Method for improving credibility of symmetric encryption algorithm of trust anchor, controller, equipment and medium

Through the coordinated work of the trust anchor and the encryption monitoring module, the credibility of the symmetric encryption algorithm of the MCU's HSM module is improved, and the problem that the HSM side ciphertext comparison results cannot guarantee the functional safety level is solved, and the application in key functional safety scenarios is realized.

CN120378126APending Publication Date: 2025-07-25UNITED AUTOMOTIVE ELECTRONICS SYST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410103105.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-24
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The hardware resources of the MCU's HSM module are not developed in accordance with functional safety standards, resulting in the comparison results of the actual ciphertext, actual ciphertext and target ciphertext obtained by the HSM side cannot guarantee the functional safety level and cannot be applied to critical functional safety scenarios.

Method used

The trust anchor and encryption monitoring module were introduced, and the trust anchor had low credibility, but the actual ciphertext was generated through the symmetric encryption algorithm and the trust verification data was generated based on the monitoring problem. The encryption monitoring module had a high credibility and compared, improving the credibility of the symmetric encryption algorithm.

Benefits of technology

Without affecting the host function, the computing function security level of the symmetric encryption algorithm of trust anchors is improved, and a solution to replace and supplement the existing functional security mechanism is provided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378126A_ABST
    Figure CN120378126A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of vehicles, and discloses a method for improving the credibility of a symmetric encryption algorithm of a trust anchor, a controller, equipment and a medium, and the method comprises the steps: encrypting to-be-transmitted data through the trust anchor with lower credibility in an encryption execution stage of the trust anchor to obtain an actual ciphertext; and determining a first answer according to the first monitoring question in the encryption process, further generating first trust verification data according to the first answer and the actual ciphertext, and generating first host verification data based on the first preset answer and the target ciphertext through an encryption monitoring module with relatively high credibility. And performing first comparison on the first trust verification data and the first host verification data, so that the computing function security level of the symmetric encryption algorithm of the trust anchor can be improved on the premise of not influencing the functions of the host, and a scheme for replacing and supplementing an existing function security mechanism is provided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicles, and in particular to a method for improving the credibility of a symmetric encryption algorithm of a trust anchor, a controller, a device, and a medium. Background Art

[0002] To further improve the safety design of road vehicle-related products and evaluate the safety level of automobiles, ISO26262 "Functional Safety of Road Vehicles" evaluates the safety levels for different safety objectives based on the analysis of risks and hazards of the whole vehicle under various working conditions, introduces the concept of Automotive Safety Integrity Level (ASIL), and defines four different ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. Among them, ASIL D represents the highest safety integrity, while ASIL A represents the lowest safety integrity. In addition, if the identified risk is QM, there is no corresponding safety requirement. That is, from QM, ASIL-A / B / C / D, the functional safety has gradually become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.

[0003] With the improvement of the vehicle networking level, there will be more and more interactions between future functional safety and information security. On the one hand, ensuring information security is the basis for realizing functional safety; on the other hand, functional safety may also need to rely on information security mechanisms to achieve. To meet the requirements of storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments, a trust anchor needs to be equipped. The implementation methods of the trust anchor in MCU (Micro Controller Unit) applications are such as HSM (Hardware Security Module), etc.

[0004] In related technologies, some HSM firmware follows the requirements of the functional safety process for development, but currently, there are still a large number of HSM module hardware of MCUs that are not developed according to the functional safety standards, that is, there is no corresponding functional safety mechanism to cover the failure of their hardware resources. In the design of MCUs with HSMs, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module.

[0005] Symmetric Cryptography is an encryption method in which the same key is used for both encryption and decryption, and the key needs to be securely transmitted between the sender and the receiver. Due to the fact that symmetric cryptography algorithms are public, have a small computational load, fast encryption speed, and high encryption efficiency, they are currently widely used in the field of automotive information security, such as verifying software, message integrity, confidentiality, etc. Common symmetric cryptography algorithms include: AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc. In related technologies, the original content is sent to the HOST side as the actual content of the HOST side. Based on the symmetric encryption algorithm of the HSM, the HSM driver function located on the HOST side of the HSM is first called to transfer the actual content to the HSM firmware on the HSM side, and then the symmetric encryption calculation is triggered. After the calculation is completed, the actual ciphertext or the comparison result between the actual ciphertext and the target ciphertext can be fed back from the HSM side to the HOST side; the decryption process is similar. The target ciphertext is the ciphertext obtained by pre-encrypting the original content through symmetric encryption.

[0006] Since the hardware resources on the HSM side are not currently covered by a functional safety mechanism, the actual ciphertext obtained on it, the comparison result between the actual ciphertext and the target ciphertext, and the original content decrypted from the ciphertext cannot guarantee the functional safety level and can only be considered QM, and cannot be applied to functional safety critical scenarios. Summary of the Invention

[0007] The embodiments of the present invention provide a method, a controller, a device, and a medium for improving the credibility of the symmetric encryption algorithm of a trust anchor to solve the technical problem in related technologies that since the HSM module hardware of the MCU is not developed according to the functional safety standard, that is, the failure of its hardware resources is not covered by the corresponding functional safety mechanism, the actual ciphertext obtained on the HSM side, the comparison result between the actual ciphertext and the target ciphertext, and the original content decrypted from the ciphertext cannot guarantee the functional safety level and can only be considered QM, and cannot be applied to functional safety critical scenarios.

[0008] An embodiment of the present invention provides a method for improving the credibility of a symmetric encryption algorithm of a trust anchor, which is applied to a controller. The controller includes a trust anchor and a host, and the host includes an encryption monitoring module. The credibility of the encryption monitoring module is higher than that of the trust anchor. The method includes: the host obtains data to be transmitted, a target ciphertext, and a first monitoring problem, and sends the data to be transmitted and the first monitoring problem to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted; the trust anchor encrypts the data to be transmitted based on a symmetric encryption algorithm to obtain an actual ciphertext, and during the process of encrypting the data to be transmitted, determines a first answer according to the first monitoring problem, generates first trust verification data based on the first answer and the actual ciphertext, and sends the first trust verification data to the encryption monitoring module; the encryption monitoring module generates first host verification data according to the target ciphertext and a first preset answer of the first monitoring problem, and performs a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result.

[0009] In an embodiment of the present invention, the method further includes: the host sends the target ciphertext to the trust anchor; the trust anchor performs a second comparison between the target ciphertext and the actual ciphertext, determines a trust anchor integrity verification result based on the second comparison result, and sends the trust anchor integrity verification result to the encryption monitoring module; the encryption monitoring module performs a seventh comparison based on the trust anchor integrity verification result and the first comparison result to obtain a seventh comparison result.

[0010] In an embodiment of the present invention, the method further includes: after performing a first comparison between the first host verification data and the first trust verification data, the host obtains new data to be transmitted, a new target ciphertext, and a new first monitoring problem, and sends the new data to be transmitted, the new target ciphertext, and the new first monitoring problem to the trust anchor. The new target ciphertext is determined by encrypting the new data to be transmitted. The new data to be transmitted may be the same as or different from the data to be transmitted, and the new first monitoring problem may be the same as or different from the first monitoring problem. The trust anchor encrypts the new data to be transmitted to obtain a new actual ciphertext, and during the process of encrypting the new data to be transmitted, determines a new first answer based on the new first monitoring problem, generates new first trust verification data based on the new first answer and the new actual ciphertext. The trust anchor performs a third comparison between the new target ciphertext and the new actual ciphertext, determines the trust anchor integrity verification result based on the third comparison result, and sends the new first trust verification data and the trust anchor integrity verification result to the encryption monitoring module. The encryption monitoring module generates new first host verification data according to the new target ciphertext and a new first preset answer to the new first monitoring problem, and performs a fourth comparison between the new first host verification data and the new first trust verification data to obtain a fourth comparison result.

[0011] In an embodiment of the present invention, before the host obtains the data to be transmitted and the target ciphertext, the method includes: the data sender calculates an original ciphertext according to the original content data; the data sender sends the original content data and the original ciphertext to the host, so that the host receives the original content data as the actual transmitted content data, uses the original ciphertext as the target ciphertext of the actual transmitted content data, and determines the actual transmitted content data as the data to be transmitted.

[0012] In an embodiment of the present invention, before the host obtains the data to be transmitted and the target ciphertext, the method includes: the data sender sends the original content data to the host; if the host does not receive the original ciphertext of the original content data, determines the preset verification data as the data to be transmitted, and determines the preset ciphertext of the preset verification data as the target ciphertext, where the preset ciphertext is obtained by encrypting the preset verification data.

[0013] In an embodiment of the present invention, if the preset ciphertext is an incorrect ciphertext of the preset verification data, performing a first comparison between the first host verification data and the first trust verification data includes: if the first host verification data is different from the first trust verification data, determining that the monitoring of the symmetric encryption algorithm for the trust anchor passes; if the first host verification data is the same as the first trust verification data, determining that the monitoring of the symmetric encryption algorithm for the trust anchor fails.

[0014] In an embodiment of the present invention, after performing the first comparison between the first host verification data and the first trust verification data, the method further includes: the host uses the received original content data as the actual transmitted content data and sends it to the trust anchor for the trust anchor to encrypt the actual transmitted content data to obtain a content ciphertext.

[0015] In an embodiment of the present invention, the host obtains a first monitoring problem, including any one of the following: obtaining a preset problem and determining the preset problem as the first monitoring problem; obtaining multiple preset problems and determining one or more selected preset problems as the first monitoring problem; obtaining a sent first monitoring problem and multiple preset problems, screening out the sent first monitoring problem from the multiple preset problems, and determining one or more screened preset problems as the first monitoring problem; obtaining a sent first monitoring problem and multiple preset problems, determining multiple randomly selected preset problems as preselected problems, if the problem content of the preselected problems is the same as the problem content of the sent first monitoring problem, adjusting the problem order of the multiple preset problems in the preselected problems so that the problem order of the preselected problems is different from the problem order of the sent first monitoring problem, and determining the adjusted preselected problems as the first monitoring problem.

[0016] In an embodiment of the present invention, determining a first answer to the first monitoring problem includes: the trust anchor matching the first monitoring problem with a plurality of preset local problems in a preset question-answer table. If a match is successful with a preset local problem, determining the preset local answer corresponding to the preset local problem as a first answer sub-answer. The preset question-answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem, and the trust anchor stores the preset question-answer table; the trust anchor triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as a second answer sub-answer, and the trust anchor is provided with the preset function module; the trust anchor collects one or more monitoring results of its own security mechanisms based on the first monitoring problem, and determines the one or more monitoring results of its own security mechanisms as a third answer sub-answer; the trust anchor generates the first answer based on at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.

[0017] In an embodiment of the present invention, before the encryption monitoring module generates first host verification data according to the target ciphertext and the first preset answer to the first monitoring problem, the method includes: the encryption monitoring module matching the first monitoring problem with a plurality of preset local problems in a preset question-answer table. If a match is successful with a preset local problem, determining the preset local answer corresponding to the preset local problem as a first preset sub-answer. The preset question-answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem, and the encryption monitoring module stores the question-answer table; the encryption monitoring module triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as a second preset sub-answer, and the encryption monitoring module is provided with the preset function module; the encryption monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as a third preset sub-answer based on the first monitoring problem; the encryption monitoring module generates the first preset answer based on at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; the encryption monitoring module determines the first host verification data according to the target ciphertext and the first preset answer.

[0018] In an embodiment of the present invention, the trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, including: if the actual transmission content data is determined as the data to be transmitted, the trust anchor encrypts the actual transmission content data with a first sub-encryption key to obtain the actual ciphertext; if the preset verification data is determined as the data to be transmitted, the trust anchor encrypts the preset verification data with a second sub-encryption key to obtain the actual ciphertext; wherein, the first sub-encryption key and the second sub-encryption key are the same or different.

[0019] In an embodiment of the present invention, before the trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, the method includes: storing the encryption key in the trust anchor for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext; or storing the encryption key in the host in a read-only form, and sending the encryption key to the trust anchor by the host for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext.

[0020] In an embodiment of the present invention, the method further includes: counting the number of occurrences of a first event of an encryption target event in a preset statistical period, where the encryption target event includes at least one of the following: the first comparison result is different, the seventh comparison result is different, and the fourth comparison result is different; if the number of occurrences of the first event is greater than a first preset quantity threshold, controlling the controller to enter a preset security state.

[0021] In an embodiment of the present invention, the method further includes: receiving new original content data sent by a data sender as new actual transmission content data; determining a new estimated actual ciphertext calculation time for the new actual transmission content data; if the new estimated actual ciphertext calculation time is greater than or equal to a preset duration threshold, sending the new actual transmission content data to the trust anchor to encrypt the new actual transmission content data by the trust anchor to obtain a new actual ciphertext; if the new estimated actual ciphertext calculation time is less than the preset duration threshold, encrypting the new actual transmission content data by an encryption monitoring module or the trust anchor to obtain a new actual ciphertext.

[0022] An embodiment of the present invention also provides a method for improving the credibility of the symmetric encryption algorithm of a trust anchor. The controller includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: the host obtains a ciphertext to be transmitted and a second monitoring question, and sends the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content based on the symmetric encryption algorithm; the trust anchor decrypts the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determines a second answer according to the second monitoring question, generates second trust verification data based on the second answer and the decrypted transmission data, and sends the second trust verification data and the decrypted transmission data to the decryption monitoring module; the decryption monitoring module generates second host verification data according to the decrypted transmission data and the second preset answer of the second monitoring question, and compares the second host verification data with the second trust verification data to obtain a fifth comparison result.

[0023] In an embodiment of the present invention, the method includes: the host obtains a preset verification ciphertext, preset verification data, and a third monitoring question, and sends the preset verification ciphertext and the third monitoring question to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring question is the same as or different from the second monitoring question; the trust anchor decrypts the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determines a third answer according to the third monitoring question, generates third trust verification data based on the third answer and the decrypted verification data, and sends the third trust verification data to the decryption monitoring module; the decryption monitoring module generates third host verification data according to the preset verification data and the third preset answer of the third monitoring question, and compares the third host verification data with the third trust verification data to obtain a sixth comparison result 。

[0024] In an embodiment of the present invention, the host obtains a second monitoring problem, including any one of the following: obtaining a preset problem and determining the preset problem as the second monitoring problem; obtaining multiple preset problems and determining one or more selected preset problems as the second monitoring problem; obtaining multiple preset problems and the second monitoring problems that have been sent, screening out the second monitoring problems that have been sent from the multiple preset problems, and determining one or more preset problems after screening as the second monitoring problem; obtaining multiple preset problems and the second monitoring problems that have been sent, determining multiple randomly selected preset problems as preselected problems, if the problem content of the preselected problems is the same as the problem content of the second monitoring problems that have been sent, adjusting the problem sorting of the multiple preset problems in the preselected problems so that the problem sorting of the preselected problems is different from the problem sorting of the second monitoring problems that have been sent, and determining the adjusted preselected problems as the second monitoring problem.

[0025] In an embodiment of the present invention, determining a second answer according to the second monitoring problem includes: the trust anchor matches the second monitoring problem with multiple preset local problems in a preset problem answer table, if a match is successful with a preset local problem, determining the preset local answer corresponding to the preset local problem as a fourth answer sub - answer, the preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem, and the trust anchor stores the preset problem answer table; the trust anchor triggers a preset function module based on the second monitoring problem to output a function answer, and determines the function answer as a fifth answer sub - answer, and the trust anchor is provided with the preset function module; the trust anchor collects one or more monitoring results of its own security mechanisms based on the second monitoring problem, and determines the one or more monitoring results of its own security mechanisms as a sixth answer sub - answer; the trust anchor generates the second answer according to at least one of the fourth answer sub - answer, the fifth answer sub - answer, and the sixth answer sub - answer.

[0026] In an embodiment of the present invention, before the decryption monitoring module generates second host verification data according to the decrypted transmission data and the second preset answer to the second monitoring question, the method includes: the decryption monitoring module matches the second monitoring question with a plurality of preset local questions in a preset question answer table, if it matches a preset local question successfully, determines the preset local answer corresponding to the preset local question as a fourth preset sub-answer, the preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question, and the decryption monitoring module stores the question answer table; the decryption monitoring module triggers a preset function module to output a function answer based on the second monitoring question, and determines the function answer as a fifth preset sub-answer, and the decryption monitoring module is provided with the preset function module; the decryption monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as a sixth preset sub-answer based on the second monitoring question; the decryption monitoring module generates the second preset answer according to at least one of the fourth preset sub-answer, the fifth preset sub-answer and the sixth preset sub-answer.

[0027] In an embodiment of the present invention, the trust anchor decrypting the preset verification ciphertext to obtain decrypted verification data includes that the trust anchor decrypts the preset verification ciphertext through a first decryption sub-key to obtain decrypted verification data; the trust anchor decrypting the ciphertext to be transmitted to obtain decrypted transmission data includes that the trust anchor decrypts the ciphertext to be transmitted through a second decryption sub-key to obtain decrypted transmission data; wherein, the first decryption sub-key and the second decryption sub-key are the same or different.

[0028] In an embodiment of the present invention, if the number of the preset verification ciphertexts is multiple, at least one of the preset verification ciphertexts is the correct ciphertext of the preset verification data, and at least one of the preset verification ciphertexts is the incorrect ciphertext of the preset verification data. Determining a sixth comparison sub-result according to each preset verification ciphertext, and determining the final sixth comparison result based on all the sixth comparison sub-results includes: If the preset verification ciphertext is the correct ciphertext of the preset verification data, the method for determining the sixth comparison sub-result includes: If the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as a correct result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as an incorrect result; If the preset verification ciphertext is the incorrect ciphertext of the preset verification data, the method for determining the sixth comparison sub-result includes: If the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as a correct result; if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as an incorrect result; Counting the number of results where the sixth comparison sub-result is an incorrect result; If the number of results is less than the preset result threshold, determining that the monitoring passes; if the number of results is greater than or equal to the preset result threshold, controlling the controller to enter a preset safe state.

[0029] In an embodiment of the present invention, the method further includes: If all the preset verification ciphertexts are the correct ciphertexts of the preset verification data, determining a sixth comparison sub-result according to each preset verification ciphertext, and determining the final sixth comparison result based on all the sixth comparison sub-results includes: If the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as a correct result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as an incorrect result; Counting the number of results where the sixth comparison sub-result is an incorrect result; If the number of results is less than the preset result threshold, determining that the monitoring passes; if the number of results is greater than or equal to the preset result threshold, controlling the controller to enter a preset safe state.

[0030] In an embodiment of the present invention, the method further includes: if all the preset verification ciphertexts are incorrect ciphertexts of the preset verification data, determining a sixth comparison sub-result according to each preset verification ciphertext, and determining a final sixth comparison result based on all the sixth comparison sub-results, including: if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as an incorrect result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as a correct result; counting the number of results where the sixth comparison sub-result is an incorrect result; if the number of results is less than a preset result threshold, determining that the monitoring passes; if the number of results is greater than or equal to the preset result threshold, controlling the controller to enter a preset security state.

[0031] In an embodiment of the present invention, before the trust anchor decrypts the ciphertext to be transmitted to obtain decrypted transmission data, the method includes: storing the decryption key in the trust anchor for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data; or storing the decryption key in the host in a read-only form, and sending the decryption key to the trust anchor by the host for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data.

[0032] In an embodiment of the present invention, the method further includes: counting the number of occurrences of a second event of a decryption target event in a preset statistical period, where the decryption target event includes at least one of the following: the fifth comparison result is incorrect, and the sixth comparison result is incorrect; if the number of occurrences of the second event is greater than a second preset quantity threshold, controlling the controller to enter a preset security state.

[0033] In an embodiment of the present invention, before the host sends the ciphertext to be transmitted and a second monitoring problem to the trust anchor, the method includes: determining the estimated decryption content calculation time of the ciphertext to be transmitted; if the decryption content calculation time is greater than or equal to a preset duration threshold, triggering the sending of the ciphertext to be transmitted and the second monitoring problem to the trust anchor; if the decryption content calculation time is less than the preset duration threshold, decrypting the ciphertext to be transmitted by the host to obtain decrypted transmission data, or triggering the sending of the ciphertext to be transmitted and the second monitoring problem to the trust anchor.

[0034] An embodiment of the present invention further provides a method for improving the credibility of the symmetric encryption algorithm of a trust anchor. The controller includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: the host obtains a preset verification ciphertext, preset verification data, and a third monitoring question, and sends the preset verification ciphertext and the third monitoring question to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring question is the same as or different from the second monitoring question; the trust anchor decrypts the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determines a third answer according to the third monitoring question, generates third trust verification data based on the third answer and the decrypted verification data, and sends the third trust verification data to the decryption monitoring module; the decryption monitoring module generates third host verification data according to the preset verification data and the third preset answer of the third monitoring question, and compares the third host verification data with the third trust verification data to obtain a sixth comparison result.

[0035] An embodiment of the present invention further provides a controller. The controller includes a trust anchor and a host. The host includes an encryption monitoring module and a decryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. Wherein: the host is used to obtain data to be transmitted, a target ciphertext, and a first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted; the trust anchor is used to encrypt the data to be transmitted based on the symmetric encryption algorithm to obtain an actual ciphertext, and during the process of encrypting the data to be transmitted, determines a first answer according to the first monitoring question, generates first trust verification data based on the first answer and the actual ciphertext, and sends the first trust verification data to the encryption monitoring module; the encryption monitoring module is used to generate first host verification data according to the target ciphertext and the first preset answer of the first monitoring question, and compare the first host verification data with the first trust verification data to obtain a first comparison result.

