Method for improving credibility of digital signature verification process of trust anchor, controller, system, equipment and medium
By introducing a high-reliability verification process monitoring module and trust anchor comparison in the host, the problem that the HSM terminal verification successful flag cannot guarantee the functional safety level, and the credibility of the trust anchor verification results is improved, and it is suitable for key functional safety scenarios.
Patent Information
- Application Number
- CN202410103079.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-24
- Publication Date
- 2025-07-25
AI Technical Summary
The hardware resources of the MCU's HSM module are not developed in accordance with functional safety standards, resulting in the successful verification flag on the HSM side that cannot guarantee the functional safety level and cannot be applied to critical functional safety scenarios.
By introducing a highly reliable signature verification process monitoring module into the host, the signature verification process of the trust anchor is monitored, the digital signature is decrypted and compared with the transmitted digital summary. Combined with the comparison results of the host signature verification process monitoring module, the trustworthiness of the digital signature verification process of the trust anchor is improved.
Ensure that the trust anchor verification results can reach the functional safety level, and are suitable for key functional safety scenarios, improving the credibility of the trust anchor's digital signature verification process.
Smart Images

Figure CN120378105A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicles, and in particular, to a method, a controller, a system, a device and a medium for improving the credibility of the digital signature verification process of a trust anchor. Background Art
[0002] To further improve the safety design of road vehicle-related products and evaluate the safety level of automobiles, based on the analysis of the risks and hazards of the whole vehicle under various working conditions, ISO26262 "Functional Safety of Road Vehicles" assesses the safety levels for different safety objectives, introduces the concept of Automotive Safety Integrity Level (ASIL), and defines four different ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. Among them, ASIL D represents the highest safety integrity, while ASIL A represents the lowest safety integrity. Additionally, if a risk is identified as QM, there is no corresponding safety requirement. That is, gradually increasing from QM, ASIL-A / B / C / D, currently functional safety has become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.
[0003] With the improvement of the vehicle networking level, there will be more and more interactions between future functional safety and information security. On the one hand, ensuring information security is the basis for realizing functional safety; on the other hand, functional safety may also need to rely on information security mechanisms to achieve. To meet the requirements of storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments, a trust anchor needs to be equipped. The implementation methods of the trust anchor in MCU (Micro Controller Unit) applications include HSM (Hardware Security Module), etc.
[0004] In the related art, some HSM firmware is developed in accordance with the requirements of the functional safety process. However, there are still a large number of HSM module hardware of MCUs that are not developed according to the functional safety standard, that is, there is no corresponding functional safety mechanism to cover the failure of its hardware resources. In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other parts except the HSM module. The signature verification algorithm is an algorithm widely used in the field of automotive information security. The implementation of the signature verification algorithm based on the HSM usually uses the signature verification success flag bit of the digital signature by the HSM side as the final signature verification result. Since the hardware resources of the HSM side currently have no functional safety mechanism to cover, the signature verification success flag bit obtained on it cannot guarantee the functional safety level and can only be considered as QM and cannot be applied to functional safety critical scenarios. Therefore, it is necessary to design a scheme to improve the credibility of the digital signature verification process based on the trust anchor of the HSM with a higher functional safety level. Summary of the Invention
[0005] The embodiments of the present invention provide a method, a controller, a system, a device and a medium for improving the credibility of the digital signature verification process of a trust anchor, so as to solve the technical problem in the related art that since the HSM module hardware of the MCU is not developed according to the functional safety standard, that is, there is no corresponding functional safety mechanism to cover the failure of its hardware resources, resulting in that the signature verification success flag bit obtained on the HSM side cannot guarantee the functional safety level and can only be considered as QM and cannot be applied to functional safety critical scenarios, and it is necessary to design a scheme to improve the credibility of the digital signature verification process based on the trust anchor of the HSM with a higher functional safety level.
[0006] An embodiment of the present invention provides a method for improving the credibility of the digital signature verification process of a trust anchor, which is applied to a controller. The controller includes a trust anchor and a host. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor. The method includes: the host obtains the data to be transmitted and a digital signature, and sends the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting the original digital digest calculated from the data to be transmitted; the trust anchor decrypts the digital signature to obtain a decrypted digital digest, and determines the transmitted digital digest according to the received data to be transmitted, and performs a first comparison between the decrypted digital digest and the transmitted digital digest, and determines the trust anchor signature verification result based on the first comparison result, and sends the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module; the signature verification process monitoring module performs a second comparison between the decrypted digital digest and the pre-transmission digital digest, determines the host signature verification result based on the second comparison result, and determines the same or different status of the signature verification results between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the pre-transmission digital digest is determined according to the data to be transmitted.
[0007] In an embodiment of the present invention, the method further includes: the signature verification process monitoring module sends a monitoring question to the trust anchor, so that the trust anchor determines the answer to the monitoring question while decrypting the digital signature to obtain a decrypted digital digest and determining the transmitted digital digest according to the received data to be transmitted.
[0008] In an embodiment of the present invention, after the signature verification process monitoring module sends a monitoring question to the trust anchor, the method further includes: while the trust anchor decrypts the digital signature to obtain a decrypted digital digest and determines the transmitted digital digest according to the received data to be transmitted, the trust anchor determines the answer to the monitoring question according to the monitoring question; the trust anchor determines trust verification data according to the answer and the transmitted digital digest, and sends the trust verification data to the signature verification process monitoring module; the signature verification process monitoring module performs a third comparison between the trust verification data and the host verification data to obtain a third comparison result, and improves the credibility of the digital signature verification process of the trust anchor by comparing the third comparison result with the same or different status of the signature verification results, wherein the host verification data is determined according to the decrypted digital digest and the preset answer to the monitoring question.
[0009] In one embodiment of the present invention, after the signature verification process monitoring module sends the monitoring question to the trust anchor, the method further includes: while the trust anchor decrypts the digital signature to obtain a decrypted digital summary and determines the digital summary after transmission according to the received data to be transmitted, the trust anchor determines an answer according to the monitoring question; the trust anchor determines answer verification data according to the answer, and sends the answer verification data to the signature verification process monitoring module; the signature verification process monitoring module performs a fifth comparison on the answer verification data and the prior verification data, and obtains a seventh comparison result based on the fifth comparison result and the similarity and difference status of the verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the prior verification data is determined according to the preset answer to the monitoring question.
[0010] In one embodiment of the present invention, after determining that one or more signature verification results are different from each other, the method further includes: the host sends the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor; the trust anchor decrypts the digital signature of the actual transmission content data to obtain a decrypted actual content summary, determines the actual content summary after transmission according to the actual transmission content data, and determines a re-verification answer according to the re-verification question while decrypting to obtain the decrypted actual content summary and determining the actual content summary after transmission, and generates a The new trust verification data is compared with the decrypted actual content summary and the transmitted actual content summary to obtain a new trust anchor verification result, and the new trust anchor verification result, the new trust verification data and the decrypted actual content summary are sent to the verification process monitoring module; the verification process monitoring module determines the new host verification data according to the decrypted actual content summary and the standard verification answer to the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host verification result, and determines the verification result similarities and differences between the new host verification result and the new trust anchor verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
[0011] In an embodiment of the present invention, before the signature verification process monitoring module sends a monitoring problem to the trust anchor, the method includes any one of the following: obtaining a preset problem and determining the preset problem as the monitoring problem; obtaining a plurality of preset problems and determining one or more selected preset problems as the monitoring problem; obtaining the sent monitoring problem and a plurality of preset problems, screening out the sent monitoring problem from the plurality of preset problems, and determining one or more preset problems after screening as the monitoring problem; obtaining the sent monitoring problem and a plurality of preset problems, determining a plurality of randomly selected preset problems as preselected problems, if the problem content of the preselected problems is the same as the problem content of the sent monitoring problem, adjusting the problem order of the plurality of preset problems in the preselected problems so that the problem order of the preselected problems is different from the problem order of the sent monitoring problem, and determining the adjusted preselected problems as the monitoring problem.
[0012] In an embodiment of the present invention, determining an answer based on the monitoring problem includes: the trust anchor matching the monitoring problem with a plurality of preset local problems in a preset problem answer table, if the match with a preset local problem is successful, determining the preset local answer corresponding to the preset local problem as the first answer sub-answer, the preset problem answer table including at least one preset local problem and the preset local answer corresponding to each preset local problem, and the trust anchor storing the preset problem answer table; the trust anchor triggering a preset function module based on the monitoring problem to output a function answer and determining the function answer as the second answer sub-answer, the trust anchor being provided with the preset function module; the trust anchor collecting one or more self-owned security mechanism monitoring results of the trust anchor based on the monitoring problem and determining the one or more self-owned security mechanism monitoring results as the third answer sub-answer; the trust anchor generating the answer based on at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.
[0013] In an embodiment of the present invention, the method for determining a preset answer to the monitoring problem includes: the signature verification process monitoring module matches the monitoring problem with multiple preset local problems in a preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the first preset sub-answer. The preset problem answer table includes at least one preset local problem and a preset local answer corresponding to each preset local problem. The signature verification process monitoring module stores the problem answer table; the signature verification process monitoring module triggers a preset function module to output a function answer based on the monitoring problem, and determines the function answer as the second preset sub-answer. The signature verification process monitoring module is provided with the preset function module; the signature verification process monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as the third preset sub-answer based on the monitoring problem; the signature verification process monitoring module generates the preset answer according to at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer.
[0014] In an embodiment of the present invention, before the host obtains the data to be transmitted and the digital signature, the method includes: the data sender calculates an original digital digest based on the original content data; the data sender encrypts the original digital digest to generate an original signature; the data sender sends the original content data and the original signature to the host for the host to receive the original content data as the actual transmitted content data and use the original signature as the digital signature of the actual transmitted content data.
[0015] In an embodiment of the present invention, before the host obtains the data to be transmitted and the digital signature, the method includes: the host receives the original content data sent by the data sender and uses it as the actual transmitted content data; determines the estimated actual digest calculation time of the actual transmitted content data; if the estimated actual digest calculation time is greater than or equal to a preset duration threshold, determines the preset verification data as the data to be transmitted, and the estimated preset digest calculation time of the preset verification data is less than the preset duration threshold; if the estimated actual digest calculation time is less than the preset duration threshold, determines the actual transmitted content data as the data to be transmitted.
[0016] In an embodiment of the present invention, if the preset verification data is determined as the data to be transmitted, the method further includes: the host sending the actual transmission content data and the actual digital signature of the actual transmission content data to the trust anchor; the trust anchor decrypting the actual digital signature of the actual transmission content data to obtain a decrypted actual content digest, and determining a post-transmission actual content digest according to the received actual transmission content, performing a fourth comparison on the decrypted actual content digest and the post-transmission actual content digest, determining a new trust anchor signature verification result based on the fourth comparison result, and enhancing the credibility of the new trust anchor signature verification result.
[0017] In an embodiment of the present invention, the trust anchor decrypts the digital signature of the actual transmission content data with a first sub-decryption key; the trust anchor decrypts the digital signature of the preset verification data with a second sub-decryption key; wherein, the first sub-decryption key is the same as or different from the second sub-decryption key.
[0018] In an embodiment of the present invention, before the trust anchor decrypts the digital signature to obtain a decrypted digital digest, the method includes: storing the decryption key in the trust anchor for the trust anchor to decrypt the digital signature with the decryption key to obtain a decrypted digital digest; or, storing the decryption key in the host in a read-only form, and sending the decryption key to the trust anchor by the host for the trust anchor to decrypt the digital signature with the decryption key to obtain a decrypted digital digest.
[0019] In an embodiment of the present invention, the method further includes: counting the number of events with different signature verification result similarity and difference states within a preset statistical period; if the number of events is greater than a preset number threshold, controlling the controller to enter a preset safe state.
[0020] An embodiment of the present invention further provides a controller. The controller includes a trust anchor and a host. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor. Wherein: The host is configured to obtain data to be transmitted and a digital signature, and send the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting an original digital digest calculated based on the data to be transmitted; The trust anchor is configured to decrypt the digital signature to obtain a decrypted digital digest, and determine a transmitted digital digest according to the received data to be transmitted, perform a first comparison between the decrypted digital digest and the transmitted digital digest, determine a trust anchor signature verification result based on the first comparison result, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module; The signature verification process monitoring module is configured to perform a second comparison between the decrypted digital digest and a pre-transmission digital digest, determine a host signature verification result based on the second comparison result, and determine a signature verification result similarity / difference status between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor. Wherein, the pre-transmission digital digest is determined according to the data to be transmitted.
[0021] In an embodiment of the present invention, the host further includes a trust anchor driver function module. The trust anchor driver function module is configured to obtain data to be transmitted and a digital signature, send the data to be transmitted and the digital signature to the trust anchor, and receive the trust anchor signature verification result and the decrypted digital digest, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module.
[0022] In an embodiment of the present invention, the signature verification process monitoring module is disposed in the trust anchor driver function module.
[0023] In an embodiment of the present invention, the host further includes a mode switching module. The mode switching module is configured to, after the host receives the original content data sent by the data sender and uses it as the actual transmission content data, determine the expected actual digest calculation time of the actual transmission content data, and determine the data to be transmitted according to the comparison result between the expected actual digest calculation time and a preset duration threshold. The data to be transmitted includes the actual transmission content data or preset verification data, and the expected preset digest calculation time of the preset verification data is less than the preset duration threshold.
