can be the data set in advance by those skilled in the art. The data size of the preset verification data is limited to ensure that the time for calculating the digital digest of the preset verification data by the HOST (host) can be completed within the time required by the Fault Tolerant Time Interval (FTTI) and other requirements.
[0068] It can be understood that the estimated calculation time for the preset digital digest of the preset verification data is less than the preset duration threshold. The estimated calculation time for the preset digital digest is also the estimated time required to calculate the digital digest of the preset verification data. The estimated actual calculation time for the digital digest and the estimated calculation time for the preset digital digest can be estimated and calibrated in advance by means known to those skilled in the art, and the method provided in this embodiment can obtain them by querying the data; the estimated actual calculation time for the digital digest and the estimated calculation time for the preset digital digest can also be estimated by other means known to those skilled in the art.
[0069] In one embodiment, before the host obtains the data to be transmitted and the target digital digest, the method includes: the data sender calculates the original digital digest based on the original content data; the data sender sends the original content data and the original digital digest to the host, so that the host receives the original content data as the actual transmitted content data, takes the original digital digest as the target digital digest of the actual transmitted content data, and determines the actual transmitted content data as the data to be transmitted. At this time, if the host receives the original content data and the original digital digest, it can use the original content data as the data to be transmitted and the original digital digest as the target digital digest for subsequent processes. The target digital digest is calculated by the data sender based on the original content data using a hashing algorithm. Of course, when the host receives the original content data and the original digital digest, those skilled in the art can also set one or more preset verification data as the data to be transmitted, and the digital digest corresponding to the one or more preset verification data (preset digital digest) as the target digital digest for one or more monitoring operations, and execute the method provided in this embodiment once using the original content data and the original digital digest during the monitoring process as a supplement to the monitoring process.
[0070] In another embodiment, before the host obtains the data to be transmitted and the target digital digest, the method includes: the data sender sends the original content data to the host; determines the preset verification data as the data to be transmitted, and determines the preset digital digest of the preset verification data as the target digital digest, where the preset digital digest is obtained by calculating the preset verification data. Sometimes, the host may only receive the original content data and not the original digital digest. In this case, the HOST cannot perform the verification of the subsequent process based on the known target digital digest of the actual transmitted content data. To monitor the digest trust status of the actual digital digest calculated by the hashing algorithm of the trust anchor, this solution can be implemented using the preset verification data and the corresponding preset digital digest of the preset verification data. For example, the preset verification data can be used as the data to be transmitted, and the preset digital digest can be used as the target digital digest to execute this solution. To ensure the normal operation of the controller, the size of the preset verification data can be set so that the time for the HOST to calculate the preset digital digest is less than the preset duration threshold. It should be noted that the preset digital digest can be calculated by the HOST itself or pre-calculated and stored in the HOST for subsequent use. The specific implementation method can be selected by those skilled in the art according to needs. The target digital digest is obtained by the HOST by calculating the preset verification data, or the preset digital digest is calculated from the preset verification data in other ways known to those skilled in the art and pre-stored in the HOST or in a storage space communicatively connected to the HOST. In this embodiment, when determining the preset verification data as the data to be transmitted, in one process of improving the credibility of the hashing algorithm of the trust anchor, one or more different preset verification data can be determined as the data to be transmitted for verification respectively. The result is monitored through the first comparison. It should be noted that this monitoring can be in one process of improving the credibility of the hashing algorithm of the trust anchor or in multiple processes of improving the credibility of the hashing algorithm of the trust anchor. If the number of occurrences of different events in the first comparison result exceeds the preset quantity threshold within a certain preset monitoring duration or a certain preset number of monitoring times, that is, within the preset statistical period, the controller will be controlled to enter the preset safe state. After entering the preset safe state, it can be set that the actual transmitted content data will no longer be sent to the trust anchor. In another embodiment, before sending the data to be transmitted and the monitoring problem to the trust anchor, the method includes: the host receives the original content data sent by the data sender and uses it as the actual transmitted content data; determines the estimated actual digest calculation time of the actual transmitted content data; if the estimated actual digest calculation time is less than the preset duration threshold, the actual digital digest of the data to be transmitted is calculated by the digest monitoring module.If the estimated actual digest calculation time is less than the preset duration threshold, it indicates that performing the digital digest calculation on the HOST side will not affect the normal functions of the controller. At this time, the technical solution of this embodiment can be continued to use the actual transmitted content data or the preset verification data as the data to be transmitted, or the digital digest calculation can be performed through the HOST side. Specifically, those skilled in the art can choose according to their needs.
[0071] Continuing the above embodiment, if the estimated actual digest calculation time is greater than or equal to the preset duration threshold and the host has received the original digital digest of the original content data, the actual transmitted content data is determined as the data to be transmitted, and the original digital digest is determined as the target digital digest; if the estimated actual digest calculation time is greater than or equal to the preset duration threshold and the host has not received the original digital digest of the original content data, the preset verification data is determined as the data to be transmitted, and the preset digital digest of the preset verification data is determined as the target digital digest.
[0072] To avoid the situation where the computing power overhead of directly calculating the actual digital digest of the actual transmitted content data on the HOST side is too large due to the excessive calculation amount of the actual transmitted content data, and it cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety failures, or it will affect the normal functions of the controller, and it is not suitable to directly obtain the hash function calculation result or the integrity verification success flag bit with a high functional safety level through the HOST side security core, a scheme of setting alternative preset verification data and preset digital digest can be adopted to replace the actual transmitted content data and the content digital digest of the actual transmitted content data to improve the credibility of the hash algorithm of the trust anchor. Specifically, by first calculating the estimated duration required to calculate the digital digest of the actual transmitted content data, that is, the estimated actual digest calculation time. If this estimated actual digest calculation time is greater than or equal to the preset duration threshold, it indicates that performing the digital digest calculation on the HOST side may affect the normal functions of the controller. At this time, the calculation of the actual digital digest can be set to be performed in a trust anchor such as an HSM. According to whether the original digital digest is received, it is judged whether to use the actual transmitted content data or the preset verification data as the data to be transmitted. If the original digital digest is not received, the preset verification data is used as the data to be transmitted, and the preset digital digest of the preset verification data is used as the target digital digest. If the original digital digest is received, the actual transmitted content data is used as the data to be transmitted, and the original digital digest is used as the target digital digest.
[0073] The data to be transmitted can be pre-set as the actual transmitted content data or the preset verification data. Sometimes, to make the solution more universal and flexible, the method of determining the data to be transmitted can also be adopted based on the comparison result between the estimated actual digest calculation time and the preset duration threshold provided in the above embodiments.
[0074] Among them, the estimated actual digest calculation time is the time taken for the estimated digest monitoring module to calculate the digital digest before transmission for the actual transmitted content data. This estimated actual digest calculation time can be pre-calibrated and known when the digest monitoring module receives the actual transmitted content data, or can be estimated by the digest monitoring module after receiving the actual transmitted content data, or can also be determined by other methods known to those skilled in the art. The preset duration threshold can be the duration required by the Fault Tolerant Time Interval (FTTI) of the host's functional safety, or other durations set by those skilled in the art.