[0036] An embodiment of the present invention further provides a controller, the controller includes a trust anchor and a host, the host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor, wherein: the host is used to obtain a ciphertext to be transmitted and a second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor, and the ciphertext to be transmitted is obtained by encrypting the original content based on a symmetric encryption algorithm; the trust anchor is used to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain decrypted transmission data, and during the decryption of the ciphertext to be transmitted, determine a second answer according to the second monitoring question, generate second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module; the decryption monitoring module is used to generate second host verification data according to the decrypted transmission data and the second preset answer of the second monitoring question, and perform a fifth comparison between the second host verification data and the second trust verification data to obtain a fifth comparison result.

[0037] An embodiment of the present invention further provides a controller, the controller includes a trust anchor and a host, the host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor, wherein: the host is used to obtain a preset verification ciphertext, preset verification data and a third monitoring question, and send the preset verification ciphertext and the third monitoring question to the trust anchor, the preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring question is the same as or different from the second monitoring question; the trust anchor is used to decrypt the preset verification ciphertext based on a symmetric encryption algorithm to obtain decrypted verification data, and during the decryption of the preset verification ciphertext, determine a third answer according to the third monitoring question, generate third trust verification data based on the third answer and the decrypted verification data, and send the third trust verification data to the decryption monitoring module; the decryption monitoring module is used to generate third host verification data according to the preset verification data and the third preset answer of the third monitoring question, and perform a sixth comparison between the third host verification data and the third trust verification data to obtain a sixth comparison result.

[0038] An embodiment of the present invention further provides a controller, which includes a trust anchor and a host. The host includes an encryption monitoring module and a decryption monitoring module. The credibility of the encryption monitoring module is higher than that of the trust anchor, and the credibility of the decryption monitoring module is higher than that of the trust anchor. Wherein: The host is configured to obtain data to be transmitted, a target ciphertext, and a first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted; The trust anchor is configured to encrypt the data to be transmitted based on a symmetric encryption algorithm to obtain an actual ciphertext, and during the process of encrypting the data to be transmitted, determine a first answer according to the first monitoring question, generate first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module; The encryption monitoring module is configured to generate first host verification data according to the target ciphertext and a first preset answer of the first monitoring question, and perform a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result; The host is further configured to obtain a ciphertext to be transmitted and a second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content based on a symmetric encryption algorithm; The trust anchor is further configured to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determine a second answer according to the second monitoring question, generate second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module; The decryption monitoring module is configured to generate second host verification data according to the decrypted transmission data and a second preset answer of the second monitoring question, and perform a fifth comparison between the second host verification data and the second trust verification data to obtain a fifth comparison result.

[0039] An embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any one of the above embodiments is implemented.

[0040] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method described in any one of the above embodiments is implemented.

[0041] In the solution implemented by the method, controller, device, and medium for enhancing the credibility of the symmetric encryption algorithm of the trust anchor provided above, in the encryption stage of the trust anchor, the method for enhancing the credibility of the symmetric encryption algorithm of the trust anchor encrypts the data to be transmitted through a trust anchor with relatively low credibility to obtain the actual ciphertext, determines the first answer based on the first monitoring problem during the encryption process, and then generates the first trust verification data based on the first answer and the actual ciphertext. The first host verification data is generated by the encryption monitoring module with relatively high credibility based on the first preset answer and the target ciphertext. The first trust verification data is compared with the first host verification data for the first time to enhance the credibility of the symmetric encryption algorithm of the trust anchor. It can achieve enhancing the computational functional safety level of the symmetric encryption algorithm of the trust anchor without affecting the host function, and provides a solution to replace and supplement the existing functional safety mechanism.

[0042] Optionally, in the decryption stage of the trust anchor, the method for enhancing the credibility of the symmetric encryption algorithm of the trust anchor decrypts the transmitted ciphertext through a trust anchor with relatively low credibility to obtain the decrypted transmission data, determines the second answer based on the second monitoring problem during the decryption process, and then generates the second trust verification data based on the second answer and the decrypted transmission data. The second host verification data is generated by the decryption monitoring module with relatively high credibility based on the second preset answer and the decrypted transmission data. The second trust verification data is compared with the second host verification data for the fifth time to enhance the credibility of the symmetric encryption algorithm of the trust anchor. The decryption monitoring module with relatively high credibility determines the decryption trust status, which can achieve enhancing the computational functional safety level of the original content (i.e., the decrypted transmission data) obtained by decrypting the transmitted ciphertext by the trust anchor without affecting the host function, enhancing the credibility of the symmetric encryption algorithm of the trust anchor, and providing a solution to replace and supplement the existing functional safety mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0044] Figure 1 A schematic diagram of a symmetric encryption algorithm provided for an embodiment of the invention;

[0045] Figure 2 A flowchart of the method for enhancing the credibility of the symmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;

[0046] Figure 3A specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0047] Figure 4 For Figure 3 A specific flowchart of the monitoring stage of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor;

[0048] Figure 5 For Figure 3 A data transmission diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided;

[0049] Figure 6 Another specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0050] Figure 7 For Figure 6 A specific flowchart of the monitoring stage of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor;

[0051] Figure 8 For Figure 6 A data transmission diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided;

[0052] Figure 9 Another specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0053] Figure 10 For Figure 9 A specific flowchart of the monitoring stage of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor;

[0054] Figure 11 For Figure 9 A data transmission diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided;

[0055] Figure 12 Another specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0056] Figure 13 Another specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0057] Figure 14 A flowchart of the method for determining the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0058] Figure 15A specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0059] Figure 16 A specific flowchart of the method for monitoring the symmetric encryption process at the HSM end provided by the embodiment of the present invention;

[0060] Figure 17 For Figure 16 A data transmission diagram of the method for monitoring the symmetric encryption process at the HSM end provided;

[0061] Figure 18 A specific flowchart of the method for monitoring the data transmission process of transmitting the decrypted original content from the HSM end to the HOST end provided by the embodiment of the present invention;

[0062] Figure 19 For Figure 18 A data transmission diagram of the method for monitoring the data transmission process of transmitting the decrypted original content from the HSM end to the HOST end provided;

[0063] Figure 20 A structural diagram of the controller provided by the embodiment of the present invention;

[0064] Figure 21 Another structural diagram of the controller provided by the embodiment of the present invention;

[0065] Figure 22 Another structural diagram of the controller provided by the embodiment of the present invention;

[0066] Figure 23 A structural diagram of an electronic device in an embodiment of the present invention;

[0067] Figure 24 Another structural diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners

[0068] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0069] To enable those skilled in the art to better understand the improvements in the technical solutions provided by the present disclosure, the present disclosure briefly introduces the implementation method of the symmetric encryption algorithm based on HSM and related information in the related art.

[0070] A Trust Anchor is a module required to meet the requirements for storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments. In MCU applications, the implementation methods of Trust Anchor include Secure Hardware Extension (SHE), Hardware Security Module (HSM), Secure Element (SE), etc. Among them, HSM is a specification proposed by the E-safety Vehicle Intrusion protected Applications (EVITA, 2008 - 2011), a research project on vehicle communication security for Vehicle to Everything (V2X) in the European Union, which is divided into three levels: Light, Medium, and Full. Currently, the mainstream automotive-grade MCUs are equipped with Hardware Security Modules (HSMs), and the Full level has become a trend to meet the information security requirements of vehicle controllers.

[0071] Symmetric Cryptography is an algorithm widely used in the field of automotive information security. It is a type of encryption method where the same key is used for both encryption and decryption. Since symmetric encryption algorithms are public, have a small computational amount, fast encryption speed, and high encryption efficiency, they are currently widely used in the field of automotive information security, such as for verifying software, message integrity, confidentiality, etc. Common symmetric encryption algorithms include AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc. Please refer to Figure 1 , Figure 1 a schematic diagram of a symmetric encryption algorithm provided for an invention embodiment, as Figure 1 shown. During the symmetric encryption process, the original data is encrypted by the sender using a key (encryption key) to obtain an encrypted message, which is transmitted to the receiver. The receiver decrypts it using the key (decryption key) to obtain the original data.

[0072] In addition, with the increasing complexity of automotive electronic control systems and the introduction of a large number of electrical and electronic components, while bringing control convenience and diversity, it also brings certain risks to vehicle safety due to inevitable systematic failures and random hardware failures. To further improve the safety design of road vehicle-related products, the ISO26262 road vehicle functional safety standard has been introduced. Based on the analysis of the risks and hazards of the vehicle under various working conditions, this standard assesses the safety levels (Automotive Safety Integrity Level, ASIL) for different safety objectives, gradually increasing from QM, ASIL-A / B / C / D. Currently, functional safety has become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.

[0073] In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module. To improve the calculation speed of the symmetric encryption algorithm, a symmetric encryption algorithm hardware acceleration unit can be equipped on the HSM side. Currently, the implementation of the symmetric encryption algorithm based on HSM first calls the HSM driver function located on the HOST side of the HSM to transfer the actual content to the HSM firmware on the HSM side, and then triggers the symmetric encryption calculation. After the calculation is completed, the actual ciphertext or the comparison result between the actual ciphertext and the target ciphertext (the target ciphertext obtained by symmetric encryption based on the original content) can be fed back from the HSM side to the HOST side; the decryption process is similar.

[0074] Since the hardware resources on the HSM side are currently not covered by a functional safety mechanism, the actual ciphertext, the comparison result between the actual ciphertext and the target ciphertext, and the original content decrypted from the ciphertext obtained on it cannot guarantee the functional safety level and can only be considered as QM, and cannot be applied to functional safety critical scenarios.

[0075] It can be foreseen that there will be more and more interactions between functional safety and information security in the future. On the one hand, because ensuring information security is the basis for achieving functional safety; secondly, functional safety may also need to rely on information security mechanisms to achieve. Although some HSM firmware (software running on the HSM) follows the requirements of the functional safety process for development, the HSM module hardware of current mainstream MCUs has not been developed according to the functional safety standard, that is, there is no corresponding functional safety mechanism to cover the failure of its hardware resources. Therefore, how to improve the functional safety level of information security mechanisms is a brand-new topic.

[0076] For current mainstream MCUs, the HOST side has a perfect functional safety mechanism to ensure that the diagnostic coverage rate of its hardware failures can meet the requirements of the highest ASIL-D; moreover, it has at least one secure core with a Lockstep mechanism, and the Lockstep mechanism can make the diagnostic coverage rate of the MCU core meet the requirements of ASIL-D.

[0077] If directly calculated through the secure core on the HOST side, although the correctness of the symmetric encryption algorithm calculation can be ensured, since the symmetric encryption algorithm has high requirements for computing power, it will occupy a large amount of computing power on the HOST side and affect the normal function. Based on this, the embodiment of the present application designs a solution for improving the functional safety level of the symmetric encryption algorithm based on HSM.

[0078] The MCU hardware resources used to implement the symmetric encryption algorithm calculation from the HSM side mainly include: the CPU, storage, bus, clock, power supply on the HSM side, and the symmetric encryption algorithm hardware acceleration unit. Among them, the clock, power supply are the same as those on the HOST side and can be covered by the HOST side, but other resources need to design additional functional safety mechanisms to cover their failures.

[0079] The inventors found that it is very meaningful and forward-looking to design a solution for improving the functional safety level of the symmetric encryption algorithm based on HSM. To solve the above problems, the embodiment of the present invention proposes a method, a controller, a device and a medium for improving the credibility of the symmetric encryption algorithm of the trust anchor. The solution provided by the present invention will be described in detail through specific embodiments below.

[0080] The method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present application can be applied to the controller MCU. The controller includes a trust anchor Trust Anchor and a host HOST. The host includes at least one of an encryption monitoring module and a decryption monitoring module, and the credibility of the encryption monitoring module and the decryption monitoring module is higher than the credibility of the trust anchor Trust Anchor.

[0081] The credibility in this embodiment can be evaluated by the above-mentioned Automotive Safety Integrity Level (ASIL), or can be implemented using other trust rules set by those skilled in the art. For example, as exemplified in the above embodiment, the credibility of the trust anchor is QM, and the credibility of the host is ASIL D. It should be noted that the encryption (decryption) monitoring module can be a "symmetric encryption (decryption) monitoring software" designed in the security core at the HOST end. In order to achieve the corresponding ASIL level for the integrity check success flag, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to ensure freedom from interference (FFI) with other software of ASIL / QM level. The encryption monitoring module and the decryption monitoring module can be the same entity module or different entity modules.

[0082] In another embodiment, credibility can be understood as the degree of trust that can actually be achieved in an actual application scenario, even in the presence of possible software interference, rather than just referring to the degree of trust calculated during the design of the software or module.

[0083] This method can be applied to application scenarios such as verifying the integrity and confidentiality of software and messages in the field of automotive information security.

[0084] In one embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in this embodiment can be applied to the process of symmetric encryption and decryption of the trust anchor of each controller. That is, in the process of the trust anchor performing symmetric encryption and decryption on the received data each time, the solution of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in this embodiment is executed, so as to ensure the credibility of the symmetric encryption and decryption results of the data received by the trust anchor each time.

[0085] In another embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in this embodiment can also be triggered randomly, or at intervals of a preset detection duration, or at intervals of a preset number of data transmissions, etc., to verify whether the symmetric encryption and decryption results of the trust anchor are credible.

[0086] The encryption monitoring module and the decryption monitoring module can be hardware units with computing capabilities that meet the requirements of the functional safety level, such as: hardware acceleration units, at least one security core with a lockstep mechanism, etc.

[0087] The implementation methods of the trust anchor include, but are not limited to, methods known to those skilled in the art such as SHE, HSM, or SE. In the MCU design with a trust anchor, the MCU can be divided into a trust anchor end (hereinafter referred to as the trust anchor) and a host end (hereinafter referred to as the host). The host is the other part except for modules such as the trust anchor like HSM, and the trust anchor is the module part such as HSM.

[0088] The credibility in this embodiment can be evaluated by the above-mentioned vehicle safety integrity level ASIL, or can also be achieved by other trust rules set by those skilled in the art for the field of functional safety. Functional safety can be understood as the absence of unreasonable risks caused by hazards resulting from abnormal functional manifestations of electronic / electrical systems. For example, as exemplified in the above embodiment, the credibility of the trust anchor is QM, and the credibility of the host is ASIL D. In another embodiment, the credibility can be understood as the trustworthy degree that can actually be achieved in the actual application scenario even in the presence of possible software interferences, rather than only referring to the trustworthy degree calculated during the design of the software or module.

[0089] Please refer to Figure 2 as shown in Figure 2 FIG. 10 is a schematic flowchart of a method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention. The method includes the following steps:

[0090] Step S210, the host obtains the data to be transmitted, the target ciphertext, and the first monitoring problem, and sends the data to be transmitted and the first monitoring problem to the trust anchor.

[0091] Among them, the target ciphertext is determined by encrypting the data to be transmitted.

[0092] The data to be transmitted can be the actual transmission content data that needs to be transmitted according to actual needs or preset verification data set in advance. When the data to be transmitted is the actual transmission content data, the actual transmission content data can be the data sent by the data sender to the MCU and received by the host end. When the data to be transmitted is the preset verification data, it can also be the data set in advance by those skilled in the art.

[0093] The target ciphertext is determined based on the data to be transmitted. When the data to be transmitted is the actual transmitted content data, the target ciphertext is the original ciphertext obtained by encrypting the actual transmitted content data. When the data to be transmitted is the preset verification data, the target ciphertext can be the preset ciphertext which is the correct ciphertext obtained by a trusted device encrypting the preset verification data, or can be a wrong ciphertext different from the correct ciphertext determined after the trusted device encrypts the preset verification data to obtain the correct ciphertext as the preset ciphertext. In other words, in the case where the data to be transmitted is the preset verification data, since the preset ciphertext as the target ciphertext can be intervened by those skilled in the art at this time, the correct ciphertext can be set as the preset ciphertext for subsequent verification, or the wrong ciphertext can be set as the preset ciphertext for verification. The wrong ciphertext is also determined based on the correct ciphertext after obtaining the correct ciphertext by encrypting the preset verification data.

[0094] Before the trust anchor completes the encryption step, it may be at the same time when starting the encryption step or during the encryption process that the host sends the first monitoring question to the trust anchor, so as to be able to answer the first monitoring question during the encryption process of the trust anchor to obtain the first answer. The number of the first monitoring questions can be one or more. If there are multiple ones, the multiple first monitoring questions can be sent at one time or in batches, which can be set by those skilled in the art according to needs. The first monitoring question can also be sent to the trust anchor together with the data to be transmitted.

[0095] In this step, it can be the encryption monitoring module that obtains the data to be transmitted and the target ciphertext, or the driver of the HOST side (HSM HOST Driver) that obtains the data to be transmitted and the target ciphertext and sends them to the trust anchor. Specifically, it can be set by those skilled in the art according to needs.

[0096] In the embodiments of the present application, the "ciphertexts" such as the actual ciphertext, the original ciphertext, the target ciphertext, the ciphertext to be transmitted, and the preset verification ciphertext can be implemented by using hash algorithms such as SHA1, SHA2, MD5, etc. The specific types of the ciphertext algorithms are not limited herein, but in the same symmetric encryption algorithm credibility improvement process of the trust anchor, the same ciphertext algorithm is adopted.

[0097] In this embodiment, multiple generation methods of the first monitoring question are provided, specifically as follows. The host obtains the first monitoring question, including any one of the following:

[0098] Obtain the preset question and determine the preset question as the first monitoring question. It can be understood that if this method is used alone, there will be fixedly one or a set (each set of questions contains multiple sub-questions) of preset monitoring questions, and the same monitoring questions are sent each time.

[0099] Obtain multiple preset questions, and determine one or more selected preset questions as the first monitoring questions. It can be understood that if this method is used alone, there are multiple preset monitoring questions, and one or more of them are selected as the current first monitoring questions each time. The number of questions selected each time can be different or the same. The questions selected in several adjacent times can be the same or at least partially different. The selection method can be random selection or other selection methods set by those skilled in the art. Similar to the previous embodiment, a preset question can be only one question or include multiple questions. If both of the two preset questions include multiple questions, the number of questions included in these two preset questions can be the same or different, and the actual content of the questions can be partially the same or completely different, and specifically can be set by those skilled in the art according to needs;

[0100] Obtain the sent first monitoring questions and multiple preset questions, screen out the sent first monitoring questions from the multiple preset questions, and determine the one or more preset questions after screening as the first monitoring questions. By using this method, it can be ensured that the first monitoring questions sent each time are different from the previous ones. By controlling the sampling range of the sent first monitoring questions, such as the last 20 times, the last 1 day, etc., the possible minimum occurrence period of sending the same first monitoring questions twice can be controlled. The sent first monitoring questions are the first monitoring questions sent in history. The subsequent sent second monitoring questions and sent third monitoring questions can be the monitoring questions sent to the trust anchor before. It can distinguish whether different monitoring processes are used as the corresponding sent monitoring questions, or it can also not distinguish the specific monitoring process, and regard all the monitoring questions sent to the trust anchor as the sent monitoring questions;

[0101] Obtain the sent first monitoring questions and multiple preset questions, determine the randomly selected multiple preset questions as the preselected questions. If the question content of the preselected questions is the same as the question content of the sent first monitoring questions, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the sent first monitoring questions, and determine the adjusted preselected questions as the first monitoring questions. By using this method, on the premise of limited questions, by adjusting the order of the questions, the order in which the trust anchor collects answers can be adjusted, and then the timing of the trust anchor collecting the answers corresponding to the questions can be adjusted. Without adding new preset questions, the effect of increasing the failure coverage rate can also be achieved.

[0102] In one embodiment, multiple preset questions can be divided into different level sets, and there are at least some differences in the types of hardware resources required to answer the preset questions in each level set. In this way, subsequent preset questions in the corresponding level set can be adaptively considered as the first monitoring questions according to the hardware resources that need to be key protected against failure.

[0103] By increasing the number of preset questions, updating the preset questions, making the first monitoring questions issued in recent times different, or switching the order of the questions in the first monitoring questions, etc., the failure coverage rate can be increased. For example, the failure modes are jamming, being too large, and being too small. A first monitoring question may only obtain a conclusion of being too large or too small, but cannot obtain a conclusion of whether there is jamming. At this time, through the participation of multiple first monitoring questions, more failure modes can be detected as much as possible. By increasing the first monitoring questions, especially the first monitoring questions that can only obtain answers by invoking different resources, the more categories of hardware resources used to generate answers, the wider the diagnostic coverage, the more failure situations covered, and the higher the coverage rate.

[0104] It should be noted that the first monitoring questions and the first preset answers corresponding to the first monitoring questions can be preset in advance and stored in the storage space that can be communicatively connected to the host, or stored in the host storage space.

[0105] In step S220, the trust anchor encrypts the data to be transmitted based on the symmetric encryption algorithm to obtain the actual ciphertext. During the process of encrypting the data to be transmitted, the first answer is determined according to the first monitoring question, the first trust verification data is generated based on the first answer and the actual ciphertext, and the first trust verification data is sent to the encryption monitoring module.

