Method for improving credibility of asymmetric encryption algorithm of trust anchor, controller, equipment and medium

By introducing a high-reliability encryption monitoring module into the controller to monitor the encryption results of the trust anchor, the problem of unreliable encryption results caused by the failure of the hardware resources of the HSM module is solved, and trustworthy encryption in key functional safety scenarios is achieved.

CN120378127APending Publication Date: 2025-07-25UNITED AUTOMOTIVE ELECTRONICS SYST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410104424.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-24
Publication Date
2025-07-25

Smart Images

  • Figure CN120378127A_ABST
    Figure CN120378127A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of vehicles, and discloses an asymmetric encryption algorithm credibility improvement method of a trust anchor, a controller, equipment and a medium. And obtaining host encryption verification data through an encryption monitoring module with relatively high credibility, receiving trust anchor encryption verification data obtained by a trust anchor with relatively low credibility through calculation based on an asymmetric encryption algorithm, and performing third comparison on the trust anchor encryption verification data and the host encryption verification data to obtain a third comparison result. According to the technical scheme, the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor can be monitored based on the encryption monitoring module with high credibility, so that the credibility of the asymmetric encryption algorithm of the trust anchor can be improved, and the functional security level of the encryption result of the trust anchor can be ensured, so that the method is applied to functional security key scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of vehicles, and in particular to a method for improving the credibility of an asymmetric encryption algorithm of a trust anchor, a controller, a device, and a medium. Background Art

[0002] With the improvement of the degree of vehicle networking, information security issues have become increasingly prominent, and the ISO21434 automotive network security standard has been officially released in 2021. In order to meet the requirements for the storage of controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments, it is necessary to be equipped with a trust anchor (such as an HSM module).

[0003] In addition, with the increasing complexity of automotive electronic control systems and the introduction of a large number of electrical and electronic components, while bringing control convenience and diversity, it also brings certain risks to vehicle safety due to inevitable systematic failures and random hardware failures. To further improve the safety design of road vehicle-related products, the ISO26262 road vehicle functional safety standard has been introduced. Based on the analysis of the risks and hazards of the vehicle under various working conditions, this standard evaluates the safety levels (Automotive Safety Integrity Level, ASIL) for different safety objectives and defines four different ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. Among them, ASIL D represents the highest safety integrity, while ASIL A represents the lowest safety integrity. In addition, if a risk is identified as QM, there is no corresponding safety requirement. That is, from QM, ASIL-A / B / C / D, the functional safety has gradually become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.

[0004] With the improvement of the degree of vehicle networking, there will be more and more interactions between future functional safety and information security. On the one hand, ensuring information security is the basis for achieving functional safety; on the other hand, functional safety may also need to rely on information security mechanisms to achieve.

[0005] In related technologies, some HSM firmware has been developed in accordance with the requirements of the functional safety process. However, currently, there are still a large number of HSM modules of MCUs that have not been developed in accordance with the functional safety standard, that is, the failure of their hardware resources is not covered by corresponding functional safety mechanisms. Therefore, how to improve the functional safety level of information security mechanisms is a brand-new topic.

[0006] In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module.

[0007] Asymmetric encryption algorithms are currently widely used in the field of automotive information security. However, since the hardware resources on the HSM side currently have no functional safety mechanism coverage, the encryption results obtained on it cannot guarantee the functional safety level and can only be considered QM, and cannot be applied to functional safety critical scenarios. Summary of the Invention

[0008] An embodiment of the present invention provides a method, a controller, a device, and a medium for improving the credibility of an asymmetric encryption algorithm of a trust anchor, so as to solve the technical problem in the related art that since the hardware of the HSM module of the MCU is not developed according to the functional safety standard, that is, the failure of its hardware resources has no corresponding functional safety mechanism coverage, resulting in the encryption result obtained on the HSM side not being able to guarantee the functional safety level, and can only be considered QM, and cannot be applied to functional safety critical scenarios.

[0009] An embodiment of the present invention provides a method for improving the credibility of an asymmetric encryption algorithm of a trust anchor, which is applied to a controller. The controller includes a trust anchor and a host. The host includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. The method includes: the encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host; the encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0010] In an embodiment of the present invention, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: the host obtains initial actual data; determines the expected host encryption time of the initial actual data; if the expected host encryption time is less than a preset time threshold, determines the initial actual data as the data to be encrypted; if the expected host encryption time is greater than or equal to the preset time threshold, determines the initial test data as the data to be encrypted, determines the host encryption test data as the host encryption verification data, the expected host encryption time of the initial test data is less than the preset time threshold, and the host encryption test data is obtained by encrypting the initial test data through the host public key.

[0011] In an embodiment of the present invention, if the initial actual data is determined as the data to be encrypted, the method includes: the encryption monitoring module obtains the host encryption verification data, including that the encryption monitoring module encrypts the initial actual data through the host public key to obtain the host second encrypted transmission data, and uses the host second encrypted transmission data as the host encryption verification data; the encryption monitoring module obtains the trust anchor encryption verification data, including that the trust anchor encrypts the initial actual data through the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor encrypted transmission data, and sends the trust anchor encrypted transmission data to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor encrypted transmission data as the trust anchor encryption verification data.

[0012] In an embodiment of the present invention, after obtaining the third comparison result, the method further includes at least one of the following: if the third comparison result is that the host second encrypted transmission data is the same as the trust anchor encrypted transmission data, determine at least one of the following, the trust anchor encrypted transmission data can be stored, the asymmetric encryption algorithm of the trust anchor is credible, the data transmission link between the trust anchor and the encryption monitoring module is credible; if the third comparison result is that the host second encrypted transmission data is different from the trust anchor encrypted transmission data, determine that the trust anchor encrypted transmission data cannot be stored.