[0075] After the host receives the actual transmitted content data, by selecting appropriate data as the data to be transmitted based on the magnitude relationship between the estimated actual digest calculation time and the preset duration threshold, the solution is made more flexible and has better applicability.
[0076] In this step, it can be the digest monitoring module that receives the data to be transmitted and the target digital digest, or similar to that described in the above embodiments, the driver (HSM HOST Driver) at the HOST end obtains the data to be transmitted and the target digital digest, and sends the data to be transmitted, the monitoring problem, and the target digital digest (if needed to be sent) to the trust anchor. Specifically, it can be set by those skilled in the art according to needs.
[0077] To avoid the problem that the computing power overhead is too large when the host directly calculates the digital digest before transmission, and it cannot be completed within the time required by the Fault Tolerant Time Interval (FTTI) and other requirements, or it will affect the normal function of the controller MCU, the size of the preset verification data is limited to ensure that it can be completed within the time required by the Fault Tolerant Time Interval and other requirements based on the time for the host to calculate the digital digest before transmission. The preset duration threshold is greater than or equal to the Fault Tolerant Time Interval FTTI.
[0078] The "digital digest" such as the actual digital digest, the original digital digest, and the target digital digest provided in the embodiments of the present application can be implemented using hash algorithms such as SHA1, SHA2, MD5, etc. The specific types of digital digest algorithms are not limited here, but in the same process of improving the credibility of the hash algorithm of the trust anchor, the same digital digest algorithm is used.
[0079] In another embodiment, before the host obtains the data to be transmitted and the target digital summary, the method includes: selecting a set from a pre-designed set of one or more sets of preset verification data and the preset digital summary of the preset verification data as the current data to be transmitted and the target digital summary, and the set is obtained by the host. It should be noted that the preset digital summary of the preset verification data can be calculated by a third party (non-host). The pre-designed set of one or more sets of preset verification data and the preset digital summary of the preset verification data can be stored in the host of the MCU, or can be stored in a preset storage space connected to the host. The preset digital summary of the preset verification data is also a verification digital summary calculated based on the preset verification data.
[0080] In order to further avoid the risk of failure of other hardware resources of the trust anchor causing the HSM to calculate the actual digital summary, while triggering the trust anchor to calculate the actual digital summary, the trust anchor can answer the received monitoring questions and obtain the answers. By comparing the answers with the preset answers to the monitoring questions, it can be further determined whether the trust anchor is credible during the digital signature verification process.
[0081] It should be noted that the monitoring questions and the data to be transmitted can be sent synchronously or asynchronously, and the specific sending method can be selected by those skilled in the art according to needs.
[0082] Before the trust anchor completes the calculation of the actual digital summary, it may be before starting to calculate the actual digital summary, or during the process of calculating the actual digital summary, the monitoring question is sent to the trust anchor. This enables the monitoring question to be answered and the answer to be obtained during the process of the trust anchor calculating the actual digital summary. The number of monitoring questions can be one or more. If there are multiple monitoring questions, the multiple monitoring questions can be sent at one time or in batches, which can be set by those skilled in the art as needed.
[0083] In one embodiment, multiple modes for generating monitoring problems are provided, and the host obtains the monitoring problem, including any one of the following:
[0084] Obtaining preset questions and determining the preset questions as monitoring questions. It can be understood that if this method is used alone, there is a fixed one or a set of preset monitoring questions (each set of questions contains multiple sub-questions), and the same monitoring question is issued each time;
[0085] Obtain multiple preset questions, and determine one or more selected preset questions as monitoring questions. It can be understood that if this method is used alone, there are multiple preset monitoring questions, and each time one or more of them are selected as the current monitoring questions. The number of questions selected each time can be different or the same. The questions selected in several adjacent times can be the same or at least partially different. The selection method can be random selection or other selection methods set by those skilled in the art. Similar to the previous embodiment, a preset question can be only one question or can include multiple questions. If both of the two preset questions include multiple questions, the number of questions included in these two preset questions can be the same or different, and the actual content of the questions can be partially the same or completely different, and specifically can be set by those skilled in the art according to needs;
[0086] Obtain the sent monitoring questions and multiple preset questions, screen out the sent monitoring questions from the multiple preset questions, and determine the one or more preset questions after screening as the monitoring questions. By using this method, it can be ensured that the monitoring questions sent each time are different from the previous time. By controlling the sampling range of the sent monitoring questions, such as the last 20 times, the last 1 day, etc., the possible minimum occurrence frequency of sending the same monitoring questions twice can be controlled;
[0087] Obtain the sent monitoring questions and multiple preset questions, determine the randomly selected multiple preset questions as the preselected questions. If the question content of the preselected questions is the same as the question content of the sent monitoring questions, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the sent monitoring questions, and determine the adjusted preselected questions as the monitoring questions. By using this method, on the premise of limited questions, by adjusting the order of the questions, the order of collecting answers by the trust anchor can be adjusted, and then the timing of the trust anchor collecting the answers corresponding to the questions can be adjusted, and the effect of increasing the failure coverage rate can also be achieved without adding new preset questions.
[0088] In one embodiment, multiple preset questions can be divided into different level sets, and there are at least partial differences in the types of hardware resources required to answer the preset questions in each level set. In this way, subsequent selection of the preset questions in the corresponding level set as monitoring questions can be adapted according to the hardware resources that need to be focused on preventing failures.
[0089] By increasing the number of preset questions, updating the preset questions, controlling the difference in the monitoring questions issued in the most recent several times, or switching the order of the monitoring questions, etc., the failure coverage rate can be increased. For example, if the failure modes are jamming, being too large, and being too small, a monitoring question may only be able to obtain a conclusion that it is too large or too small, but cannot obtain a conclusion on whether there is jamming. At this time, through the participation of multiple monitoring questions, more failure modes can be detected as much as possible. By increasing the monitoring questions, especially the monitoring questions that can only obtain answers by invoking different resources, the more categories of hardware resources used to generate the answers, the wider the diagnostic coverage, the more failure situations covered, and the higher the coverage rate.
[0090] It should be noted that the monitoring questions and the corresponding preset answers can be preset in advance and stored in the storage space that can be communicatively connected to the host, or stored in the host storage space.
[0091] Due to the addition of monitoring questions and answer answers, the credibility of the hash algorithm of the trust anchor is more credible. In the case of partial hardware resource failures of the trust anchor, problems can also be discovered in a timely manner through the above methods.
[0092] Step S120, the trust anchor calculates the actual digital digest for the data to be transmitted using the hash algorithm, and during the process of calculating the actual digital digest for the data to be transmitted, determines the answer based on the monitoring questions, generates trust verification data based on the answer and the actual digital digest, and sends the trust verification data to the digest monitoring module.