[0106] The encryption key is stored in the trust anchor, and this encryption key is the same as the encryption key of the target ciphertext. This can ensure that on the premise of the same data to be transmitted, the target ciphertext encrypted with the same encryption key by different devices is the same as the actual ciphertext.

[0107] In this embodiment, determining a first response answer according to a first monitoring problem includes: The trust anchor matches the first monitoring problem with multiple preset local problems in a preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the first response sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The trust anchor stores the preset problem answer table; The trust anchor triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as the second response sub-answer. The trust anchor is provided with a preset function module; The trust anchor collects one or more monitoring results of its own security mechanisms based on the first monitoring problem, and determines the one or more monitoring results of its own security mechanisms as the third response sub-answer; The trust anchor generates a first response answer according to at least one of the first response sub-answer, the second response sub-answer, and the third response sub-answer. The generation method of the first response answer can be by looking up a table, or obtained through operations of a preset function module such as a Linear Feedback Shift Register (LFSR), or by collecting the monitoring results of the original security mechanism of the trust anchor, or a combination of at least one of the above three methods, or obtained by combining other methods set by those skilled in the art to obtain the first response answer.

[0108] In this embodiment, before the encryption monitoring module generates the first host verification data according to the target ciphertext and the first preset answer of the first monitoring problem, the method includes: The encryption monitoring module matches the first monitoring problem with multiple preset local problems in a preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the first preset sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The encryption monitoring module stores the problem answer table; The encryption monitoring module triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as the second preset sub-answer. The encryption monitoring module is provided with a preset function module; The encryption monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as the third preset sub-answer based on the first monitoring problem; The encryption monitoring module generates a first preset answer according to at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; The encryption monitoring module determines the first host verification data according to the target ciphertext and the first preset answer.

[0109] The host stores a first preset answer corresponding to the first monitoring problem. This first preset answer can be understood as the standard answer. The acquisition method of the first preset answer can be that all are pre-stored in advance, or a preset function the same as the trust anchor is set to achieve the effect of outputting the same answer. The acquisition method of the first preset answer can also be other methods known to those skilled in the art. It should be noted that in this embodiment, it is not limited that the first preset answer and the first answer adopt the same acquisition method, that is, the acquisition methods can be the same or different. However, regardless of whether the first preset answer and the first answer are obtained by the same method, their accurate answers are the same. That is, if the content of the first preset answer is M, then if the trust anchor is trustworthy during the encryption process, the content of the first answer should also be M.

[0110] It should be noted that the calculation of the first trust verification data and the first host verification data in the following text can be implemented by using the CRC (Cyclic Redundancy Check) algorithm or other algorithms known to those skilled in the art that can ensure the integrity of functional safety data.

[0111] For example, the determination method of the first trust verification data is: the trust anchor performs a cyclic redundancy check on the first answer and the actual ciphertext to determine the first trust verification value, and uses this first trust verification value as the first trust verification data.

[0112] In one embodiment, the manner in which the trust anchor sends the first trust verification data to the encryption monitoring module can be that the trust anchor directly sends the first trust verification data to the encryption monitoring module, or the trust anchor sends the first trust verification data to the driver of the HOST side (HSM HOST Driver), and sends it to the encryption monitoring module through this driver.

[0113] Step S230, the encryption monitoring module generates first host verification data according to the target ciphertext and the first preset answer of the first monitoring problem, and performs a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result.

[0114] In one embodiment, if the preset ciphertext is the wrong ciphertext of the preset verification data, performing a first comparison between the first host verification data and the first trust verification data includes: if the first host verification data is different from the first trust verification data, it is determined that the monitoring of the symmetric encryption algorithm of the trust anchor passes; if the first host verification data is the same as the first trust verification data, it is determined that the monitoring of the symmetric encryption algorithm of the trust anchor fails.

[0115] In one embodiment, if the preset verification data is determined as the data to be transmitted, after the first comparison between the first host verification data and the first trust verification data, the method further includes: the host uses the received original content data as the actual transmission content data and sends it to the trust anchor for the trust anchor to encrypt the actual transmission content data to obtain the content ciphertext. At this time, since the credibility improvement algorithm of the symmetric encryption algorithm of the trust anchor has been executed before, the credibility of the content ciphertext is improved.

[0116] In one embodiment, the encryption trust status of the actual ciphertext can also be determined based on the first comparison result.

[0117] It should be noted that the generation time of the first host verification data only needs to be limited before "the first comparison between the first host verification data and the first trust verification data", which can be after receiving the first trust verification data or before receiving the first trust verification data, and is not limited here.

[0118] For example, the calculation method of the first host verification data is: the encryption monitoring module performs a cyclic redundancy check on the first preset answer and the target ciphertext to determine the first host verification value, and uses the first host verification value as the first host verification data.

[0119] In one embodiment, before the host obtains the data to be transmitted and the target ciphertext, the method includes: the data sender calculates the original ciphertext based on the original content data; the data sender sends the original content data and the original ciphertext to the host for the host to receive the original content data as the actual transmission content data, use the original ciphertext as the target ciphertext of the actual transmission content data, and determine the actual transmission content data as the data to be transmitted.

[0120] At this time, if the host receives the original content data and the original ciphertext, the original content data can be used as the data to be transmitted and the original ciphertext can be used as the target ciphertext for subsequent processes. The target ciphertext is calculated by the data sender from the original content data.

[0121] However, sometimes the host may only receive the original content data and not receive the original ciphertext. The following embodiments provide a solution that can use the preset verification data and the preset ciphertext to improve the credibility of the symmetric encryption algorithm of the trust anchor when only the actual transmission content data is received and the original ciphertext is not received.

[0122] In another embodiment, before the host obtains the data to be transmitted and the target ciphertext, the method includes: the data sender sends the original content data to the host; if the host does not receive the original ciphertext of the original content data, the preset verification data is determined as the data to be transmitted, and the preset ciphertext of the preset verification data is determined as the target ciphertext, and the preset ciphertext is obtained by encrypting the preset verification data.

[0123] It can be that when the host receives the original content data, regardless of the time-consuming of the host to calculate the actual ciphertext, the process of improving the credibility of the symmetric encryption algorithm of the trust anchor is triggered. It can also be that when the host receives the original content data, and does not receive the original ciphertext, and the original content data is required to be encrypted at the trust anchor, or the actual ciphertext calculation time of the original content data is greater than the preset time threshold and is not suitable for encryption at the host side, the credibility of the symmetric encryption algorithm of the trust anchor is improved under such a prerequisite.

[0124] In one embodiment, before determining the preset verification data as the data to be transmitted, the method includes: the host receives the original content data sent by the data sender as the actual transmitted content data; determines the expected actual ciphertext calculation time of the actual transmitted content data; if the expected actual ciphertext calculation time is greater than or equal to the preset time threshold, triggers determining the preset verification data as the data to be transmitted; if the expected actual ciphertext calculation time is less than the preset time threshold, triggers determining the preset verification data as the data to be transmitted, or obtaining the actual ciphertext by encrypting the actual transmitted content data through the encryption monitoring module.

[0125] The expected actual ciphertext calculation time is also the time-consuming for the expected encryption monitoring module to encrypt and calculate the actual transmitted content data to obtain the target ciphertext. The expected actual ciphertext calculation time can be pre-calibrated and known when the encryption monitoring module receives the actual transmitted content data, or can be estimated by the encryption monitoring module after receiving the actual transmitted content data, or can also be determined by other methods known to those skilled in the art.

[0126] If the computing power overhead of directly calculating the actual ciphertext (HOST side) of the actual content (actual transmitted content data) by the secure core on the HOST side (host) is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), without affecting the normal function of the controller, then symmetric encryption calculation can be directly performed on the HOST side to obtain a symmetric encryption calculation result with a high functional safety level and an integrity verification success flag bit. Moreover, in order to achieve that the symmetric encryption algorithm calculation result on the HOST side reaches the corresponding ASIL level, the software development process of the symmetric encryption algorithm on the HOST side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed freedom from interference (FFI) with software of other ASIL / QM levels.

[0127] However, when the calculation amount of the actual content is large, the computing power overhead of directly calculating the actual ciphertext of the actual content whose integrity needs to be guaranteed on the HOST side is large, and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller. Then, the above method cannot be used to directly calculate through the secure core on the HOST side to obtain a symmetric encryption calculation result with a high functional safety level, an integrity verification success flag bit, or the original content obtained by decryption. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in this embodiment is required to obtain a symmetric encryption calculation result with a high functional safety level and an integrity verification success flag bit with a high functional safety level.

[0128] Sometimes, the host may only receive the original content data and not the original ciphertext. At this time, the HOST cannot perform subsequent verification based on the target ciphertext of the known actual transmitted content data. To monitor the symmetric encryption algorithm used to achieve the encrypted trusted state of the actual ciphertext calculated for the symmetric encryption of the trust anchor, this solution can be implemented using preset verification data and the preset ciphertext corresponding to the preset verification data. For example, the preset verification data can be used as the data to be transmitted, and the preset ciphertext can be used as the target ciphertext to execute this solution. To ensure the normal operation of the controller, the size of the preset verification data can be set so that the time for the HOST side to calculate the preset ciphertext is less than the preset duration threshold. The preset duration threshold can be equal to or greater than the Fault Tolerant Time Interval (FTTI), and the preset duration threshold can also be set by those skilled in the art according to needs.

[0129] In one embodiment, if the preset ciphertext is the correct ciphertext of the preset verification data, comparing the first host verification data with the first trust verification data includes: if the first host verification data is the same as the first trust verification data, the result of the first comparison is correct, the monitoring is successful, and in an example, the encrypted trusted state is considered to be trusted; if the first host verification data is different from the first trust verification data, the result of the first comparison is incorrect, the monitoring fails, and in an example, the encrypted trusted state is considered to be doubtful. Since the preset ciphertext is also the target ciphertext at this time, and this preset ciphertext is the correct ciphertext calculated by the trusted device, the first preset answer is also trusted. At this time, the first host verification data is also accurate. Considering that the credibility of the host is relatively high, it can be considered that the first host verification data is a trusted and accurate result and can be used as a standard for verifying the actual ciphertext. If the answer given by the trust anchor during the encryption process is accurate and the actual ciphertext obtained by encryption is also accurate, then the first trust verification data can be deduced to be accurate. At this time, if the first host verification data is the same as the first trust verification data, it means that the actual ciphertext obtained by the trust anchor is trusted; otherwise, it means that the actual ciphertext encrypted by the trust anchor is untrusted, that is, doubtful.

[0130] It should be noted that the correct preset ciphertext can be calculated by the HOST side itself, or can be pre-calculated by other trusted devices and stored on the HOST side for subsequent use. The specific implementation method can be selected by those skilled in the art according to needs. The preset ciphertext is obtained by the HOST through calculating the preset verification data, or by using other methods known to those skilled in the art to calculate the preset verification data to obtain the preset ciphertext, and is pre-stored on the HOST side or in the storage space communicatively connected to the HOST side.

[0131] In another embodiment, if the preset ciphertext is an incorrect ciphertext of the preset verification data, comparing the first host verification data with the first trust verification data includes: if the first host verification data is different from the first trust verification data, the monitoring is successful, the result of the first comparison is correct, and in one example, the encrypted trusted state is considered to be trusted; if the first host verification data is the same as the first trust verification data, the monitoring fails, the result of the first comparison is incorrect, and in one example, the encrypted trusted state is considered to be doubtful. Since the preset ciphertext is also the target ciphertext at this time, and this preset ciphertext is an incorrect ciphertext different from the correct ciphertext set after being calculated by the trusted device, the first preset answer is trusted. At this time, the first host verification data is also incorrect. Considering that the credibility of the host is relatively high, it can be considered that the first host verification data is a trusted incorrect result and can be used as a standard for verifying the actual ciphertext. If the answer given by the trust anchor during the encryption process is accurate and the actual ciphertext obtained by encryption is also accurate, then the first trust verification data can be deduced to be accurate. At this time, if the first host verification data is the same as the first trust verification data, it means that the actual ciphertext obtained by the trust anchor is untrusted, that is, doubtful. Otherwise, it means that the actual ciphertext encrypted by the trust anchor is trusted.

[0132] It should be noted that by using the preset verification data and the preset ciphertext to improve the credibility of the symmetric encryption algorithm of the trust anchor, the determination result of a set of preset verification data and preset ciphertext can be used as the final determination result. To further improve the reliability of the result, multiple sets of preset verification data and preset ciphertext can also be set, and the credibility of the symmetric encryption algorithm of the trust anchor can be improved by separately executing the symmetric encryption algorithm of the trust anchor with multiple sets of preset verification data and preset ciphertext, thereby further improving the credibility of the symmetric encryption algorithm of the trust anchor.

[0133] In one embodiment, after the first comparison, the method further includes: the host uses the received original content data as the actual transmitted content data and sends it to the trust anchor for the trust anchor to encrypt the actual transmitted content data to obtain the content ciphertext. At this time, since the actual ciphertext encrypted by the trust anchor has been verified to be trusted through the preset verification data and the preset ciphertext, the trust anchor can be directly used to encrypt the actual transmitted content data, and the credibility of the actual ciphertext obtained by encryption is increased from the original low credibility to a credibility higher than that of the trust anchor and lower than or equal to the credibility of the encryption monitoring module, realizing the improvement of credibility. If the credibility of the trust anchor is QM and the credibility of the encryption monitoring module is ASIL D, then the credibility X of the trust anchor for symmetric encryption at this time can be: ASIL D≥X>QM. The value of X may be affected by the security of the entire system, so it may be lower than ASIL D.

[0134] If the preset verification data is used as the data to be transmitted, as mentioned in the above embodiments, the preset ciphertext can be pre-computed, and directly obtained when the host needs it, which can avoid subsequent repeated computations. It is also possible to adopt the scheme of the host computing separately each time. If the scheme of the host computing the preset key corresponding to the preset verification data separately each time is adopted, in order to avoid the problem that the computing power overhead is too large when the host directly computes the preset ciphertext, and it cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller MCU, the size of the preset verification data is limited to ensure that it can be completed within the time required by requirements such as the function safety fault tolerance time interval based on the time for the host to compute the preset ciphertext.

[0135] In one embodiment, if the data to be transmitted is the preset verification data, before the host obtains the data to be transmitted and the target ciphertext, the method includes: selecting one set from a set or multiple sets of preset verification data designed in advance and the preset ciphertext of the preset verification data as the current data to be transmitted and the target ciphertext, and being obtained by the host. It should be noted that the preset ciphertext of the preset verification data can be computed by a third party (non-host). The set or multiple sets of preset verification data designed in advance and the preset ciphertext of the preset verification data can be stored in the host of the MCU, or can be stored in a preset storage space communicatively connected to the host.

[0136] In another embodiment, the preset ciphertext can be computed by the host. At this time, if the data to be transmitted is the preset verification data, before the host obtains the data to be transmitted and the target ciphertext, the method includes: selecting one set from a set or multiple sets of preset verification data designed in advance as the current data to be transmitted and being obtained by the host, and then computing the target ciphertext by the host for the selected preset verification data. Since the data size of the preset verification data is limited to be small, even if the target ciphertext is computed by the host at this time, it will not affect the normal use of the MCU.

[0137] In one embodiment, the number of preset verification data is one or more. The reliability of the symmetric encryption algorithm of the trust anchor is improved once according to each preset verification data and the preset ciphertext of the preset verification data. That is, when there is one preset verification data, the method for improving the reliability of the symmetric encryption algorithm of the trust anchor is executed once. When the number of preset verification data is multiple, the method for improving the reliability of the symmetric encryption algorithm of the trust anchor can be executed asynchronously or synchronously multiple times. The number of encrypted target events with the first comparison result being incorrect is counted, or if the encryption trust status of a certain number of actual ciphertexts is in doubt, the system is triggered to enter the safe state; otherwise, it is considered trustworthy. The use of multiple preset verification data can increase the failure coverage rate. When there are multiple preset verification data, in multiple events of improving the reliability of the symmetric encryption algorithm of the trust anchor, the usage order of each preset verification data can be the same, or switched according to the preset order, or randomly switched.

[0138] In the foregoing solution, the target ciphertext is only used by the host, and the trust anchor does not receive the target ciphertext. However, in order to further improve the reliability of the symmetric encryption algorithm, the target ciphertext can also be sent to the trust anchor, and the target ciphertext is compared with the actual ciphertext calculated by the trust anchor for a second comparison. Based on the result of the second comparison, the integrity verification result of the trust anchor is determined, and then based on the integrity verification result of the trust anchor and the first comparison result, the encryption trust status of the actual ciphertext is jointly improved, and the reliability of the symmetric encryption algorithm of the trust anchor is enhanced.

[0139] Based on the above principle, in one embodiment, before determining the encryption trust status of the actual ciphertext based on the first comparison result, the method further includes: the host sends the target ciphertext to the trust anchor; the trust anchor performs a second comparison on the target ciphertext and the actual ciphertext, determines the integrity verification result of the trust anchor based on the result of the second comparison, and sends the integrity verification result of the trust anchor to the encryption monitoring module for a seventh comparison to further improve the reliability of the symmetric encryption algorithm of the trust anchor.

[0140] At this time, the method can further include that the encryption monitoring module determines the encryption trust status of the actual ciphertext based on the integrity verification result of the trust anchor and the first comparison result.

[0141] At this time, the method further includes: the encryption monitoring module determines the seventh comparison result based on the integrity verification result of the trust anchor and the first comparison result, and the seventh comparison result can represent the encryption trust status of the actual ciphertext. The integrity verification result of the trust anchor and the first comparison result can be represented by different flag bits or other ways with the same representation rules, as long as the representation rules of the integrity verification result of the trust anchor and the first comparison result are consistent.

[0142] For example, the trust anchor integrity verification result is represented by a first flag bit (trust anchor side), and the first comparison result is represented by a second flag bit (host side). If the target ciphertext is the same as the actual ciphertext, the first flag bit is represented as "1"; if the target ciphertext is different from the actual ciphertext, the first flag bit is represented as "0". If the first host verification data is the same as the first trust verification data, the second flag bit is represented as "1"; if the first host verification data is different from the first trust verification data, the second flag bit is represented as "0". At this time, the trustworthiness of the result of the symmetric encryption algorithm can be determined based on the same or different states of the trust anchor integrity verification result and the first comparison result, and the credibility of the symmetric encryption algorithm can be improved. It should be noted that the above "1" and "0" are only examples, and those skilled in the art can set other representation methods as needed, such as "true" and "false", etc.

[0143] In this scenario, if the data to be transmitted is the actual transmitted content data, the encryption trustworthiness of the actual ciphertext determined based on the trust anchor integrity verification result and the first comparison result can be as follows: If the target ciphertext is the same as the actual ciphertext and the first host verification data is the same as the first trust verification data, the encryption trustworthiness of the actual ciphertext is trustworthy, and the seventh comparison result is correct. At this time, it can be considered that the result of encrypting the data to be transmitted by the trust anchor is reliable. If the target ciphertext is different from the actual ciphertext and / or the first host verification data is different from the first trust verification data, the encryption trustworthiness of the actual ciphertext is in doubt, and the seventh comparison result is incorrect. At this time, it can be considered that the result of encrypting the data to be transmitted by the trust anchor is unreliable. The occurrence of a doubtful event may be due to the integrity of the actual transmitted content data sent to the trust anchor being damaged and / or the partial hardware of the trust anchor being unreliable, resulting in an error in the first answer.

[0144] In one embodiment, after determining the encryption trustworthiness of the actual ciphertext, the method further includes: increasing the credibility of the symmetric encryption algorithm of the trust anchor of the actual ciphertext to the result trustworthiness of the trust anchor integrity verification result.

[0145] Regardless of whether the final result is trustworthy or untrustworthy, correct or incorrect, to a certain extent, the credibility of the symmetric encryption algorithm of the trust anchor is improved. The trust anchor integrity verification result can have a relatively high credibility (with a high functional safety level) and can thus be applied by other modules.

[0146] To improve the reliability of the solution, in one embodiment, the method further includes: after performing a first comparison between the first host verification data and the first trust verification data, the host obtains new data to be transmitted, a new target ciphertext, and a new first monitoring problem, and sends the new data to be transmitted, the new target ciphertext, and the new first monitoring problem to the trust anchor. The new target ciphertext is determined by encrypting the new data to be transmitted. The new data to be transmitted may be the same as or different from the data to be transmitted, and the new first monitoring problem may be the same as or different from the first monitoring problem. The trust anchor encrypts the new data to be transmitted to obtain a new actual ciphertext, and during the process of encrypting the new data to be transmitted, determines a new first answer based on the new first monitoring problem, generates a new first trust verification data based on the new first answer and the new actual ciphertext. The trust anchor performs a third comparison between the new target ciphertext and the new actual ciphertext, determines the trust anchor integrity verification result based on the third comparison result, and sends the new first trust verification data and the trust anchor integrity verification result to the encryption monitoring module. The encryption monitoring module generates a new first host verification data based on the new target ciphertext and the new first preset answer of the new first monitoring problem, performs a fourth comparison between the new first host verification data and the new first trust verification data to obtain a fourth comparison result. By executing this process, the credibility of the symmetric encryption algorithm of the trust anchor is improved. For example, first, use the data A to be transmitted and the target ciphertext a to improve the credibility of the symmetric encryption algorithm of the trust anchor once. At this time, only send the first monitoring problem and the data A to be transmitted to the trust anchor, without sending the target ciphertext a. Then, based on steps S210 - S230, obtain the encryption trusted state t1. Then, there are the following two methods:

[0147] 1. Use the same data A to be transmitted and the target ciphertext a to improve the credibility of the symmetric encryption algorithm of the trust anchor once. This time, in addition to sending the first monitoring problem (which may be the same as or different from the first monitoring problem sent for the first time) and the data A to be transmitted to the trust anchor, also send the target ciphertext a. The trust anchor determines the trust anchor integrity verification result based on the target ciphertext a and the new actual ciphertext, generates a new first trust verification data based on the new actual ciphertext and the first answer (corresponding to the first monitoring problem), and then sends the new first trust verification data and the integrity verification result to the host as well, so that the host determines the fourth comparison result based on the new first trust verification data and the new first host verification data, and jointly improves the credibility of the symmetric encryption algorithm of the trust anchor based on the fourth comparison result and the trust anchor integrity verification result. It is also possible to determine the encryption trusted state of the new actual ciphertext through the above method and use it as the final encryption trusted state.