[0024] In an embodiment of the present invention, the signature verification process monitoring module is further configured to determine a monitoring problem and send the monitoring problem to the trust anchor driving function module; the trust anchor driving function module is further configured to send the monitoring problem to the trust anchor; the trust anchor is further configured to, while decrypting the digital signature to obtain a decrypted digital digest and determining a transmitted digital digest according to the received data to be transmitted, determine an answer to the monitoring problem, and determine trust verification data according to the answer and the transmitted digital digest, and send the trust verification data to the trust anchor driving function module; the trust anchor driving function module is further configured to send the trust verification data to the signature verification process monitoring module; the signature verification process monitoring module is further configured to perform a third comparison between the trust verification data and host verification data to obtain a third comparison result, so as to improve the credibility of the digital signature verification process of the trust anchor, where the host verification data is determined according to the decrypted digital digest and a preset answer to the monitoring problem.
[0025] In an embodiment of the present invention, the host is further configured to, after the signature verification process monitoring module determines one or more signature verification result similarity / difference states, send the received actual transmitted content data, the digital signature of the actual transmitted content data, and a re-verification problem to the trust anchor; the trust anchor is further configured to decrypt the digital signature of the actual transmitted content data to obtain a decrypted actual content digest, determine a transmitted actual content digest according to the actual transmitted content data, and, while decrypting to obtain the decrypted actual content digest and determining the transmitted actual content digest, determine a re-verification answer according to the re-verification problem, generate new trust verification data based on the re-verification answer and the transmitted actual content digest, compare the decrypted actual content digest with the transmitted actual content digest to obtain a new trust anchor signature verification result, and send the new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; the signature verification process monitoring module is further configured to determine new host verification data according to the decrypted actual content digest and a standard verification answer to the re-verification problem, perform a sixth comparison between the new host verification data and the information trust verification data to obtain a new host signature verification result, and determine the signature verification result similarity / difference state between the new host signature verification result and the new trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
[0026] In an embodiment of the present invention, the trust anchor driving function module is further configured to send the actual transmission content data and the digital signature of the actual transmission content data to the trust anchor; the trust anchor is further configured to decrypt the actual digital signature of the actual transmission content data to obtain a decrypted actual content digest, and determine a post - transmission actual content digest according to the received actual transmission content, perform a fourth comparison on the decrypted actual content digest and the post - transmission actual content digest, determine a new trust anchor signature verification result based on the fourth comparison result, and improve the credibility of the new trust anchor signature verification result.
[0027] In an embodiment of the present invention, the signature verification process monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lock - step module.
[0028] An embodiment of the present invention further provides a system for improving the credibility of the digital signature verification process of a trust anchor. The system for improving the credibility of the digital signature verification process of a trust anchor includes a data sender and a controller. The controller includes a trust anchor and a host. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor. The data sender is configured to calculate an original digital digest according to the original content data, encrypt the original digital digest to generate an original signature, and send the original content data and the original signature to the host, so that the host uses the received original content data as the actual transmission content data and the original signature as the digital signature of the actual transmission content data. The host is configured to obtain the data to be transmitted and the digital signature, and send the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting the original digital digest calculated according to the data to be transmitted. The data to be transmitted includes the actual transmission content data or preset verification data. The trust anchor is configured to decrypt the digital signature to obtain a decrypted digital digest, and determine a post - transmission digital digest according to the received data to be transmitted, perform a first comparison on the decrypted digital digest and the post - transmission digital digest, determine a trust anchor signature verification result based on the first comparison result, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module. The signature verification process monitoring module is configured to perform a second comparison on the decrypted digital digest and the pre - transmission digital digest, determine a host signature verification result based on the second comparison result, and determine the same - different state of the signature verification results between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, where the pre - transmission digital digest is determined according to the data to be transmitted.
[0029] In an embodiment of the present invention, the host is further configured to, after the signature verification process monitoring module determines one or more signature verification result similarity / difference states, send the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor; the trust anchor decrypts the digital signature of the actual transmission content data to obtain a decrypted actual content digest, determines a post-transmission actual content digest based on the actual transmission content data, and while decrypting to obtain the decrypted actual content digest and determining the post-transmission actual content digest, determines a re-verification answer based on the re-verification question, generates new trust verification data based on the re-verification answer and the post-transmission actual content digest, compares the decrypted actual content digest with the post-transmission actual content digest to obtain a new trust anchor signature verification result, and sends the new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; the signature verification process monitoring module determines new host verification data based on the decrypted actual content digest and the standard verification answer of the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host signature verification result, and determines the signature verification result similarity / difference state between the new host signature verification result and the new trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
[0030] An embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any of the above embodiments is implemented.
[0031] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the method described in any of the above embodiments is implemented.
[0032] In the solution implemented by the above-provided method, controller, system, device, and medium for improving the credibility of the digital signature verification process of the trust anchor, the method decrypts the digital signature through a trust anchor with relatively low credibility to obtain a decrypted digital digest, calculates a post-transmission digital digest based on the data to be transmitted, determines the trust anchor signature verification result based on the first comparison result between the decrypted digital digest and the post-transmission digital digest, determines the host signature verification result by a signature verification process monitoring module with relatively high credibility based on the second comparison result between the decrypted digital digest and the pre-transmission digital digest, and then determines the signature verification result similarity / difference state between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, such that the trust anchor signature verification result can ensure the functional safety level and can be applied to functional safety critical scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0033] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0034] Figure 1 It is a schematic flowchart of a signature verification method based on HSM provided by an embodiment of the present invention;
[0035] Figure 2 It is a schematic flowchart of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0036] Figure 3 It is a specific schematic flowchart of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0037] Figure 4 It is a specific schematic flowchart of the monitoring stage of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0038] Figure 5 It is another specific schematic flowchart of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0039] Figure 6 It is another specific schematic flowchart of the monitoring stage of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0040] Figure 7 It is a schematic diagram of an over - coverage monitoring scheme for other hardware resource failures at the HSM end provided by an embodiment of the present invention;
[0041] Figure 8 It is a specific schematic flowchart of a method for determining data to be transmitted provided by an embodiment of the present invention;
[0042] Figure 9 It is another specific schematic flowchart of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0043] Figure 10 It is another specific schematic flowchart of a method for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0044] Figure 11 It is a schematic diagram of the structure of a controller provided by an embodiment of the present invention;
[0045] Figure 12 A schematic structural diagram of a system for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention;
[0046] Figure 13 A schematic structural diagram of an electronic device in an embodiment of the present invention;
[0047] Figure 14 Another schematic structural diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0048] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0049] To enable those skilled in the art to better understand the improvements in the technical solutions provided by the present disclosure, the present disclosure briefly introduces the implementation method of the signature verification algorithm based on HSM and related information in the related art.
[0050] A trust anchor is a module required to meet the requirements of storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments. The implementation methods of trust anchors in MCU applications include Secure Hardware Extension (SHE), Hardware Security Module (HSM), Secure Element (SE), etc. Among them, HSM is a specification proposed by the E-safety Vehicle Intrusion proTected Applications (EVITA, 2008 - 2011), that is, a research project of the European Union for vehicle communication security of Vehicle to Everything (V2X), and is divided into three levels: Light, Medium, and Full. Currently, mainstream automotive-grade MCUs are all equipped with a Hardware Security Module (HSM), and the Full level has become a trend to meet the information security requirements of vehicle controllers.
[0051] Signature verification algorithms are currently widely used in the field of automotive information security, such as for secure flashing of controllers. Signature verification algorithms can ensure the integrity and authenticity of data. First, the original content (hereinafter abbreviated as the original content) whose integrity and authenticity need to be ensured is processed through a hash (HASH) algorithm to obtain the original digital digest. Then, the original digital digest is encrypted with a private key to obtain a digital signature (Signature). When verifying the digital signature (hereinafter abbreviated as signature verification), the digital signature is decrypted with the public key to obtain the target digital digest, and the digital digest of the actual content (hereinafter abbreviated as the actual content, which is also the original content received by the decrypting party) whose integrity and authenticity need to be ensured is calculated using the hash algorithm to obtain the actual digital digest. By comparing the actual digital digest and the target digital digest, the integrity and authenticity of the data are judged. In automotive controllers, the signature verification process is mainly completed to confirm the integrity, authenticity, etc. of programs, messages, etc.
[0052] In addition, with the increasing complexity of automotive electronic control systems and the introduction of a large number of electrical and electronic components, while bringing control convenience and diversity, it also brings certain risks to vehicle safety due to inevitable systematic failures and random hardware failures. To further improve the safety design of road vehicle-related products, the ISO26262 Road Vehicle Functional Safety Standard has been introduced. Based on the analysis of risks and hazards of the vehicle under various working conditions, this standard evaluates the safety levels (Automotive Safety Integrity Level, ASIL) for different safety objectives, gradually increasing from QM, ASIL-A / B / C / D. Currently, functional safety has become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.
[0053] In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module. In related technologies, please refer to Figure 1 , Figure 1 which is a schematic flowchart of a signature verification method based on HSM provided by an embodiment of the present invention, as Figure 1As shown, an example of the implementation method of HSM-based signature verification is that the data sender first obtains the original digital digest of the original content through a hashing (HASH) algorithm, encrypts the original digital digest with the private key to obtain the digital signature, and the data sender sends the original content and the digital signature to the HSM at the HOST end. At this time, the original content is used as the actual content, and the driver (HSM HOST Driver) function of the HSM at the HOST end is called to pass the actual content and the digital signature to the HSM firmware at the HSM end, and then the calculation is triggered, so that the actual digital digest of the actual content will be calculated at the HSM end, and the target digital digest will be obtained by decrypting the digital signature and the public key. The signature verification success flag bit at the HSM end is set by judging whether the actual digital digest and the target digital digest are equal, that is Figure 1 the signature verification result in, and send it to the driver (HSM HOST Driver) at the HOST end. The HOST end determines whether the signature verification is successful based on the signature verification success flag bit at the HSM end. Among them, if the actual digital digest and the target digital digest are equal, the signature verification success flag bit is set to TRUE, and if the actual digital digest and the target digital digest are not equal, the signature verification success flag bit is set to FALSE. It should be noted that the above setting method of the signature verification success flag bit is only an example, and those skilled in the art can set it according to needs.
[0054] Since the hardware resources at the HSM end are currently not covered by a functional safety mechanism, the signature verification success flag bit obtained thereon cannot guarantee the functional safety level and can only be considered as QM, and cannot be applied to functional safety critical scenarios.
[0055] For current mainstream MCUs, the HOST end has a perfect functional safety mechanism to ensure that the diagnostic coverage rate of its hardware failures can meet the requirements of the highest ASIL-D; and, it has at least one secure core with a lockstep mechanism, and the lockstep mechanism can make the diagnostic coverage rate of the MCU core meet the requirements of ASIL-D.
[0056] If the signature verification is directly calculated through the secure core at the HOST end, although the correctness of the signature verification calculation can be guaranteed, because the information security algorithm has high requirements for computing power, it will occupy a lot of computing power at the HOST end and affect the normal function; secondly, it is more secure and reliable to store the key in the HSM. If the signature verification is directly performed at the HOST end, the key security is difficult to fully guarantee. Based on this, the embodiment of the present application designs a solution for improving the functional safety level of the signature verification algorithm based on trust anchors such as HSM.
[0057] The MCU hardware resources used to implement the digital signature verification process from the HSM side mainly include: the CPU, storage, bus, clock, power supply on the HSM side, and the information security algorithm hardware acceleration unit (including: HASH algorithm, asymmetric algorithm, etc.). Among them, the clock, power supply are the same as those on the HOST side and can be covered by the HOST side, but other resources need to design additional functional safety mechanisms to cover their failures.
[0058] The inventors found that it is very meaningful and forward-looking to design a solution for improving the functional safety level of the digital signature verification process based on HSM. That is, it is necessary to design a solution for improving the credibility of the digital signature verification process of the trust anchor based on HSM with a higher functional safety level (such as the automotive safety integrity level).
[0059] To solve the above problems, the embodiments of the present invention propose a method, a controller, a system, a device and a medium for improving the credibility of the digital signature verification process of the trust anchor. The solutions provided by the present invention will be described in detail through specific embodiments below.
[0060] The method provided by the embodiments of the present application can be applied to the controller MCU, which includes a trust anchor TrustAnchor and a host HOST. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor Trust Anchor. This method can be applied to application scenarios such as the secure refresh of the vehicle controller.
[0061] In one embodiment, in order to achieve the corresponding ASIL level for the signature verification result, the software development process of the monitoring software on the HOST side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be free from interference (Freedom From Interference, FFI) with software of other ASIL / QM levels.
[0062] In one embodiment, according to the needs of those skilled in the art, this method can be applied to each trust anchor signature verification process of the controller, randomly, or at intervals of a preset detection duration, or at intervals of a preset number of data transmissions, etc., to trigger this method once to improve the credibility of the digital signature verification process of the trust anchor.
[0063] The signature verification process monitoring module can be a hardware unit with computing capabilities that can meet the requirements of the functional safety level, such as: a hardware acceleration unit, at least one secure core with a Lockstep mechanism, etc.
[0064] The implementation methods of the trust anchor include, but are not limited to, methods known to those skilled in the art such as SHE, HSM, or SE. In the MCU design with a trust anchor, the MCU can be divided into a trust anchor end (hereinafter referred to as the trust anchor) and a host end (hereinafter referred to as the host). The host is the other part except for modules such as the trust anchor like HSM, and the trust anchor is the module part such as HSM.