[0093] The way the trust anchor calculates the actual digital digest for the data to be transmitted is the same as the digest calculation method of the target digital digest, and the hash algorithm used is the same, so that it can be ensured that the same digital digest can be calculated for the same data content by different calculation entities. For the two processes of improving the credibility of the hash algorithm of the trust anchor, the same or different digest calculation methods can be adopted, and the selection of the digest calculation method can be chosen by those skilled in the art according to needs.
[0094] In this embodiment, determining an answer to a monitoring question includes: The trust anchor matches the monitoring question with multiple preset local questions in a preset question-answer table. If a match is successful with a preset local question, the preset local answer corresponding to the preset local question is determined as the first sub-answer. The preset question-answer table includes at least one preset local question and the preset local answer corresponding to each preset local question. The trust anchor stores the preset question-answer table; The trust anchor triggers a preset function module based on the monitoring question to output a function answer, and determines the function answer as the second sub-answer. The trust anchor is provided with a preset function module; The trust anchor collects one or more monitoring results of its own security mechanisms based on the monitoring question, and determines the one or more monitoring results of its own security mechanisms as the third sub-answer; The trust anchor generates an answer based on at least one of the first sub-answer, the second sub-answer, and the third sub-answer. That is to say, the answer can be generated by looking up a table, or obtained through operations of a preset function module such as a Linear Feedback Shift Register (LFSR), or by collecting the monitoring results of the original security mechanism of the trust anchor, etc.
[0095] In this embodiment, before the digest monitoring module generates host verification data based on the target digital digest and the preset answer to the monitoring question, the method includes: The digest monitoring module matches the monitoring question with multiple preset local questions in a preset question-answer table. If a match is successful with a preset local question, the preset local answer corresponding to the preset local question is determined as the first preset sub-answer. The preset question-answer table includes at least one preset local question and the preset local answer corresponding to each preset local question. The digest monitoring module stores the question-answer table; The digest monitoring module triggers a preset function module based on the monitoring question to output a function answer, and determines the function answer as the second preset sub-answer. The digest monitoring module is provided with a preset function module; The digest monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as the third preset sub-answer based on the monitoring question; The digest monitoring module generates a preset answer based on at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; The digest monitoring module determines the host verification data based on the target digital digest and the preset answer. In other words, the preset answer corresponding to the monitoring answer is stored in the host, and this preset answer can be understood as the standard answer. The acquisition method of the preset answer can be that all are pre-stored, or a preset function the same as that of the trust anchor can be set to achieve the effect of outputting the same answer. The acquisition method of the preset answer can also be other methods known to those skilled in the art. It should be noted that in this embodiment, it is not limited that the preset answer and the answer adopt the same acquisition method, that is, the acquisition methods can be the same or different.
[0096] It should be noted that the calculation of the trust verification data and the host verification data mentioned later can be implemented by using the CRC (Cyclic Redundancy Check) algorithm or other algorithms known to those skilled in the art that can ensure the integrity of functional safety data. For example, the determination method of the trust verification data is as follows: The trust anchor performs a cyclic redundancy check on the answer and the actual digital digest to determine the trust verification value, and uses this trust verification value as the trust verification data. Another example is that the calculation method of the host verification data is as follows: The digest monitoring module performs a cyclic redundancy check on the preset answer and the target digital digest to determine the host verification value, and uses this host verification value as the host verification data.
[0097] Step S130: The digest monitoring module generates host verification data based on the target digital digest and the preset answer of the monitoring question, and performs a first comparison between the host verification data and the trust verification data to obtain a first comparison result.
[0098] Through the above steps S110 - S130, regardless of the first comparison result, the functional safety level of the calculation and verification of the hashing algorithm executed by the trust anchor end has been improved to a certain extent.
[0099] In one embodiment, when the actual transmitted content data is used as the data to be transmitted, after obtaining the first comparison result, the method further includes: If the first comparison result is that the host verification data is the same as the trust verification data, the integrity verification result of the high functional safety level passes, that is, the host verification result can be determined according to the first comparison result as the integrity verification success flag bit, and this integrity verification success flag bit is credible; otherwise, if the first comparison result is that the host verification data is different from the trust verification data, the integrity verification result of the high functional safety level fails, that is, the host verification result can be determined according to the first comparison result as the integrity verification success flag bit, and this integrity verification success flag bit is not credible.
[0100] In another embodiment, when the preset verification data is used as the data to be transmitted, after obtaining the first comparison result, the method further includes: If the first comparison result is that the host verification data is the same as the trust verification data, the integrity verification result of the high functional safety level passes, and to a certain extent, it can be considered that the calculation and verification of the hashing algorithm of the trust anchor are credible; otherwise, if the first comparison result is that the host verification data is different from the trust verification data, the integrity verification result of the high functional safety level fails, and to a certain extent, it can be considered that the calculation and verification of the hashing algorithm of the trust anchor are not credible.
[0101] In another embodiment, before determining the trust status of the actual digital digest based on the first comparison result, the method further includes: the host sending the target digital digest to the trust anchor; the trust anchor performing a second comparison on the target digital digest and the actual digital digest, determining the trust anchor verification result based on the second comparison result, and sending the trust anchor verification result to the digest monitoring module; the digest monitoring module performing a third comparison on the trust anchor verification result and the first comparison result to obtain a third comparison result, so as to improve the credibility of the hash algorithm of the trust anchor. If the target digital digest is the same as the actual digital digest, the trust anchor verification result is the same; otherwise, if the target digital digest is different from the actual digital digest, the trust anchor verification result is different.
[0102] In this embodiment, after obtaining the third comparison result, the method further includes: if the third comparison result is that the trust anchor verification result is the same as the first comparison result, determining that the trust status of the trust anchor verification result is trustworthy; if the third comparison result is that the trust anchor verification result is different from the first comparison result, determining that the trust status of the trust anchor signature verification result is in doubt.
[0103] In other words, if the target digital digest is the same as the actual digital digest, and the host verification data is the same as the trust verification data, the third comparison result is that the same integrity verification result is trustworthy, and at this time the trust anchor signature verification result is trustworthy; on the contrary, if any of the following abnormal situations occurs, the third comparison result is different. The abnormal situations are: 1. The target digital digest is the same as the actual digital digest, and the host verification data is different from the trust verification data. 2. The target digital digest is different from the actual digital digest, and the host verification data is the same as the trust verification data. When an abnormal situation occurs, obviously there are problems with the integrity and security of the data to be transmitted during the data transmission process, so the actual digital signature calculated by the trust anchor for the data to be transmitted is not trustworthy, and the integrity verification result is not trustworthy.