[0148] 2. Use the data to be transmitted B and the target ciphertext b different from the first time to improve the credibility of the symmetric encryption algorithm of the trust anchor. This time, in addition to sending the first monitoring problem (which can be the same as or different from the first monitoring problem sent in the first time) and the data to be transmitted B to the trust anchor, the target ciphertext b also needs to be sent. The trust anchor determines the integrity verification result of the trust anchor based on the target ciphertext b and the new actual ciphertext, generates new first trust verification data based on the new actual ciphertext and the first answer (corresponding to the first monitoring problem), and then sends the new first trust verification data and the integrity verification result to the host as well, so that the host determines the fourth comparison result based on the new first trust verification data and the new first host verification data, and jointly improves the credibility of the symmetric encryption algorithm of the trust anchor based on the fourth comparison result and the integrity verification result of the trust anchor. Based on this method, the encryption trust status of the new actual ciphertext can also be determined, and then used as the final encryption trust status.

[0149] If there is an original ciphertext, an exemplary implementation is that the data to be transmitted A and the target ciphertext a are preset verification data and a preset ciphertext, and the data to be transmitted B and the target ciphertext b are actual transmission content data and the original ciphertext.

[0150] If there is an original ciphertext, another exemplary implementation is that the data to be transmitted A and the target ciphertext a are actual transmission content data and the original ciphertext, and the data to be transmitted B and the target ciphertext b are also actual transmission content data and the original ciphertext.

[0151] Another exemplary implementation is that the data to be transmitted A and the target ciphertext a are preset verification data E and a preset ciphertext e, and the data to be transmitted B and the target ciphertext b are preset verification data F and a preset ciphertext f.

[0152] If there is an original ciphertext, another exemplary implementation is that the data to be transmitted A and the target ciphertext a are actual transmission content data and the original ciphertext, and the data to be transmitted B and the target ciphertext b are preset verification data F and a preset ciphertext f.

[0153] In an embodiment, if the scheme supports using either the actual transmission content data or the preset verification data as the data to be transmitted, at this time, the trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, including: if the actual transmission content data is determined as the data to be transmitted, the trust anchor encrypts the actual transmission content data through the first sub-encryption key to obtain the actual ciphertext; if the preset verification data is determined as the data to be transmitted, the trust anchor encrypts the preset verification data through the second sub-encryption key to obtain the actual ciphertext; where the first sub-encryption key and the second sub-encryption key are the same or different.

[0154] That is, when the solution supports two types of data to be transmitted (actual transmission content data and preset verification data), two sets of key pairs can be set separately to implement, or the same key pair can be shared. The specific selection can be determined by those skilled in the art according to needs.

[0155] In one embodiment, before the trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, the method includes: storing the encryption key in the trust anchor for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext; or storing the encryption key in the host in a read-only form, and sending the encryption key to the trust anchor through the host for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext. The encryption key needs to be stored in a medium that can ensure the integrity of the key, which can be directly stored inside the trust anchor or stored in a host software with single write, etc.

[0156] In one embodiment, the method further includes: counting the number of occurrences of a first event of an encryption target event in a preset statistical period, where the encryption target event includes at least one of the following: the first comparison result is different, the seventh comparison result is different, and the fourth comparison result is different; if the number of occurrences of the first event is greater than a first preset quantity threshold, controlling the controller to enter a preset security state.

[0157] For example, count the number of occurrences of the encryption target event in the most recent preset duration as the number of occurrences of the event. When the number of occurrences of the event is greater than the preset quantity threshold, control the controller to enter the preset security state. The preset security state can be set by those skilled in the art according to the specific application scenario of the controller as needed. For example, for a motor controller or an engine controller, entering the preset security state may switch the power output, and for an autonomous driving ADAS controller, it may send a security signal to the upper-layer decision-making controller, indicating that an abnormality is known. Among them, the preset statistical period can be the time set by those skilled in the art or rules such as the number of event executions. For example, the previous 30 minutes, the number of times of the process of improving the credibility of the symmetric encryption algorithm of the trust anchor executed before, etc. A process of improving the credibility of the verification result of a trust anchor can be realized by multiple data to be transmitted. At this time, the preset statistical period can cover a process of improving the credibility of the symmetric encryption algorithm of a trust anchor, or can cover multiple processes of improving the credibility of the symmetric encryption algorithm of trust anchors. At this time, the number of occurrences of the event is the cumulative quantity of multiple processes.

[0158] In one embodiment, the method further includes: when the controller does not enter the preset safe state, enhancing the credibility of the actual ciphertext provided by the trust anchor. In this way, the encryption result of the trust anchor is no longer QM, but the credibility of the encryption result and the integrity verification result of the trust anchor is assigned according to the automotive safety integrity level of the security core of the encryption monitoring module. If the automotive safety integrity level of the security core of the encryption monitoring module is ASIL-D, the highest possible automotive safety integrity level of the trust anchor integrity verification result may also be ASIL-D. Of course, the credibility of the trust anchor for encrypting the data to be transmitted may not be solely related to the influencing factors mentioned in this embodiment. At this time, after the credibility of the symmetric encryption algorithm of the trust anchor is enhanced to be trustworthy, the credibility of the actual ciphertext encrypted by the trust anchor can also be enhanced according to certain preset rules, but it is necessary to ensure that the credibility of the actual ciphertext is higher than that of the trust anchor and not higher than that of the encryption monitoring module.

[0159] In one embodiment, the method further includes: the host receives new original content data sent by the data sender as new actual transmission content data; determines the new estimated actual ciphertext calculation time of the new actual transmission content data; if the new estimated actual ciphertext calculation time is greater than or equal to the preset duration threshold, sends the new actual transmission content data to the trust anchor to encrypt the new actual transmission content data through the trust anchor to obtain a new actual ciphertext; if the new estimated actual ciphertext calculation time is less than the preset duration threshold, encrypts the new actual transmission content data through the encryption monitoring module or the trust anchor to obtain a new actual ciphertext. In one example, additional conditions such as the encryption trust status being doubtful and / or the controller not entering the preset safe state can also be defined at this time.

[0160] That is to say, after it is determined that the process of the trust anchor encrypting and transmitting the encryption result is trustworthy, for the newly received original content data that needs to be encrypted, its estimated actual ciphertext calculation time can be estimated. If the time is too long, that is, greater than or equal to the preset duration threshold, the trust anchor needs to be used to perform the encryption. If the time is shorter, that is, less than the preset duration threshold, the trust anchor can be selected to perform the encryption or the encryption can be directly performed on the host.

[0161] The method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the above embodiment encrypts the data to be transmitted through the trust anchor with relatively low credibility to obtain the actual ciphertext, determines the first answer to the first monitoring question during the encryption process, and then generates the first trust verification data based on the first answer and the actual ciphertext. The first trust verification data is compared with the first host verification data generated by the encryption monitoring module with relatively high credibility based on the first preset answer and the target ciphertext, so as to improve the credibility of the symmetric encryption algorithm of the trust anchor, and then the encryption trust status of the actual ciphertext can be improved. By performing steps such as the first comparison by the encryption monitoring module with relatively high credibility, it is possible to improve the credibility of the symmetric encryption algorithm of the trust anchor without affecting the host function, and improve the security level of the calculation function of the trust anchor for the actual ciphertext, providing a solution to replace and supplement the existing functional security mechanism.

[0162] By setting the preset verification data and the preset ciphertext, in the scenario where there is only the actual transmitted content data but no original ciphertext, the preset verification data and the preset ciphertext designed in advance can be used as the data to be transmitted and the target ciphertext, and then the credibility verification of the encryption process of the trust anchor can be carried out. In an optional embodiment, the number of the preset verification data can be one or more, that is, before sending the actual transmitted content data to the trust anchor, the method can be executed by using one or more preset verification data as the data to be transmitted to improve the credibility of the trust anchor.

[0163] Optionally, by adding the first monitoring question during the encryption process of the trust anchor and synchronously determining the first answer during the encryption process, the scenario where the hardware resources related to the ciphertext calculation and encryption algorithm of the trust anchor fail is covered.

[0164] Optionally, by sending the target ciphertext to the trust anchor, the trust anchor determines the trust anchor integrity verification result according to the similarities and differences between the target ciphertext and the actual ciphertext, and determines the encryption trust status of the actual ciphertext based on the trust anchor integrity verification result and the first comparison result, further improving the reliability of improving the credibility of the symmetric encryption algorithm of the trust anchor for the final actual ciphertext.

[0165] Optionally, by configuring multiple sets of variable first monitoring questions and a flexible and changeable generation method for the first answer, the diagnostic coverage rate can be improved, and the failure situations of multiple hardware resources at multiple trust anchor ends can be covered.

[0166] The solution provided in this embodiment designs a solution for improving the functional safety level of symmetric encryption algorithms based on trust anchors such as HSM. This solution can improve the functional safety level of the symmetric encryption algorithm calculation based on trust anchors such as HSM without affecting the functions of the HOST side, enabling the symmetric encryption algorithm based on trust anchors such as HSM to replace and supplement the existing functional safety mechanisms to ensure the data integrity related to functional safety and expand its scope of use.

[0167] Taking the controller as the MCU, the MCU is divided into a host and a trust anchor, the trust anchor is the HSM, and the data to be transmitted is the actual transmitted content data (hereinafter referred to as the actual content) as an example. The implementation of monitoring is mainly completed in the encryption monitoring module. The encryption monitoring module is a trusted module. Taking the symmetric encryption monitoring software as an implementation example, the symmetric encryption monitoring software has an ASIL, and the credibility of the encryption monitoring module is higher than that of the trust anchor. Taking the encryption monitoring module as ASIL-D and the HSM as QM as an example, the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in the above embodiment is illustrated.

[0168] The application of the symmetric encryption algorithm in the automotive controller can be divided into the following two types of scenarios:

[0169] A. Scenario 1: The target ciphertext is known, that is, the actual ciphertext is calculated based on the actual content and compared with the target ciphertext to verify the integrity of the actual content, and the integrity verification success flag bit is obtained.

[0170] B. Scenario 2: The target ciphertext is unknown, that is, the actual ciphertext is calculated based on the actual content and used as the basis for integrity verification at the receiving end of the actual content, while only symmetric encryption calculation is performed at the sending end.

[0171] If the computing power overhead of directly calculating the actual ciphertext of the actual content (HOST side) or decrypting to obtain the original content (HOST) by the security core on the HOST side is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of the functional safety fault tolerance, and it will not affect the normal functions of the controller, then the symmetric encryption calculation can be directly performed on the HOST side to obtain the symmetric encryption calculation result with a high functional safety level and the integrity verification success flag bit. Moreover, in order to achieve the corresponding ASIL level for the symmetric encryption algorithm calculation result on the HOST side, the software development process of the symmetric encryption algorithm on the HOST side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to ensure freedom from interference (FFI) with other software of ASIL / QM levels.

[0172] However, when the actual content calculation amount is large, the computing power overhead for directly calculating the actual ciphertext of the actual content that needs to be guaranteed integrity on the HOST side is large, and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller. Then, the above method cannot be used to directly obtain a symmetric encryption calculation result with a high functional safety level and a successful integrity verification flag bit through the HOST side security core, and a functional safety mechanism needs to be designed additionally.

[0173] For the above A, there are the following two situations for Scenario 1 where the target ciphertext is known:

[0174] A1. Only calculate the actual ciphertext of the actual content on the HSM side and transmit it to the HOST side, and judge the actual ciphertext and the target ciphertext on the HOST side to verify the integrity of the actual content;

[0175] A2. Calculate the actual ciphertext of the actual content through symmetric encryption on the HSM side, and conduct a comparison and judgment between the actual ciphertext and the target ciphertext, and transmit the successful integrity verification flag bit to the HOST side;

[0176] For A1, in order to prevent the actual ciphertext calculated on the HSM side from not matching the known target ciphertext, but due to the failure of the hardware resources on the HSM side, the actual ciphertext transmitted to the HOST side is equal to the known target ciphertext, that is, the HOST side does not detect that the integrity of the actual content is damaged, etc., then monitor according to the monitoring scheme shown in Figure 3 , Figure 4 , Figure 5 . Figure 3 FIG. is a specific flowchart of a method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention, Figure 4 is Figure 3 a specific flowchart of a monitoring stage of a method for improving the credibility of the symmetric encryption algorithm of the trust anchor, Figure 5 is Figure 3 a data transmission schematic diagram of a method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by Figure 3 , Figure 4 and Figure 5 shown, in the pre-preparation stage, the data sender calculates the original ciphertext based on the original content (if the transmission is error-free, that is, the subsequent actual content), encrypts the original ciphertext to obtain the original ciphertext, and the data sender sends the original ciphertext and the original content to the host of the MCU ( Figure 3Shown as HOST in the middle, the HOST takes the received original content as the actual content and the original ciphertext as the target ciphertext. When the monitoring starts, the HOST side will determine the first monitoring problem and send the actual content and the first monitoring problem to the HSM side. The HSM side encrypts the actual content to obtain the actual ciphertext. During the encryption process, it determines the first answer to the first monitoring problem and performs a cyclic redundancy check based on the first answer and the actual ciphertext, calculates the first trust verification value, and takes this first trust verification value as the first trust verification data, that is Figure 3 、 Figure 4 and Figure 5 "CRC(First answer + Actual ciphertext)" in, where CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. The meaning of the subsequent verification data is similar to that of the first trust verification data and will not be elaborated. Send CRC(First answer + Actual ciphertext) to the HOST side. The HOST side determines the first preset answer according to the first monitoring problem and calculates the first host verification data according to the first preset answer and the target ciphertext, that is Figure 3 、 Figure 4 and Figure 5 "CRC(First preset answer + Target ciphertext)" in. It should be noted that this first host verification data only needs to be completed before comparing CRC(First answer + Actual ciphertext) and CRC(First preset answer + Target ciphertext). Figure 3 The step position in is only an example and does not serve as a limitation on the specific steps between the determination of the first host verification data and other steps. Please refer to Figure 4 and Figure 5, the symmetric encryption monitoring software on the HOST side sends the first monitoring problem to the driver on the HOST side (HSM HOST Driver, the trusted anchor driver function module), and through the HSM HOST Driver, the actual content and the first monitoring problem are sent to the HSM Firmware on the HSM side. The credibility of the HSM HOST Driver and the HSM Firmware can be QM. The HSM Firmware sends the obtained CRC (the first answer + the actual ciphertext) to the symmetric encryption monitoring software through the HSM HOST Driver. The symmetric encryption monitoring software calculates the CRC (the first preset answer + the target ciphertext) and determines whether the CRC (the first preset answer + the target ciphertext) is equal to the CRC (the first answer + the actual ciphertext), that is, performs the first comparison to obtain the first comparison result. If so, that is, they are equal (the same), the first comparison result is correct, and the encryption trust status of the actual ciphertext can also be determined to be trustworthy, and the integrity verification result of the high functional safety level passes. If not, that is, they are not equal (not the same), the first comparison result is incorrect, and the encryption trust status of the actual ciphertext can also be determined to be doubtful, and the integrity verification result of the high functional safety level fails.

[0177] For A2, a "symmetric encryption monitoring software" is designed in the security core on the HOST side. In order to achieve the integrity verification success flag bit reaching the corresponding ASIL level, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to ensure freedom from interference (FFI) with other software of ASIL / QM levels.

[0178] While triggering the HSM side to calculate the actual ciphertext according to the actual content, the "symmetric encryption monitoring software" will send the first monitoring problem to the HSM side. To improve the diagnostic coverage, the first monitoring problem can be dynamically changed, for example: 0x0, 0x1, 0x2, 0x3…0xF.

[0179] Secondly, the method for obtaining the first answer in the HSM side Firmware based on the first monitoring problem can also be selected according to the diagnostic coverage requirements. It can be obtained directly by looking up a table or obtained through operations such as a linear feedback shift register (LFSR); if you want to further improve the diagnostic coverage, the monitoring results of various software and hardware resources on the HSM side can also be integrated. The first preset answer for each first monitoring problem is known in the "symmetric encryption monitoring software".

[0180] Finally, the "symmetric encryption monitoring software" calculates CRC (known monitoring answer + target ciphertext) based on the known target ciphertext, and determines whether the CRC (monitoring answer + actual ciphertext) from the HSM side is equal to CRC (known monitoring answer + target ciphertext), obtaining the integrity check success flag bit (HOST side), and then compares it with the integrity check success flag bit (HSM side) to determine whether the monitoring passes. Among them, CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. Figure 6 Another specific process schematic diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. Figure 7 For Figure 6 A specific process schematic diagram of the monitoring stage of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor. Figure 8 For Figure 6 The data transmission schematic diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided. As Figure 6 、 Figure 7 And Figure 8 As shown, in the pre-preparation stage, the data sender calculates the original ciphertext based on the original content (if the transmission is error-free, that is, the subsequent actual content), encrypts the original ciphertext to obtain the original ciphertext, and the data sender sends the original ciphertext and the original content to the host of the MCU ( Figure 6 Shown as HOST in), the HOST takes the received original content as the actual content and the original ciphertext as the target ciphertext. When the monitoring starts, the HOST side determines the first monitoring question, and sends the actual content, the target ciphertext, and the first monitoring question to the HSM side. The HSM side encrypts the actual content to obtain the actual ciphertext. During the encryption process, the first answer to the first monitoring question is determined, and a cyclic redundancy check is performed based on the first answer and the actual ciphertext, and the first trust verification value is calculated. This first trust verification value is used as the first trust verification data, that is, Figure 6 、 Figure 7 And Figure 8"CRC(First response answer + actual ciphertext)". The CRC(First response answer + actual ciphertext) is sent to the HOST side. The HSM side also compares the target ciphertext with the actual ciphertext for the second time to determine the integrity verification success flag (HSM side), that is, the trust anchor integrity verification result mentioned in the foregoing embodiment. It should be noted that the separate transmission of the integrity verification success flag (HSM side) and CRC(First response answer + actual ciphertext) in the figure is only an example. The integrity verification success flag (HSM side) and CRC(First response answer + actual ciphertext) can also be sent synchronously, or the CRC(First response answer + actual ciphertext) can be sent first and then the integrity verification success flag (HSM side). This is not limited here and can be selected by those skilled in the art according to needs. The step sequence in the attached figure of this embodiment is only an example and does not limit the order of steps. Those skilled in the art can flexibly set the execution order of some steps according to needs. The HOST side determines the first preset answer according to the first monitoring question, and calculates the first host verification data according to the first preset answer and the target ciphertext, that is Figure 6 , Figure 7 and Figure 8 "CRC(First preset answer + target ciphertext)" in. It should be noted that the first host verification data needs to be completed before comparing CRC(First preset answer + target ciphertext) and CRC(First response answer + actual ciphertext) to obtain the first comparison result. Figure 6 The step position in is only an example and does not serve as a schematic of the specific steps between the determination of the first host verification data and other steps. Then, the seventh comparison is performed according to the first comparison result and the integrity verification success flag (HSM side) to obtain the seventh comparison result, so as to further improve the credibility of the symmetric encryption algorithm of the trust anchor. Please refer to Figure 7 and Figure 8, the symmetric encryption monitoring software on the HOST side sends the first monitoring problem to the driver on the HOST side (HSM HOST Driver, the trusted anchor driver function module). Through the HSM HOST Driver, the actual content, the target ciphertext, and the first monitoring problem are sent to the HSM Firmware on the HSM side. The credibility of the HSM HOST Driver and the HSM Firmware can be QM. The HSM Firmware sends the obtained CRC (the first answer + the actual ciphertext) and the integrity verification success flag (HSM side) to the symmetric encryption monitoring software through the HSM HOST Driver. The symmetric encryption monitoring software calculates the CRC (the first preset answer + the target ciphertext) and determines whether the CRC (the first preset answer + the target ciphertext) is equal to the CRC (the first answer + the actual ciphertext), that is, performs the first comparison to obtain the first comparison result. Then, it determines whether the first comparison result is consistent with the integrity verification success flag (HSM side) (performs the seventh comparison to obtain the seventh comparison result). If the two are inconsistent, the monitoring fails, triggering subsequent fault confirmation and response steps. For example, increase the number of occurrences of the first event, and then based on the updated number of occurrences of the first event, decide whether to trigger the controller to enter the preset safe state, etc. If they are consistent, the monitoring passes, and the integrity verification result is credible, further improving the credibility of the symmetric encryption algorithm of the trusted anchor in the above manner.