[0013] In an embodiment of the present invention, if the initial test data is determined as the data to be encrypted and the host encryption test data is determined as the host encryption verification data, the encryption monitoring module obtains the trust anchor encryption verification data, including: the trust anchor receives the initial test data sent by the encryption monitoring module, encrypts the initial test data through the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor second encrypted test data as the trust anchor encryption verification data.

[0014] In an embodiment of the present invention, after obtaining the third comparison result, the method further includes at least one of the following: if the third comparison result is that the trust anchor second encrypted test data is the same as the host encryption test data, determine at least one of the following, the asymmetric encryption algorithm of the trust anchor is credible, the data transmission link between the trust anchor and the encryption monitoring module is credible; if the third comparison result is that the trust anchor second encrypted test data is different from the host encryption test data, determine at least one of the following, the asymmetric encryption algorithm of the trust anchor is not credible, the data transmission link between the trust anchor and the encryption monitoring module is not credible.

[0015] In an embodiment of the present invention, the method further includes: the encryption monitoring module sends new initial test data; the trust anchor receives the new initial test data sent by the encryption monitoring module, encrypts the new initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain new trust anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received new trust anchor second encrypted test data as trust anchor encryption verification data; the encryption monitoring module uses the new host encryption verification data of the new initial test data as the new host encryption verification data, and makes a third comparison between the new host encryption verification data and the new trust anchor encryption verification data to obtain a new third comparison result.

[0016] In an embodiment of the present invention, after obtaining the third comparison result, the method further includes: counting the number of encryption anomaly events where the third comparison result is that the host encryption verification data is different from the trust anchor encryption verification data within a preset statistical period; if the number of encryption anomaly events is greater than a second preset number threshold, controlling the controller to enter a secure state.

[0017] In an embodiment of the present invention, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: the transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes the transmission monitoring module. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data using the host public key; the trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key is available.

[0018] In an embodiment of the present invention, when the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, it includes: the transmission monitoring module encrypts the initial test data using the host public key to obtain host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.

[0019] In an embodiment of the present invention, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm through the trust anchor private key to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.

[0020] In an embodiment of the present invention, the method further includes: if the second comparison result is that the initial test data is the same as the first decrypted test data, storing the initial test data and the host encrypted test data in the transmission monitoring module.

[0021] In an embodiment of the present invention, the transmission monitoring module determines host transmission verification data and test transmission data based on the initial test data, including: the transmission monitoring module encrypts the initial test data through the host public key to obtain host encrypted test data; determines the initial test data and the host encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.

[0022] In an embodiment of the present invention, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data based on the asymmetric encryption algorithm through the trust anchor public key to obtain trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm through the trust anchor private key to obtain second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result that the host transmission verification data is the same as the trust anchor transmission verification data includes: the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data.

[0023] In an embodiment of the present invention, the method further includes: if the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, storing the initial test data and the host encrypted test data in the transmission monitoring module.

[0024] An embodiment of the present invention also provides a controller, which includes a trust anchor and a host. The host includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. Wherein: The encryption monitoring module is used to obtain host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by encrypting the data to be encrypted through the host public key by the encryption monitoring module. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host; The encryption monitoring module is also used to perform a third comparison on the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0025] In an embodiment of the present invention, the controller further includes an early warning module, which is used to, after obtaining the third comparison result, count the number of encryption anomaly events where the third comparison result is that the host encryption verification data is different from the trust anchor encryption verification data within a preset statistical period; if the number of encryption anomaly events is greater than a second preset number threshold, control the controller to enter a safe state.

[0026] In an embodiment of the present invention, the controller further includes a transmission monitoring module. The transmission monitoring module is used to obtain initial test data before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, and determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data through the host public key. The credibility of the transmission monitoring module is higher than that of the trust anchor; The trust anchor is also used to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feedback it to the transmission monitoring module; The transmission monitoring module is also used to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result. If the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, it is determined that the host public key is available.

[0027] An embodiment of the present invention also provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method of any of the above embodiments is implemented.

[0028] An embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method of any of the above embodiments is implemented.

[0029] In the solution implemented by the method, controller, device, and medium for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided above, during the encryption stage of the trust anchor, the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor obtains host encryption verification data through an encryption monitoring module with relatively high credibility, and receives trust anchor encryption verification data calculated by the trust anchor with relatively low credibility based on the asymmetric encryption algorithm. The trust anchor encryption verification data is compared with the host encryption verification data for the third time to obtain a third comparison result. Through the above process, it is possible to monitor the calculation and transmission processes of the asymmetric encryption algorithm of the trust anchor based on the encryption monitoring module with relatively high credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor and ensuring the functional safety level of the encryption result of the trust anchor for application in functional safety critical scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0031] Figure 1 Schematic flowchart of an implementation method for transmitting an asymmetric encryption public key based on HSM provided by an embodiment of the invention;

[0032] Figure 2 Schematic flowchart of an implementation method for decrypting asymmetric data based on HSM provided by an embodiment of the invention;

[0033] Figure 3 Schematic flowchart of an implementation method for storing asymmetric encrypted data based on HSM provided by an embodiment of the invention;

[0034] Figure 4 Schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention;

[0035] Figure 5 Specific schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention;

[0036] Figure 6 Specific schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention;

[0037] Figure 7 Another schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention;

[0038] Figure 8 Another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0039] Figure 9 For Figure 8 The data transmission schematic diagram of the method shown;

[0040] Figure 10 Another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0041] Figure 11 For Figure 10 The data transmission schematic diagram of the method shown;

[0042] Figure 12 Another flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0043] Figure 13 Another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0044] Figure 14 Another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;

[0045] Figure 15 A schematic structural diagram of the controller provided by the embodiment of the present invention;

[0046] Figure 16 Another schematic structural diagram of the controller provided by the embodiment of the present invention;

[0047] Figure 17 Another schematic structural diagram of the controller provided by the embodiment of the present invention;

[0048] Figure 18 A schematic structural diagram of an electronic device in an embodiment of the present invention;

[0049] Figure 19 Another schematic structural diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners

[0050] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0051] To enable those skilled in the art to better understand the improvements of the technical solutions provided by the present disclosure, the present disclosure briefly introduces the implementation method of the asymmetric encryption algorithm based on HSM and related information in the related art.