[0104] For the convenience of comparison, those skilled in the art can represent the trust anchor verification result through a preset trust anchor verification success flag bit, and represent the first comparison result through a preset host verification success flag bit. The representation rules of the trust anchor verification success flag bit and the host verification success flag bit are the same. In this way, by comparing the similarities and differences between the host verification success flag bit and the trust anchor verification success flag bit, the trust status of the digest can be obtained more quickly.
[0105] In one embodiment, after obtaining the first comparison result by using the preset verification data as the data to be transmitted, the method further includes: the host uses the received original content data as the actual transmitted content data and sends it to the trust anchor, so that the trust anchor calculates the digest of the actual transmitted content data to obtain the content digital digest; the credibility of the content digital digest is higher than that of the trust anchor, and the credibility of the content digital digest is lower than or equal to that of the digest monitoring module. In one embodiment, regardless of whether the first comparison result is the same or different, even if it is different, as long as the controller does not enter the preset safe state, that is, after monitoring by using the preset verification data as the data to be transmitted (the credibility of the hashing algorithm of the trust anchor is improved), regardless of what the large first comparison result of the most recent monitoring is, as long as the controller does not enter the preset safe state, the host still uses the received original content data as the actual transmitted content data and sends it to the trust anchor for the trust anchor to calculate the digest of the actual transmitted content data to obtain the content digital digest, and does not perform the method process of improving the credibility of the hashing algorithm of the trust anchor on the content digital digest itself. At this time, the credibility of the content digital digest is improved, and the credibility of the trust anchor verification result obtained by the trust anchor is also improved.
[0106] In one embodiment, the method further includes: counting the number of occurrences of events where the first comparison result or the third comparison result is different within a preset statistical period; if the number of occurrences of events is greater than a preset number threshold, controlling the controller to enter a preset safe state. For example, count the number of occurrences where the first comparison result obtained by monitoring is different as the number of occurrences of events within the most recent preset duration, or count the number of occurrences where the third comparison result obtained by monitoring is different as the number of occurrences of events, or use the sum of the number of occurrences where the third comparison result obtained by monitoring is different and the number of occurrences where the first comparison result is different as the final number of occurrences of events. When the number of occurrences of events is greater than the preset number threshold, control the controller to enter the preset safe state. The preset safe state can be set by those skilled in the art according to the specific application scenario of the controller as needed. For example, for a motor controller or an engine controller, entering the preset safe state may switch the power output. For an autonomous driving ADAS controller, it may transmit a safety signal to the upper-level decision-making controller, indicating that it is aware of an abnormality, etc.
[0107] In another embodiment, if the first comparison result and / or the third comparison result is the same, the method further includes: enhancing the credibility of the actual digital digest based on the credibility of the digest monitoring module. In this way, the signature verification result of the trust anchor is no longer that of QM, but the credibility of the actual digital digest is enhanced according to the automotive safety integrity level of the security core of the digest monitoring module. If the automotive safety integrity level of the security core of the digest monitoring module is ASIL-D, the automotive safety integrity level of the actual digital digest is at most ASIL-D at this time. Subsequently, the digital digest calculated by the trust anchor also defaults to have a relatively high credibility.
[0108] The method for enhancing the hash algorithm credibility of the trust anchor provided by the embodiment of the present application calculates the actual digital digest by using the trust anchor with relatively low credibility for the data to be transmitted. In this process, the trust anchor determines the answer based on the monitoring problem, and then generates the trust verification data according to the answer and the actual digital digest. The relatively high-credibility digest monitoring module generates the host verification data according to the target digital digest and the preset answer. By obtaining the first comparison result between the host verification data and the trust verification data through this verification process, the credibility of the hash algorithm of the trust anchor can be enhanced, so that the functional safety level of the calculation and verification of the hash algorithm of the trust anchor is improved, and the calculation result of the hash function or the integrity verification success flag bit obtained by the calculation can be applied to the functional safety critical scenario. In the above manner, the credibility of the calculation and verification functions of the hash algorithm of the trust anchor can be enhanced.
[0109] Optionally, by adding monitoring problems during the process of the trust anchor calculating the digest and synchronously determining the answers during the digest calculation process, this solution covers the scenario where the hardware resources for the trust anchor digital digest calculation fail. By comparing the trust verification data with the host verification data, the reliability of the final enhancement of the hash algorithm credibility of the trust anchor is further improved.
[0110] Optionally, by configuring multiple sets of variable monitoring problems and a flexible and changeable answer generation method, the diagnostic coverage rate can be improved, and the failure situations of multiple hardware resources at multiple trust anchor ends can be covered.
[0111] Optionally, when the expected actual digest calculation time of the actual transmitted content data is greater than or equal to the preset duration threshold, the preset verification data is used as the data to be transmitted to enhance the credibility of the hash algorithm of the trust anchor. On the one hand, it solves the problem that due to the excessive data volume of the actual transmitted content data, the computing power overhead of the host is too large, affecting the normal function of the controller. On the premise of ensuring the credibility of the enhancement of the hash algorithm credibility of the trust anchor, the computing power overhead of the host is reduced.
[0112] It can be seen that the solution provided in this embodiment can improve the functional safety level of the hash algorithm based on trust anchors such as HSM without affecting the functions of the HOST (host) side, enabling the hash algorithm based on trust anchors such as HSM to replace and supplement the existing functional safety mechanisms to ensure the data integrity related to functional safety and expand its scope of use.
[0113] Taking the controller as the MCU, dividing the MCU into a host and a trust anchor, with the trust anchor being the HSM, and the data to be transmitted being the actual transmitted content data (hereinafter referred to as the actual content) as an example, the implementation of monitoring is mainly completed in the digest monitoring module. The digest monitoring module is a trusted module, and an example is given for the method of improving the credibility of the hash algorithm of the trust anchor provided in the above embodiment.
[0114] It should be noted that the sending method in the following examples can be separate sending or synchronous sending. Specifically, those skilled in the art can select according to needs. The steps shown in the figure are only for illustration and do not limit the sequence of steps. The steps in subsequent figures are also for illustration and do not limit the sequence of steps, and will not be elaborated further.
[0115] When the calculation amount of the actual content is large, the computing power overhead of directly calculating the actual digital digest of the actual content whose integrity needs to be ensured on the HOST side is large, and the calculation cannot be completed within the time required by requirements such as the functional safety fault tolerance time interval (Fault Tolerant TimeInterval, FTTI), or it will affect the normal functions of the controller. Then, the above method cannot be used to directly obtain the hash function calculation result or the integrity verification success flag bit with a high functional safety level through the security core on the HOST side, and a functional safety mechanism needs to be designed additionally. For the above scenarios, it is divided into the following situations:
[0116] A. Scenario 1: The target digital digest is known:
[0117] 1. Only calculate the actual digital digest of the actual content on the HSM side and transmit it to the HOST side, and judge the actual digital digest and the target digital digest on the HOST side to verify the integrity of the actual content;
[0118] 2. Calculate the actual digital digest of the actual content on the HSM side, and compare and judge the actual digital digest and the target digital digest, and transmit the integrity verification success flag bit to the HOST side;
[0119] B. Scenario 2: The target digital digest is known.