[0181] Regarding the above B, for the scenario of unknown target ciphertext in Scenario 2: Calculate the actual ciphertext of the actual content on the HSM side. At this time, due to the unknown target ciphertext, the HOST side cannot perform verification based on the known target ciphertext. Taking the "actual content for monitoring" as the preset verification data and the "target ciphertext for monitoring" as the preset ciphertext as an example, to implement the monitoring of the symmetric encryption algorithm calculation on the HSM side, design one or more sets of "actual content for monitoring" and "target ciphertext for monitoring" specifically for monitoring. For the convenience of key management, the monitoring symmetric key and the actually used symmetric key can be the same, or the monitoring symmetric key can be injected separately; the size of the "actual content for monitoring" needs to ensure that the time for calculating the actual ciphertext of the actual content for monitoring on the HOST side can be completed within the time required by the functional safety fault tolerance time interval (Fault Tolerant Time Interval, FTTI), etc. Using multiple sets can increase the failure coverage rate. Or the "target ciphertext for monitoring" corresponding to the "actual content for monitoring" can also be directly preset on the HOST side as the basis for monitoring judgment. The monitoring process of the "symmetric encryption monitoring software" for one set of "actual content for monitoring" and "target ciphertext for monitoring" is as Figure 9 , Figure 10 and Figure 11As shown. Before calculating the actual ciphertext, the "symmetric encryption monitoring software" is executed at least once. That is, a set of preset verification data and preset ciphertext can be selected to improve the credibility of the symmetric encryption algorithm of the trust anchor, or multiple sets of preset verification data and preset ciphertext can be selected to perform the process of improving the credibility of the symmetric encryption algorithm of the trust anchor multiple times. The specific number of executions can be selected by those skilled in the art according to needs and is not limited herein. Figure 9 Another specific process schematic diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention, Figure 10 is Figure 9 a specific process schematic diagram of a monitoring stage of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor, Figure 11 is Figure 9 a data transmission schematic diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided. As Figure 9 , Figure 10 and Figure 11 shown, in the pre-preparation stage, the data sender sends the original content to the host of the MCU ( Figure 9 shown as HOST in Figure 9 , Figure 10 and Figure 11 ), without sending the original ciphertext. The HOST takes the received original content as the actual content. When the monitoring starts, the HOST side will determine the first monitoring problem, determine the monitoring actual content as the data to be transmitted, determine the monitored target ciphertext obtained by encrypting the monitoring actual content as the target ciphertext, and send the monitoring actual content and the first monitoring problem to the HSM side. The HSM side encrypts the monitoring actual content to obtain the actual ciphertext of the monitoring actual content. During the encryption process, the first answer to the first monitoring problem is determined, and a cyclic redundancy check is performed according to the first answer and the actual ciphertext of the monitoring actual content, and the first trust verification value is calculated. This first trust verification value is used as the first trust verification data, that is, Figure 9 , Figure 10 and Figure 11 the "CRC (first answer + actual ciphertext of the monitoring actual content)" in Figure 9The step positions in it are only examples and do not serve as a schematic indication of the specific steps between the determination of the first host verification data and other steps. The above steps can also be repeated multiple times through multiple sets of monitoring actual content and monitoring target ciphertext. If the first comparison result is different each time, the occurrence count of the first event is incremented by 1. If the controller does not enter the preset security state, the HOST sends the actual content to the HSM, and the HSM encrypts the actual content to obtain the content ciphertext. The credibility of this content ciphertext is improved.

[0182] Please refer to Figure 10 and Figure 11 , the symmetric encryption monitoring software on the HOST side issues the first monitoring problem to the driver on the HOST side (HSM HOST Driver, trust anchor driver function module), and through the HSM HOST Driver, the monitoring actual content and the first monitoring problem are issued to the HSM Firmware on the HSM side. The credibility of this HSM HOST Driver and HSM Firmware can be QM. The HSM Firmware sends the obtained CRC (the first answer + the actual ciphertext of the monitoring actual content) to the symmetric encryption monitoring software through the HSM HOST Driver. The symmetric encryption monitoring software calculates the CRC (the first preset answer + the monitoring target ciphertext), and determines whether the CRC (the first preset answer + the monitoring target ciphertext) is equal to the CRC (the first answer + the actual ciphertext of the monitoring actual content). If so, the monitoring passes; if not, that is, they are not equal (different, inconsistent), then the monitoring fails.

[0183] Please refer to Figure 12 , Figure 12 is another specific process schematic diagram of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 12 shown, in the pre-preparation stage, the data sender sends the original content to the host HOST of the MCU without sending the original ciphertext, and the HOST takes the received original content as the actual content. When the monitoring starts, the HOST side determines the first monitoring problem, determines the monitoring actual content as the data to be transmitted, determines the monitoring target ciphertext obtained by encrypting the monitoring actual content as the target ciphertext, and sends the monitoring actual content, the monitoring target ciphertext, and the first monitoring problem to the HSM side. The HSM side encrypts the monitoring actual content to obtain the actual ciphertext of the monitoring actual content. During the encryption process, the first answer to the first monitoring problem is determined, and a cyclic redundancy check is performed based on the first answer and the actual ciphertext of the monitoring actual content to calculate the first trust verification value, and this first trust verification value is used as the first trust verification data, that is Figure 12"CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring)". The HSM side will also perform a second comparison between the target ciphertext for monitoring and the actual ciphertext to determine the integrity check success flag (HSM side), which is also the trust anchor integrity check result mentioned in the foregoing embodiments. It should be noted that the separate transmission of the integrity check success flag (HSM side) and CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring) in the figure is only an example. The integrity check success flag (HSM side) and CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring) can also be transmitted synchronously, or CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring) can be sent first and then the integrity check success flag (HSM side). This is not limited herein and can be selected by those skilled in the art according to needs. The step sequence in the attached drawings of this embodiment is only an example and does not limit the order of steps. Those skilled in the art can flexibly set the execution order of some steps according to needs. The integrity check success flag (HSM side) and CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring) are sent to the HOST side. The HOST side determines the first preset answer according to the first monitoring question, and calculates the first host check data according to the first preset answer and the target ciphertext for monitoring, that is Figure 12 "CRC(First Preset Answer + Target Ciphertext for Monitoring)" therein. It should be noted that the first host check data only needs to be completed before comparing CRC(First Answer + Actual Ciphertext of the Actual Content for Monitoring) and CRC(First Preset Answer + Target Ciphertext for Monitoring). Figure 12 The step position therein is only an example and does not serve as a schematic illustration of the specific steps between the determination of the first host check data and other steps. Then, a seventh comparison is performed according to the first comparison result and the integrity check success flag (HSM side) to obtain the seventh comparison result, so as to further improve the credibility of the symmetric encryption algorithm of the trust anchor. If the controller does not enter the preset security state, the HOST sends the actual content to the HSM, and the HSM encrypts the actual content to obtain the content ciphertext. The credibility of this content ciphertext is improved.

[0184] Please refer to Figure 13 , Figure 13 which is another specific flowchart of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. Taking the example that the first and second times use different preset verification data to improve the credibility of the symmetric encryption algorithm of the trust anchor and the first monitoring questions used twice are the same, as Figure 13 shown, in the pre-preparation stage, the data sender sends the original content to the host of the MCU ( Figure 13As shown in the figure as HOST), the original ciphertext is not sent, and the HOST uses the received original content as the actual content. When the monitoring starts, the HOST side determines the first monitoring problem, determines the monitoring actual content E as the data to be transmitted, determines the monitored target ciphertext e obtained by encrypting the monitoring actual content as the target ciphertext, and sends the monitoring actual content E and the first monitoring problem to the HSM side. The HSM side encrypts the monitoring actual content to obtain the actual ciphertext of the monitoring actual content. During the encryption process, it determines the first answer to the first monitoring problem, and performs a cyclic redundancy check based on the first answer and the actual ciphertext u of the monitoring actual content, calculates the first trust verification value, and uses this first trust verification value as the first trust verification data, that is Figure 13 "CRC (the first answer + the actual ciphertext u of the monitoring actual content)" in. Send CRC (the first answer + the actual ciphertext u of the monitoring actual content) to the HOST side. The HOST side determines the first preset answer according to the first monitoring problem, and calculates the first host verification data according to the first preset answer and the monitored target ciphertext e, that is Figure 13 "CRC (the first preset answer + the monitored target ciphertext e)" in. Compare CRC (the first preset answer + the monitored target ciphertext e) with CRC (the first answer + the actual ciphertext u of the monitoring actual content). Determine the monitoring actual content F as the data to be transmitted, determine the monitored target ciphertext f obtained by encrypting the monitoring actual content as the target ciphertext, and send the monitoring actual content F, the monitored target ciphertext f and the first monitoring problem to the HSM side. The HSM side encrypts the monitoring actual content to obtain the actual ciphertext v of the monitoring actual content. During the encryption process, it determines the first answer to the first monitoring problem, and performs a cyclic redundancy check based on the first answer and the actual ciphertext of the monitoring actual content, calculates the first trust verification value, and uses this first trust verification value as the first trust verification data, that is Figure 13"CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring)". The HSM side will also perform a third comparison between the target ciphertext for monitoring and the actual ciphertext to determine the integrity verification success flag (HSM side), which is also the trust anchor integrity verification result mentioned in the foregoing embodiments. It should be noted that the separate transmission of the integrity verification success flag (HSM side) and CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring) in the figure is only an example. The integrity verification success flag (HSM side) and CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring) can also be transmitted synchronously, or CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring) can be transmitted first and then the integrity verification success flag (HSM side). This is not limited here and can be selected by those skilled in the art according to needs. The step sequence in the drawings of this embodiment is only an example and does not limit the order of steps. Those skilled in the art can flexibly set the execution order of some steps according to needs. Transmit the integrity verification success flag (HSM side) and CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring) to the HOST side. The HOST side determines the first preset answer according to the first monitoring question, and calculates the first host verification data according to the first preset answer and the target ciphertext for monitoring, that is, Figure 13 "CRC(First Preset Answer + Target Ciphertext f for Monitoring)". It should be noted that the first host verification data only needs to be completed before comparing CRC(First Answer + Actual Ciphertext v of the Actual Content for Monitoring) and CRC(First Preset Answer + Target Ciphertext f for Monitoring) to obtain the fourth comparison result. Figure 13 The step position in Figure 13 is only an example, and does not serve as a schematic of the specific step sequence between the determination of the first host verification data and other steps. Then, perform a fourth comparison based on the new first comparison result and the integrity verification success flag (HSM side) to obtain the fourth comparison result, so as to jointly improve the credibility of the symmetric encryption algorithm of the trust anchor. If the host does not enter the preset safe state, the HOST sends the actual content to the HSM, and the HSM encrypts the actual content to obtain the content ciphertext. The credibility of this content ciphertext has been improved. It should be noted that Figure 13 the execution order of the two actual contents E and F for monitoring can be either one first. Figure 13 is only an example. The specific number of actual contents for monitoring can also be set by those skilled in the art according to needs. Figure 13 is also only an example. Of course, it can also be to execute only through one or more actual contents for monitoring.

[0185] For the fault confirmation and response when the above-mentioned monitoring fails, a fault failure counter can be set to count the number of events of the encrypted target event. If the fault failure counter is greater than the threshold (that is, the number of occurrences of the first event is greater than the first preset number threshold), the system is allowed to enter a safe state according to the requirements of the actual functional safety goals.

[0186] See also Figure 14 As shown, Figure 14 A flow chart of a method for improving the credibility of a symmetric encryption algorithm of a trust anchor provided by an embodiment of the present invention, the method comprising the following steps:

[0187] Step S1410: The host obtains the ciphertext to be transmitted and the second monitoring question, and sends the ciphertext to be transmitted and the second monitoring question to the trust anchor.

[0188] The ciphertext to be transmitted is obtained by encrypting the original content based on a symmetric encryption algorithm. It can be the ciphertext to be transmitted obtained by encrypting the original content in advance by the data sender. The original content and the aforementioned original content data can be the same data or different data, which is not limited here. The ciphertext to be transmitted is the data that actually needs to be decrypted.

[0189] The second monitoring question and the ciphertext to be transmitted can be sent synchronously or asynchronously. The second monitoring question needs to be sent to the trust anchor before the trust anchor decrypts the ciphertext to be transmitted to obtain the decrypted transmission data. The second monitoring question can be sent to the trust anchor before the trust anchor decrypts or during the decryption process, so that the trust anchor can determine the second answer while decrypting. Similar to the first monitoring question, the number of the second monitoring question can be one or more. If there are multiple second monitoring questions, the multiple second monitoring questions can be sent at one time or in batches, which can be set by those skilled in the art as needed.

[0190] Similarly, the third monitoring question and the preset verification ciphertext described below can be sent synchronously or asynchronously. It is only necessary to send the third monitoring question to the trust anchor before the trust anchor decrypts the ciphertext to be transmitted to obtain the decryption verification data. The third monitoring question can be sent to the trust anchor before or during the decryption process of the trust anchor, so that the trust anchor can determine the third answer while decrypting. Similar to the first monitoring question, the number of the third monitoring question can be one or more. If there are multiple third monitoring questions, the multiple third monitoring questions can be sent at one time or in batches, which can be set by those skilled in the art as needed.

[0191] In one embodiment, multiple methods for generating the second monitoring question and the third monitoring question are provided, and the host obtains the second monitoring question or the third monitoring question, including any one of the following:

[0192] Obtain a preset question and determine the preset question as the second monitoring question or the third monitoring question. It can be understood that if this method is used alone, there will always be one or a set (each set contains multiple sub-questions) of preset monitoring questions, and the same monitoring questions are sent each time.

[0193] Obtain multiple preset questions and determine one or more selected preset questions as the second monitoring question or the third monitoring question. It can be understood that if this method is used alone, there are multiple preset monitoring questions, and one or more of them are selected as the current second monitoring question or third monitoring question each time. The number of questions selected each time can be different or the same. The questions selected in several adjacent times can be the same or at least partially different. The selection method can be random selection or other selection methods set by those skilled in the art. Similar to the previous embodiment, a preset question can be only one question or include multiple questions. If both of the two preset questions include multiple questions, the number of questions included in these two preset questions can be the same or different, and the actual content of the questions can be partially the same or completely different, and specifically can be set by those skilled in the art according to needs.

[0194] Obtain multiple preset questions, as well as the sent second monitoring questions and the sent third monitoring questions. Screen out the sent second monitoring questions from the multiple preset questions, and determine one or more preset questions after screening as the second monitoring question. Screen out the sent third monitoring questions from the multiple preset questions, and determine one or more preset questions after screening as the third monitoring question. By using this method, it can be ensured that the first monitoring question sent each time is different from the previous one. By controlling the sampling range of the sent first monitoring questions, such as the last 20 times, the last 1 day, etc., the possible minimum occurrence period of sending the same first monitoring question twice can be controlled.

[0195] Obtain multiple preset questions, the second monitored question that has been sent, and the third monitored question that has been sent. Determine multiple randomly selected preset questions as preselected questions. If the question content of the preselected questions is the same as the question content of the second monitored question that has been sent, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the second monitored question that has been sent. Determine the adjusted preselected questions as the second monitored question. If the question content of the preselected questions is the same as the question content of the third monitored question that has been sent, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the third monitored question that has been sent. Determine the adjusted preselected questions as the third monitored question. By using this method, under the premise of limited questions, by adjusting the order of the questions, the order in which the trust anchor collects answers can be adjusted, and then the timing of the trust anchor collecting the answers corresponding to the questions can be adjusted. Without adding new preset questions, the effect of increasing the failure coverage rate can also be achieved.

[0196] The generation methods of the second monitored question and the third monitored question can be the same or different.

[0197] In one embodiment, multiple preset questions can be divided into different level sets, and there are at least some differences in the types of hardware resources required to answer the preset questions in each level set. In this way, subsequently, according to the hardware resources that need to be focused on preventing failures, the preset questions in the corresponding level set can be adaptively considered and selected as the second monitored question or the third monitored question.

[0198] By increasing the number of preset questions, updating the preset questions, controlling that the first monitored questions sent in the recent several times are different, or switching the order of the questions in the second monitored question and the third monitored question, etc., the failure coverage rate can be increased. For example, the failure modes are jamming, being too large, and being too small. A first monitored question may only be able to obtain a conclusion of being too large or too small, but cannot obtain a conclusion of whether there is jamming. At this time, through the participation of multiple second monitored questions or third monitored questions, more failure modes can be detected as much as possible. By increasing the second monitored question or the third monitored question, especially the second monitored question or the third monitored question that can only obtain the answer by calling different resources, the more types of hardware resources used to generate the answer, the wider the diagnostic coverage, the more failure situations covered, and the higher the coverage rate.

[0199] It should be noted that the second monitored question and the second preset answer corresponding to the second monitored question can be preset in advance and stored in the storage space that can be communicatively connected to the host, or stored in the host storage space. The third monitored question and the third preset answer corresponding to the third monitored question can be preset in advance and stored in the storage space that can be communicatively connected to the host, or stored in the host storage space.

[0200] It should be noted that the third monitoring problem and the second monitoring problem can be the same or different during one round of verification.

[0201] Step S1420: The trust anchor decrypts the to-be-transmitted ciphertext based on a symmetric encryption algorithm to obtain decrypted transmission data. During the process of decrypting the to-be-transmitted ciphertext, the second answer is determined according to the second monitoring problem. The second trust verification data is generated based on the second answer and the decrypted transmission data, and the second trust verification data and the decrypted transmission data are sent to the decryption monitoring module.

[0202] The decryption key is stored in the trust anchor, and the decryption key and the encryption key of the to-be-transmitted ciphertext are a pair of key pairs.

[0203] In one embodiment, determining the second answer according to the second monitoring problem includes: the trust anchor matches the second monitoring problem with multiple preset local problems in the preset question answer table. If the match with a preset local problem is successful, the preset local answer corresponding to the preset local problem is determined as the fourth answer sub-answer. The preset question answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The trust anchor stores the preset question answer table; the trust anchor triggers the preset function module to output a function answer based on the second monitoring problem, and determines the function answer as the fifth answer sub-answer. The trust anchor is provided with a preset function module; the trust anchor collects one or more monitoring results of its own security mechanisms based on the second monitoring problem, and determines one or more monitoring results of its own security mechanisms as the sixth answer sub-answer; the trust anchor generates the second answer according to at least one of the fourth answer sub-answer, the fifth answer sub-answer, and the sixth answer sub-answer.

[0204] The generation method of the second answer can be by looking up a table, or obtained by operating through a preset function module such as a Linear Feedback Shift Register (LFSR), or by collecting the monitoring results of the original security mechanism of the trust anchor, or a combination of at least one of the above three methods, or obtained by combining other methods set by those skilled in the art to obtain the second answer.

[0205] In one embodiment, determining a third response answer according to a third monitoring problem includes: The trust anchor matches the second monitoring problem with multiple preset local problems in a preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the seventh response sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The trust anchor stores the preset problem answer table; The trust anchor triggers a preset function module based on the third monitoring problem to output a function answer, and determines the function answer as the eighth response sub-answer. The trust anchor is provided with a preset function module; The trust anchor collects one or more monitoring results of its own security mechanisms based on the third monitoring problem, and determines the one or more monitoring results of its own security mechanisms as the ninth response sub-answer; The trust anchor generates a third response answer according to at least one of the seventh response sub-answer, the eighth response sub-answer, and the ninth response sub-answer.

[0206] The generation method of the third response answer can be by looking up a table, or obtained through operations of a preset function module such as a Linear Feedback Shift Register (LFSR), or by collecting the monitoring results of the original security mechanisms of the trust anchor, or a third response answer is obtained by combining at least one of the above three methods, or in combination with other methods set by those skilled in the art.

[0207] In one embodiment, before the decryption monitoring module generates the second host verification data according to the decrypted transmission data and the second preset answer of the second monitoring problem, the method includes: The decryption monitoring module matches the second monitoring problem with multiple preset local problems in a preset problem answer table. If a match is successful with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the fourth preset sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The decryption monitoring module stores the problem answer table; The decryption monitoring module triggers a preset function module based on the second monitoring problem to output a function answer, and determines the function answer as the fifth preset sub-answer. The decryption monitoring module is provided with a preset function module; The decryption monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as the sixth preset sub-answer based on the second monitoring problem; The decryption monitoring module generates a second preset answer according to at least one of the fourth preset sub-answer, the fifth preset sub-answer, and the sixth preset sub-answer.

[0208] The host stores a second preset answer corresponding to the second monitoring problem. This second preset answer can be understood as the standard answer. The acquisition method of the second preset answer can be that all are pre-stored, or a preset function the same as that of the trust anchor can be set to achieve the effect of outputting the same answer. The acquisition method of the second preset answer can also be other methods known to those skilled in the art. It should be noted that in this embodiment, it is not limited that the second preset answer and the second answer adopt the same acquisition method, that is, the acquisition methods can be the same or different. However, regardless of whether the second preset answer and the second answer are obtained by the same method, their accurate answers are the same. That is, if the content of the second preset answer is M, then if the trust anchor is trustworthy during the decryption process, the content of the second answer should also be M.