[0052] A trust anchor is a module required to meet the requirements of storing secure data (keys / root certificates) of the controller, cryptographic algorithms and their hardware acceleration, secure applications, secure chip operating environment, etc. The implementation methods of the trust anchor in MCU applications include Secure Hardware Extension (SHE), Hardware Security Module (HSM), Secure Element (SE), etc. Among them, HSM is a specification proposed by the E-safety Vehicle Intrusion proTected Applications (EVITA, 2008 - 2011), that is, a research project of the European Union for the vehicle communication security of Vehicle to Everything (V2X), which is divided into three levels: Light, Medium, and Full. Currently, the mainstream automotive-grade MCUs are equipped with a Hardware Security Module (HSM), and the Full level has become a trend to meet the information security requirements of vehicle controllers.

[0053] An asymmetric encryption algorithm refers to an algorithm that uses different keys during the encryption and decryption processes. For example, when two communication parties (such as A and B) exchange data, A and B first exchange their public keys. Then, when exchanging data, A can use B's public key to encrypt the data to be exchanged, and B can use its own private key to decrypt the encrypted data after receiving it. Therefore, the asymmetric encryption algorithm is also called the public key encryption algorithm.

[0054] The asymmetric encryption algorithm is currently widely used in the field of automotive information security, such as the public key transfer of controllers, encrypted communication, data encrypted storage, etc. The asymmetric encryption and decryption algorithms can ensure the confidentiality of data. Even if a third party obtains the data encrypted by the asymmetric encryption, they still cannot know the meaning of the data. Encryption and decryption generally use international standard algorithms, such as the RSA algorithm (an asymmetric encryption algorithm based on the large number factorization problem) and the Elliptic Curve Cryptography (ECC) algorithm (elliptic curve cryptographic algorithm). In the asymmetric encryption algorithm, the number of controllers determines the number of public-private key pairs. The controllers receiving the messages need to distribute their public keys to other controllers in advance, and only the controllers with the private keys can decrypt the data encrypted with the public key.

[0055] As an example, the application of the HSM-based asymmetric encryption and decryption algorithm in public key transmission, encrypted communication, and encrypted data storage is as Figure 1 , Figure 2 and Figure 3 shown.

[0056] When the controller is used as a data receiving end, the controller includes a host end and a trust anchor end. Taking the trust anchor as the HSM host end, it includes a software monitoring module HOST Software and a trust anchor host driver module HSM HOST Driver, and the HSM end includes a hardware security module firmware HSM Firmware as an example. Please refer to Figure 1 , Figure 1 which is a schematic flow chart of an implementation method for the transmission of an asymmetric encryption public key based on HSM provided by an invention embodiment, as Figure 1 shown. The data receiving end HOST Software first calls the driver (HSM HOST Driver) function of the HSM located at the HOST end to request the generation of a public-private key pair. That is, HOSTSoftware sends a public-private key pair generation request 1, 2 to the HSM Firmware through the HSM HOST Driver. After the HSM firmware (HSM Firmware) at the HSM end generates the key pair, it records the private key and the public key and returns the public key to the HOST end. That is, Figure 1 in 3, 4 of Figure 1 , the HSM Firmware sends the public key to the HOST Software through the HSM HOST Driver. The HOST Software sends the public key to the data sending end. That is,

[0057] When the controller is used as a data receiving end, the controller includes a host end and a trust anchor end. Taking the trust anchor as the HSM host end, it includes a software monitoring module HOST Software and a trust anchor host driver module HSM HOST Driver, and the HSM end includes a hardware security module firmware HSM Firmware as an example. Please refer to Figure 2 , Figure 2 which is a schematic flow chart of an implementation method for the asymmetric data decryption based on HSM provided by an invention embodiment, as Figure 2 shown. After the HOST Software at the data receiving end receives the encrypted data sent by the data sending end (that is, Figure 2 the encrypted data reception in Figure 2In the transmission process of the encrypted data in 2 and 3, the HSM firmware on the HSM side decrypts it with the private key and returns the data to the HOST Software through the HSM HOSTDriver on the HOST side, that is Figure 2 The original data decrypted with the private key as shown in 4 and 5 in Figure 1 The generated public-private key pair.

[0058] When the controller is used as the data storage side (data sending side), the controller includes a host side and a trust anchor side. Taking the software monitoring module HOST Software and the trust anchor host driver module HSM HOSTDriver in the HSM host side with the trust anchor as an example, the HSM side includes the hardware security module firmware HSM Firmware. Please refer to Figure 3 , Figure 3 The flow schematic diagram of an implementation method for asymmetric encrypted data storage based on HSM provided for the invention embodiment, as Figure 3 shown, the HOST Software on the data storage side first calls the driver (HSM HOST Driver) function of the HSM located on the HOST side to request the data to be stored ( Figure 3 The original data in 1 and 2 in Figure 3 to be encrypted with the public key. After the HSM firmware (HSM Firmware) on the HSM side encrypts the data, it returns the data to the HOST Software through the driver HSM HOST Driver on the HOST side, that is Figure 1 The data encrypted with the public key as shown in 3 and 4 in Figure 3 The generated public-private key pair. Then execute

[0059] Since the hardware resources on the HSM side are currently not covered by a functional safety mechanism, the encryption or decryption results obtained on it cannot guarantee the functional safety level and can only be considered as QM and cannot be applied to functional safety critical scenarios.