[0065] The credibility can be evaluated by the aforementioned Automotive Safety Integrity Level (ASIL) of the vehicle, or can also be achieved by other trust rules for the functional safety field set by those skilled in the art. Functional safety can be understood as the absence of unreasonable risks caused by hazards resulting from abnormal functional manifestations of electronic / electrical systems. For example, as shown in the above embodiments, the credibility of the trust anchor is QM, and the credibility of the host is ASIL D. In another embodiment, the credibility can be understood as the degree of trust that can actually be achieved in the actual application scenario, even if there may be software interference, rather than just referring to the degree of trust calculated during the design of the software or module.
[0066] Please refer to Figure 2 as shown in Figure 2 FIG. is a schematic flowchart of a method for improving the credibility of the digital signature verification process of the trust anchor provided by an embodiment of the present invention. The method includes the following steps:
[0067] Step S210, the host obtains the data to be transmitted and the digital signature, and sends the data to be transmitted and the digital signature to the trust anchor.
[0068] Among them, the digital signature is generated by encrypting the original digital digest calculated based on the data to be transmitted.
[0069] The digital signature is determined based on the data to be transmitted. When the data to be transmitted is the actual transmission content data, the digital signature is obtained by encrypting the original digital digest calculated based on the actual transmission content data; when the data to be transmitted is the preset verification data, the digital signature can be obtained by encrypting the digital digest calculated by a trusted device (including but not limited to the host or other devices) for the preset verification data. When the data to be transmitted is the preset verification data, the pre-transmission digital digest below can also be the digital digest obtained during the process of calculating the digital signature of the preset verification data stored in the host to directly serve as the pre-transmission digital digest.
[0070] The data to be transmitted can be selected by those skilled in the art according to needs as the actual transmission content data that needs to be transmitted actually or the preset verification data set in advance. When the data to be transmitted is the actual transmission content data, the actual transmission content data can be the data sent by the data sender to the MCU and received by the host end. When the data to be transmitted is the preset verification data, it can also be the data set in advance by those skilled in the art.
[0071] In one embodiment, after the host obtains the data to be transmitted and the digital signature, the method further includes: determining a pre-transmission digital digest according to the data to be transmitted. At this time, whether the data to be transmitted is actual transmission content data or preset verification data, the pre-transmission digital digest can be calculated at the host side.
[0072] In this step, it can be the signature verification process monitoring module that obtains the data to be transmitted and the digital signature, or similar to the above-described embodiment, the driver at the HOST side (HSM HOST Driver) obtains the data to be transmitted and the digital signature and sends them to the trust anchor. Specifically, it can be set by those skilled in the art according to needs.
[0073] It should be noted that the implementation of "determining the pre-transmission digital digest according to the data to be transmitted" only needs to be before the subsequent step of "performing a second comparison between the decrypted digital digest and the pre-transmission digital digest", and it is not required to be completed before step S220.
[0074] In order to avoid excessive computing power overhead when the host directly calculates the pre-transmission digital digest, and the problem that the calculation cannot be completed within the time required by the functional safety fault tolerance time interval (Fault Tolerant Time Interval, FTTI), etc., or it will affect the normal function of the controller MCU, the size of the preset verification data is limited by the time for the host to calculate the pre-transmission digital digest to ensure that it can be completed within the time required by the functional safety fault tolerance time interval, etc. That is, the expected preset digest calculation time of the preset verification data is less than the preset duration threshold, and the preset duration threshold is greater than or equal to the functional safety fault tolerance time interval, and the preset duration threshold can also be configured by those skilled in the art according to needs.
[0075] The "digital digests" such as the actual digital digest, the original digital digest, the pre-transmission digital digest, the post-transmission digital digest, and the post-transmission actual content digest provided in the embodiments of the present application can be implemented using hash algorithms such as SHA1, SHA2, MD5, etc. The specific types of digital digest algorithms are not limited here, but in the process of improving the credibility of the digital signature verification of the same trust anchor, the same digital digest algorithm is used.
[0076] In one embodiment, before the host obtains the data to be transmitted and the digital signature, the method includes: the data sender calculates the original digital digest according to the original content data; the data sender encrypts the original digital digest to generate the original signature; the data sender sends the original content data and the original signature to the host for the host to receive the original content data as the actual transmission content data and the original signature as the digital signature of the actual transmission content data.
[0077] It can be understood that the data sender stores an encryption key and obtains a digital signature by encrypting the original digital digest to enhance the security and integrity of the original digital digest during transmission. After the data sender sends the original content data and the original signature to the host, the host obtains the actual transmitted content data and the digital signature of the actual transmitted content data. When using the actual transmitted content data as the data to be transmitted, on the one hand, the host calculates the pre-transmission digital signature based on the received actual transmitted content, and on the other hand, it sends the actual transmitted content and the digital signature to the trust anchor. Depending on the security of the transmission process, the actual transmitted content data received by the host may be the same as the actual transmitted content data sent by the data sender, or there may be differences. Correspondingly, the actual transmitted content data received by the trust anchor may be the same as or different from the actual transmitted content data sent by the host.
[0078] In another embodiment, before the host obtains the data to be transmitted and the digital signature, the method includes: selecting one set from a pre-designed set or multiple sets of preset verification data and the digital signature of the preset verification data as the current data to be transmitted and the digital signature, which are obtained by the host. It should be noted that the digital signature of the preset verification data can be calculated by a third party (non-host). The pre-designed set or multiple sets of preset verification data and the digital signature of the preset verification data can be stored in the host of the MCU or in a preset storage space communicatively connected to the host. The digital signature of the preset verification data is also generated by encrypting the verification digital digest (which is also regarded as the original digital digest at this time) calculated based on the preset verification data. As mentioned in the above embodiment, the verification digital digest used to calculate the digital signature of the preset verification data can be directly stored in the host so that the verification digital digest can be directly used as the pre-transmission digital digest in subsequent processes.
[0079] Based on the above-provided embodiments, it can be seen that this method supports pre-setting whether the data to be transmitted is selected from the actual transmitted content data or the preset verification data.
[0080] Sometimes, to make the solution more general and flexible, in one embodiment, before the host obtains the data to be transmitted and the digital signature, the method further includes: the host receives the original content data sent by the data sender and uses it as the actual transmission content data; determines the estimated actual time consumption for calculating the digest of the actual transmission content data; determines the data to be transmitted according to the comparison result between the estimated actual time consumption for calculating the digest and the preset duration threshold. The data to be transmitted includes the actual transmission content data or the preset verification data, and the estimated preset time consumption for calculating the digest of the preset verification data is less than the preset duration threshold. If the estimated actual time consumption for calculating the digest is greater than or equal to the preset duration threshold, the preset verification data is determined as the data to be transmitted, and the estimated preset time consumption for calculating the digest of the preset verification data is less than the preset duration threshold; if the estimated actual time consumption for calculating the digest is less than the preset duration threshold, the actual transmission content data is determined as the data to be transmitted.
[0081] Among them, the estimated actual time consumption for calculating the digest is also the time consumption for the estimated signature verification process monitoring module to calculate the digital digest before transmission for the actual transmission content data. This estimated actual time consumption for calculating the digest can be pre-calibrated and known when the signature verification process monitoring module receives the actual transmission content data, or can be estimated by the signature verification process monitoring module after receiving the actual transmission content data, or can also be determined by other methods known to those skilled in the art. The preset duration threshold can be the duration required by the functional safety fault tolerance time interval (Fault Tolerant TimeInterval, FTTI) of the host, or other durations set by those skilled in the art.
[0082] By selecting appropriate data as the data to be transmitted based on the magnitude relationship between the estimated actual time consumption for calculating the digest and the preset duration threshold after the host receives the actual transmission content data, the solution is made more flexible and has better applicability.
[0083] Step S220, the trust anchor decrypts the digital signature to obtain the decrypted digital digest, and determines the digital digest after transmission according to the received data to be transmitted, makes a first comparison between the decrypted digital digest and the digital digest after transmission, determines the trust anchor signature verification result based on the first comparison result, and sends the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module.
[0084] It should be noted that in step S220, the sequence between "the trust anchor decrypts the digital signature to obtain the decrypted digital digest" and "determines the digital digest after transmission according to the received data to be transmitted" is not limited, and either one can be executed first, or they can be executed simultaneously.
[0085] In one embodiment, a public key is stored in the trust anchor. By decrypting the digital signature (which is obtained by encrypting the original digital digest with a private key) with the public key, a decrypted digital digest can be obtained. If the entire transmission process is secure and trustworthy, the decrypted digital digest is the same as the original digital digest. However, if an abnormal event occurs, there may be a difference between the decrypted digital digest and the original digital digest.
[0086] The encryption and decryption algorithms mentioned in the above embodiments can adopt asymmetric encryption algorithms, such as: ECC, RSA, SM2, etc. It is necessary to define that the decryption key of the trust anchor and the encryption key when generating the digital signature are a pair of key pairs.
[0087] In one embodiment, the trust anchor decrypts the digital signature of the actual transmission content data with the first sub-decryption key; the trust anchor decrypts the digital signature of the preset verification data with the second sub-decryption key; wherein, the first sub-decryption key and the second sub-decryption key are the same or different.
[0088] That is to say, when the scheme supports two types of data to be transmitted, the actual transmission content data and the preset verification data, two sets of key pairs can be set respectively to achieve this, or the same key pair can be shared. The specific choice can be determined by those skilled in the art according to needs.
[0089] In one embodiment, if the method uses the preset verification data as the data to be transmitted, at this time, the digital digest (such as the HASH value) calculated from the preset verification data can be stored in the signature verification process monitoring module in advance and directly used as the digital digest before subsequent transmission to avoid repeated calculation later.
[0090] In one embodiment, before the trust anchor decrypts the digital signature to obtain the decrypted digital digest, the method includes: storing the decryption key in the trust anchor for the trust anchor to decrypt the digital signature with the decryption key to obtain the decrypted digital digest; or, storing the decryption key in the host in read-only form, and sending the decryption key to the trust anchor through the host for the trust anchor to decrypt the digital signature with the decryption key to obtain the decrypted digital digest.
[0091] It should be noted that the decryption key needs to be stored in a medium that can ensure the integrity of the key, which can be directly stored inside the trust anchor or stored in a host software with single-write, etc.
[0092] According to the setting of those skilled in the art, the decryption key can be a public key, and the digital signature can be generated by encrypting with the encryption key, that is, the private key.
[0093] In one embodiment, a first comparison is made between the decrypted digital digest and the transmitted digital digest to obtain a first comparison result, including: if the first comparison result is that the decrypted digital digest is the same as the transmitted digital digest, the monitoring is successful and the signature verification result is credible; otherwise, if the first comparison result is that the decrypted digital digest is different from the transmitted digital digest, the monitoring fails and subsequent fault confirmation and response are triggered. For example, the trust anchor signature verification result can be characterized by the signature verification success flag bit (at the HSM end) in the foregoing embodiment. Taking the trust anchor signature verification result determined by the first comparison result being represented by the first flag bit (at the trust anchor end) and the host signature verification result determined by the second comparison result being represented by the second flag bit (at the host end) as an example. If the decrypted digital digest is the same as the digital digest before transmission, the second flag bit is represented as "1"; if the decrypted digital digest is different from the digital digest before transmission, the second flag bit is represented as "0". If the decrypted digital digest is the same as the transmitted digital digest, the first flag bit is represented as "1"; if the decrypted digital digest is different from the transmitted digital digest, the first flag bit is represented as "0". It should be noted that the above "1" and "0" are only examples, and those skilled in the art can set other representation methods according to needs, such as "true" and "false", etc.
[0094] To further avoid risks in the signature verification process caused by the failure of other hardware resources of the trust anchor, while triggering the trust anchor to perform digital signature verification, the trust anchor can answer the received monitoring questions to obtain an answer, and further improve the credibility of the digital signature verification process of the trust anchor by comparing the answer with the preset answer to the monitoring question.
[0095] In one embodiment, the trust anchor performing digital signature verification may include at least one of the two processes of decrypting the digital signature to obtain a decrypted digital digest and determining the transmitted digital digest according to the received data to be transmitted.
[0096] In one embodiment, the method further includes: the verification process monitoring module sends monitoring questions to the trust anchor, so that the trust anchor can determine the answer to the monitoring question while decrypting the digital signature to obtain the decrypted digital summary and determining the digital summary after transmission according to the received data to be transmitted. That is, before the trust anchor completes the digital signature verification action, it may be the start of the verification action, or during the verification action, the monitoring question is sent to the trust anchor. It is possible to answer the monitoring question and obtain the answer during the digital signature verification process of the trust anchor. The number of monitoring questions can be one or more. If there are multiple monitoring questions, multiple monitoring questions can be issued at one time or in batches, which can be set by those skilled in the art according to needs. It should be noted that the above-mentioned digital signature verification action and digital signature verification process are that the trust anchor decrypts the digital signature to obtain the decrypted digital summary, and determines the digital summary after transmission according to the received data to be transmitted.