[0209] In one embodiment, before the decryption monitoring module generates the third host verification data according to the preset verification data and the third preset answer of the third monitoring problem, the method includes: the decryption monitoring module matches the third monitoring problem with multiple preset local problems in the preset question answer table. If it matches successfully with a preset local problem, it determines the preset local answer corresponding to the preset local problem as the seventh preset sub-answer. The preset question answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The decryption monitoring module stores the question answer table; the decryption monitoring module triggers the preset function module to output the function answer based on the third monitoring problem and determines the function answer as the eighth preset sub-answer. The decryption monitoring module is provided with a preset function module; the decryption monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as the ninth preset sub-answer based on the third monitoring problem; the decryption monitoring module generates the third preset answer according to at least one of the seventh preset sub-answer, the eighth preset sub-answer, and the ninth preset sub-answer.

[0210] The host stores a third preset answer corresponding to the third monitoring problem. This third preset answer can be understood as the standard answer. The acquisition method of the third preset answer can be that all are pre-stored, or a preset function the same as that of the trust anchor can be set to achieve the effect of outputting the same answer. The acquisition method of the third preset answer can also be other methods known to those skilled in the art. It should be noted that in this embodiment, it is not limited that the third preset answer and the third answer adopt the same acquisition method, that is, the acquisition methods can be the same or different. However, regardless of whether the third preset answer and the third answer are obtained by the same method, their accurate answers are the same. That is, if the content of the third preset answer is M, then if the trust anchor is trustworthy during the decryption process, the content of the third answer should also be M.

[0211] It should be noted that the calculation of the second trust verification data, the second host verification data, the third trust verification data, and the third host verification data can be implemented using the CRC (Cyclic Redundancy Check) algorithm or other algorithms known to those skilled in the art that can ensure the integrity of functional safety data.

[0212] For example, the determination method of the second trust verification data is as follows: The trust anchor performs a cyclic redundancy check on the second response answer and the actual ciphertext to determine the second trust verification value, and uses this second trust verification value as the second trust verification data.

[0213] In an embodiment, the way for the trust anchor to send the second trust verification data and the third trust verification data to the decryption monitoring module can be that the trust anchor directly sends the second trust verification data and the third trust verification data to the decryption monitoring module, or the trust anchor sends the second trust verification data and the third trust verification data to the driver (HSMHOST Driver) of the HOST side, and then sends them to the decryption monitoring module through this driver.

[0214] The first monitoring question, the second monitoring question, and the third monitoring question can be the same question or different questions. The three questions can adopt the same generation method or different generation methods. The first response answer, the second response answer, and the third response answer can be the same question or different questions. The three response answers can adopt the same generation method or different generation methods. Correspondingly, the first preset answer, the second preset answer, and the third preset answer can be the same question or different questions. The three preset answers can adopt the same generation method or different generation methods.

[0215] Step S1430, the decryption monitoring module generates the second host verification data based on the decrypted transmission data and the second preset answer of the second monitoring question, and compares the second host verification data with the second trust verification data to obtain the fifth comparison result.

[0216] In another embodiment, the decryption trust status of the decrypted transmission data can also be determined based on the fifth comparison result. If the fifth comparison result is the same, and / or the controller has not entered the preset safe state, then the decrypted transmission data is stored or sent to the preset data user.

[0217] In an exemplary embodiment, after the trusted anchor decrypts and obtains the decrypted transmission data, if the decrypted transmission data is obtained by decrypting a symmetric encryption ciphertext, the decrypted transmission data may be first sent to a preset data user, or stored according to a preset storage rule. At the same time or later, continue to execute the method for improving the credibility of the symmetric encryption algorithm of the trusted anchor in the decryption stage provided in this embodiment. If the controller enters a preset security state, trigger the generation and send a data untrusted notification to the data user to avoid risks caused by incorrect data. Generally, the decryption speed of the trusted anchor is faster than that of the host, and the decryption results of the trusted anchor are usually reliable. The event of being unreliable relative to being reliable is a small probability event. Through the above method, the data processing speed can be further improved without waiting for the monitoring result. Moreover, through the generation and sending mechanism of the untrusted notification, the subsequent risk problems caused by untrusted decrypted transmission data can also be avoided.

[0218] It should be noted that the generation timing of the second host verification data needs to be limited before "performing the fifth comparison between the second host verification data and the second trust verification data". It can be after receiving the second trust verification data or before receiving the second trust verification data. There is no limitation here.

[0219] For example, the calculation method of the second host verification data is as follows: The decryption monitoring module performs a cyclic redundancy check on the second preset answer and the target ciphertext to determine the second host verification value, and uses the second host verification value as the second host verification data.

[0220] In an embodiment, to cover the failure of the trusted anchor decryption process and the data transmission process when the trusted anchor transmits the decrypted original content to the host, and to implement the monitoring of the trusted anchor symmetric encryption process, one or more sets of "preset verification ciphertexts" and "preset verification data" specifically for monitoring are designed. The preset verification data may be the same as the "preset verification data" mentioned in the foregoing embodiment or different, and can be specifically selected by those skilled in the art according to needs. Correspondingly, the preset verification ciphertext may be the preset ciphertext mentioned in the foregoing embodiment or different from the preset ciphertext.

[0221] In one embodiment, the method includes: the host obtains a preset verification ciphertext, preset verification data, and a third monitoring problem, and sends the preset verification ciphertext and the third monitoring problem to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring problem is the same as or different from the second monitoring problem; the trust anchor decrypts the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determines a third answer based on the third monitoring problem, generates third trust verification data based on the third answer and the decrypted verification data, and sends the third trust verification data to the decryption monitoring module; the decryption monitoring module generates third host verification data according to the preset verification data and the third preset answer to the third monitoring problem, compares the third host verification data with the third trust verification data for the sixth time, and obtains a sixth comparison result.

[0222] The sixth comparison result includes: 1. The third host verification data is the same as the third trust verification data; 2. The third host verification data is different from the third trust verification data.

[0223] The preset verification ciphertext can be the correct ciphertext obtained by encrypting the preset verification data by a trusted device, or after obtaining the correct ciphertext by encrypting the preset verification data by a trusted device, determining an incorrect ciphertext different from the correct ciphertext as the preset verification ciphertext. In other words, the preset verification ciphertext can be intervened by those skilled in the art. Therefore, the correct ciphertext can be set as the preset verification ciphertext for subsequent verification, or the incorrect ciphertext can be set as the preset verification ciphertext for verification. The incorrect ciphertext is also determined based on the correct ciphertext obtained by encrypting the preset verification data.

[0224] It should be noted that the correct preset ciphertext can be calculated by the HOST itself, or can be pre-calculated by other trusted devices and stored in the HOST for subsequent use. The specific implementation method can be selected by those skilled in the art according to needs. The preset verification ciphertext is calculated by the HOST for the preset verification data, or the preset verification ciphertext is calculated for the preset verification data in other ways known to those skilled in the art, and is pre-stored in the HOST or in a storage space communicatively connected to the HOST.

[0225] In one embodiment, if all the preset verification ciphertexts are the correct ciphertexts of the preset verification data, the preset comparison result includes that the third host verification data is the same as the third trust verification data; if all the preset verification ciphertexts are the incorrect ciphertexts of the preset verification data, the preset comparison result includes that the third host verification data is different from the third trust verification data. That is, whether there is one or more preset verification ciphertexts, as long as the preset verification ciphertext is the correct ciphertext, on the premise that the system has not entered the preset security state, that is, the number of times when the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data is less than the second preset quantity threshold, it is considered that the third host verification data is the same as the third trust verification data, that is, the preset comparison result is achieved. Whether there is one or more preset verification ciphertexts, as long as the preset verification ciphertext is the incorrect ciphertext, on the premise that the system has not entered the preset security state, that is, the number of times when the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data is less than the second preset quantity threshold, it is considered that the third host verification data is different from the third trust verification data, that is, the preset comparison result is achieved.

[0226] In the above embodiment, when monitoring is performed multiple times, all the preset verification ciphertexts are either all correct ciphertexts or all incorrect ciphertexts. To make the monitoring more flexible and diverse, some of the preset verification ciphertexts can also be set as correct ciphertexts and some of the preset verification ciphertexts can be set as incorrect ciphertexts. (In the above embodiments of the encryption scenario, verification can also be performed in the way of some correct ciphertexts and some incorrect ciphertexts. For details, reference can be made to the embodiments here and will not be elaborated). In another embodiment, if the number of preset verification ciphertexts is multiple, at least one preset verification ciphertext is the correct ciphertext of the preset verification data, and at least one preset verification ciphertext is the incorrect ciphertext of the preset verification data. A sixth comparison sub-result is determined according to each preset verification ciphertext, and the final sixth comparison result determined based on all the sixth comparison sub-results includes:

[0227] If the preset verification ciphertext is the correct ciphertext of the preset verification data, the method for determining the sixth comparison sub-result includes: if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, the sixth comparison sub-result is determined as the correct result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, the sixth comparison sub-result is determined as the incorrect result;

[0228] If the preset verification ciphertext is an incorrect ciphertext of the preset verification data, the determination method of the sixth comparison result includes: if the third host verification data corresponding to the preset verification ciphertext is different from the third trusted verification data, determining the sixth comparison result as the correct result; if the third host verification data corresponding to the preset verification ciphertext is the same as the third trusted verification data, determining the sixth comparison result as the incorrect result; counting the number of results where the sixth comparison result is the incorrect result; if the number of results is less than the preset result threshold, determining that the monitoring passes; if the number of results is greater than or equal to the preset result threshold, controlling the controller to enter the preset security state.

[0229] It should be noted that the preset result threshold can be the second preset quantity threshold, or other values set by those skilled in the art. The second preset quantity threshold can be a fixed value or a variable value. For example, a counter can be used, and the second preset quantity threshold can be updated in a countdown manner, etc.

[0230] The above correct result and incorrect result can be set by those skilled in the art according to needs with corresponding representation methods for subsequent statistics. Correspondingly, for the determination method when the number of results is less than the preset result threshold for the sixth comparison result, only one example is given above. Those skilled in the art can also change it to other ways according to needs for representation.

[0231] First, monitor the decryption process of the trust anchor through the preset verification ciphertext. If the decryption process of the trust anchor is reliable, then monitor the transmission process of the content data after decrypting the trust anchor, that is, execute steps S1410 - S1430. The process of verification using the preset verification ciphertext is similar to the relevant steps of the foregoing steps S1410 - S1430. For details, reference can be made to the description of the above embodiments and will not be elaborated here.

[0232] In one embodiment, before triggering the step of sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor, the method includes: setting the number of preset verification ciphertexts to be one or more, determining a sixth comparison result according to each preset verification ciphertext, and determining the final sixth comparison result based on all the sixth comparison results.

[0233] Taking the case where the preset verification ciphertext is the correct ciphertext of the preset verification data as an example, if the sixth comparison sub-result greater than the second preset quantity threshold is that the third host verification data is different from the third trusted verification data, enter the preset security state. It should be noted that the preset security state of the decryption part may be the same as or different from the preset security state of the encryption part in the foregoing embodiments. Otherwise, if the preset security state is not entered, that is, if the sixth comparison sub-result less than the second preset quantity threshold is that the third host verification data is different from the third trusted verification data, then the sixth comparison result is that the third host verification data is the same as the third trusted verification data. For example, the number of preset verification ciphertexts is one or more. According to each preset verification data and the preset verification ciphertext of the preset verification data, the monitoring result (the sixth comparison sub-result) of the trust anchor for the data transmission process is determined once. Based on the monitoring results of the trust anchor for the data transmission process corresponding to all the preset verification data, the final monitoring result (the sixth comparison result) of the trust anchor for the data transmission process is determined. That is, when there is one preset verification data, the monitoring of the trust anchor for the data transmission process is performed once to obtain the monitoring result (the sixth comparison result) of the trust anchor for the data transmission process. When the number of preset verification data is multiple, the monitoring of the trust anchor for the data transmission process can be performed separately or synchronously multiple times to obtain multiple monitoring results (the sixth comparison sub-results) of the trust anchor for the data transmission process. If the monitoring results of the trust anchor for the data transmission process exceeding a certain quantity (the second preset quantity threshold) are "the third host verification data is different from the third trusted verification data", then trigger to enter the preset security state. Otherwise, it is considered that the sixth comparison result is that the third host verification data is the same as the third trusted verification data, and continue to execute step S1410-step S1430. When using multiple preset verification ciphertexts to improve the credibility of the symmetric encryption algorithm of the trust anchor, in different processes of improving the credibility of the symmetric encryption algorithm of the trust anchor, the use order of the multiple preset verification ciphertexts can be unchanged, randomly switched, or switched according to a preset order to improve the coverage rate of hardware failures.

[0234] In one embodiment, the trust anchor decrypts the preset verification ciphertext to obtain decrypted verification data, including that the trust anchor decrypts the preset verification ciphertext with a first decryption sub-key to obtain decrypted verification data; the trust anchor decrypts the ciphertext to be transmitted to obtain decrypted transmission data, including that the trust anchor decrypts the ciphertext to be transmitted with a second decryption sub-key to obtain decrypted transmission data; wherein, the first decryption sub-key and the second decryption sub-key are the same or different. That is, when monitoring the decryption process of the trust anchor, the second decryption sub-key used to decrypt the preset verification ciphertext and the first decryption sub-key used to decrypt the ciphertext to be transmitted during the monitoring process of the transmission process of the content data after decrypting the trust anchor can be the same or different. However, it should be known that the decryption key of the preset verification ciphertext and the encryption key of the preset verification data are a pair of key pairs, and the encryption key of the data to be transmitted and the decryption key of the ciphertext to be transmitted are a pair of key pairs.

[0235] When this solution supports the ciphertext to be transmitted and the preset verification ciphertext, two sets of key pairs can be set separately, or the same key pair can be shared. The specific choice can be determined by those skilled in the art according to needs.

[0236] In one embodiment, before the trust anchor decrypts the ciphertext to be transmitted to obtain decrypted transmission data, the method includes: storing the decryption key in the trust anchor for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data; or storing the decryption key in the host in a read-only form, and sending the decryption key from the host to the trust anchor for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data. The decryption key needs to be stored in a medium that can ensure the integrity of the key, which can be directly stored inside the trust anchor or stored in the host software with single-write capabilities, etc.

[0237] In one embodiment, the method further includes: counting the number of occurrences of a second event of a decryption target event in a preset statistical period, where the decryption target event includes at least one of the following: the fifth comparison result is incorrect, the sixth comparison result is incorrect; if the number of occurrences of the second event is greater than a second preset quantity threshold, controlling the controller to enter a preset safe state.

[0238] For example, count the number of occurrences of the fifth comparison result being incorrect and the sixth comparison result being incorrect in the most recent preset duration as the number of occurrences of the event. When the number of occurrences of the second event is greater than the preset second preset quantity threshold, control the controller to enter a preset safe state. The preset safe state can be set by those skilled in the art according to the specific application scenario of the controller as needed. For example, for a motor controller or an engine controller, entering the preset safe state may switch the power output, and for an autonomous driving ADAS controller, it may transmit a safety signal to the upper-layer decision-making controller, indicating that an abnormality is known, etc.

[0239] The second preset quantity threshold and the first preset quantity threshold can be set by those skilled in the art according to needs. For example, they can be determined according to the quantity of the total preset verification data, or the quantity of the total preset verification ciphertext, etc. The quantity of the second event occurrence and the quantity of the first event occurrence can be the quantity accumulated in a certain period of time, or can be obtained by counting according to the counting method required by those skilled in the art.

[0240] The credibility of the trust anchor decrypting the to-be-transmitted ciphertext may not be solely related to the influencing factors mentioned in this embodiment. At this time, after the decryption trusted state is determined to be trusted, the credibility of the decrypted transmission data decrypted by the trust anchor can also be improved according to certain preset rules, but it is necessary to ensure that the credibility of the decrypted transmission data is higher than the credibility of the trust anchor and not higher than the credibility of the decryption monitoring module.

[0241] In one embodiment, before the host sends the to-be-transmitted ciphertext and the second monitoring problem to the trust anchor, the method includes: determining the estimated decryption content calculation time of the to-be-transmitted ciphertext; if the decryption content calculation time is greater than or equal to the preset duration threshold, triggering to send the to-be-transmitted ciphertext and the second monitoring problem to the trust anchor; if the decryption content calculation time is less than the preset duration threshold, decrypting the to-be-transmitted ciphertext by the host to obtain the decrypted transmission data, or triggering to send the to-be-transmitted ciphertext and the second monitoring problem to the trust anchor.

[0242] The preset duration threshold can be equal to or greater than the functional safety fault tolerance time interval (Fault Tolerant Time Interval, FTTI), and the preset duration threshold can also be set by those skilled in the art according to needs. The preset duration threshold of the decryption process and the preset duration threshold of the encryption process can be equal or unequal, and those skilled in the art can choose according to needs.

[0243] The estimated decryption content calculation time is also the estimated time for the decryption monitoring module to decrypt the to-be-transmitted ciphertext to obtain the decrypted transmission data. The estimated decryption content calculation time can be pre-calibrated and known when the decryption monitoring module receives the to-be-transmitted ciphertext, or can be estimated by the decryption monitoring module after receiving the to-be-transmitted ciphertext, or can also be determined by other methods known to those skilled in the art.

[0244] If the computing power overhead for the host-side (host) security core to directly decrypt the ciphertext to be transmitted is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), without affecting the normal function of the controller, then symmetric encryption calculation can be directly performed on the host side to obtain a symmetric encryption calculation result with a high functional safety level. Moreover, in order to achieve the corresponding ASIL level for the calculation result of the symmetric encryption algorithm on the host side, the software development process of the symmetric encryption algorithm on the host side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed Freedom From Interference (FFI) with other ASIL / QM level software.

[0245] However, when the amount of calculation for decrypting the ciphertext to be transmitted is large, the computing power overhead for directly calculating the decrypted transmission data whose integrity needs to be guaranteed on the host side is large, and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller. Then, the above method cannot be used to directly calculate the original content obtained by decryption with a high functional safety level through the host-side security core, and it is necessary to monitor the decryption process through the decryption trusted state determination method provided in this embodiment. Or first monitor the decryption transmission process, and then monitor the decryption algorithm itself.

[0246] In one embodiment, before the host obtains the preset verification ciphertext, the method includes: selecting one set from a set or multiple sets of preset verification data and the preset verification ciphertext of the preset verification data designed in advance as the current preset verification ciphertext and preset verification data, and being obtained by the host. It should be noted that the preset verification ciphertext of the preset verification data can be calculated by a third party (non-host). The set or multiple sets of preset verification data designed in advance and the preset verification ciphertext of the preset verification data can be stored in the host of the MCU, or can be stored in a preset storage space communicatively connected to the host.

[0247] In another embodiment, the preset verification ciphertext can be calculated by the host. At this time, select one set from a set or multiple sets of preset verification data designed in advance as the current preset verification data and be obtained by the host, and then calculate the preset verification ciphertext through the host for the selected preset verification data. Since the data size of the preset verification data is limited to be small, even if the preset verification ciphertext is calculated by the host at this time, it will not affect the normal use of the MCU.

[0248] The method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in the above embodiments, in the stage of the trust anchor performing the decryption task, decrypts the ciphertext to be transmitted by the trust anchor with relatively low credibility to obtain the decrypted transmission data, determines the second answer according to the second monitoring problem during the decryption process, and then generates the second trust verification data according to the second answer and the decrypted transmission data. The second host verification data generated by the decryption monitoring module with relatively high credibility based on the second preset answer and the decrypted transmission data is used to perform the fifth comparison with the second trust verification data, and then the fifth comparison result is obtained. The decryption monitoring module with relatively high credibility determines the decryption trust status, which can improve the security level of the computing function of the trust anchor for decrypting the ciphertext to be transmitted without affecting the host function, and provides a solution to replace and supplement the existing functional safety mechanism.

[0249] Optionally, by adding the second monitoring problem during the decryption process of the trust anchor and synchronously determining the second answer during the decryption process, this solution covers the scenarios where the hardware resources related to the ciphertext calculation and decryption algorithm of the trust anchor fail.

[0250] Optionally, before decrypting the ciphertext to be transmitted that actually needs to be decrypted, the decryption process of the trust anchor is monitored one or more times through the preset verification ciphertext and the preset verification data of the preset verification ciphertext, that is, one or more sixth comparison sub-results are obtained through the preset verification data of one or more sets of preset verification ciphertexts, and then the sixth comparison result is obtained. On the premise that the sixth comparison result is that the third host verification data is the same as the third trust verification data, the step of sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor is triggered, further improving the reliability of improving the credibility of the symmetric encryption algorithm of the trust anchor for the final actual ciphertext. Or, by counting the number of times when each sixth comparison sub-result is that the third host verification data is different from the third trust verification data, it is judged whether the controller enters the preset safety state, and whether to trigger the step of sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor is determined according to whether the controller enters the preset safety state.

[0251] Optionally, by configuring multiple sets of variable second monitoring problems, third monitoring problems, and flexible ways of generating the second answer and the third answer, the diagnostic coverage rate can be improved, and the failure situations of multiple hardware resources at multiple trust anchor ends can be covered.

[0252] The solution provided in this embodiment designs a solution for improving the functional safety level of symmetric encryption algorithms based on trust anchors such as HSM. This solution can improve the functional safety level of the symmetric encryption algorithm calculation based on trust anchors such as HSM without affecting the functions of the HOST side, enabling the symmetric encryption algorithm based on trust anchors such as HSM to replace and supplement the existing functional safety mechanisms to ensure the data integrity related to functional safety and expand its scope of use.