[0060] For current mainstream MCUs, the HOST side has a perfect functional safety mechanism to ensure that the diagnostic coverage rate of its hardware failures can meet the requirements of the highest ASIL-D; and, it has at least one safety core with a Lockstep mechanism, and the Lockstep mechanism can make the diagnostic coverage rate of the MCU core meet the requirements of ASIL-D.

[0061] In asymmetric encryption, the public key is a public key that can be distributed externally, while the private key is a key that must be securely stored within the HSM. Therefore, the inventor utilized the characteristic of public key sharing to design a solution for enhancing the functional security level of the asymmetric encryption and decryption algorithm based on the HSM.

[0062] The MCU hardware resources used for generating the public and private key pairs and performing asymmetric encryption and decryption at the HSM side mainly include: the CPU, storage, bus, clock, power supply at the HSM side, and the information security algorithm hardware acceleration unit (asymmetric encryption and decryption algorithm). Among them, the clock, power supply, and the HOST side are of the same origin and can be overridden by the HOST side. However, additional functional safety mechanisms need to be designed to cover the failures of other resources.

[0063] The method for enhancing the credibility of the asymmetric encryption algorithm of the trust anchor provided in the embodiments of the present application can be applied to the controller MCU. The controller includes a trust anchor Trust Anchor and a host HOST. The host includes a software monitoring module, and the software monitoring module includes at least one of a transmission monitoring module, an encryption monitoring module, and a decryption monitoring module. The credibility of the transmission monitoring module, the encryption monitoring module, and the decryption monitoring module is higher than the credibility of the trust anchor Trust Anchor. At least two of the transmission monitoring module, the encryption monitoring module, and the decryption monitoring module can be integrated into one module or can be separated, and no limitation is made in this regard.

[0064] The credibility in this embodiment can be evaluated by the above-mentioned vehicle safety integrity level ASIL, or can also be achieved by other trust rules set by those skilled in the art for the field of functional safety. Functional safety can be understood as the absence of unreasonable risks caused by hazards resulting from abnormal functional behaviors of electronic / electrical systems. For example, as exemplified in the above embodiments, the credibility of the trust anchor is QM, and the credibility of the host is ASIL D. It should be noted that the encryption (decryption) monitoring module can be a "symmetric encryption (decryption) monitoring software" designed in the security core of the HOST side. In order to achieve the corresponding ASIL level for the integrity check success flag bit, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be guaranteed freedom from interference (FFI) with other ASIL / QM level software. The encryption monitoring module and the decryption monitoring module can be the same entity module or different entity modules.

[0065] In another embodiment, the credibility can be understood as the degree of trust that can actually be achieved in an actual application scenario, even in the presence of possible software interference, rather than just referring to the degree of trust calculated during the design of the software or module.

[0066] This method can be applied to application scenarios such as public key transfer, encrypted communication, and encrypted data storage in the field of automotive information security.

[0067] In one embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment can be applied to the process of asymmetric encryption and decryption of the trust anchor of each controller. That is, in the process of each execution of the trust anchor for asymmetric encryption and decryption of the received data, the solution of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment is executed, thereby ensuring the credibility of the results of asymmetric encryption and decryption of the received data by the trust anchor each time.

[0068] In another embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment can also be triggered randomly, or at intervals of a preset detection duration, or at intervals of a preset number of data transmissions, etc., to verify whether the results of asymmetric encryption and decryption of the trust anchor are credible.

[0069] The transmission monitoring module, encryption monitoring module, and decryption monitoring module can be hardware units with computing capabilities that meet the requirements of functional safety levels, such as: hardware acceleration units, at least one secure core with a Lockstep mechanism, etc.

[0070] The implementation methods of the trust anchor include but are not limited to SHE, HSM, SE, etc., which are known to those skilled in the art. In the design of an MCU with a trust anchor, the MCU can be divided into a trust anchor end (hereinafter referred to as the trust anchor) and a host end (hereinafter referred to as the host). The host is the other part except for modules such as the trust anchor like HSM, and the trust anchor is the module part such as HSM.

[0071] In another embodiment, credibility can be understood as the credible degree that can actually be achieved in an actual application scenario, even if there may be software interference, rather than just the credible degree calculated during the design of the software or module.

[0072] Please refer to Figure 4 as shown Figure 4 which is a schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention, providing a functional safety improvement solution for asymmetric data decryption. The method includes the following steps:

[0073] Step S410, the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor.

[0074] Among them, the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm.

[0075] Before step S410, continue to refer to Figure 1 , the trust anchor generates a trust anchor public key and a trust anchor private key. The trust anchor sends the trust anchor public key to the decryption monitoring module of the host, and the decryption monitoring module uses the received trust anchor public key as the host public key. The data to be decrypted can be obtained by the decryption monitoring module encrypting the initial test data in advance according to the host public key, or the data sender can receive the trust anchor public key sent by the controller in advance as the sender public key and encrypt the unencrypted actual data based on this sender public key.

[0076] Step S420, the decryption monitoring module determines the trust anchor decryption comparison data according to the trust anchor decryption verification data, and makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.