[0097] In this embodiment, multiple methods for generating monitoring questions are provided, specifically as follows: before the signature verification process monitoring module sends the monitoring questions to the trust anchor, the method includes any one of the following:
[0098] Obtaining preset questions and determining the preset questions as monitoring questions. It can be understood that if this method is used alone, there is a fixed one or a set of preset monitoring questions (each set of questions contains multiple sub-questions), and the same monitoring question is issued each time;
[0099] Acquire multiple preset questions, and determine the selected one or more preset questions as monitoring questions. It can be understood that if this method is used alone, there are multiple preset monitoring questions, and one or more are selected from them as the current monitoring questions each time. The number of questions selected each time can be different or the same, and the questions selected for several consecutive times can be the same or at least partially different. The selection method can be random selection, or other selection methods set by those skilled in the art can be adopted. Similar to the previous embodiment, a preset question can be only one question or multiple questions. If two preset questions both include multiple questions, the number of questions included in the two preset questions can be the same or different, and the actual content of the questions can be partially the same or completely different, which can be specifically set by those skilled in the art as needed;
[0100] Obtain the sent monitoring questions and multiple preset questions, screen out the sent monitoring questions from the multiple preset questions, and determine one or more preset questions after screening as monitoring questions. By using this method, it can be ensured that the monitoring questions sent each time are different from the previous ones. By controlling the sampling range of the sent monitoring questions, such as the last 20 times, the last 1 day, etc., the minimum possible occurrence frequency of sending the same monitoring questions twice can be controlled. The sent monitoring questions are the monitoring questions historically sent to the trust anchor;
[0101] Obtain the sent monitoring questions and multiple preset questions, determine the randomly selected multiple preset questions as preselected questions. If the question content of the preselected questions is the same as the question content of the sent monitoring questions, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the sent monitoring questions, and determine the adjusted preselected questions as monitoring questions. By using this method, on the premise of limited questions, by adjusting the question order, the order of collecting answers by the trust anchor can be adjusted, and then the timing of the trust anchor collecting the answers corresponding to the questions can be adjusted. Without adding new preset questions, the effect of increasing the failure coverage rate can also be achieved.
[0102] In an embodiment, the multiple preset questions can be divided into different level sets, and there are at least some differences in the types of hardware resources required to answer the preset questions in each level set. In this way, subsequently, according to the hardware resources that need to be focused on preventing failures, the preset questions in the corresponding level set can be adaptively considered and selected as monitoring questions.
[0103] By increasing the number of preset questions, updating the preset questions, controlling that the monitoring questions sent in the recent several times are different, or switching the order of the monitoring questions, etc., the failure coverage rate can be increased. For example, the failure modes are jamming, being too large, and being too small. A monitoring question may only be able to obtain a conclusion of being too large or too small, but cannot obtain a conclusion of whether there is jamming. At this time, through the participation of multiple monitoring questions, more failure modes can be detected as much as possible. By increasing the monitoring questions, especially the monitoring questions that can only obtain answers by calling different resources, the more types of hardware resources used to generate the answers, the wider the diagnostic coverage, the more failure situations covered, and the higher the coverage rate.
[0104] It should be noted that the monitoring questions and the preset answers corresponding to the monitoring questions can be preset in advance and stored in the storage space that can be communicatively connected to the host, or stored in the host storage space.
[0105] In step S230, the signature verification process monitoring module performs a second comparison between the decrypted digital digest and the pre - transmission digital digest, determines the host signature verification result based on the second comparison result, and determines the similarity and difference status of the signature verification results between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
[0106] Among them, the pre - transmission digital digest is determined according to the data to be transmitted. When the data to be transmitted is preset verification data, it can be calculated by the signature verification process monitoring module according to the preset verification data, or the HASH value obtained when calculating the digital signature for the preset verification data can be stored. At this time, there is no need for separate calculation. As long as the preset verification data is determined, the corresponding HASH value is the pre - transmission digital digest. When the data to be transmitted is the actual transmission content data, the pre - transmission digital digest is calculated by the signature verification process monitoring module according to the actual transmission content data.
[0107] In this embodiment, since the host does not store the decryption key and cannot decrypt the digital signature, it determines the pre - transmission digital digest locally according to the data to be transmitted, and then receives the decrypted digital digest decrypted by the trust anchor from the trust anchor. By comparing the two, if the second comparison result is that the decrypted digital digest is the same as the pre - transmission digital digest, then the host signature verification result is successful. Otherwise, if the second comparison result is that the decrypted digital digest is different from the pre - transmission digital digest, then the host signature verification result is failed. Correspondingly, the host signature verification result is similar to the trust anchor signature verification result, and both can be represented by the signature verification success flag bit in the foregoing embodiment. Subsequently, the similarity and difference status of the signature verification results is obtained according to whether the host signature verification result is the same as the trust anchor signature verification result. If the two are the same, the monitoring passes, and the trust anchor signature verification result credibility status is credible; if the two are different, obviously at least one of the data to be transmitted or the digital signature has problems in integrity and security during the data transmission process, the monitoring fails, and the trust anchor signature verification result credibility status is doubtful.
[0108] Through the method provided in the above - mentioned embodiment, the credibility of the trust anchor signature verification result determined by the trust anchor end can be improved on the basis of the credibility of the trust anchor, such as being upgraded from QM to the highest ASIL level, etc.
[0109] In one embodiment, after the signature verification process monitoring module sends a monitoring problem to the trust anchor, the method further includes: while the trust anchor decrypts the digital signature to obtain a decrypted digital digest and determines the digital digest after transmission according to the received data to be transmitted, the trust anchor determines an answer to the monitoring problem according to the monitoring problem; the trust anchor determines trust verification data according to the answer and the digital digest after transmission, and sends the trust verification data to the signature verification process monitoring module; the signature verification process monitoring module performs a third comparison between the trust verification data and the host verification data, and based on the result of the third comparison, to improve the credibility of the digital signature verification process of the trust anchor, wherein the host verification data is determined according to the decrypted digital digest and the preset answer to the monitoring problem. Different from the foregoing embodiments, in this embodiment, the improvement of the credibility of the digital signature verification process of the trust anchor is not only directly realized according to the same or different status of the signature verification result, but is jointly realized by combining the same or different status of the signature verification result and the result of the third comparison. Due to the addition of the monitoring problem and the answer, in the case of the failure of some hardware resources of the trust anchor, the problem can be timely discovered through the above method, further improving the credibility of the digital signature verification process of the trust anchor.
[0110] It can be understood that before the signature verification process monitoring module performs a third comparison between the trust verification data and the host verification data, the method further includes that the host determines the host verification data according to the decrypted digital digest and the preset answer to the monitoring problem.
[0111] It should be noted that the calculation of the trust verification data and the host verification data can be implemented by using the CRC (Cyclic Redundancy Check) algorithm or other algorithms known to those skilled in the art that can ensure the integrity of functional safety data.
[0112] In another embodiment, after the signature verification process monitoring module sends the monitoring question to the trust anchor, the method further includes: while the trust anchor decrypts the digital signature to obtain the decrypted digital summary and determines the digital summary after transmission according to the received data to be transmitted, the trust anchor determines the answer according to the monitoring question; the trust anchor determines the answer verification data according to the answer, and sends the answer verification data to the signature verification process monitoring module; the signature verification process monitoring module performs a fifth comparison between the answer verification data and the prior verification data, and obtains a seventh comparison result based on the fifth comparison result and the similarity and difference state of the verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the prior verification data is determined according to the preset answer to the monitoring question. This embodiment is different from the above embodiment in that the answer verification data here only performs CRC calculation on the answer itself, and the prior verification data also only performs CRC calculation on the preset answer, so that the answer can also be used to verify whether there is a hardware resource abnormality in the trust anchor during the signature verification process. It can be understood that before the signature verification process monitoring module performs the fifth comparison between the answer verification data and the prior verification data, the method also includes the host determining the prior verification data according to the preset answer to the monitoring question.
[0113] In this embodiment, the answer is determined according to the monitoring question, including: the trust anchor matches the monitoring question with multiple preset local questions in the preset question answer table, if the match with a preset local question is successful, the preset local answer corresponding to the preset local question is determined as the first answer sub-answer, the preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question, and the trust anchor stores the preset question answer table; the trust anchor triggers the preset function module to output the function answer based on the monitoring question, and determines the function answer as the second answer sub-answer, and the trust anchor is provided with a preset function module; the trust anchor collects one or more self-owned security mechanism monitoring results of the trust anchor based on the monitoring question, and determines one or more self-owned security mechanism monitoring results as the third answer sub-answer; the trust anchor generates the answer according to at least one of the first answer sub-answer, the second answer sub-answer and the third answer sub-answer. That is, the generation method of the answer can be a table lookup, or it can be obtained by calculation through a preset function module such as a linear feedback shift register (LFSR), or the monitoring results of the original security mechanism of the trust anchor are collected.
[0114] In this embodiment, the method for determining the preset answer to the monitoring problem includes: the signature verification process monitoring module matches the monitoring problem with multiple preset local problems in the preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the first preset sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The signature verification process monitoring module stores the problem answer table; the signature verification process monitoring module triggers the preset function module based on the monitoring problem to output a function answer, and determines the function answer as the second preset sub-answer. The signature verification process monitoring module is provided with a preset function module; the signature verification process monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as the third preset sub-answer based on the monitoring problem; the signature verification process monitoring module generates a preset answer according to at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer. In other words, the preset answer corresponding to the monitoring answer is stored in the host. This preset answer can be understood as the standard answer. The acquisition method of the preset answer can be that all are pre-stored in advance, or a preset function the same as that of the trust anchor can be set to achieve the effect of outputting the same answer. The acquisition method of the preset answer can also be other methods known to those skilled in the art. It should be noted that in this embodiment, it is not limited that the preset answer and the answered answer adopt the same acquisition method, that is, the acquisition methods can be the same or different.
[0115] In one embodiment, the method further includes: counting the number of events with different signature verification result similarity / difference status within a preset statistical period; if the number of events is greater than a preset quantity threshold, controlling the controller to enter a preset security state. For example, within the recently preset duration, when the number of events is greater than the preset quantity threshold, controlling the controller to enter the preset security state. The preset security state can be set by those skilled in the art according to the specific application scenario of the controller as needed. For example, for a motor controller or an engine controller, entering the preset security state may switch the power output. For an autonomous driving ADAS controller, it may transmit a safety signal to the upper-layer decision-making controller, indicating that an abnormality is known. The signature verification result similarity / difference status being different means that the monitoring fails.
[0116] Among them, the preset statistical period can be the time set by those skilled in the art or rules such as the number of event executions. For example, the previous 30 minutes, the number of times of the process for improving the credibility of the trust anchor signature verification result previously executed, etc. A process for improving the credibility of a trust anchor signature verification result can be realized by multiple data to be transmitted. At this time, the preset statistical period can cover a process for improving the credibility of a trust anchor signature verification result, or can cover multiple processes for improving the credibility of trust anchor signature verification results. At this time, the number of events is the cumulative quantity of multiple processes.
[0117] The credibility of the signature verification result of the trust anchor can be improved in the above manner, reaching a credibility higher than that of the trust anchor and lower than that of the host. The signature verification result of the trust anchor is no longer QM, but the credibility of the signature verification result of the trust anchor is improved according to the automotive safety integrity level of the secure core of the signature verification process monitoring module. If the automotive safety integrity level of the secure core of the signature verification process monitoring module is ASIL-D, the automotive safety integrity level of the signature verification result of the trust anchor at this time is also higher than QM and lower than or equal to ASIL-D. In one example, after the credibility improvement is completed, during the subsequent preset exemption review duration, the credibility of the signature verification result determined by the trust anchor is improved, or the credibility of the signature verification results of the preset exemption review quantity of digital signatures signed by the subsequent trust anchor is improved.
[0118] The improvement of the credibility of the digital signature verification process of the trust anchor can be triggered by a triggering method set by those skilled in the art or triggered based on the host receiving the actual transmitted content data. When the improvement of the credibility of the digital signature verification process of the trust anchor is triggered based on the host receiving the actual transmitted content data, if the data to be transmitted at this time is not the actual transmitted content data, after the monitoring is completed, the actual transmitted content data and the digital signature of the actual transmitted content data need to be sent to the trust anchor for signature verification. The credibility of the digital signature verification process of the trust anchor is prompted. If the trusted state of the signature verification result of the trust anchor is trusted at this time, the credibility of the signature verification result of the digital signature of the actual transmitted content data can be improved.
[0119] In one embodiment, if the preset verification data is determined as the data to be transmitted, the method further includes: the host sending the actual transmitted content data and the actual digital signature of the actual transmitted content data to the trust anchor; the trust anchor decrypting the actual digital signature of the actual transmitted content data to obtain the decrypted actual content digest, and determining the transmitted actual content digest according to the received actual transmitted content, making a fourth comparison between the decrypted actual content digest and the transmitted actual content digest, determining a new signature verification result of the trust anchor based on the fourth comparison result, and improving the credibility of the new signature verification result of the trust anchor. At this time, the credibility of the new signature verification result of the trust anchor is higher than that of the trust anchor and lower than or equal to that of the host. In this embodiment, due to the large amount of data of the actual transmitted content data in the early stage, one or more preset verification data are used as the data to be transmitted as a compromise to improve the credibility of the digital signature verification process of the trust anchor. The actual transmitted content data still needs to be transmitted later. As an example, the normal transmission process is adopted at this time, and there is no need to repeatedly improve the credibility of the digital signature verification process of the trust anchor for the transmission process of the actual transmitted content data, and the verified signature verification result of the trust anchor can be directly used.
[0120] Sometimes, in addition to the risk of hardware resource failure related to the digital digest calculation of the trust anchor and the decryption of the asymmetric algorithm, there may also be risks of other hardware resource failures. To reduce the risks of other hardware resource failures, a solution that combines determining the answer based on monitoring issues during the signature verification process can also be adopted to reduce the risks of other hardware resource failures.