[0120] For scenario A1, that is, when the target digital digest is known, only calculate the actual digital digest of the actual content at the HSM side and transmit it to the HOST side. At the HOST side, judge the actual digital digest and the target digital digest to verify the integrity of the actual content. To prevent the situation where the actual digital digest calculated at the HSM side is actually inconsistent with the known target digital digest, but due to the failure of the hardware resources at the HSM side, the actual digital digest transmitted to the HOST side is equal to the known target digital digest, that is, the HOST side does not detect that the integrity of the actual content is damaged. A specific implementation method provided in this embodiment is as follows. Please refer to Figure 2 、 Figure 3 and Figure 4 , Figure 2 is a specific flow schematic diagram of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention, Figure 3 is a specific flow schematic diagram of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention, Figure 4 is Figure 2 the data transmission schematic diagram of the method for improving the credibility of the hash algorithm of the trust anchor shown. As Figure 2 、 Figure 3 and Figure 4 shown, in the pre-preparation stage, the data sender calculates the original digital digest according to the original content (if the transmission is error-free, that is, the subsequent actual content). The data sender sends the original digital digest and the original content to the host of the MCU ( Figure 2 shown as HOST in), and the HOST takes the received original content as the actual content and the original digital digest as the target original digital digest, that is, the HOST receives the above original digital digest and original content to obtain the target digital digest and the actual content. If the computing overhead of directly calculating the actual digital signature of the actual content that needs to ensure integrity and authenticity at the secure core of the HOST side is small, and it can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), and it will not affect the normal function of the controller, then the monitoring can be directly implemented at the HOST side. Or adopt the method provided in this embodiment. After the monitoring starts, the HOST side determines the monitoring problem, and sends the monitoring problem and the actual content to the HSM side. The HSM side calculates the actual digital digest of the actual content based on the hash algorithm, and determines the answer according to the monitoring problem during the process of calculating the actual digital digest, and then calculates the trust verification data according to the answer and the actual digital digest, that is, in Figure 2 、 Figure 3 and Figure 4Shown in the middle as "CRC(actual digital digest + answer)", the HSM side sends the trust verification data (CRC(actual digital digest + answer)) to the HOST side. The HOST side itself determines the preset answer according to the monitored problem, and determines the host verification data based on the preset answer and the target digital digest, that is, in Figure 2 、 Figure 3 and Figure 4 shown as CRC(preset answer + target digital digest). The HOST side compares CRC(answer + actual digital digest) and CRC(preset answer + target digital digest) to obtain the first comparison result. Among them, CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. If the first comparison result is that the two are different, it means that the integrity verification result of the high functional safety level fails. Otherwise, if the first comparison result is that the two are the same, it means that the integrity verification result of the high functional safety level passes. While triggering the HSM side to calculate the actual digital digest, the digital digest monitoring software (with ASIL level) sends a monitoring problem to the HSM Firmware on the HSM side through the HSM HOST Drive (QM). In order to improve the diagnostic coverage, the monitoring problem can be dynamically changed, for example: 0x0, 0x1, 0x2, 0x3…0xF. Secondly, the method for obtaining the answer in the HSM side Firmware (QM) based on the monitoring problem can also be selected according to the diagnostic coverage requirements. It can be obtained directly by looking up the table or based on; if you want to further improve the diagnostic coverage, you can also integrate the monitoring results of various software and hardware resources on the HSM side. The answer for each monitoring problem is known in the digital digest monitoring software.
[0121] For the failure confirmation and response when the above monitoring fails, a failure counter can be set to count the number of events where the first comparison result is different. If the failure counter is greater than the threshold (that is, the number of events is greater than the preset number threshold), the system is made to enter the safe state according to the requirements of the actual functional safety target.
[0122] For scenario A2, that is, when the target digital digest is known, the actual digital digest of the actual content is calculated at the HSM side, and the actual digital digest is compared with the target digital digest to judge, and the integrity verification success flag is passed to the HOST side. In the security core of the HOST side, "digital digest monitoring software" is designed. In order to achieve that the integrity verification success flag reaches the corresponding ASIL level, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed freedom from interference (FFI) with other ASIL / QM level software. When triggering the HSM side to calculate the actual digital digest according to the actual content, the digital digest monitoring software will send a monitoring problem to the HSM side. In order to improve the diagnostic coverage, the monitoring problem can be dynamically changed, for example: 0x0, 0x1, 0x2, 0x3…0xF. Secondly, the method of obtaining the monitoring answer based on the monitoring problem in the HSM side firmware can also be selected according to the diagnostic coverage requirements, which can be obtained by directly looking up a table, or can be obtained based on operations such as a linear feedback shift register (LFSR); if you want to further improve the diagnostic coverage, you can also integrate the monitoring results of various software and hardware resources on the HSM side. The preset answers for each monitoring problem are known in the digital digest monitoring software. Finally, the "digital digest monitoring software" calculates CRC (preset answer + target digital digest) according to the known target digital digest, and judges whether CRC (answer answer + actual digital digest) from the HSM side is equal to CRC (preset answer + target digital digest) to obtain the integrity verification success flag (HOST side), and then compares it with the integrity verification success flag (HSM side) to judge whether the monitoring passes. Among them, CRC (Cyclic Redundancy Check) is a cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. Another specific implementation manner provided by this embodiment is as follows. Please refer to Figure 5 、 Figure 6 and Figure 7 , Figure 5 is another specific flow diagram of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention, Figure 6 is another specific flow diagram of the monitoring stage of the method for improving the credibility of the hash algorithm of the trust anchor provided by the embodiment of the present invention, Figure 7 is Figure 5 the data transmission diagram of the method for improving the credibility of the hash algorithm of the trust anchor shown. As Figure 5 、 Figure 6 and Figure 7As shown, in the pre - preparation stage, the data sender calculates the original digital digest based on the original content (which is also the subsequent actual content if the transmission is error - free). The data sender sends the original digital digest and the original content to the host of the MCU ( Figure 5 shown as HOST in it), and the HOST takes the received original content as the actual content and the original digital digest as the target original digital digest. That is, the HOST receives the above - mentioned original digital digest and original content to obtain the target digital digest and the actual content. If the computing overhead of directly calculating the actual digital signature of the actual content whose integrity and authenticity need to be guaranteed by the security core at the HOST end is small, and it can be completed within the time required by requirements such as the Fault - Tolerant Time Interval (FTTI), and it does not affect the normal function of the controller, then it can also be directly monitored and implemented at the HOST end. Or adopt the method provided in this embodiment. After the monitoring starts, the HOST end determines the monitoring problem, and sends the monitoring problem, the target digital digest, and the actual content to the HSM end. The HSM end calculates the actual digital digest for the actual content based on the hash algorithm, and determines the answer according to the monitoring problem during the process of calculating the actual digital digest, and then calculates the trust verification data based on the answer and the actual digital digest, that is, in Figure 5 , Figure 6 and Figure 7 shown as "CRC(answer + actual digital digest)". The HSM end also conducts a second comparison between the target digital digest and the actual digital digest to determine the integrity verification success flag bit (HSM end). The HSM end sends the trust verification data (CRC(answer + actual digital digest)) and the integrity verification success flag bit (HSM end) to the HOST end. The HOST end itself determines the preset answer according to the monitoring problem, and determines the host verification data based on the preset answer and the target digital digest, that is, in Figure 5 , Figure 6 and Figure 7 shown as CRC(preset answer + target digital digest). The HOST end compares CRC(answer + actual digital digest) and CRC(preset answer + target digital digest) to obtain the first comparison result. The HOST end also conducts a third comparison between the first comparison result and the integrity verification success flag bit (HSM end) to obtain the third comparison result. Among them, CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. If the third comparison result shows that the two are different, it means that the integrity verification result of the high - functional - safety - level fails, triggering subsequent fault confirmation and response. Otherwise, if the third comparison result shows that the two are the same, it means that the integrity verification result of the high - functional - safety - level is credible. As Figure 7As shown, the monitoring problem can be sent to the HSM HOST Driver (QM) by the digital digest monitoring software (ASIL). The HSM HOST Driver (QM) sends the actual content, the target digital digest, and the monitoring problem to the HSM Firmware (QM). Then, the HSM Firmware (QM) feeds back the CRC (answer + actual digital digest) calculated at the HSM side and the integrity verification success flag (HSM side) to the digital digest monitoring software through the HSM HOST Driver.