[0077] Among them, depending on the determination method of the trust anchor decryption verification data, the trust anchor decryption comparison data can be directly the trust anchor decryption verification data, or the decryption monitoring module processes the trust anchor decryption verification data to obtain the trust anchor decryption comparison data. Correspondingly, based on the different selected trust anchor decryption comparison data, the host decryption comparison data also needs to be adjusted accordingly. The host decryption comparison data can be the data to be decrypted itself, or the data to be decrypted and the original data corresponding to the data to be decrypted.

[0078] In an embodiment, before the decryption monitoring module receives the original encrypted transmission data, the method includes: the encryption monitoring module of the data sender receives the trust anchor public key sent by the controller, uses the trust anchor public key as the sender public key, encrypts the unencrypted actual data through the sender public key to obtain the original encrypted transmission data, and sends the original encrypted transmission data to the decryption monitoring module.

[0079] Taking the controller's actual processing of the data to be decrypted sent by the data sender as an example, in an embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the decryption monitoring module receives the original encrypted transmission data and sends it to the trust anchor. The data to be decrypted includes the original encrypted transmission data, and the original encrypted transmission data is encrypted based on the sender public key of the data sender for the unencrypted actual data. The data sender uses the trust anchor public key generated by the received trust anchor as the sender public key; the trust anchor decrypts the original encrypted transmission data through the trust anchor private key based on the asymmetric encryption algorithm to obtain the trust anchor decrypted transmission data, uses the trust anchor decrypted transmission data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.

[0080] Continuing from the above embodiments, the decryption monitoring module determines the trust anchor decryption comparison data according to the trust anchor decryption verification data, including: the decryption monitoring module encrypts the trust anchor decryption transmission data through the host public key to obtain the host first encrypted transmission data, and uses the host first encrypted transmission data as the trust anchor decryption comparison data. The host public key is the trust anchor public key sent by the trust anchor received by the host. At this time, the method further includes: determining the original encrypted transmission data as the host decryption comparison data.

[0081] As described in the above embodiments, it can be understood that first, the data sender (similar to Figure 1 the object sent by the 5 public keys shown) uses the received public key (trust anchor public key) as the sender public key, and encrypts the unencrypted actual data through the sender public key to obtain the original encrypted transmission data. For details, refer to Figure 2 the solution in. The data sender sends the original encrypted transmission data to the controller, which is received by the decryption monitoring module. The decryption monitoring module sends the original encrypted transmission data (similar to Figure 2 the encrypted data in) to the trust anchor, triggering the trust anchor to decrypt the original encrypted transmission data through the trust anchor private key based on the asymmetric encryption algorithm to obtain the trust anchor decryption transmission data (similar to Figure 2 the original data decrypted with the private key in), and feedback the trust anchor decryption transmission data to the decryption monitoring module. Then, the decryption monitoring module encrypts the trust anchor decryption transmission data through the host public key to obtain the host first encrypted transmission data, and compares the host first encrypted transmission data with the originally received original encrypted transmission data for the first time to obtain the first comparison result.

[0082] In one embodiment, after comparing the trust anchor decryption comparison data with the host decryption comparison data for the first time to obtain the first comparison result, the method further includes at least one of the following: if the first comparison result is that the host first encrypted transmission data is the same as the original encrypted transmission data, the monitoring is successful, and determine at least one of the following, the trust anchor decryption transmission data is available, the asymmetric encryption algorithm is trustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; if the first comparison result is that the host first encrypted transmission data is different from the original encrypted transmission data, the monitoring fails, and determine at least one of the following, the trust anchor decryption transmission data is unavailable, the asymmetric encryption algorithm is untrustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is untrustworthy; wherein, the host decryption comparison data includes the original encrypted transmission data.

[0083] If the computing power overhead of directly performing public key encryption on the HOST-side security core is small and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST side. Since the HOST-side monitoring software has obtained the public key during the public key upload phase (the host receives the trust anchor public key sent by the trust anchor and uses it as the host public key) and stores it in the ASIL area (such as the aforementioned decryption monitoring module), then the decrypted original data (trust anchor decrypted transmission data) can be encrypted again with the public key (host public key). If the data after public key encryption (host first encrypted transmission data) is the same as the received encrypted data (original encrypted transmission data), then the decrypted original data (trust anchor decrypted transmission data) is considered available; otherwise, it is not available.

[0084] Taking the trust anchor as the HSM as an example, please refer to Figure 5 , Figure 5 which is a specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 5 shown, if the computing power overhead of directly performing public key encryption on the HOST-side security core is small and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST side. Since the HOST-side monitoring software has obtained the public key during the public key upload phase and stores it in the ASIL area, then the decrypted original data can be encrypted again with the public key. If the data after public key encryption is the same as the received encrypted data, then the decrypted original data is considered available; otherwise, it is not available. Combining Figure 1 and Figure 2 's solution, after the generation and transmission of the key pair are completed, the host side will receive the encrypted data (original encrypted transmission data, which is obtained by encrypting the unencrypted actual data with the externally issued public key, i.e., the sender's public key), and send it to the HSM for decryption with the trust anchor private key to obtain the trust anchor decrypted transmission data. After the host side starts the process of monitoring the credibility of the asymmetric encryption algorithm of the trust anchor, first the host side ( Figure 5The HOST side (in the above) will obtain the public key (i.e., the host public key) from the secure area (ASIL area, such as the decryption monitoring module with the decryption monitoring software set above). Then, the HOST side receives the decrypted original data (i.e., the trust anchor decrypted transmission data) decrypted by the HSM, and encrypts the decrypted original data with the host public key to obtain the first encrypted transmission data of the host. It is judged whether the data is consistent after public key encryption, that is, whether the first encrypted transmission data of the host is consistent with the original encrypted transmission data. If so, that is, the two are consistent, it means the monitoring passes and the decrypted original data (trust anchor decrypted transmission data) is available. Otherwise, if the two are inconsistent, it means the decrypted original data is unavailable.