[0121] In one embodiment, the method further includes: the host sending the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor; the trust anchor decrypting the digital signature of the actual transmission content data to obtain the decrypted actual content digest, determining the post-transmission actual content digest based on the actual transmission content data, and while decrypting to obtain the decrypted actual content digest and determining the post-transmission actual content digest, determining the re-verification answer according to the re-verification question, generating new trust verification data based on the re-verification answer and the post-transmission actual content digest, comparing the decrypted actual content digest with the post-transmission actual content digest to obtain a new trust anchor signature verification result, and sending the new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; the signature verification process monitoring module determining new host verification data according to the decrypted actual content digest and the standard verification answer of the re-verification question, performing a sixth comparison on the new host verification data and the information trust verification data to obtain a new host signature verification result, and determining the signature verification result similarity / difference status between the new host signature verification result and the new trust anchor signature verification result to enhance the credibility of the digital signature verification process of the trust anchor.
[0122] It should be noted that the re-verification problem in the above embodiments and the aforementioned monitoring problem may be the same problem, or may be other problems set by those skilled in the art. The acquisition methods of the re-verification problem and the monitoring problem may be the same or different. When the preset verification data is determined as the data to be transmitted and the monitoring problem is also adopted in the process of improving the credibility of the digital signature verification process of the trust anchor, the monitoring problem and the re-verification problem may be the same or different. The determination method of the corresponding re-verification answer may refer to the determination method of the answer in the above embodiments. The determination method of the standard verification answer and the preset answer is similar and may refer to the generation method of the preset answer in the above embodiments. The correspondence between the re-verification problem, the re-verification answer, the standard verification answer and the monitoring problem, the answer, and the preset answer in the foregoing embodiments is consistent. The difference in names is only to remind that when the preset verification data is determined as the data to be transmitted and the monitoring problem is also adopted in the process of determining the credible state of the trust anchor signature verification result, in the subsequent process of improving the credibility of the digital signature verification process of the new trust anchor for the actual transmitted content data, the monitoring problem adopted may be the same as or different from the previous one. Therefore, the description of "re-verification problem" is adopted. The correspondence between the re-verification problem, the re-verification answer, the standard verification answer and the monitoring problem, the answer, and the preset answer in the foregoing embodiments is consistent and will not be elaborated herein.
[0123] When using Figure 2 the scheme shown to improve the credibility of the digital signature verification process of the trust anchor, it is possible to cover the failure of the hardware resources related to the calculation of the digital digest of the trust anchor and the decryption of the asymmetric algorithm. It is also possible to use multiple preset verification data and the digital signatures of the preset verification data to perform multiple processes of improving the credibility of the digital signature verification of the trust anchor to increase the failure coverage rate. When there are multiple preset verification data, each monitoring (the process of improving the credibility of the digital signature verification of the trust anchor) switches in sequence or randomly, or uses the preset verification data in the same order as the data to be transmitted.
[0124] In one embodiment, the number of preset verification data is one or more. An improvement monitoring process for the credibility of the digital signature verification process of the trust anchor is determined according to each preset verification data and the digital signature of the preset verification data. The improvement result of the credibility of the digital signature verification process of the final trust anchor is based on the improvement of the credibility of the digital signature verification process of the trust anchor corresponding to all the preset verification data. That is, when there is one preset verification data, the monitoring of the failure of the hardware resources related to the digital digest calculation and asymmetric algorithm decryption by the trust anchor is performed once, and the credibility of the digital signature verification process of the trust anchor is improved. When the number of preset verification data is multiple, the determination of the credible state of the trust anchor verification result can be performed separately or synchronously to obtain multiple credible states of the trust anchor verification result. If the same / different states of the verification results exceed a certain number (preset number threshold), or the number of monitoring failures is greater than the preset number threshold, the preset security state is triggered. Otherwise, it is considered that the credible state of the final trust anchor verification result is credible, and then the actual transmitted content data and the digital signature of the actual transmitted content data are used to determine the credible state of the new trust anchor verification result. When using multiple preset verification data to determine the credible state, in different credible state determination processes, the use order of the multiple preset verification data can be unchanged, randomly switched, or switched according to the preset order to improve the coverage of hardware failures.
[0125] The method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present application calculates the pre-transmission digital digest according to the data to be transmitted through the verification process monitoring module with higher credibility, decrypts the digital signature by the trust anchor with lower credibility to obtain the decrypted digital digest, and calculates the post-transmission digital digest according to the data to be transmitted. The trust anchor verification result is determined by the first comparison result between the decrypted digital digest and the post-transmission digital digest, and the host verification result is determined by the second comparison result between the decrypted digital digest and the pre-transmission digital digest. Then 确定 The same / different state of the verification results between the host verification result and the trust anchor verification result is used to improve the credibility of the digital signature verification process of the trust anchor. The credible state of the trust anchor verification result is determined by the verification process monitoring module with higher credibility, so that the trust anchor verification result can ensure the functional safety level and can be applied to functional safety critical scenarios.
[0126] Optionally, by adding monitoring problems during the verification process of the trust anchor and synchronously determining the answers during the verification process, the scenario of the failure of the hardware resources related to the digital digest calculation and decryption algorithm of the trust anchor is covered. By comparing the trust verification data with the host verification data, the reliability of the improvement of the credibility of the digital signature verification process of the trust anchor is further improved.
[0127] Optionally, by configuring multiple sets of variable monitoring problems and flexible ways of generating answer answers, the diagnostic coverage rate can be improved, and the failure conditions of multiple hardware resources of multiple trust anchor ends can be covered.
[0128] Optionally, when the estimated actual digest calculation time of the actual transmitted content data is greater than or equal to the preset duration threshold, the preset verification data is used as the data to be transmitted to improve the credibility of the trust anchor signature verification process. On the one hand, it solves the problem that due to the excessive data volume of the actual transmitted content data, the computing power overhead of the host is too large, affecting the normal function of the controller. On the premise of ensuring the improvement of the credibility of the digital signature verification process of the trust anchor, the computing power overhead of the host is reduced.
[0129] It can be seen that the solution provided in this embodiment can improve the functional safety level of the digital signature verification process based on the trust anchor without affecting the function of the HOST (host) side, so that the digital signature information security mechanism based on the trust anchor can replace and supplement the existing functional safety mechanism and expand its scope of use.
[0130] Taking the controller as the MCU below, the MCU is divided into a host and a trust anchor. The trust anchor is the HSM, which stores the public key. The data to be transmitted is the actual transmitted content data (hereinafter referred to as the actual content), the trust anchor signature verification result is the signature verification success flag B, and the host signature verification result is the signature verification success flag A. The implementation of monitoring is mainly completed in the signature verification process monitoring module. The signature verification process monitoring module is a trusted module, and an example is given for the method for improving the credibility of the digital signature verification process of the trust anchor provided in the above embodiment. Please refer to Figure 3 and Figure 4 , Figure 3 is a specific flow diagram of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present invention. Figure 4 is a specific flow diagram of a monitoring stage of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present invention. As shown in Figure 3 and Figure 4 shown, in the pre-preparation stage, the data sender calculates the original digital digest according to the original content, encrypts the original digital digest with the private key stored by the data sender to obtain the original signature, and the data sender sends the original signature and the original content to the host of the MCU ( Figure 3Shown as HOST in the figure, the HOST takes the received original content as the actual content and the original signature as the digital signature. That is, the HOST receives the above original signature and original content to obtain the actual content and the digital signature. If the computing power overhead for the HOST-side security core to directly calculate the actual digital signature of the actual content that needs to be guaranteed integrity and authenticity is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), and it will not affect the normal function of the controller, then the monitoring can be directly implemented on the HOST side. At the start of monitoring, the HOST side will calculate the actual digital digest A based on the actual content (that is, the digital digest before transmission mentioned above). The calculation steps of the actual digital digest A only need to be completed before the subsequent comparison of the actual digital digest A with the target digital digest. And the HOST side will send the actual content and the digital signature to the HSM side. The HSM side calculates the target digital digest (that is, the decrypted digital digest mentioned above) based on the public key and the digital signature, and calculates the actual digital digest B based on the actual content (that is, the digital digest after transmission mentioned above). Compare the target digital digest with the actual digital digest B to obtain the signature verification success flag B (that is, the trust anchor signature verification result mentioned above), and send the target digital digest and the signature verification success flag B to the HOST, so that the HOST can obtain the target digital digest (HSM side) decrypted by the HSM side based on the signature (digital signature) and the public key. It should be noted that this sending method can be the separate sending as shown in Figure 3 or synchronous sending. Specifically, those skilled in the art can choose according to needs. The steps shown in the figure are only for illustration and do not limit the sequence. The steps in the subsequent figures are only for illustration and do not limit the sequence, so they will not be elaborated. After receiving the target digital digest, the HOST side compares it with its own actual digital digest A, that is, determines whether the actual digital digest A (HOST side) is equal to the target digital digest (HSM side). If so, the signature verification success flag A (HOST side) is set to TRUE. If not, the signature verification success flag A (HOST side) is set to FALSE, and then compare it with the signature verification success flag B to obtain the same or different status of the signature verification result. By judging whether the signature verification success flag A (HOST side) is equal to the signature verification success flag B (HSM side), if so, the monitoring passes, and the trust status of the trust anchor signature verification result is trustworthy, that is, the signature verification result of the HSM side is trustworthy, that is, the signature verification success flag B is trustworthy, and the subsequent other processes can directly apply this signature verification success flag B. If not, the monitoring fails, triggering subsequent fault confirmation and response, such as entering a preset safe state, etc., and the monitoring ends.
[0131] In addition, if an error occurs in the asymmetric decryption process on the HSM side, it will directly lead to an incorrect target digital digest, which will then be detected by subsequent monitoring. Moreover, in order to achieve a corresponding ASIL level for the signature verification result, the monitoring software development process on the HOST side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed freedom from interference (FFI) with other ASIL / QM level software. In one embodiment, the digital signature verification process monitoring software can also be implemented in the HSM HOST Driver (trusted).
[0132] For the solution that uses the actual content as the data to be transmitted, it is not necessary to adopt monitoring issues as a strengthening means, or monitoring issues can be adopted as a strengthening means. Those skilled in the art can make a flexible choice. If monitoring issues are selected as a strengthening means, the specific implementation method is similar to the way of adopting monitoring issues when using preset verification data, and reference can be made to the following embodiments, which will not be elaborated here.
[0133] If the computing power overhead of directly calculating the actual digital signature of the actual content that needs to be guaranteed integrity and authenticity on the HOST side is large and cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety faults, or it will affect the normal function of the controller, then the monitoring is divided into two parts.
[0134] First, design one or more sets of "actual content for monitoring" and "digital signature for monitoring" specifically for monitoring. For the convenience of key management, the public key of the digital signature for monitoring and the actual digital signature can be the same, or a public key can be injected separately for the digital signature for monitoring; the size of the actual content for monitoring needs to ensure that the calculation of the digital digest of the actual content for monitoring based on the HOST side can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety faults. Then, based on Figure 3 the method, replace the "actual content" with the "actual content for monitoring" and the "digital signature" with the "digital signature for monitoring" to cover the hardware resource failures related to the digital digest calculation and asymmetric algorithm decryption on the HSM side. Specifically, reference can be made to Figure 3 the relevant description, which will not be elaborated here. Using multiple sets of "actual content for monitoring" and "digital signature for monitoring" for monitoring can increase the failure coverage rate, and the order of the actual content for monitoring can be switched sequentially or randomly each time monitoring is performed. The HASH value corresponding to the "actual content for monitoring" here can also be preset on the HOST side and directly used as the monitoring basis subsequently (that is, the aforementioned actual digital digest A).
[0135] Then, based on the HSM side, calculate the actual digital digest B of the actual content, decrypt the target digital digest based on the digital signature and the public key using the asymmetric algorithm, and design a monitoring scheme as shown in Figure 5 、 Figure 6 and Figure 7 to cover the failure of other hardware resources on the HSM side.