[0123] For the failure confirmation and response when the above monitoring fails, a failure counter can be set to count the number of events where the third comparison result is different. If the failure counter is greater than the threshold (i.e., the number of events is greater than the preset quantity threshold), the system is made to enter the safe state according to the requirements of the actual functional safety target.
[0124] For scenario B, that is, the unknown target digital digest: Calculate the actual digital digest of the actual content at the HSM side. At this time, due to the unknown target digital digest, the HOST side cannot perform verification based on the known target digital digest. Taking the preset verification data as the monitoring actual content as an example, to implement the monitoring of the hashing algorithm calculation at the HSM side, design one set or multiple sets of "monitoring actual content" specifically for monitoring. The size of the "monitoring actual content" needs to ensure that the time for calculating the digital digest of the monitoring actual content based on the HOST side can be completed within the time requirements such as the functional safety fault tolerance time interval (FTTI). Using multiple sets can increase the failure coverage rate. Or the "monitoring digital digest" corresponding to the "monitoring actual content" is also directly preset at the HOST side as the basis for monitoring judgment. The monitoring process of the digital digest monitoring software for one set of "monitoring actual content" and "monitoring digital digest" is as Figure 8 shown. Before calculating the actual digital digest, execute the digital digest monitoring software at least once. Please refer to Figure 8 , Figure 8 which is another specific process schematic diagram of the monitoring stage of the method for improving the credibility of the hashing algorithm of the trust anchor provided by the embodiment of the present invention. Figure 9 which is another specific process schematic diagram of the monitoring stage of the method for improving the credibility of the hashing algorithm of the trust anchor provided by the embodiment of the present invention, Figure 10 is Figure 8 the data transmission schematic diagram of the method for improving the credibility of the hashing algorithm of the trust anchor shown. As Figure 8 , Figure 9 and Figure 10As shown, in the pre - preparation stage, the data sender calculates the original digital digest based on the original content (which is also the subsequent actual content if the transmission is error - free). The data sender sends the original digital digest and the original content to the host of the MCU ( Figure 8 shown as HOST in Figure 8 ). The HOST determines the actual content for monitoring as the data to be transmitted, and determines the target digital digest for monitoring calculated from the actual content for monitoring as the target digital digest. After the monitoring starts, the HOST side determines the monitoring problem and sends the actual content for monitoring and the monitoring problem to the trust anchor ( Figure 8 shown as HSM in Figure 8 ). The HSM side calculates the actual digital digest of the actual content for monitoring based on the hash algorithm, and determines the answer according to the monitoring problem during the process of calculating the actual digital digest of the actual content for monitoring. Then, it calculates the trust verification data based on the answer and the actual digital digest of the actual content for monitoring, that is, in Figure 8 shown as "CRC(answer + actual digital digest of the actual content for monitoring)". The HSM side sends the trust verification data (CRC(answer + actual digital digest of the actual content for monitoring)) to the HOST side. The HOST side itself determines the preset answer according to the monitoring problem, and determines the host verification data based on the preset answer and the target digital digest for monitoring of the actual content for monitoring, that is, in Figure 8 shown as CRC(preset answer + target digital digest for monitoring). The HOST side compares CRC(answer + actual digital digest of the actual content for monitoring) and CRC(preset answer + target digital digest for monitoring) to obtain the first comparison result. Among them, CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. If the first comparison result shows that the two are different, it means that the monitoring fails and triggers subsequent fault confirmation and response. Otherwise, if the first comparison result shows that the two are the same, the monitoring is successful.
[0125] For the fault confirmation and response when the above - mentioned monitoring fails (the integrity check result of the high - functional safety level fails), a fault failure counter can be set to count the number of events where the first comparison result is different. If the fault failure counter is greater than the threshold (that is, the number of events is greater than the preset number threshold), the system will enter the safe state according to the requirements of the actual functional safety target.
[0126] After performing the above steps one or more times through one or more preset verification data, continue to refer to Figure 8 , the HOST side sends the actual content to the HSM side, and the HSM side calculates the actual digital digest for this actual content. At this time, the credibility of the actual digital digest (content digital digest) calculated by the HSM side has been improved.
[0127] As shown in Figure 10 the figure, it can be that the monitoring problem is sent to the HSM HOST Driver (QM) by the digital digest monitoring software (ASIL), the HSM HOST Driver (QM) sends the actual content for monitoring and the monitoring problem to the HSM Firmware (QM), and then the HSM Firmware (QM) feeds back the CRC (answer + actual digital digest of the actual content for monitoring) calculated at the HSM end to the digital digest monitoring software through the HSM HOST Driver.
[0128] This solution designs a solution for improving the functional safety level of the hash algorithm based on HSM. This solution can improve the functional safety level of the hash algorithm based on HSM without affecting the functions of the HOST side, enabling the hash algorithm based on HSM to replace and supplement the existing functional safety mechanisms to ensure the integrity of data related to functional safety and expand its scope of use.
[0129] It should be noted that the types of the above-mentioned hash algorithms (such as: SHA1, SHA2, MD5) are not limited, and the digital digest monitoring software can also be implemented in the HSM HOST Driver; the secure core can also be other hardware units with computing capabilities that can meet the requirements of the functional safety level, such as: hardware acceleration units; the above-mentioned CRC algorithm can also be other algorithms that can ensure the integrity of functional safety data.