[0085] Through the above method, if the first encrypted transmission data of the host is the same as the original encrypted transmission data, it means that the decryption result of the HSM side is credible, that is, the trust anchor decrypted transmission data is available. Correspondingly, the asymmetric encryption algorithm of the trust anchor is credible, and the data transmission link between the trust anchor and the host is also credible. On the contrary, if the first encrypted transmission data of the host is different from the original encrypted transmission data, then at least the following two situations exist: 1. There is a problem with the data transmission link between the trust anchor and the host; 2. There is a problem with the asymmetric encryption algorithm of the trust anchor. Since there is no further way to judge which part or all of them have problems, it can be determined that the trust anchor decrypted transmission data decrypted by the HSM at this time is problematic and unavailable. At this time, the trust anchor decrypted transmission data can be sent to the decryption data usage object for its use.

[0086] In one embodiment, after the trust anchor decrypts the original encrypted transmission data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the trust anchor decrypted transmission data, the method further includes: sending the trust anchor decrypted transmission data to the decryption data usage object. Since the speed of the asymmetric encryption calculation of the HSM is faster than that of the HOST side, therefore, in order to further improve the data processing speed of the entire system, after the HSM calculates the trust anchor decrypted transmission data, without waiting for the monitoring result of the host, the trust anchor decrypted transmission data can be directly sent to the decryption data usage object. Since the probability that the overall calculation of the trust anchor is credible is generally higher than the probability that it is not credible, therefore, through this method, the overall processing efficiency of the system can be effectively improved.

[0087] Continuing from the above embodiments, after performing a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes: If the first comparison result indicates that the host's first encrypted transmission data is different from the original encrypted transmission data, a data unavailable message is generated and sent to the decryption data usage object. That is, although the trust anchor decrypted transmission data has been sent to the decryption data usage object, once it is found that the trust anchor decrypted transmission data is unavailable and there are problems, the host generates a data unavailable message and sends it to the decryption data usage object for remediation. If the first comparison result indicates that the host's first encrypted transmission data is the same as the original encrypted transmission data, subsequent steps can be executed according to the settings of those skilled in the art. For example, a data available message is generated and sent to the decryption data usage object. After the decryption data usage object processes the trust anchor decrypted transmission data to obtain a data processing result, it waits or, after receiving the data available message that has already been received, will apply the data processing result in the next step. This can synchronize the process of the decryption data usage object processing the trust anchor decrypted transmission data with the host's monitoring of the trust anchor asymmetric encryption algorithm, not only improving the processing efficiency but also ensuring the reliability of the data result. Another example is that no message can be generated. As long as the decryption data usage object does not receive a data unavailable message, it is defaulted that the previously received trust anchor decrypted transmission data is available.

[0088] The above embodiments provide a solution for the host to monitor the trust anchor asymmetric encryption algorithm after receiving the original encrypted transmission data sent by the data sender. As mentioned in the above embodiments, this process can execute the above solution once for each received original encrypted transmission data, or execute it once. If the first comparison result is the same, the execution can be paused for a certain period of time or the monitoring of subsequent several original encrypted transmission data can be temporarily not executed, and the result of the trust anchor decryption is defaulted to be available. The specific implementation method can be selected by those skilled in the art according to needs.

[0089] In another embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: The decryption monitoring module obtains the host encrypted test data, sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting the initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the host received by the trust anchor; The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decryption test data, uses the third decryption test data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.

[0090] The initial test data can be random values generated randomly, data pre-configured by those skilled in the art, or achieved through other technical solutions known to those skilled in the art. The host-encrypted test data can be obtained by encrypting the initial test data with the host public key. The host can pre-store the initial test data and encrypt the initial test data with the host public key when needed to obtain the host-encrypted test data. It can also be that the initial test data and the host-encrypted test data corresponding to the initial test data are pre-stored. It should be noted that the host can store a set of initial test data and the host-encrypted test data corresponding to the initial test data, or multiple sets of initial test data and the host-encrypted test data corresponding to the initial test data. When in use, the currently used initial test data can be switched randomly or in sequence.

[0091] Continuing with the above embodiment, when only using the above-provided scheme for initial test data to improve the trust anchor asymmetric encryption algorithm, the method further includes, after obtaining the first comparison result, sending the original encrypted transmission data to the trust anchor, decrypting the original encrypted transmission data by the trust anchor to obtain the trust anchor decrypted transmission data. At this time, it can be defaulted that the trust anchor decrypted transmission data is available, and no longer use the original encrypted transmission data as the data to be decrypted for Figure 4 the credibility improvement scheme shown. Of course, it can also be determined whether to directly default to using the trust anchor decrypted transmission data as available data or to execute the scheme of using the original encrypted transmission data as the data to be decrypted again based on the relationship between the first estimated host encryption time of the original encrypted transmission data and the preset time threshold, Figure 4 and determine whether the trust anchor decrypted transmission data is available based on the execution result. It can also be based on the monitoring interval principle set by those skilled in the art. For example, every time a monitoring is performed and the first comparison result is the same, the next several original encrypted transmission data are suspended, or the execution of the Figure 4 credibility improvement scheme shown is suspended for a certain period of time.