[0136] Taking the controller as the MCU, dividing the MCU into a host HOST and a trust anchor, where the trust anchor is the HSM which stores the public key, and the data to be transmitted is the preset verification data (taking the actual content for monitoring as an example), the method for improving the credibility of the digital signature verification process of the trust anchor provided in the above embodiment will be illustrated by examples. There is digital signature verification process monitoring software (ASIL) in the signature verification process monitoring module such as the host security core. The actual content for monitoring and the monitoring problems sent by the digital signature verification process monitoring software are sent to the trust anchor firmware HSM Firmware (QM) of the HSM through the trust anchor host driver HSM HOSTDriver (QM). Figure 5 This is another specific flowchart of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present invention. Figure 6 This is another specific flowchart of the monitoring stage of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present invention. Figure 7 This is a schematic diagram of a coverage monitoring scheme for the failure of other hardware resources on the HSM side provided by the embodiment of the present invention. As shown in Figure 5 、 Figure 6 and Figure 7 Digital signature verification process monitoring software (with ASIL level) is designed in the security core on the HOST side. In order to achieve that the signature verification result reaches the corresponding ASIL level, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed freedom from interference (FFI) with other software of ASIL / QM level. The HSM is of QM level. Please refer to Figure 5 、 Figure 6 and Figure 7, the HOST side obtains the actual content for monitoring and the digital signature for monitoring, and calculates the actual digital digest A based on the actual content for monitoring. (That is, the digital digest before transmission mentioned in the foregoing embodiment). It should be noted that the actual digital digest A can be directly calculated by the HOST side. It can also be that when setting the actual content for monitoring, the HASH value obtained when generating the digital signature for monitoring is stored as the actual digital digest A (HOST side) here. In this case, there is no need to separately calculate the actual digital digest A, and directly obtain the HASH value corresponding to the actual content for monitoring as the actual digital digest A. The determination step of the actual digital digest A can be carried out before the subsequent verification signature success flag A (that is, the host verification signature result mentioned in the foregoing embodiment), and is not limited to Figure 5 the step sequence shown. The HOST side sends the actual content for monitoring and the digital signature for monitoring to the HSM side, and sends a monitoring question. It should be noted that the steps of sending the actual content for monitoring and the digital signature for monitoring and sending the monitoring question can be separated or synchronized. Specifically, those skilled in the art can choose according to needs. Figure 5 The illustration shown is only an example and does not limit the step sequence. After receiving the digital signature for monitoring, the HSM decrypts it according to the public key to obtain the target digital digest (that is, the decrypted digital digest mentioned in the foregoing embodiment). The HSM calculates the actual digital digest B (that is, the digital digest after transmission mentioned in the foregoing embodiment) based on the received actual content for monitoring, and while calculating the target digital digest and the actual digital digest B, answers the monitoring question to determine the monitoring answer. By comparing the target digital digest with the actual digital digest B, the verification signature success flag B (HSM side, that is, the trust anchor verification signature result mentioned in the foregoing embodiment) is obtained. The HSM also determines the trust verification data based on the actual digital digest B and the monitoring answer. The trust verification data is shown as Figure 5 "CRC(actual digital digest B + monitoring answer)" in. The HSM sends the target digital digest, the verification signature success flag B, and CRC(actual digital digest B + monitoring answer) to the HOST side. The HOST compares the target digital digest with the actual digital digest A to obtain the verification signature success flag A. If so, that is, the target digital digest is equal to the actual digital digest A, the verification signature success flag A is set to TRUE. If not, that is, the target digital digest is not equal to the actual digital digest A, the verification signature success flag A is set to FALSE. Determine the known monitoring answer (that is, the preset answer) according to the monitoring question, and determine the host verification data. The host verification data is shown as Figure 5It is shown as CRC (target digital digest + known monitoring answer) in the middle. Finally, by comparing whether the signature verification success flag bit A is consistent with the signature verification success flag bit B, and comparing whether CRC (target digital digest + known monitoring answer) is equal to CRC (actual digital digest B + monitoring answer), the credibility of the digital signature verification process of the trust anchor is improved in this way. If so, that is, the signature verification success flag bit A is consistent with the signature verification success flag bit B, and CRC (target digital digest + known monitoring answer) is equal to CRC (actual digital digest B + monitoring answer), then the monitoring passes and the signature verification success flag bit B is credible. If not, that is, the signature verification success flag bit A is different from the signature verification success flag bit B, and / or CRC (target digital digest + known monitoring answer) is not equal to CRC (actual digital digest B + monitoring answer), then the monitoring fails, triggering subsequent fault confirmation and response. The specific implementation method of the monitoring failure refers to the description of the above embodiments and will not be elaborated here.
[0137] It should be noted that the target digital digest, the signature verification success flag bit B, and CRC (actual digital digest B + monitoring answer) can be sent to the HOST simultaneously or successively, and can be specifically set by those skilled in the art according to needs, which is not limited here. Among them, CRC (Cyclic Redundancy Check) is a cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. In this embodiment, the CRC algorithm is used as an example, and those skilled in the art can also select other similar algorithms to implement the calculation of the verification data according to needs.
[0138] While triggering the signature verification at the HSM end, the digital signature verification process monitoring software (with an ASIL level) will send a monitoring question to the HSM end. To improve the diagnostic coverage, the monitoring question can be dynamically changed, for example: 0x0, 0x1, 0x2, 0x3…0xF. Secondly, the method for obtaining the monitoring answer (answer) based on the monitoring question in the HSM end Firmware can also be selected according to the diagnostic coverage requirements, which can be obtained directly by looking up a table or based on; if you want to further improve the diagnostic coverage, the monitoring results of various software and hardware resources at the HSM end can also be integrated. The monitoring answer (preset answer) for each monitoring question is known in the digital signature verification process monitoring software.
[0139] For the above-mentioned fault confirmation and response when the monitoring fails, a fault failure counter can be set to count the number of events where the signature verification result difference state is different (that is, the number of times of monitoring failure) within a preset statistical period. If the fault failure counter is greater than the threshold (that is, the number of events is greater than the preset quantity threshold), the system will enter the safe state according to the requirements of the actual functional safety target.
[0140] Please refer to Figure 8 ,Figure 8 This is a specific flowchart of the method for determining data to be transmitted provided by the embodiments of the present invention. As Figure 8 shown, after the data sender calculates the original digital digest based on the original content and encrypts the original digital digest to obtain the original signature, the original content and the original signature are sent to the HOST. After receiving them, the HOST obtains the actual transmission content data and the digital signature, determines the expected actual digest calculation time of the actual transmission content data, and based on the comparison result between the expected actual digest calculation time and the preset duration threshold, determines the preset verification data or the actual transmission content data as the data to be transmitted. Subsequently, according to the specific selection of the data to be transmitted, the method for improving the credibility of the digital signature verification process of the trust anchor shown in Figure 3 or Figure 5 can be executed, which will not be elaborated here.
[0141] In an embodiment, if the preset verification data is determined as the data to be transmitted and the controller has not entered the safe mode, then subsequently, when the actual transmission content data is transmitted to the trust anchor, the verification signature can be performed in the manner of related technologies, and there is no need to improve the credibility of the trust anchor verification process for the verification result of the digital signature of the actual transmission content data this time. The trust anchor verification result can be directly regarded as a result with high credibility.
[0142] Taking the controller as the MCU, dividing the MCU into the host HOST and the trust anchor, the trust anchor is the HSM which stores the public key, and the data to be transmitted is the preset verification data (taking the actual content for monitoring as an example) as an example, the method for improving the credibility of the digital signature verification process of the trust anchor provided by the above embodiments will be illustrated. In the verification signature process monitoring module such as the host security core, there is digital signature verification process monitoring software (ASIL), and the actual content for monitoring and the monitoring problems sent by the digital signature verification process monitoring software are sent to the trust anchor firmware HSM Firmware (QM) of the HSM through the trust anchor host driver HSM HOSTDriver (QM).
[0143] Figure 9 This is another specific flowchart of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiments of the present invention. As Figure 9As shown, the data sender calculates the original digital digest based on the actual transmitted content data, encrypts the original digital digest to obtain the original signature, and sends it to the HOST side as the digital signature of the actual transmitted content data and the actual transmitted content data (for convenience of description, hereinafter referred to as the original signature). If the computing power overhead of directly calculating the original signature that needs to be guaranteed integrity and authenticity at the HOST side is relatively large, and it cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller, then the monitoring is divided into two parts. The coverage monitoring of the hardware resource failures related to the digital digest calculation at the HSM side and the asymmetric algorithm decryption is first performed using the actual monitoring content and the monitoring digital signature. At this time, multiple sets of actual monitoring content and monitoring digital signatures can be designed for multiple monitoring, and the final monitoring result is determined based on the multiple monitoring results. Alternatively, a set of actual monitoring content and monitoring digital signatures can be used for monitoring. The following takes the monitoring using a set of actual monitoring content and monitoring digital signatures as an example. The HOST side sends the actual monitoring content and the monitoring digital signature to the HSM and sends a monitoring problem. The HSM calculates the target digital digest a based on the public key and the monitoring digital signature, calculates the actual digital digest B based on the actual monitoring content, compares the target digital digest a and the actual digital digest B to obtain the signature verification success flag B. During the calculation of the target digital digest a and the signature verification success flag B, the monitoring answer (reply answer) is determined according to the monitoring problem, and the trust anchor verification data is calculated based on the monitoring answer and the actual digital digest B, that is, Figure 9 the CRC (actual digital digest B + monitoring answer) in Figure 9 The CRC (actual digital digest B + monitoring answer), the target digital digest a, and the signature verification success flag B are sent to the HOST. The HOST calculates the actual digital digest A based on the actual monitoring content (this step can be omitted and implemented using pre-stored data), determines the known monitoring answer (preset answer) according to the monitoring problem, and then calculates the host verification data based on the known monitoring answer and the target digital digest a, that is,In the CRC (target digital digest a + known monitoring answer), the actual digital digest A is compared with the target digital digest a to obtain the signature verification success flag bit A. The signature verification success flag bit A and the signature verification success flag bit B are compared, and CRC (actual digital digest B + monitoring answer) is compared with CRC (target digital digest a + known monitoring answer). If the controller does not enter the preset safe state, the HOST sends the actual transmitted content data and the original signature to the HSM. The HSM calculates the target digital digest b based on the public key and the original signature, and calculates the actual digital digest C based on the actual transmitted content data. The target digital digest b and the actual digital digest C are compared to obtain the signature verification success flag bit C. The credibility of the signature verification success flag bit C is improved. An example is that the credibility of the signature verification success flag bit C is higher than the credibility of the trust anchor and lower than or equal to the credibility of the host. Without affecting the functions of the HOST side, the functional safety level of the digital signature verification process based on the HSM is improved, so that the digital signature information security mechanism based on the HSM can replace and supplement the existing functional safety mechanism and expand its application scope.
[0144] Figure 10 Another specific flowchart of the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiment of the present invention is shown in Figure 9As shown in the figure, the data sender calculates the original digital digest based on the actual transmission content data, encrypts the original digital digest to obtain the original signature, and sends it to the HOST side as the digital signature of the actual transmission content data and the actual transmission content data (for the convenience of description, hereinafter referred to as the original signature). If the computing power overhead of directly calculating the original signature that needs to be guaranteed integrity and authenticity at the HOST side is relatively large, and it cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller, then the monitoring is divided into two parts. The coverage monitoring of the hardware resource failures related to the digital digest calculation at the HSM side and the asymmetric algorithm decryption is first performed using the actual monitoring content and the monitoring digital signature. At this time, multiple sets of actual monitoring content and monitoring digital signatures can be designed for multiple monitors to determine the final monitoring result based on the multiple monitoring results, or a set of actual monitoring content and monitoring digital signature can be used for monitoring. The following takes the monitoring using a set of actual monitoring content and monitoring digital signature as an example. The HOST side sends the actual monitoring content and the monitoring digital signature to the HSM. The HSM calculates the target digital digest a according to the public key and the monitoring digital signature, calculates the actual digital digest B according to the actual monitoring content, compares the target digital digest a and the actual digital digest B to obtain the signature verification success flag B, and sends the target digital digest a and the signature verification success flag B to the HOST. The HOST calculates the actual digital digest A according to the actual monitoring content (this step can be omitted and implemented using pre-stored data), compares the actual digital digest A and the target digital digest a to obtain the signature verification success flag A, and compares the signature verification success flag A and the signature verification success flag B. If the signature verification success flag A and the signature verification success flag B are the same, the monitoring passes, that is, the coverage monitoring of the hardware resource failures related to the digital digest calculation at the HSM side and the asymmetric algorithm decryption is completed. However, there is still a risk of coverage of other hardware resource failures at the HSM side. To avoid the result being untrusted due to other hardware resource failures at the HSM side, the effectiveness of other hardware resources can be verified by adding monitoring questions. Specifically, before, after, or at the same time as the above-mentioned solution, on the premise that the controller has not entered the preset safe state, the HOST sends the actual transmission content data, the original signature, and the monitoring question (that is, the re-verification question) to the HSM. The HSM calculates the target digital digest b according to the public key and the original signature, calculates the actual digital digest C according to the actual transmission content data, compares the target digital digest b and the actual digital digest C to obtain the signature verification success flag C, and determines the monitoring answer (the answer to the question, that is, the re-verification answer) according to the monitoring question during the calculation of the target digital digest b and the signature verification success flag C. A new trust anchor verification data is calculated based on the monitoring answer and the actual digital digest C, that is, Figure 9The CRC (actual digital digest C + monitored answer) therein sends the CRC (actual digital digest C + monitored answer), the target digital digest b, and the signature verification success flag bit C to the HOST. The HOST determines the known monitored answer (preset answer, i.e., the standard verification answer) according to the monitored question, and then calculates the new host verification data based on the known monitored answer and the target digital digest b, that is Figure 9 The CRC (target digital digest b + known monitored answer) therein compares the CRC (target digital digest b + known monitored answer) with the CRC (actual digital digest C + monitored answer) to obtain the signature verification success flag bit D, and compares the signature verification success flag bit D and the signature verification success flag bit C. If the signature verification success flag bit A and the signature verification success flag bit B are the same, the new trust anchor signature verification result credibility state is credible, such as Figure 9 shown in the embodiment. The credibility of the signature verification success flag bit C is higher than that of the trust anchor and lower than or equal to that of the host, realizing the improvement of the functional safety level of the digital signature verification process based on HSM without affecting the functions of the HOST side, enabling the digital signature information security mechanism based on HSM to replace and supplement the existing functional safety mechanism and expand its application scope.
[0145] It should be noted that the steps of fault confirmation and response in the above embodiments can be set by those skilled in the art according to needs and are not limited herein.
[0146] It can be seen that the method for improving the credibility of the digital signature verification process of the trust anchor provided by the embodiments of the present invention designs a scheme for improving the functional safety level of the digital signature verification process based on HSM. This scheme can improve the functional safety level of the digital signature verification process based on HSM without affecting the functions of the HOST side, enabling the digital signature information security mechanism based on HSM to replace and supplement the existing functional safety mechanism and expand its application scope.