[0130] In an embodiment, a controller is provided, and this controller is used to implement the method for improving the credibility of the hash algorithm of the trust anchor provided in any one of the above-mentioned embodiments. Please refer to Figure 11 , Figure 11 which is a schematic structural diagram of the controller provided in the embodiment of the present invention. As shown in Figure 11As shown, the controller 1100 includes a trust anchor 1110 and a host 1120. The host 1120 includes a digest monitoring module 1121, and the credibility of the digest monitoring module 1121 is higher than that of the trust anchor 1110. The detailed description of each functional module is as follows: The host 1120 is used to obtain the data to be transmitted, the target digital digest, and the monitoring question, send the data to be transmitted and the monitoring question to the trust anchor 1110. The target digital digest is obtained by calculating the data to be transmitted based on the hashing algorithm; The trust anchor 1110 is used to calculate the actual digital digest of the data to be transmitted through the hashing algorithm, and during the process of calculating the actual digital digest of the data to be transmitted, determine the answer according to the monitoring question, generate trust verification data based on the answer and the actual digital digest, and send the trust verification data to the digest monitoring module 1121; The digest monitoring module 1121 is used to generate host verification data according to the target digital digest and the preset answer of the monitoring question, and perform a first comparison between the host verification data and the trust verification data to obtain a first comparison result. To improve the credibility of the hashing algorithm of the trust anchor.
[0131] In one embodiment, the host further includes a trust anchor driver function module, which is used to obtain the data to be transmitted and the target digital digest, receive the monitoring question sent by the digest monitoring module, send the monitoring question, the data to be transmitted, and the target digital digest to the trust anchor, and receive the trust verification data and send the trust verification data to the digest monitoring module.
[0132] In one embodiment, the digest monitoring module is disposed in the trust anchor driver function module.
[0133] In one embodiment, the host further includes a mode switching module, which is used to determine the estimated actual digest calculation time of the actual transmission content data after the host receives the original content data sent by the data sender and uses it as the actual transmission content data. If the estimated actual digest calculation time is less than the preset duration threshold, calculate the actual digital digest of the data to be transmitted through the digest monitoring module.
[0134] In one embodiment, the host is further used to determine the preset verification data as the data to be transmitted if the host only receives the original content data and does not receive the original digital digest, and determine the preset digital digest of the preset verification data as the target digital digest. The preset digital digest is obtained by calculating the preset verification data.
[0135] In one embodiment, after the host uses the digest monitoring module to obtain the first comparison result, the host also uses the received original content data as the actual transmitted content data and sends it to the trust anchor, so that the trust anchor can calculate the digest of the actual transmitted content data to obtain the content digital digest. The credibility of the content digital digest is higher than that of the trust anchor, and the credibility of the content digital digest is lower than or equal to that of the digest monitoring module.
[0136] In one embodiment, the digest monitoring module is set in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.
[0137] For the specific limitations of the controller, reference can be made to the limitations of the method for improving the credibility of the hash algorithm of the trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the electronic device in hardware form or independent of the processor, or stored in the memory in the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0138] In this embodiment, the controller essentially sets multiple modules to execute the method for improving the credibility of the hash algorithm of the trust anchor in any of the above embodiments. For the specific functions and technical effects, reference can be made to the above embodiments, which will not be elaborated here.
[0139] In one embodiment, an electronic device is provided. The electronic device can be a server, and its internal structure diagram can be as Figure 12 shown. The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the server side of a method for improving the credibility of the hash algorithm of the trust anchor.
[0140] In one embodiment, an electronic device is provided. The electronic device can be a client, and its internal structure diagram can be as Figure 13As shown in the figure. The electronic device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a method for improving the credibility of the hash algorithm of a trust anchor.
[0141] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are realized:
[0142] Obtain the data to be transmitted, the target digital digest, and the monitoring problem through the host, and send the data to be transmitted and the monitoring problem to the trust anchor. The target digital digest is obtained by calculating the data to be transmitted based on the hash algorithm;
[0143] The trust anchor calculates the actual digital digest of the data to be transmitted through the hash algorithm, and during the process of calculating the actual digital digest of the data to be transmitted, determine the answer to the monitoring problem according to the monitoring problem, generate trust verification data based on the answer and the actual digital digest, and send the trust verification data to the digest monitoring module;
[0144] The digest monitoring module generates host verification data according to the target digital digest and the preset answer of the monitoring problem, and performs a first comparison between the host verification data and the trust verification data to obtain a first comparison result. To improve the credibility of the hash algorithm of the trust anchor.
[0145] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the following steps are realized:
[0146] Obtain the data to be transmitted, the target digital digest, and the monitoring problem through the host, and send the data to be transmitted and the monitoring problem to the trust anchor. The target digital digest is obtained by calculating the data to be transmitted based on the hash algorithm;
[0147] The trust anchor calculates the actual digital digest of the data to be transmitted through the hash algorithm, and during the process of calculating the actual digital digest of the data to be transmitted, determine the answer to the monitoring problem according to the monitoring problem, generate trust verification data based on the answer and the actual digital digest, and send the trust verification data to the digest monitoring module;
[0148] The host verification data is generated by the abstract monitoring module according to the target digital abstract and the preset answers to the monitoring questions, and the host verification data is compared with the trust verification data for the first time to obtain the first comparison result, so as to improve the credibility of the hash algorithm of the trust anchor.
[0149] It should be noted that for the functions or steps that can be realized by the above computer-readable storage medium or electronic device, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described in detail here.
[0150] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0151] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used for illustration. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device, system, and controller can be divided into different functional units or modules to complete all or part of the functions described above.
[0152] The embodiments provided above are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for improving the credibility of a hash algorithm for a trust anchor, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes a digest monitoring module, wherein the credibility of the digest monitoring module is higher than that of the trust anchor, and the method includes: The host obtains the data to be transmitted, the target digital digest and the monitoring question, and sends the data to be transmitted and the monitoring question to the trust anchor, where the target digital digest is obtained by calculating the data to be transmitted based on a hashing algorithm; The trust anchor calculates the actual digital digest of the data to be transmitted through the hashing algorithm, and during the process of calculating the actual digital digest of the data to be transmitted, determines the answer according to the monitoring question, generates trust verification data based on the answer and the actual digital digest, and sends the trust verification data to the digest monitoring module; The digest monitoring module generates host verification data according to the target digital digest and the preset answer of the monitoring question, and performs a first comparison between the host verification data and the trust verification data to obtain a first comparison result.
2. The method for improving the credibility of the hash algorithm of the trust anchor according to claim 1, wherein The method further includes: The host sends the target digital digest to the trust anchor; The trust anchor performs a second comparison between the target digital digest and the actual digital digest, determines the trust anchor verification result based on the second comparison result, and sends the trust anchor verification result to the digest monitoring module; The digest monitoring module performs a third comparison between the trust anchor verification result and the first comparison result to obtain a third comparison result.