[0253] In another embodiment, a method for determining the trusted state of trust anchor encryption and decryption is further provided. This method includes the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in any of the above embodiments (including the trust anchor executing the encryption task stage and the trust anchor executing the decryption task stage). It should be noted that the execution sequence of the method for improving the algorithm credibility of the trust anchor during the decryption process and the encryption process is not limited, and it can be carried out simultaneously or one party can be prior to the other party. In one embodiment, a method for improving the credibility of the symmetric encryption algorithm of the trust anchor is further provided, which is applied to a controller. The controller includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. This method includes:

[0254] The host obtains a preset verification ciphertext, preset verification data, and a third monitoring question, and sends the preset verification ciphertext and the third monitoring question to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring question is the same as or different from the second monitoring question;

[0255] The trust anchor decrypts the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determines a third answer based on the third monitoring question, generates third trust verification data based on the third answer and the decrypted verification data, and sends the third trust verification data to the decryption monitoring module;

[0256] The decryption monitoring module generates third host verification data based on the preset verification data and the third preset answer to the third monitoring question, and compares the third host verification data with the third trust verification data to obtain a sixth comparison result.

[0257] The limitations of the relevant technical features in this embodiment can refer to the relevant descriptions of the above embodiments and will not be elaborated.

[0258] By using the preset verification ciphertext to monitor the controller, the credibility of the symmetric encryption algorithm of the trust anchor in the decryption stage can be improved to a certain extent.

[0259] Taking the controller as an MCU, the MCU is divided into a host and a trust anchor. The trust anchor is an HSM, the preset verification ciphertext is the target ciphertext for monitoring, the preset verification data is the actual content for monitoring, the target ciphertext for monitoring is the correct ciphertext, and the ciphertext to be transmitted is the symmetric encryption ciphertext as an example. The implementation of monitoring is mainly completed in the decryption monitoring module. The decryption monitoring module is a trusted module. Taking the symmetric encryption monitoring software as an implementation example, the symmetric encryption monitoring software has ASIL, and the credibility of the decryption monitoring module is higher than that of the trust anchor. Taking the decryption monitoring module as ASIL-D and the HSM as QM as an example, the decryption trusted state determination method provided in the above embodiment is illustrated by way of example.

[0260] The application of the symmetric encryption algorithm in automotive controllers also has the following scenarios:

[0261] C. Scenario 3, decrypting the ciphertext based on symmetric encryption to obtain the original content.

[0262] If the computing power overhead for directly decrypting to obtain the original content (HOST) on the HOST side of the security core is small, the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), and it will not affect the normal function of the controller, then the symmetric encryption calculation can be directly performed on the HOST side to obtain the decrypted original content with a high functional safety level. And, in order to achieve the corresponding ASIL level for the calculation result of the symmetric encryption algorithm on the HOST side, the software development process of the symmetric encryption algorithm on the HOST side and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and it is necessary to ensure freedom from interference (FFI) with other software of ASIL / QM levels.

[0263] However, if the computing power overhead for directly calculating the decrypted original content whose integrity needs to be guaranteed on the HOST side is large, the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI), or it will affect the normal function of the controller, then the above method cannot be used to directly calculate the decrypted original content (decrypted transmission data) with a high functional safety level through the security core on the HOST side, and a functional safety mechanism needs to be designed additionally.

[0264] For the above Scenario C3, decrypting the ciphertext based on symmetric encryption to obtain the original content. This scenario involves the decryption process of the symmetric encryption algorithm and needs to cover the failures of the decryption process on the HSM side and the data transmission process of transmitting the decrypted original content from the HSM side to the HOST side. The following functional safety mechanisms are designed for the above two parts of failures.

[0265] To monitor the symmetric encryption process at the HSM end, one or more sets of "ciphertext for monitoring" and "actual content for monitoring" dedicated to monitoring are designed. For the convenience of key management, the symmetric key for monitoring can be the same as the symmetric key actually used, or a separate symmetric key for monitoring can be injected. The design of the "ciphertext for monitoring" and the "actual content for monitoring" needs to ensure that the time for calculating the "actual content for monitoring" based on the "ciphertext for monitoring" at the HOST end can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI). Using multiple sets can increase the failure coverage rate. Or the "actual content for monitoring" corresponding to the "ciphertext for monitoring" can also be directly preset at the HOST end as the basis for monitoring judgment.

[0266] Taking the monitoring process of the "symmetric encryption monitoring software" with one set of "ciphertext for monitoring" and "actual content for monitoring" as an example, please refer to Figure 16 and Figure 17 , Figure 16 which is a specific flowchart of the method for monitoring the symmetric encryption process at the HSM end provided by an embodiment of the present invention. Figure 17 is Figure 16 a data transmission diagram of the method for monitoring the symmetric encryption process at the HSM end provided. As Figure 16 and Figure 17 shown, the symmetric encryption monitoring software at the HOST end issues the first monitoring problem to the driver at the HOST end (HSM HOST Driver, trust anchor driver function module), and through the HSM HOST Driver, the ciphertext for monitoring and the third monitoring problem are issued to the HSM Firmware at the HSM end. The credibility of the HSM HOST Driver and the HSM Firmware can be QM. The HSM Firmware sends the obtained CRC (the third answer + the actual content obtained by decrypting the ciphertext for monitoring) to the symmetric encryption monitoring software through the HSM HOST Driver. The symmetric encryption monitoring software calculates the CRC (the third preset answer + the actual content for monitoring), and judges whether the CRC (the third preset answer + the actual content for monitoring) is equal to the CRC (the third answer + the actual content obtained by decrypting the ciphertext for monitoring), that is, performs the sixth comparison to obtain the sixth comparison result. If so, the monitoring passes; if not, the monitoring fails. Passing the monitoring can trigger the step of sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor.

[0267] Before actually decrypting the ciphertext to be transmitted to calculate the actual content, at least one Figure 16 and Figure 17 monitoring process of the "symmetric encryption monitoring software" is executed.

[0268] To monitor the data transmission process of the decrypted original content transmitted from the HSM side to the HOST side, a monitoring mechanism as shown in Figure 18 and Figure 19 is also designed in the "symmetric encryption monitoring software". Figure 18 FIG. is a specific flow schematic diagram of the method for monitoring the data transmission process of the decrypted original content transmitted from the HSM side to the HOST side provided by the embodiment of the present invention. Figure 19 It is Figure 18 a data transmission schematic diagram of the method for monitoring the data transmission process of the decrypted original content transmitted from the HSM side to the HOST side provided by Figure 18 and Figure 19 As shown, the symmetric encryption monitoring software on the HOST side issues the first monitoring problem to the driver on the HOST side (HSM HOST Driver, trust anchor driver function module), and through the HSM HOST Driver, the symmetric encryption ciphertext and the second monitoring problem are issued to the HSM Firmware on the HSM side. The credibility of the HSM HOST Driver and the HSM Firmware can be QM. The HSM Firmware sends the obtained CRC (the second answer + the decrypted original content) to the symmetric encryption monitoring software through the HSM HOST Driver. The symmetric encryption monitoring software calculates the CRC (the second preset answer + the decrypted original content), and determines whether the CRC (the second preset answer + the decrypted original content) is equal to the CRC (the second answer + the decrypted original content), that is, performs the fifth comparison to obtain the fifth comparison result. If so, the monitoring passes; if not, the monitoring fails. Furthermore, the decryption trust status of the decrypted transmission data is obtained. Through the above method, the credibility of the decrypted original content can be improved.

[0269] For the failure confirmation and response when the above monitoring fails, a failure counter can be set. If the failure counter is greater than the threshold, the system is made to enter the safe state according to the requirements of the actual functional safety target.

[0270] Please refer to Figure 15 , Figure 15 FIG. is a specific flow schematic diagram of the decryption trust status determination method provided by the embodiment of the present invention. As shown in Figure 15 , in the pre-preparation stage, the data sender sends the symmetric encryption ciphertext to the host of the MCU ( Figure 15Shown as HOST in the middle, HOST will receive. When the monitoring starts, the HOST side will determine the third monitoring question and the monitoring ciphertext, and send the third monitoring question and the monitoring ciphertext to the HSM side. The HSM side decrypts the monitoring ciphertext to obtain the actual content obtained by decrypting the monitoring ciphertext. During the decryption process, it determines the third answer to the third monitoring question, and performs a cyclic redundancy check based on the third answer and the actual content obtained by decrypting the monitoring ciphertext, calculates the third trust verification value, and uses this third trust verification value as the third trust verification data, that is Figure 15 "CRC(third answer + actual content obtained by decrypting the monitoring ciphertext)" in, where CRC (Cyclic Redundancy Check) is the cyclic redundancy check code, and "+" means that the content before and after participates in the CRC calculation together. Send CRC(third answer + actual content obtained by decrypting the monitoring ciphertext) to the HOST side. The HOST side determines the third preset answer according to the third monitoring question, and calculates the third host verification data according to the third preset answer and the actual monitoring content, that is Figure 15 "CRC(third preset answer + actual monitoring content)" in Figure 15 The step position in is only an example and does not serve as a schematic of the specific steps between the determination of the third host verification data and other steps. Compare CRC(third answer + actual content obtained by decrypting the monitoring ciphertext) with CRC(third preset answer + actual monitoring content) to obtain the sixth comparison result. On the premise that the controller has not entered the preset safe state, determine the second monitoring question, and the HOST sends the symmetric encryption ciphertext and the second monitoring question to the HSM. The HSM decrypts the symmetric encryption ciphertext to obtain the decrypted original content. During the decryption process, it determines the second answer according to the second monitoring question, and performs a cyclic redundancy check based on the second answer and the decrypted original content, calculates the second trust verification value, and uses this second trust verification value as the second trust verification data, that is Figure 15 "CRC(second answer + decrypted original content)" in, send CRC(second answer + decrypted original content) and the decrypted original content to the HOST. The HOST determines the second preset answer according to the second monitoring question, and performs a cyclic redundancy check based on the second preset answer and the decrypted original content, calculates the second host verification value, and uses this second host verification value as the second host verification data, that is Figure 15 "CRC(second preset answer + decrypted original content)" in, compare CRC(second preset answer + decrypted original content) with CRC(second answer + decrypted original content), the fifth comparison result. Exemplarily, the decryption trust state of the decrypted original content can also be determined based on the fifth comparison result.

[0271] In one embodiment, a controller is provided, which is used to implement the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in any of the above embodiments. Please refer to Figure 20 , Figure 20 FIG. is a schematic structural diagram of the controller provided in the embodiment of the present invention. As Figure 20 shown, the controller 2000 includes a trust anchor 2010 and a host 2020. The host 2020 includes an encryption monitoring module 2021, and the credibility of the encryption monitoring module 2021 is higher than that of the trust anchor 2010. The detailed description of each functional module is as follows:

[0272] The host 2020 is configured to obtain data to be transmitted, a target ciphertext, and a first monitoring question, send the data to be transmitted and the first monitoring question to the trust anchor, and the target ciphertext is determined by encrypting the data to be transmitted;

[0273] The trust anchor 2010 is configured to encrypt the data to be transmitted based on a symmetric encryption algorithm to obtain an actual ciphertext, and during the process of encrypting the data to be transmitted, determine a first answer according to the first monitoring question, generate first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module 2021;

[0274] The encryption monitoring module 2021 is configured to generate first host verification data according to the target ciphertext and a first preset answer of the first monitoring question, and perform a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result.

[0275] In one embodiment, the host further includes a trust anchor driver function module, which is configured to obtain the data to be transmitted and the target ciphertext, as well as the first monitoring question sent by the encryption monitoring module, send the data to be transmitted and the first monitoring question to the trust anchor, and receive the first trust verification data fed back by the trust anchor, and send the first trust verification data to the encryption monitoring module.

[0276] In one embodiment, the trust anchor driver function module is further configured to send the target ciphertext to the trust anchor and receive the trust anchor integrity verification result fed back by the trust anchor. At this time, the encryption monitoring module is further configured to determine the encryption trust status of the actual ciphertext based on the trust anchor integrity verification result and the first comparison result.

[0277] In one embodiment, the encryption monitoring module may be disposed in the trust anchor driver function module.

[0278] In one embodiment, the host further includes a mode switching module. The mode switching module is configured to determine the preset verification data as the data to be transmitted and determine the preset ciphertext of the preset verification data as the target ciphertext when the host receives the original content data sent by the data sender and does not receive the original ciphertext. The preset ciphertext is obtained by encrypting the preset verification data.

[0279] In one embodiment, the mode switching module is further configured to determine the estimated actual ciphertext calculation time of the actual transmission content data after the host receives the original content data sent by the data sender as the actual transmission content data; if the estimated actual ciphertext calculation time is greater than or equal to the preset duration threshold, trigger the determination of the preset verification data as the data to be transmitted; if the estimated actual ciphertext calculation time is less than the preset duration threshold, trigger the determination of the preset verification data as the data to be transmitted, or obtain the actual ciphertext by encrypting the actual transmission content data through the encryption monitoring module.

[0280] In one embodiment, the encryption monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.

[0281] In one embodiment, the controller further includes a statistics module for counting the number of occurrences of the first event with a doubtful encryption trust status; if the number of occurrences of the first event is greater than the first preset number threshold, control the controller to enter the preset security state.

[0282] For the specific limitations of the controller, reference can be made to the limitations of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0283] In this embodiment, the controller essentially sets multiple modules to execute the method for improving the credibility of the symmetric encryption algorithm of the trust anchor that performs the encryption task in any of the above embodiments. The specific functions and technical effects can be referred to the above embodiments, which will not be elaborated here.

[0284] In one embodiment, a controller is provided. The controller is used to implement the method for improving the credibility of the symmetric encryption algorithm of the trust anchor that performs the decryption task provided in any of the above embodiments. Please refer to Figure 21 , Figure 21 which is another structural schematic diagram of the controller provided by the embodiment of the present invention, as Figure 21As shown, the controller 2100 includes a trust anchor 2110 and a host 2120. The host 2120 includes a decryption monitoring module 2121, and the credibility of the decryption monitoring module 2121 is higher than that of the trust anchor 2110. The detailed description of each functional module is as follows:

[0285] The host 2120 is used to obtain the ciphertext to be transmitted and the second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content.

[0286] The trust anchor 2110 is used to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain the decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determine the second answer according to the second monitoring question, generate the second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module 2121.

[0287] The decryption monitoring module 2121 is used to generate the second host verification data according to the decrypted transmission data and the second preset answer of the second monitoring question, and compare the second host verification data with the second trust verification data to obtain the fifth comparison result.

[0288] In one embodiment, Figure 21 the host and the trust anchor in Figure 20 are similar in structure to the host and the trust anchor in the controller in

[0289] They may be the same structure or similar structures in different controllers.

[0290] In one embodiment, the host further includes a trust anchor driver function module. The trust anchor driver function module is used to obtain the ciphertext to be transmitted and the second monitoring question issued by the encryption monitoring module, send the ciphertext to be transmitted and the second monitoring question to the trust anchor, and receive the second trust verification data fed back by the trust anchor, and send the second trust verification data to the decryption monitoring module.

[0291] In one embodiment, the decryption monitoring module may be set in the trust anchor driver function module.

[0292] In one embodiment, the decryption monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.

[0293] In one embodiment, the controller further includes a statistics module for counting the number of occurrences of a second event of a decryption target event in a preset statistical period. The decryption target event includes at least one of the following: the fifth comparison result is incorrect, and the sixth comparison result is incorrect. If the number of occurrences of the second event is greater than a second preset quantity threshold, the controller is controlled to enter a preset security state.

[0294] For the specific limitations of the controller, reference can be made to the limitations of the method for improving the credibility of the symmetric encryption algorithm of the trust anchor that performs the decryption task for the trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0295] In this embodiment, the controller essentially sets multiple modules to execute the method for improving the credibility of the symmetric encryption algorithm of the trust anchor that performs the decryption task for the trust anchor in any of the above embodiments. The specific functions and technical effects can be referred to the above embodiments, and will not be elaborated here.

[0296] In one embodiment, a controller is provided. The controller includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. Among them:

[0297] The host is configured to obtain a preset verification ciphertext, preset verification data, and a third monitoring problem, and send the preset verification ciphertext and the third monitoring problem to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring problem is the same as or different from the second monitoring problem;

[0298] The trust anchor is configured to decrypt the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determine a third answer according to the third monitoring problem, generate third trust verification data based on the third answer and the decrypted verification data, and send the third trust verification data to the decryption monitoring module;

[0299] The decryption monitoring module is configured to generate third host verification data according to the third preset answer of the preset verification data and the third monitoring problem, and perform a sixth comparison between the third host verification data and the third trust verification data to obtain a sixth comparison result.

[0300] In this embodiment, the controller essentially sets up multiple modules to execute the method for improving the credibility of the symmetric encryption algorithm of the trust anchor in any of the above embodiments. For the specific functions and technical effects, please refer to the above embodiments and will not be elaborated here.

[0301] In one embodiment, a controller is provided. The controller is used to implement the method for improving the credibility of the symmetric encryption algorithm of the trust anchor provided in any of the above embodiments. Please refer to Figure 22 , Figure 22 which is another structural schematic diagram of the controller provided in the embodiment of the present invention. As Figure 22 shown, the controller 2200 includes a trust anchor 2210 and a host 2220. The host 2220 includes an encryption monitoring module 2221 and a decryption monitoring module 2222. The credibility of the encryption monitoring module 2222 is higher than that of the trust anchor 2210, and the credibility of the decryption monitoring module 2221 is higher than that of the trust anchor 2210. The detailed description of each functional module is as follows:

[0302] The host 2220 is used to obtain the data to be transmitted, the target ciphertext, and the first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted;

[0303] The trust anchor 2210 is used to encrypt the data to be transmitted based on the symmetric encryption algorithm to obtain the actual ciphertext, and during the process of encrypting the data to be transmitted, determine the first answer according to the first monitoring question, generate the first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module;

[0304] The encryption monitoring module 2221 is used to generate the first host verification data according to the target ciphertext and the first preset answer of the first monitoring question, and perform the first comparison between the first host verification data and the first trust verification data to obtain the first comparison result;

[0305] The host 2220 is further used to obtain the ciphertext to be transmitted and the second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content;

[0306] The trust anchor 2210 is further used to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain the decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determine the second answer according to the second monitoring question, generate the second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module 2222;

[0307] The decryption monitoring module 2222 is used to generate second host verification data according to the decrypted transmission data and the second preset answer to the second monitoring question, and compare the second host verification data with the second trust verification data to obtain a fifth comparison result.

[0308] In one embodiment, Figure 22 the host, trust anchor, encryption monitoring module, and decryption monitoring module in Figure 20 , Figure 21 are structurally and functionally similar to the host, trust anchor, encryption monitoring module, and decryption monitoring module in the controller in Figure 22 The controller in Figure 20 and Figure 21 has at least some of the modules and functions of the controller shown in Figure 20 and Figure 21 For specific introductions, please refer to the relevant introductions of the controller in

[0309] For specific limitations on the controller, reference can be made to the limitations on the method for improving the credibility of the symmetric encryption algorithm of the trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the electronic device in hardware form or be independent of it, or be stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0310] In this embodiment, the controller is essentially provided with multiple modules to execute the method for improving the credibility of the symmetric encryption algorithm of the trust anchor in any of the above embodiments. For specific functions and technical effects, refer to the above embodiments, which will not be elaborated here.

[0311] In one embodiment, an electronic device is provided. The electronic device can be a server, and its internal structure diagram can be as shown in Figure 23 The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the server side of a method for improving the credibility of the symmetric encryption algorithm of the trust anchor and / or a method for determining the decryption trusted state.

[0312] In one embodiment, an electronic device is provided. The electronic device can be a client, and its internal structure diagram can be as shown in Figure 24As shown in the figure. The electronic device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a method for improving the credibility of the symmetric encryption algorithm of a trust anchor and / or a method for determining the decryption trusted state.

[0313] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0314] Control the host to obtain the data to be transmitted, the target ciphertext, and the first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted;

[0315] Control the trust anchor to encrypt the data to be transmitted based on the symmetric encryption algorithm to obtain the actual ciphertext. During the process of encrypting the data to be transmitted, determine the first answer according to the first monitoring question, generate the first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module;

[0316] Control the encryption monitoring module to generate the first host verification data according to the target ciphertext and the first preset answer of the first monitoring question, compare the first host verification data with the first trust verification data to obtain the first comparison result.

[0317] In another embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0318] Control the host to obtain the ciphertext to be transmitted and the second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content;

[0319] Control the trust anchor to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain the decrypted transmission data. During the process of decrypting the ciphertext to be transmitted, determine the second answer according to the second monitoring question, generate the second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module;

[0320] The control passes through the decryption monitoring module to generate second host verification data according to the decrypted transmission data and the second preset answer to the second monitoring question, and compares the second host verification data with the second trust verification data for a fifth comparison to obtain a fifth comparison result.