[0147] In an embodiment, a controller is provided, and the controller is used to implement the method for improving the credibility of the digital signature verification process of the trust anchor provided in any of the above embodiments. Please refer to Figure 11 , Figure 11 which is a schematic structural diagram of the controller provided by the embodiments of the present invention, such as Figure 11As shown, the controller 1100 includes a trust anchor 1110 and a host 1120. The host 1120 includes a signature verification process monitoring module 1121, and the credibility of the signature verification process monitoring module 1121 is higher than that of the trust anchor 1110. The detailed description of each functional module is as follows: The host 1120 is used to obtain the data to be transmitted and the digital signature, and send the data to be transmitted and the digital signature to the trust anchor 1110. The digital signature is generated by encrypting the original digital digest calculated based on the data to be transmitted; The trust anchor 1110 is used to decrypt the digital signature to obtain the decrypted digital digest, and determine the transmitted digital digest according to the received data to be transmitted, perform a first comparison between the decrypted digital digest and the transmitted digital digest, determine the trust anchor signature verification result based on the first comparison result, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module 1121; The signature verification process monitoring module 1121 is used to perform a second comparison between the decrypted digital digest and the pre-transmission digital digest, determine the host signature verification result based on the second comparison result, and determine the status of the same or different signature verification results between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor. Among them, the pre-transmission digital digest is determined according to the data to be transmitted.
[0148] In one embodiment, the host further includes a trust anchor driver function module, which is used to obtain the data to be transmitted and the digital signature, send the data to be transmitted and the digital signature to the trust anchor, and receive the trust anchor signature verification result and the decrypted digital digest, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module.
[0149] In one embodiment, the signature verification process monitoring module is arranged in the trust anchor driver function module.
[0150] In one embodiment, the host further includes a mode switching module, which is used to determine the estimated actual digest calculation time of the actual transmission content data after the host receives the original content data sent by the data sender and uses it as the actual transmission content data, and determine the data to be transmitted according to the comparison result between the estimated actual digest calculation time and the preset duration threshold. The data to be transmitted includes the actual transmission content data or the preset verification data, and the estimated preset digest calculation time of the preset verification data is less than the preset duration threshold.
[0151] In one embodiment, the signature verification process monitoring module is further configured to determine a monitoring problem and send the monitoring problem to the trust anchor driver function module; the trust anchor driver function module is further configured to send the monitoring problem to the trust anchor; the trust anchor is further configured to, while decrypting the digital signature to obtain a decrypted digital digest and determining a post-transmission digital digest based on the received data to be transmitted, determine an answer to the monitoring problem, and determine trust verification data based on the answer and the post-transmission digital digest, and send the trust verification data to the trust anchor driver function module; the trust anchor driver function module is further configured to send the trust verification data to the signature verification process monitoring module; the signature verification process monitoring module is further configured to perform a third comparison between the trust verification data and the host verification data to further enhance the credibility of the digital signature verification process of the trust anchor, wherein the host verification data is determined based on the decrypted digital digest and a preset answer to the monitoring problem.
[0152] In one embodiment, the host is further configured to send the received actual transmission content data, the digital signature of the actual transmission content data, and a re-verification problem to the trust anchor; the trust anchor is further configured to decrypt the digital signature of the actual transmission content data to obtain a decrypted actual content digest, determine a post-transmission actual content digest based on the actual transmission content data, and, while decrypting to obtain the decrypted actual content digest and determining the post-transmission actual content digest, determine a re-verification answer based on the re-verification problem, generate new trust verification data based on the re-verification answer and the post-transmission actual content digest, compare the decrypted actual content digest with the post-transmission actual content digest to obtain a new trust anchor verification result, and send the new trust anchor verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; the signature verification process monitoring module is further configured to determine new host verification data based on the decrypted actual content digest and the standard verification answer to the re-verification problem, perform a sixth comparison between the new host verification data and the information trust verification data to obtain a new host verification result, and determine the verification result similarity / difference status between the new host verification result and the new trust anchor verification result to enhance the credibility of the digital signature verification process of the trust anchor.
[0153] The trust anchor decrypts the digital signature of the actual transmitted content data to obtain the decrypted actual content digest, determines the transmitted actual content digest based on the actual transmitted content data, and while decrypting to obtain the decrypted actual content digest and determining the transmitted actual content digest, determines the re-verification answer according to the re-verification question. A new trust verification data is generated based on the re-verification answer and the transmitted actual content digest. The decrypted actual content digest is compared with the transmitted actual content digest to obtain a new trust anchor signature verification result. The new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest are sent to the signature verification process monitoring module; The signature verification process monitoring module determines new host verification data according to the decrypted actual content digest and the standard verification answer of the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host signature verification result, and determines the signature verification result similarity / difference status between the new host signature verification result and the new trust anchor signature verification result to enhance the credibility of the digital signature verification process of the trust anchor
[0154] In one embodiment, the trust anchor driver function module is further configured to send the actual transmitted content data and the digital signature of the actual transmitted content data to the trust anchor.
[0155] Continuing with the above embodiment, the trust anchor is further configured to decrypt the actual digital signature of the actual transmitted content data to obtain the decrypted actual content digest, and determine the transmitted actual content digest according to the received actual transmitted content, perform a fourth comparison on the decrypted actual content digest and the transmitted actual content digest, determine a new trust anchor signature verification result based on the fourth comparison result, and enhance the credibility of the new trust anchor signature verification result.
[0156] In one embodiment, the signature verification process monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.
[0157] For the specific limitations of the controller, reference can be made to the limitations of the method for enhancing the credibility of the digital signature verification process of the trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0158] In this embodiment, the controller essentially sets multiple modules to execute the method for enhancing the credibility of the digital signature verification process of the trust anchor in any of the above embodiments. The specific functions and technical effects can be referred to the above embodiments, which will not be elaborated here.
[0159] In one embodiment, a system for enhancing the credibility of the digital signature verification process of the trust anchor is provided. Please refer toFigure 12 , Figure 12 is a schematic structural diagram of a system for improving the credibility of the digital signature verification process of a trust anchor provided by an embodiment of the present invention. As Figure 12 shown, the system 1200 for improving the credibility of the digital signature verification process of the trust anchor includes a data sender 1210 and Figure 11 the controller 1100 shown. The controller 1100 includes a trust anchor 1110 and a host 1120. The host 1120 includes a signature verification process monitoring module 1121, and the credibility of the signature verification process monitoring module 1121 is higher than that of the trust anchor 1110. The data sender 1210 is configured to calculate an original digital digest based on the original content data, encrypt the original digital digest to generate an original signature, and send the original content data and the original signature to the host 1120, so that the host uses the received original content data as the actual transmitted content data and the original signature as the digital signature of the actual transmitted content data. The host 1120 is configured to obtain the data to be transmitted and the digital signature. The data to be transmitted includes the actual transmitted content data or preset verification data, and send the data to be transmitted and the digital signature to the trust anchor 1110. The digital signature is generated by encrypting the original digital digest calculated based on the data to be transmitted. The trust anchor is configured to decrypt the digital signature to obtain a decrypted digital digest, and determine a transmitted digital digest based on the received data to be transmitted, perform a first comparison between the decrypted digital digest and the transmitted digital digest, determine the trust anchor signature verification result based on the first comparison result, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module 1121. The signature verification process monitoring module 921 is configured to perform a second comparison between the decrypted digital digest and the pre-transmission digital digest, determine the host signature verification result based on the second comparison result, and determine the signature verification result similarity and difference status between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, where the pre-transmission digital digest is determined based on the data to be transmitted.
[0160] In one embodiment, the host is further configured to send the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor; the trust anchor decrypts the digital signature of the actual transmission content data to obtain the decrypted actual content digest, determines the actual content digest after transmission based on the actual transmission content data, and while decrypting to obtain the decrypted actual content digest and determining the actual content digest after transmission, determines the re-verification answer according to the re-verification question, generates new trust verification data based on the re-verification answer and the actual content digest after transmission, compares the decrypted actual content digest with the actual content digest after transmission to obtain a new trust anchor signature verification result, and sends the new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; the signature verification process monitoring module determines new host verification data according to the decrypted actual content digest and the standard verification answer of the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host signature verification result, and determines the signature verification result similarity / difference status between the new host signature verification result and the new trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
[0161] If the data to be transmitted includes preset verification data and the controller has not entered the preset security state, then the host sends the actual transmission content data to the trust anchor. In one embodiment, at this time, after the trust anchor performs the signature verification operation, the trust anchor signature verification result can be directly used as the trusted result, and there is no need to perform the improvement of the credibility of the digital signature verification process of the trust anchor.
[0162] It should be noted that Figure 12 only a module outside the controller is taken as an example for illustration, and in this embodiment, it is not limited that the data sender must be a module outside the controller. The data sender can be a module inside the controller.
[0163] For the specific limitations of the system for improving the credibility of the digital signature verification process of the trust anchor, reference can be made to the limitations on the method for improving the credibility of the digital signature verification process of the trust anchor and the controller in the above text, which will not be elaborated here. Each module in the above system for improving the credibility of the digital signature verification process of the trust anchor can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above respective modules.
[0164] In one embodiment, an electronic device is provided. The electronic device can be a server, and its internal structure diagram can be as Figure 13As shown in the figure. The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps of the server side of a method for improving the credibility of the digital signature verification process of a trust anchor.
[0165] In one embodiment, an electronic device is provided. The electronic device can be a client, and its internal structure diagram can be as Figure 14 As shown in the figure. The electronic device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes non-volatile storage media and internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps of the client side of a method for improving the credibility of the digital signature verification process of a trust anchor.
[0166] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are realized:
[0167] Control the host to obtain the data to be transmitted and the digital signature, and send the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting the original digital digest calculated based on the data to be transmitted.
[0168] Control the trust anchor to decrypt the digital signature to obtain the decrypted digital digest, and determine the transmitted digital digest according to the received data to be transmitted. Perform a first comparison between the decrypted digital digest and the transmitted digital digest, determine the trust anchor verification result based on the first comparison result, and send the trust anchor verification result and the decrypted digital digest to the verification process monitoring module.
[0169] Controlling a second comparison between the decrypted digital summary and the digital summary before transmission through the signature verification process monitoring module, determining the host signature verification result based on the second comparison result, and determining the similarities and differences between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the digital summary before transmission is determined according to the data to be transmitted.
[0170] In one embodiment, a computer readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0171] The control obtains the data to be transmitted and the digital signature through the host, and sends the data to be transmitted and the digital signature to the trust anchor, where the digital signature is encrypted and generated based on the original digital summary calculated from the data to be transmitted;
[0172] Controlling to decrypt the digital signature through the trust anchor to obtain a decrypted digital summary, and determining the digital summary after transmission according to the received data to be transmitted, performing a first comparison between the decrypted digital summary and the digital summary after transmission, determining the trust anchor verification result based on the first comparison result, and sending the trust anchor verification result and the decrypted digital summary to the verification process monitoring module;
[0173] Controlling a second comparison between the decrypted digital summary and the digital summary before transmission through the signature verification process monitoring module, determining the host signature verification result based on the second comparison result, and determining the similarities and differences between the host signature verification result and the trust anchor signature verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the digital summary before transmission is determined according to the data to be transmitted.
[0174] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or electronic device can refer to the relevant descriptions on the server side and the client side in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0175] Those of ordinary skill in the art can understand that all or part of the processes in the above-described method embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-described method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0176] Those skilled in the art can clearly understand that, for the sake of convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device, system, and controller can be divided into different functional units or modules to complete all or part of the functions described above.
[0177] The embodiments provided above are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A method for improving the credibility of the digital signature verification process of a trust anchor, characterized in that, Applied to a controller, the controller comprising a trust anchor and a host, the host comprising a signature verification process monitoring module, the credibility of the signature verification process monitoring module being higher than the credibility of the trust anchor, the method comprising: The host obtains the data to be transmitted and the digital signature, and sends the data to be transmitted and the digital signature to the trust anchor, wherein the digital signature is generated by encrypting an original digital summary calculated based on the data to be transmitted; The trust anchor decrypts the digital signature to obtain a decrypted digital summary, determines a transmitted digital summary according to the received data to be transmitted, performs a first comparison between the decrypted digital summary and the transmitted digital summary, determines a trust anchor verification result based on the first comparison result, and sends the trust anchor verification result and the decrypted digital summary to the verification process monitoring module; The verification process monitoring module performs a second comparison on the decrypted digital summary and the pre-transmission digital summary, determines a host verification result based on the second comparison result, and determines the similarities and differences between the host verification result and the trust anchor verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the pre-transmission digital summary is determined according to the data to be transmitted.
2. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 1, characterized in that, The method further comprises: The signature verification process monitoring module sends monitoring questions to the trust anchor, so that the trust anchor can determine answers to the monitoring questions while decrypting the digital signature to obtain a decrypted digital summary and determining the digital summary after transmission according to the received data to be transmitted.
3. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 2, characterized in that, After the signature verification process monitoring module sends the monitoring question to the trust anchor, the method further includes: While the trust anchor decrypts the digital signature to obtain a decrypted digital summary and determines the digital summary after transmission according to the received data to be transmitted, the trust anchor determines the answer according to the monitoring question; The trust anchor determines trust verification data according to the answer and the transmitted digital summary, and sends the trust verification data to the signature verification process monitoring module; The verification process monitoring module performs a third comparison on the trust verification data and the host verification data to obtain a third comparison result, and compares the third comparison result with the verification result to improve the credibility of the digital signature verification process of the trust anchor, wherein the host verification data is determined according to the decrypted digital summary and a preset answer to the monitoring question.
4. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 2, wherein After the signature verification process monitoring module sends the monitoring question to the trust anchor, the method further includes: While the trust anchor decrypts the digital signature to obtain a decrypted digital summary and determines the digital summary after transmission according to the received data to be transmitted, the trust anchor determines the answer according to the monitoring question; The trust anchor determines answer verification data according to the answer, and sends the answer verification data to the signature verification process monitoring module; The verification process monitoring module performs a fifth comparison on the answer verification data and the prior verification data, and obtains a seventh comparison result based on the fifth comparison result and the similarities and differences between the verification result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the prior verification data is determined according to a preset answer to the monitoring question.
5. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 1-4, characterized in that, After determining that one or more signature verification results are different, the method further includes: The host sends the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor; The trust anchor decrypts the digital signature of the actual transmission content data to obtain a decrypted actual content summary, determines the actual content summary after transmission according to the actual transmission content data, and determines a re-verification answer according to the re-verification question while decrypting to obtain the decrypted actual content summary and determining the actual content summary after transmission, generates new trust verification data based on the re-verification answer and the actual content summary after transmission, compares the decrypted actual content summary with the actual content summary after transmission to obtain a new trust anchor verification result, and sends the new trust anchor verification result, the new trust verification data and the decrypted actual content summary to the verification process monitoring module; The verification process monitoring module determines new host verification data according to the decrypted actual content summary and the standard verification answer to the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host verification result, and determines the similarities and differences between the new host verification result and the new trust anchor verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
6. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 2-4, characterized in that, Before the signature verification process monitoring module sends the monitoring question to the trust anchor, the method includes any one of the following: Obtaining a preset question, and determining the preset question as the monitoring question; Acquire multiple preset questions, and determine one or more selected preset questions as the monitoring questions; Acquire a sent monitoring question and a plurality of preset questions, filter out the sent monitoring question from the plurality of preset questions, and determine the one or more preset questions after the filter out as the monitoring question; Obtain sent monitoring questions and multiple preset questions, determine the multiple randomly selected preset questions as pre-selected questions, if the question content of the pre-selected questions is the same as the question content of the sent monitoring questions, adjust the question order of the multiple preset questions in the pre-selected questions so that the question order of the pre-selected questions is different from the question order of the sent monitoring questions, and determine the adjusted pre-selected questions as the monitoring questions.
7. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 3 or 4, characterized in that Determine the answer based on the monitoring question, including: The trust anchor matches the monitoring question with a plurality of preset local questions in a preset question answer table, and if the monitoring question is successfully matched with a preset local question, determines a preset local answer corresponding to the preset local question as a first answer sub-answer, wherein the preset question answer table includes at least one preset local question and a preset local answer corresponding to each preset local question, and the trust anchor stores the preset question answer table; The trust anchor triggers a preset function module based on the monitoring problem to output a function answer, and determines the function answer as the second answer sub-answer. The preset function module is set in the trust anchor; The trust anchor collects one or more monitoring results of its own security mechanisms based on the monitoring problem, and determines the one or more monitoring results of its own security mechanisms as the third answer sub-answer; The trust anchor generates the answer based on at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.
8. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 3 or 4, characterized in that The determination method of the preset answer of the monitoring problem includes: The signature verification process monitoring module matches the monitoring problem with multiple preset local problems in the preset problem answer table. If the match with a preset local problem is successful, the preset local answer corresponding to the preset local problem is determined as the first preset sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The signature verification process monitoring module stores the problem answer table; The signature verification process monitoring module triggers a preset function module based on the monitoring problem to output a function answer, and determines the function answer as the second preset sub-answer. The preset function module is set in the signature verification process monitoring module; The signature verification process monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as the third preset sub-answer based on the monitoring problem; The signature verification process monitoring module generates the preset answer based on at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer.
9. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 5, characterized in that, Before the host obtains the data to be transmitted and the digital signature, the method includes: The data sender calculates the original digital digest based on the original content data; The data sender encrypts the original digital digest to generate the original signature; The data sender sends the original content data and the original signature to the host, so that the host receives the original content data as the actual transmitted content data, and uses the original signature as the digital signature of the actual transmitted content data.
10. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 1-4, characterized in that, Before the host obtains the data to be transmitted and the digital signature, the method includes: The host receives the original content data sent by the data sender and uses it as the actual transmitted content data; Determine the estimated actual digest calculation time of the actual transmitted content data; If the estimated actual digest calculation time is greater than or equal to the preset duration threshold, determine the preset verification data as the data to be transmitted. The estimated preset digest calculation time of the preset verification data is less than the preset duration threshold; If the estimated actual digest calculation time is less than the preset duration threshold, determine the actual transmitted content data as the data to be transmitted.
11. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 10, wherein If the preset verification data is determined as the data to be transmitted, the method further includes: The host sends the actual transmitted content data and the actual digital signature of the actual transmitted content data to the trust anchor; The trust anchor decrypts the actual digital signature of the actual transmitted content data to obtain a decrypted actual content digest, and determines a post-transmission actual content digest based on the received actual transmitted content. A fourth comparison is performed between the decrypted actual content digest and the post-transmission actual content digest, and a new trust anchor signature verification result is determined based on the fourth comparison result, and the credibility of the new trust anchor signature verification result is enhanced.
12. The method for improving the credibility of the digital signature verification process of the trust anchor according to claim 10, characterized in that, The trust anchor decrypts the digital signature of the actual transmitted content data with a first sub-decryption key; The trust anchor decrypts the digital signature of the preset verification data with a second sub-decryption key; Wherein, the first sub-decryption key is the same as or different from the second sub-decryption key.
13. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 1-4, characterized in that, Before the trust anchor decrypts the digital signature to obtain a decrypted digital digest, the method includes: Storing the decryption key in the trust anchor for the trust anchor to decrypt the digital signature with the decryption key to obtain a decrypted digital digest; Or, Storing the decryption key in the host in a read-only form, and sending the decryption key to the trust anchor through the host for the trust anchor to decrypt the digital signature with the decryption key to obtain a decrypted digital digest.
14. The method for improving the credibility of the digital signature verification process of the trust anchor according to any one of claims 1-4, characterized in that, The method further includes: Counting the number of events with different signature verification result similarity and difference status within a preset statistical period; If the number of events is greater than a preset number threshold, controlling the controller to enter a preset security state.
15. A controller, characterized in that, The controller includes a trust anchor and a host. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor. Among them: The host is used to obtain the data to be transmitted and the digital signature, and send the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting the original digital digest calculated based on the data to be transmitted; The trust anchor is used to decrypt the digital signature to obtain a decrypted digital digest, and determine a post-transmission digital digest based on the received data to be transmitted. A first comparison is performed between the decrypted digital digest and the post-transmission digital digest, and a trust anchor signature verification result is determined based on the first comparison result. The trust anchor signature verification result and the decrypted digital digest are sent to the signature verification process monitoring module; The signature verification process monitoring module is used to perform a second comparison between the decrypted digital digest and the pre-transmission digital digest, determine a host signature verification result based on the second comparison result, and determine the signature verification result similarity and difference status between the host signature verification result and the trust anchor signature verification result to enhance the credibility of the digital signature verification process of the trust anchor. Among them, the pre-transmission digital digest is determined based on the data to be transmitted.
16. The controller according to claim 15, wherein, The host further includes a trust anchor driver function module, and the trust anchor driver function module is used to obtain the data to be transmitted and the digital signature, send the data to be transmitted and the digital signature to the trust anchor, and receive the trust anchor signature verification result and the decrypted digital digest, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module.
17. The controller according to claim 16, wherein The signature verification process monitoring module is arranged in the trust anchor driving function module.
18. The controller according to claim 15, characterized in that, The host also includes a mode switching module, which is used to determine the estimated actual summary calculation time of the actual transmission content data after the host receives the original content data sent by the data sender and uses it as the actual transmission content data, and determine the data to be transmitted based on the comparison result of the estimated actual summary calculation time and a preset time threshold, the data to be transmitted includes the actual transmission content data or preset verification data, and the estimated preset summary calculation time of the preset verification data is less than the preset time threshold.
19. The controller according to claim 16, characterized in that, The signature verification process monitoring module is further used to determine monitoring issues and send the monitoring issues to the trust anchor driver function module; The trust anchor driver function module is further used to send the monitoring question to the trust anchor; The trust anchor is further used to determine the answer to the monitoring question while decrypting the digital signature to obtain the decrypted digital summary and determining the digital summary after transmission according to the received data to be transmitted, and determine the trust verification data according to the answer and the digital summary after transmission, and send the trust verification data to the trust anchor driving function module; The trust anchor driving function module is further used to send the trust verification data to the signature verification process monitoring module; The verification process monitoring module is further used to perform a third comparison between the trust verification data and the host verification data to obtain a third comparison result, so as to improve the credibility of the digital signature verification process of the trust anchor, wherein the host verification data is determined according to the decrypted digital summary and a preset answer to the monitoring question.
20. The controller according to any one of claims 15-19, characterized in that, The host is further configured to send the received actual transmission content data, the digital signature of the actual transmission content data, and the re-verification question to the trust anchor after the signature verification process monitoring module determines that one or more signature verification results are different or similar; The trust anchor is further used to decrypt the digital signature of the actual transmission content data to obtain a decrypted actual content summary, determine the actual content summary after transmission according to the actual transmission content data, and determine a re-verification answer according to the re-verification question while decrypting to obtain the decrypted actual content summary and determining the actual content summary after transmission, generate new trust verification data based on the re-verification answer and the actual content summary after transmission, compare the decrypted actual content summary with the actual content summary after transmission to obtain a new trust anchor verification result, and send the new trust anchor verification result, new trust verification data and the decrypted actual content summary to the verification process monitoring module; The verification process monitoring module is further used to determine new host verification data according to the decrypted actual content summary and the standard verification answer to the re-verification question, perform a sixth comparison on the new host verification data and the information trust verification data to obtain a new host verification result, and determine the similarities and differences between the new host verification result and the new trust anchor verification result, so as to improve the credibility of the digital signature verification process of the trust anchor.
21. The controller according to claim 18, wherein, The trust anchor driving function module is further configured to send the actual transmission content data and the digital signature of the actual transmission content data to the trust anchor; The trust anchor is further configured to decrypt the actual digital signature of the actual transmission content data to obtain a decrypted actual content digest, and determine a post-transmission actual content digest based on the received actual transmission content, perform a fourth comparison on the decrypted actual content digest and the post-transmission actual content digest, determine a new trust anchor signature verification result based on the fourth comparison result, and enhance the credibility of the new trust anchor signature verification result.
22. The controller according to any one of claims 15-19, characterized in that, The signature verification process monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.
23. A system for improving the credibility of the digital signature verification process of a trust anchor, characterized in that, The system for enhancing the credibility of the digital signature verification process of the trust anchor includes a data sender and a controller. The controller includes a trust anchor and a host. The host includes a signature verification process monitoring module, and the credibility of the signature verification process monitoring module is higher than that of the trust anchor; The data sender is configured to calculate an original digital digest based on the original content data, encrypt the original digital digest to generate an original signature, and send the original content data and the original signature to the host, so that the host uses the received original content data as the actual transmission content data, and uses the original signature as the digital signature of the actual transmission content data; The host is configured to obtain data to be transmitted and a digital signature, and send the data to be transmitted and the digital signature to the trust anchor. The digital signature is generated by encrypting an original digital digest calculated based on the data to be transmitted, and the data to be transmitted includes the actual transmission content data or preset verification data; The trust anchor is configured to decrypt the digital signature to obtain a decrypted digital digest, and determine a post-transmission digital digest based on the received data to be transmitted, perform a first comparison on the decrypted digital digest and the post-transmission digital digest, determine a trust anchor signature verification result based on the first comparison result, and send the trust anchor signature verification result and the decrypted digital digest to the signature verification process monitoring module; The signature verification process monitoring module is configured to perform a second comparison on the decrypted digital digest and the pre-transmission digital digest, determine a host signature verification result based on the second comparison result, and determine a signature verification result similarity / difference status between the host signature verification result and the trust anchor signature verification result, so as to enhance the credibility of the digital signature verification process of the trust anchor, where the pre-transmission digital digest is determined based on the data to be transmitted.
24. The trust anchor digital signature verification process credibility improvement system according to claim 23, characterized in that, The host is further configured to send the received actual transmission content data, the digital signature of the actual transmission content data, and a re-verification question to the trust anchor after the signature verification process monitoring module determines one or more signature verification result similarity / difference statuses; The trust anchor decrypts the digital signature of the actual transmitted content data to obtain a decrypted actual content digest, determines a post-transmission actual content digest based on the actual transmitted content data, and while decrypting to obtain the decrypted actual content digest and determining the post-transmission actual content digest, determines a re-verification answer according to the re-verification question, generates new trust verification data based on the re-verification answer and the post-transmission actual content digest, compares the decrypted actual content digest with the post-transmission actual content digest to obtain a new trust anchor signature verification result, and sends the new trust anchor signature verification result, the new trust verification data, and the decrypted actual content digest to the signature verification process monitoring module; The signature verification process monitoring module determines new host verification data according to the decrypted actual content digest and the standard verification answer of the re-verification question, performs a sixth comparison on the new host verification data and the information trust verification data to obtain a new host signature verification result, and determines the signature verification result similarity / difference status between the new host signature verification result and the new trust anchor signature verification result to enhance the credibility of the digital signature verification process of the trust anchor.
25. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method according to any one of claims 1 to 14.
26. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the method according to any one of claims 1 to 14.