3. The method for improving the credibility of the hash algorithm of the trust anchor according to claim 2, characterized in that, After obtaining the third comparison result, the method further includes: If the third comparison result shows that the trust anchor verification result is the same as the first comparison result, determine that the trust status of the trust anchor verification result is trustworthy; If the third comparison result shows that the trust anchor verification result is different from the first comparison result, determine that the trust status of the trust anchor signature verification result is in doubt.
4. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the host obtains the data to be transmitted and the target digital digest, the method includes: The data sender calculates the original digital digest based on the original content data; The data sender sends the original content data and the original digital digest to the host, so that the host receives the original content data as the actual transmitted content data, uses the original digital digest as the target digital digest of the actual transmitted content data, and determines the actual transmitted content data as the data to be transmitted.
5. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the host obtains the data to be transmitted and the target digital digest, the method includes: The data sender sends the original content data to the host; If the host does not receive the original digital digest of the original content data, determine the preset verification data as the data to be transmitted, and determine the preset digital digest of the preset verification data as the target digital digest, where the preset digital digest is obtained by calculating the preset verification data.
6. The method for improving the credibility of the hash algorithm of the trust anchor according to claim 5, characterized in that After obtaining the first comparison result, the method further includes: The host takes the received original content data as the actual transmitted content data and sends it to the trust anchor, so that the trust anchor calculates a digest of the actual transmitted content data to obtain a content digital digest. The credibility of the content digital digest is higher than that of the trust anchor, and the credibility of the content digital digest is lower than or equal to that of the digest monitoring module.
7. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, The host obtains monitoring questions, including any one of the following: Obtain a preset question and determine the preset question as the monitoring question; Obtain multiple preset questions and determine one or more selected preset questions as the monitoring question; Obtain the sent monitoring question and multiple preset questions, filter out the sent monitoring question from the multiple preset questions, and determine one or more preset questions after filtering as the monitoring question; Obtain the sent monitoring question and multiple preset questions, determine multiple randomly selected preset questions as preselected questions. If the question content of the preselected questions is the same as the question content of the sent monitoring question, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from that of the sent monitoring question, and determine the adjusted preselected questions as the monitoring question.
8. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Determine an answer according to the monitoring question, including: The trust anchor matches the monitoring question with multiple preset local questions in the preset question answer table. If it matches a preset local question successfully, determine the preset local answer corresponding to the preset local question as the first answer sub-answer. The preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question. The trust anchor stores the preset question answer table; The trust anchor triggers a preset function module to output a function answer based on the monitoring question, and determines the function answer as the second answer sub-answer. The trust anchor is provided with the preset function module; The trust anchor collects one or more monitoring results of its own security mechanisms based on the monitoring question, and determines the one or more monitoring results of its own security mechanisms as the third answer sub-answer; The trust anchor generates the answer according to at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.
9. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the digest monitoring module generates host verification data according to the target digital digest and the preset answer of the monitoring question, the method includes: The digest monitoring module matches the monitoring question with multiple preset local questions in the preset question answer table. If it matches a preset local question successfully, determine the preset local answer corresponding to the preset local question as the first preset sub-answer. The preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question. The digest monitoring module stores the question answer table; The digest monitoring module triggers a preset function module to output a function answer based on the monitoring question, and determines the function answer as the second preset sub-answer. The digest monitoring module is provided with the preset function module; The abstract monitoring module determines the monitoring results of one or more proprietary security mechanisms of the trust anchor as the third preset sub-answer based on the monitoring problem; The abstract monitoring module generates the preset answer according to at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; The abstract monitoring module determines the host verification data according to the target digital digest and the preset answer.
10. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before sending the data to be transmitted and the monitoring problem to the trust anchor, the method includes: The host receives the original content data sent by the data sender and uses it as the actual transmission content data; Determine the estimated actual digest calculation time of the actual transmission content data; If the estimated actual digest calculation time is less than the preset duration threshold, the hash algorithm credibility of the trust anchor is improved, and the actual digital digest is calculated for the data to be transmitted through the abstract monitoring module.
11. The method for improving the credibility of the hash algorithm of the trust anchor according to any one of claims 1 or 2, characterized in that The method further includes: Count the number of events where the first comparison result and / or the third comparison result are different within a preset statistical period; If the number of events is greater than the preset number threshold, control the controller to enter the preset security state.
12. A controller, characterized in that, The controller includes a trust anchor and a host, and the host includes an abstract monitoring module, where the credibility of the abstract monitoring module is higher than that of the trust anchor; The host is used to obtain the data to be transmitted, the target digital digest, and the monitoring problem, send the data to be transmitted and the monitoring problem to the trust anchor, and the target digital digest is obtained by calculating the data to be transmitted based on the hash algorithm; The trust anchor is used to calculate the actual digital digest for the data to be transmitted through the hash algorithm, and during the process of calculating the actual digital digest for the data to be transmitted, determine the answer according to the monitoring problem, generate the trust verification data based on the answer and the actual digital digest, and send the trust verification data to the abstract monitoring module; The abstract monitoring module is used to generate the host verification data according to the target digital digest and the preset answer of the monitoring problem, compare the host verification data with the trust verification data for the first time, and obtain the first comparison result.
13. The controller according to claim 12, wherein, The host further includes a trust anchor driver function module, which is used to obtain the data to be transmitted and the target digital digest, receive the monitoring problem sent by the abstract monitoring module, send the monitoring problem, the data to be transmitted, and the target digital digest to the trust anchor, and receive the trust verification data and send the trust verification data to the abstract monitoring module.
14. The controller according to claim 13, wherein The abstract monitoring module is arranged in the trust anchor driver function module.
15. The controller according to claim 12, wherein The host further includes a mode switching module, which is used to determine the estimated actual digest calculation time of the actual transmission content data after the host receives the original content data sent by the data sender and uses it as the actual transmission content data. If the estimated actual digest calculation time is less than the preset duration threshold, calculate the actual digital digest for the data to be transmitted through the abstract monitoring module.
16. The controller according to claim 12, characterized in that, The host is further configured to determine the preset verification data as the data to be transmitted and determine the preset digital digest of the preset verification data as the target digital digest if the host only receives the original content data and does not receive the original digital digest, where the preset digital digest is obtained by calculating the preset verification data.
17. The controller according to claim 16, wherein After the host obtains the first comparison result of the first comparison result by the digest monitoring module, the host is further configured to use the received original content data as the actual transmission content data and send it to the trust anchor for the trust anchor to calculate the content digital digest of the actual transmission content data, where the credibility of the content digital digest is higher than that of the trust anchor and lower than or equal to the credibility of the digest monitoring module.
18. The controller according to any one of claims 12-17, characterized in that, The digest monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.
19. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 11 is implemented.
20. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 11 is implemented.