[0321] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0322] The control passes through the host to obtain the data to be transmitted, the target ciphertext, and the first monitoring question, sends the data to be transmitted and the first monitoring question to the trust anchor, and the target ciphertext is determined by encrypting the data to be transmitted;

[0323] The control passes through the trust anchor to encrypt the data to be transmitted based on the symmetric encryption algorithm to obtain the actual ciphertext. During the process of encrypting the data to be transmitted, the first answer to the first monitoring question is determined, and the first trust verification data is generated based on the first answer and the actual ciphertext, and the first trust verification data is sent to the encryption monitoring module;

[0324] The control passes through the encryption monitoring module to generate first host verification data according to the target ciphertext and the first preset answer to the first monitoring question, and compares the first host verification data with the first trust verification data for a first comparison to obtain a first comparison result.

[0325] In another embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0326] The control passes through the host to obtain the ciphertext to be transmitted and the second monitoring question, sends the ciphertext to be transmitted and the second monitoring question to the trust anchor, and the ciphertext to be transmitted is obtained by encrypting the original content;

[0327] The control passes through the trust anchor to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain the decrypted transmission data. During the process of decrypting the ciphertext to be transmitted, the second answer to the second monitoring question is determined, and the second trust verification data is generated based on the second answer and the decrypted transmission data, and the second trust verification data and the decrypted transmission data are sent to the decryption monitoring module;

[0328] The control passes through the decryption monitoring module to generate second host verification data according to the decrypted transmission data and the second preset answer to the second monitoring question, and compares the second host verification data with the second trust verification data for a fifth comparison to obtain a fifth comparison result.

[0329] It should be noted that for the functions or steps that can be achieved by the above computer-readable storage medium or electronic device, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0330] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.

[0331] Those skilled in the art can clearly understand that for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device, system, and controller can be divided into different functional units or modules to complete all or part of the functions described above.

[0332] The embodiments provided above are only used to illustrate the technical solutions of the present invention, not to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

Claims

1. A method for improving the credibility of a symmetric encryption algorithm for trust anchors, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. The method includes: The host obtains data to be transmitted, a target ciphertext, and a first monitoring question, and sends the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted. The trust anchor encrypts the data to be transmitted based on a symmetric encryption algorithm to obtain an actual ciphertext. During the process of encrypting the data to be transmitted, the trust anchor determines a first answer according to the first monitoring question, generates first trust verification data based on the first answer and the actual ciphertext, and sends the first trust verification data to the encryption monitoring module. The encryption monitoring module generates first host verification data according to the target ciphertext and a first preset answer to the first monitoring question, and performs a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result.

2. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 1, characterized in that The method further includes: The host sends the target ciphertext to the trust anchor. The trust anchor performs a second comparison between the target ciphertext and the actual ciphertext, determines a trust anchor integrity verification result based on the second comparison result, and sends the trust anchor integrity verification result to the encryption monitoring module. The encryption monitoring module performs a seventh comparison based on the trust anchor integrity verification result and the first comparison result to obtain a seventh comparison result.

3. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 1, wherein, The method further includes: After performing the first comparison between the first host verification data and the first trust verification data, the host obtains new data to be transmitted, a new target ciphertext, and a new first monitoring question, and sends the new data to be transmitted, the new target ciphertext, and the new first monitoring question to the trust anchor. The new target ciphertext is determined by encrypting the new data to be transmitted. The new data to be transmitted may be the same as or different from the data to be transmitted, and the new first monitoring question may be the same as or different from the first monitoring question. The trust anchor encrypts the new data to be transmitted to obtain a new actual ciphertext. During the process of encrypting the new data to be transmitted, the trust anchor determines a new first answer according to the new first monitoring question, generates new first trust verification data based on the new first answer and the new actual ciphertext. The trust anchor performs a third comparison between the new target ciphertext and the new actual ciphertext, determines a trust anchor integrity verification result based on the third comparison result, and sends the new first trust verification data and the trust anchor integrity verification result to the encryption monitoring module. The encryption monitoring module generates new first host verification data according to the new target ciphertext and a new first preset answer to the new first monitoring question, and performs a fourth comparison between the new first host verification data and the new first trust verification data to obtain a fourth comparison result.

4. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the host obtains the data to be transmitted and the target ciphertext, the method includes: The data sender calculates an original ciphertext according to the original content data. The data sender sends the original content data and the original ciphertext to the host, so that the host receives the original content data as the actual transmission content data, takes the original ciphertext as the target ciphertext of the actual transmission content data, and determines the actual transmission content data as the data to be transmitted.

5. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the host obtains the data to be transmitted and the target ciphertext, the method includes: The data sender sends the original content data to the host; If the host does not receive the original ciphertext of the original content data, the preset verification data is determined as the data to be transmitted, and the preset ciphertext of the preset verification data is determined as the target ciphertext, where the preset ciphertext is obtained by encrypting the preset verification data.

6. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 5, characterized in that, If the preset ciphertext is the wrong ciphertext of the preset verification data, the first comparison between the first host verification data and the first trust verification data includes: If the first host verification data is different from the first trust verification data, it is determined that the monitoring of the symmetric encryption algorithm for the trust anchor passes; If the first host verification data is the same as the first trust verification data, it is determined that the monitoring of the symmetric encryption algorithm for the trust anchor fails.

7. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 5, characterized in that, After the first comparison between the first host verification data and the first trust verification data, the method further includes: The host takes the received original content data as the actual transmission content data and sends it to the trust anchor, so that the trust anchor encrypts the actual transmission content data to obtain a content ciphertext.

8. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, The host obtains the first monitoring problem, including any one of the following: Obtain a preset problem and determine the preset problem as the first monitoring problem; Obtain multiple preset problems and determine one or more selected preset problems as the first monitoring problem; Obtain the first sent monitoring problem and multiple preset problems, screen out the first sent monitoring problem from the multiple preset problems, and determine the one or more preset problems after screening as the first monitoring problem; Obtain the first sent monitoring problem and multiple preset problems, determine the randomly selected multiple preset problems as the preselected problems. If the problem content of the preselected problems is the same as the problem content of the first sent monitoring problem, adjust the problem sorting of the multiple preset problems in the preselected problems so that the problem sorting of the preselected problems is different from the problem sorting of the first sent monitoring problem, and determine the adjusted preselected problems as the first monitoring problem.

9. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Determine the first answer according to the first monitoring problem, including: The trust anchor matches the first monitoring problem with multiple preset local problems in the preset problem answer table. If it matches successfully with a preset local problem, the preset local answer corresponding to the preset local problem is determined as the first answer sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem, and the trust anchor stores the preset problem answer table; The trust anchor triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as the second answer sub-answer. The preset function module is set in the trust anchor; The trust anchor collects one or more monitoring results of its own security mechanisms based on the first monitoring problem, and determines the one or more monitoring results of its own security mechanisms as the third answer sub-answer; The trust anchor generates the first answer based on at least one of the first answer sub-answer, the second answer sub-answer, and the third answer sub-answer.

10. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the encryption monitoring module generates the first host verification data according to the target ciphertext and the first preset answer of the first monitoring problem, the method includes: The encryption monitoring module matches the first monitoring problem with a plurality of preset local problems in a preset problem answer table. If the match with a preset local problem is successful, the preset local answer corresponding to the preset local problem is determined as the first preset sub-answer. The preset problem answer table includes at least one preset local problem and the preset local answer corresponding to each preset local problem. The encryption monitoring module stores the problem answer table; The encryption monitoring module triggers a preset function module based on the first monitoring problem to output a function answer, and determines the function answer as the second preset sub-answer. The preset function module is set in the encryption monitoring module; The encryption monitoring module determines one or more monitoring results of the trust anchor's own security mechanisms as the third preset sub-answer based on the first monitoring problem; The encryption monitoring module generates the first preset answer based on at least one of the first preset sub-answer, the second preset sub-answer, and the third preset sub-answer; The encryption monitoring module determines the first host verification data according to the target ciphertext and the first preset answer.

11. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, The trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, including: If the actual transmission content data is determined as the data to be transmitted, the trust anchor encrypts the actual transmission content data with a first sub-encryption key to obtain the actual ciphertext; If the preset verification data is determined as the data to be transmitted, the trust anchor encrypts the preset verification data with a second sub-encryption key to obtain the actual ciphertext; Wherein, the first sub-encryption key and the second sub-encryption key are the same or different.

12. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, Before the trust anchor encrypts the data to be transmitted to obtain the actual ciphertext, the method includes: Storing the encryption key into the trust anchor for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext; Or, Storing the encryption key in the host in a read-only form, and sending the encryption key to the trust anchor by the host for the trust anchor to encrypt the data to be transmitted with the encryption key to obtain the actual ciphertext.

13. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, The method further includes: Counting the number of occurrences of the first event of the encryption target event in a preset statistical period. The encryption target event includes at least one of the following: the first comparison result is different, the seventh comparison result is different, and the fourth comparison result is different; If the number of occurrences of the first event is greater than the first preset quantity threshold, control the controller to enter a preset safe state.

14. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 1-3, characterized in that, The method further includes: Receiving new original content data sent by a data sender as new actual transmission content data; Determining a new estimated actual ciphertext calculation time for the new actual transmission content data; If the new estimated actual ciphertext calculation time is greater than or equal to a preset duration threshold, sending the new actual transmission content data to a trust anchor to encrypt the new actual transmission content data through the trust anchor to obtain a new actual ciphertext; If the new estimated actual ciphertext calculation time is less than the preset duration threshold, encrypting the new actual transmission content data through an encryption monitoring module or the trust anchor to obtain a new actual ciphertext.

15. A method for improving the credibility of a symmetric encryption algorithm for a trust anchor, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: The host obtains a ciphertext to be transmitted and a second monitoring problem, and sends the ciphertext to be transmitted and the second monitoring problem to the trust anchor. The ciphertext to be transmitted is obtained by encrypting original content based on a symmetric encryption algorithm; The trust anchor decrypts the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain decrypted transmission data, and in the process of decrypting the ciphertext to be transmitted, determines a second answer according to the second monitoring problem, generates second trust verification data based on the second answer and the decrypted transmission data, and sends the second trust verification data and the decrypted transmission data to the decryption monitoring module; The decryption monitoring module generates second host verification data according to the decrypted transmission data and a second preset answer to the second monitoring problem, and compares the second host verification data with the second trust verification data to obtain a fifth comparison result.

16. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 15, wherein The method includes: The host obtains a preset verification ciphertext, preset verification data, and a third monitoring problem, and sends the preset verification ciphertext and the third monitoring problem to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring problem is the same as or different from the second monitoring problem; The trust anchor decrypts the preset verification ciphertext based on the symmetric encryption algorithm to obtain decrypted verification data, and in the process of decrypting the preset verification ciphertext, determines a third answer according to the third monitoring problem, generates third trust verification data based on the third answer and the decrypted verification data, and sends the third trust verification data to the decryption monitoring module; The decryption monitoring module generates third host verification data according to the preset verification data and a third preset answer to the third monitoring problem, and compares the third host verification data with the third trust verification data to obtain a sixth comparison result.

17. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 15, characterized in that, The host obtaining the second monitoring problem includes any one of the following: Obtaining a preset problem and determining the preset problem as the second monitoring problem; Obtaining a plurality of preset problems and determining one or more selected preset problems as the second monitoring problem; Obtain multiple preset questions and the second monitored questions that have been sent, screen out the second monitored questions that have been sent from the multiple preset questions, and determine the one or more preset questions after screening as the second monitored questions; Obtain multiple preset questions and the second monitored questions that have been sent, determine randomly selected multiple preset questions as preselected questions. If the question content of the preselected questions is the same as the question content of the second monitored questions that have been sent, adjust the question order of the multiple preset questions in the preselected questions so that the question order of the preselected questions is different from the question order of the second monitored questions that have been sent, and determine the adjusted preselected questions as the second monitored questions.

18. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 15, wherein Determine the second answer according to the second monitored questions, including: The trust anchor matches the second monitored questions with multiple preset local questions in the preset question answer table. If a match is successful with a preset local question, determine the preset local answer corresponding to the preset local question as the fourth answer sub-answer. The preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question, and the trust anchor stores the preset question answer table; The trust anchor triggers a preset function module based on the second monitored questions to output a function answer, and determines the function answer as the fifth answer sub-answer. The trust anchor is provided with the preset function module; The trust anchor collects one or more self-owned security mechanism monitoring results of the trust anchor based on the second monitored questions, and determines the one or more self-owned security mechanism monitoring results as the sixth answer sub-answer; The trust anchor generates the second answer according to at least one of the fourth answer sub-answer, the fifth answer sub-answer and the sixth answer sub-answer.

19. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 15, wherein Before the decryption monitoring module generates the second host verification data according to the decrypted transmission data and the second preset answer of the second monitored questions, the method includes: The decryption monitoring module matches the second monitored questions with multiple preset local questions in the preset question answer table. If a match is successful with a preset local question, determine the preset local answer corresponding to the preset local question as the fourth preset sub-answer. The preset question answer table includes at least one preset local question and the preset local answer corresponding to each preset local question, and the decryption monitoring module stores the question answer table; The decryption monitoring module triggers a preset function module based on the second monitored questions to output a function answer, and determines the function answer as the fifth preset sub-answer. The decryption monitoring module is provided with the preset function module; The decryption monitoring module determines one or more self-owned security mechanism monitoring results of the trust anchor as the sixth preset sub-answer based on the second monitored questions; The decryption monitoring module generates the second preset answer according to at least one of the fourth preset sub-answer, the fifth preset sub-answer and the sixth preset sub-answer.

20. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 16, wherein The trust anchor decrypts the preset verification ciphertext to obtain decrypted verification data, including that the trust anchor decrypts the preset verification ciphertext with a first decryption sub-key to obtain decrypted verification data; The trust anchor decrypts the ciphertext to be transmitted to obtain decrypted transmission data, including that the trust anchor decrypts the ciphertext to be transmitted with a second decryption sub-key to obtain decrypted transmission data; Wherein, the first decryption sub-key and the second decryption sub-key are the same or different.

21. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 16, characterized in that, If the number of the preset verification ciphertexts is multiple, at least one of the preset verification ciphertexts is the correct ciphertext of the preset verification data, and at least one of the preset verification ciphertexts is the incorrect ciphertext of the preset verification data. Determining a sixth comparison sub-result according to each preset verification ciphertext, and determining the final sixth comparison result based on all the sixth comparison sub-results includes: If the preset verification ciphertext is the correct ciphertext of the preset verification data, the determining method of the sixth comparison sub-result includes: if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as the correct result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as the incorrect result; If the preset verification ciphertext is the incorrect ciphertext of the preset verification data, the determining method of the sixth comparison sub-result includes: if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as the correct result; if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as the incorrect result; Counting the number of results where the sixth comparison sub-result is the incorrect result; If the number of results is less than the preset result threshold, it is determined that the monitoring passes; If the number of results is greater than or equal to the preset result threshold, controlling the controller to enter the preset safe state.

22. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to claim 16, characterized in that, The method further includes: If all the preset verification ciphertexts are the correct ciphertexts of the preset verification data, determining a sixth comparison sub-result according to each preset verification ciphertext, and determining the final sixth comparison result based on all the sixth comparison sub-results includes: if the third host verification data corresponding to the preset verification ciphertext is the same as the third trust verification data, determining the sixth comparison sub-result as the correct result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trust verification data, determining the sixth comparison sub-result as the incorrect result; Counting the number of results where the sixth comparison sub-result is the incorrect result; If the number of results is less than the preset result threshold, it is determined that the monitoring passes; If the number of results is greater than or equal to the preset result threshold, controlling the controller to enter the preset safe state.

23. The method for enhancing the credibility of the symmetric encryption algorithm of the trust anchor according to claim 16, wherein, The method further includes: If all the preset verification ciphertexts are the incorrect ciphertexts of the preset verification data, Determine a sixth comparison sub-result according to each preset verification ciphertext. Determining the final sixth comparison result based on all the sixth comparison sub-results includes: if the third host verification data corresponding to the preset verification ciphertext is the same as the third trusted verification data, determine the sixth comparison sub-result as an error result; if the third host verification data corresponding to the preset verification ciphertext is different from the third trusted verification data, determine the sixth comparison sub-result as a correct result; Count the number of results where the sixth comparison sub-result is an error result; If the number of results is less than the preset result threshold, determine that the monitoring passes; If the number of results is greater than or equal to the preset result threshold, control the controller to enter a preset security state.

24. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 15-23, characterized in that, Before the trust anchor decrypts the ciphertext to be transmitted to obtain decrypted transmission data, the method includes: Store the decryption key in the trust anchor for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data; Or, Store the decryption key in the host in read-only form, and send the decryption key to the trust anchor through the host for the trust anchor to decrypt the ciphertext to be transmitted with the decryption key to obtain decrypted transmission data.

25. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 15-20, characterized in that, The method further includes: Count the number of occurrences of a second event of a decryption target event in a preset statistical period, where the decryption target event includes at least one of the following: the fifth comparison result is an error, the sixth comparison result is an error; If the number of occurrences of the second event is greater than a second preset quantity threshold, control the controller to enter a preset security state.

26. The method for improving the credibility of the symmetric encryption algorithm of the trust anchor according to any one of claims 15-23, characterized in that, Before the host sends the ciphertext to be transmitted and a second monitoring problem to the trust anchor, the method includes: Determine the estimated decryption content calculation time of the ciphertext to be transmitted; If the decryption content calculation time is greater than or equal to a preset duration threshold, trigger sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor; If the decryption content calculation time is less than the preset duration threshold, decrypt the ciphertext to be transmitted by the host to obtain decrypted transmission data, or trigger sending the ciphertext to be transmitted and the second monitoring problem to the trust anchor.

27. A method for improving the credibility of a symmetric encryption algorithm for a trust anchor, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: The host obtains a preset verification ciphertext, preset verification data, and a third monitoring problem, and sends the preset verification ciphertext and the third monitoring problem to the trust anchor. The preset verification ciphertext is determined by encrypting the preset verification data, and the third monitoring problem is the same as or different from the second monitoring problem; The trust anchor decrypts the preset verification ciphertext based on a symmetric encryption algorithm to obtain decrypted verification data, and during the process of decrypting the preset verification ciphertext, determines a third answer according to the third monitoring problem, generates third trusted verification data based on the third answer and the decrypted verification data, and sends the third trusted verification data to the decryption monitoring module; The decryption monitoring module generates third host verification data based on the preset verification data and the third preset answer to the third monitoring question, and performs a sixth comparison between the third host verification data and the third trust verification data to obtain a sixth comparison result.

28. A controller, characterized in that, The controller includes a trust anchor and a host. The host includes an encryption monitoring module and a decryption monitoring module. The credibility of the encryption monitoring module is higher than that of the trust anchor, where: The host is used to obtain the data to be transmitted, the target ciphertext, and the first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted. The trust anchor is used to encrypt the data to be transmitted based on the symmetric encryption algorithm to obtain the actual ciphertext, and during the process of encrypting the data to be transmitted, determine the first answer based on the first monitoring question, generate the first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module. The encryption monitoring module is used to generate first host verification data based on the target ciphertext and the first preset answer to the first monitoring question, and perform a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result.

29. A controller, characterized in that, The controller includes a trust anchor and a host. The host includes a decryption monitoring module. The credibility of the decryption monitoring module is higher than that of the trust anchor, where: The host is used to obtain the ciphertext to be transmitted and the second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor. The ciphertext to be transmitted is obtained by encrypting the original content based on the symmetric encryption algorithm. The trust anchor is used to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain the decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determine the second answer based on the second monitoring question, generate the second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module. The decryption monitoring module is used to generate second host verification data based on the decrypted transmission data and the second preset answer to the second monitoring question, and perform a fifth comparison between the second host verification data and the second trust verification data to obtain a fifth comparison result.

30. A controller, characterized in that, The controller includes a trust anchor and a host. The host includes an encryption monitoring module and a decryption monitoring module. The credibility of the encryption monitoring module is higher than that of the trust anchor, and the credibility of the decryption monitoring module is higher than that of the trust anchor, where: The host is used to obtain the data to be transmitted, the target ciphertext, and the first monitoring question, and send the data to be transmitted and the first monitoring question to the trust anchor. The target ciphertext is determined by encrypting the data to be transmitted. The trust anchor is used to encrypt the data to be transmitted based on a symmetric encryption algorithm to obtain an actual ciphertext, and during the process of encrypting the data to be transmitted, determine a first answer to the first monitoring question, generate first trust verification data based on the first answer and the actual ciphertext, and send the first trust verification data to the encryption monitoring module; The encryption monitoring module is used to generate first host verification data according to the target ciphertext and the first preset answer to the first monitoring question, perform a first comparison between the first host verification data and the first trust verification data to obtain a first comparison result; The host is further used to obtain the ciphertext to be transmitted and a second monitoring question, and send the ciphertext to be transmitted and the second monitoring question to the trust anchor, where the ciphertext to be transmitted is obtained by encrypting the original content based on a symmetric encryption algorithm; The trust anchor is further used to decrypt the ciphertext to be transmitted based on the symmetric encryption algorithm to obtain decrypted transmission data, and during the process of decrypting the ciphertext to be transmitted, determine a second answer to the second monitoring question, generate second trust verification data based on the second answer and the decrypted transmission data, and send the second trust verification data and the decrypted transmission data to the decryption monitoring module; The decryption monitoring module is used to generate second host verification data according to the decrypted transmission data and the second preset answer to the second monitoring question, perform a fifth comparison between the second host verification data and the second trust verification data to obtain a fifth comparison result.

31. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 27 is implemented.

32. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 27 is implemented.