[0092] In another embodiment, if the original encrypted transmission data is used as the data to be encrypted and the host decryption comparison data, and the host first encrypted transmission data is used as the trust anchor decryption comparison data, before, during, or after using the above data to improve the credibility of the trust anchor asymmetric encryption algorithm, the following scheme can also be executed to further improve the credibility of the trust anchor asymmetric encryption algorithm. For example, the following monitoring scheme is used as a periodic task, and the following process is executed at preset intervals regardless of whether the original encrypted transmission data is received.

[0093] The specific monitoring solution is as follows: The decryption monitoring module obtains the host encrypted test data and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting the initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decrypted test data, uses the third decrypted test data as the new trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs. The decryption monitoring module uses the new trust anchor decryption verification data as the new trust anchor decryption comparison data, and makes a first comparison between the new trust anchor decryption comparison data and the new host decryption comparison data to obtain a first comparison result. The new host decryption comparison data is the initial test data.

[0094] Different from the foregoing embodiment, the foregoing embodiment is a simple one-time execution of the solution for improving credibility using the host encrypted test data and the initial test data. In this embodiment, the controller not only executes the solution for improving credibility using the host encrypted test data and the initial test data, but also executes the solution for improving the credibility of the trust anchor asymmetric encryption algorithm by using the original encrypted transmission data as the data to be encrypted and the host decryption comparison data, and using the host first encrypted transmission data as the trust anchor decryption comparison data. The executions of the two are independent, and the execution order can be limited according to the needs of those skilled in the art.

[0095] In these two embodiments, after making a first comparison between the (new) trust anchor decryption comparison data and the (new) host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: If the first comparison result is that the third decrypted test data is the same as the initial test data, determine at least one of the following, the asymmetric encryption algorithm is trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; If the first comparison result is that the third decrypted test data is different from the initial test data, determine at least one of the following, the asymmetric encryption algorithm is not trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is not trustworthy; Among them, the host decryption comparison data includes the initial test data, and the trust anchor decryption comparison data includes the third decrypted test data.

[0096] Although the actually used calculation data is not the data provided by the data sending end, the above method can also be used to verify whether the asymmetric encryption algorithm, the data transmission link between the trust anchor and the decryption monitoring module is trustworthy.

[0097] For example, if the computing power overhead of directly performing public key encryption on the HOST - side security core is large and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety or it will affect the normal function of the controller, the HOST - side monitoring software does not directly participate in decrypting the received encrypted data. Instead, it additionally triggers the HSM to decrypt in periodic tasks, and judges whether the HSM and the data transfer link are invalid through the value after HSM decryption. Since the HOST - side monitoring software has obtained the ch and e_ch values during the public key upload phase and stored them in the ASIL area, the HSM can be triggered to decrypt the e_ch value once. If the decrypted value ch’ is consistent with ch, it is considered that the private key decryption and the data transfer link after decryption are available; otherwise, they are unavailable.

[0098] Taking the trust anchor as the HSM as an example, please refer to Figure 6 , Figure 6 which is a specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 6 shown, if the computing power overhead of directly performing public key encryption on the HOST - side security core is large and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety or it will affect the normal function of the controller, the HOST - side monitoring software does not directly participate in decrypting the received encrypted data. Instead, it additionally triggers the HSM to decrypt in periodic tasks, and judges whether the HSM and the data transfer link are invalid through the value after HSM decryption. Since the HOST - side monitoring software has obtained the ch and e_ch values during the public key upload phase and stored them in the ASIL area, the HSM can be triggered to decrypt the e_ch value once. If the decrypted value ch’ is consistent with ch, it is considered that the private key decryption and the data transfer link after decryption are available; otherwise, they are unavailable. Combining Figure 1 and Figure 2 's solution, after the generation and transmission of the key pair are completed, the host side will receive encrypted data (the original encrypted transmission data, which is obtained by encrypting the unencrypted actual data with the externally - issued public key, i.e., the sender's public key). Estimate the first estimated host encryption time of the original encrypted transmission data. If the first estimated host encryption time is less than the preset time threshold, then Figure 5Decryption is performed in the manner shown. If the encryption time of the first estimated host is greater than or equal to the preset time threshold, a solution for improving the credibility can be adopted using the host-encrypted test data and the initial test data. Specifically, the host side, i.e., the HOST side, first obtains the initial encrypted data ch and the host-encrypted test data e_ch from the secure area (ASIL area, such as the decryption monitoring module with the decryption monitoring software set above). Then, the host-encrypted test data e_ch is sent to the HSM. The HSM decrypts the host-encrypted test data e_ch using the trust anchor private key to obtain the trust anchor decrypted transmission data ch`. The trust anchor decrypted transmission data ch` is sent back to the host. Then, the decryption monitoring module of the host will perform a first comparison between the trust anchor decrypted transmission data ch` and the above-mentioned initial encrypted data ch. If the trust anchor decrypted transmission data ch` is the same as the above-mentioned initial encrypted data ch, it indicates that the monitoring is successful, the decryption of the trust anchor private key and the data transmission link after decryption are not invalidated, and the calculation result of the trust anchor asymmetric encryption algorithm is available. Otherwise, it is determined that the monitoring fails, which to a certain extent means that the decryption of the trust anchor private key and the data transmission link after decryption are invalidated, and the calculation result of the trust anchor asymmetric encryption algorithm is unavailable.

[0099] In one embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method includes: the decryption monitoring module receives the original encrypted transmission data and determines the first estimated host encryption time for receiving the original encrypted transmission data; if the first estimated host encryption time is less than the preset time threshold, the original encrypted transmission data is determined as the data to be decrypted and sent to the trust anchor.

[0100] Continuing with the above embodiment, if the first estimated host encryption time is greater than or equal to the preset time threshold, the host-encrypted test data is determined as the data to be decrypted and sent to the trust anchor, and the initial test data is determined as the host decryption comparison data. The host-encrypted test data is obtained by encrypting the initial test data with the host public key, where the second estimated host encryption time of the host-encrypted test data is less than the preset time threshold.

[0101] The preset time threshold can be a threshold set by those skilled in the art based on the Fault Tolerant Time Interval (FTTI), and can be greater than or equal to the Fault Tolerant Time Interval.

[0102] For example, if the currently received original encrypted transmission data is data that requires a trust anchor asymmetric encryption algorithm credibility improvement cycle, at this time, first estimate the time required for the host to encrypt the unencrypted actual data corresponding to the original encrypted transmission data, and obtain the first estimated host encryption time. The estimation method can be achieved by recording the encryption time of the original encrypted transmission data or other methods known to those skilled in the art, and is not limited here. If the first estimated host encryption time is less than the preset time threshold, it means that the host can complete the re-encryption of the data decrypted by the trust anchor without affecting its own functions. At this time, the original encrypted transmission data can be determined as the data to be decrypted, the original encrypted transmission data can be used as the data to be encrypted and the host decryption comparison data, and the host's first encrypted transmission data can be used as the trust anchor decryption comparison data to implement the scheme for improving the credibility of the trust anchor asymmetric encryption algorithm. In scenarios with high requirements for data processing efficiency, it is not necessary to wait for the first comparison result. After obtaining the trust anchor decrypted transmission data, it can be sent to the data user of the decrypted data to improve the processing efficiency. In addition, this scheme also supports directly decrypting the original encrypted transmission data by the host without passing through the trust anchor when the first estimated host encryption time is less than the preset time threshold. When the first estimated host encryption time is greater than or equal to the preset time threshold, at this time, the host cannot encrypt the data decrypted by the trust anchor, otherwise it may affect the implementation of the host's own functions. Therefore, a scheme for improving credibility by using the host encrypted test data and the initial test data can be adopted for auxiliary verification, and then the original encrypted transmission data is sent to the trust anchor for decryption. For a scheme with security status monitoring, as long as the controller does not enter the security state, it supports the trust anchor to continue decrypting the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decrypted data user. When the controller enters the security state, the step of the trust anchor continuing to decrypt the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decrypted data user is stopped. For a scheme without security status monitoring, it can be that the previous monitoring fails, and the step of the trust anchor continuing to decrypt the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decrypted data user is stopped, or other schemes set by those skilled in the art.

[0103] In one embodiment, after obtaining the first comparison result, the method further includes: counting the number of decryption exception events where the first comparison result shows that the trust anchor decryption comparison data is different from the host decryption comparison data within a preset statistical period; if the number of decryption exception events is greater than the first preset number threshold, controlling the controller to enter the security state.

[0104] The preset statistical period can be a limitation in dimensions such as the time dimension set by those skilled in the art or the number of executions of the method for improving the credibility of the trust anchor asymmetric encryption algorithm. The first preset number threshold can be set by those skilled in the art according to needs. The entry method of the secure state can be implemented in a manner known to those skilled in the art, which will not be elaborated here. As an example, within the preset statistical period, each time a new first comparison result is generated, the current number of decryption exception events can be updated once to enter the secure state in a timely manner.

[0105] In one embodiment, the method further includes a solution for pre-verifying whether the host key received by the host is available. For the relevant explanation of the specific solution, reference can be made to the Figure 8 - Figure 11 solution of the method for improving the credibility of the trust anchor asymmetric encryption algorithm shown below, which will not be elaborated here specifically.

[0106] Before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes the transmission monitoring module; the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the second comparison result shows that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host key of the host is available. Among them, the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host. At this time, it shows that the host public key stored on the host side is consistent with the trust anchor public key generated by the trust anchor. It should be noted that the credibility of the transmission monitoring module is higher than that of the trust anchor.

[0107] Continuing the above embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.

[0108] Continuing the above embodiment, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.

[0109] Continuing with the above embodiments, the method further includes: if the second comparison result is that the initial test data is the same as the first decrypted test data, storing the initial test data and the host encrypted test data in the transmission monitoring module.

[0110] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determining the initial test data and the host encrypted test data as the host transmission verification data; and determining the initial test data as the test transmission data.

[0111] Continuing with the above embodiments, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor encrypts the initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain the second decrypted test data, and determining the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, including: the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data.

[0112] Continuing with the above embodiments, the method further includes: if the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, storing the initial test data and the host encrypted test data in the transmission monitoring module.

[0113] In this way, when using the solution of the initial test data to improve the trust anchor asymmetric encryption algorithm in the foregoing embodiments, the initial test data and the host encrypted test data pre-stored by the solutions provided in this embodiment and the previous embodiment can be used.

[0114] In one embodiment, the method further includes: the encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host. The host further includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. The encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result. In the above manner, the functional safety level of the asymmetric data encryption storage of the controller can be improved. For the relevant descriptions of this part, reference can also be made to the following Figures 12 - 14 description of the provided embodiments, which will not be elaborated here.

[0115] It should be noted that for the same controller, it can be both a data receiver and a data storage (sender) Figure 4 、 Figure 12 The execution order of the method described is not limited, and it depends on the application requirements of the current controller to determine its execution sequence, or any one of them can be selectively executed.

[0116] In the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in the above embodiment, in the solution where the trust anchor decrypts the data to be decrypted, the decryption monitoring module with higher credibility receives the trust anchor decryption verification data calculated by the trust anchor with lower credibility based on the asymmetric encryption algorithm, and determines the trust anchor decryption comparison data. The trust anchor decryption comparison data is compared with the host decryption comparison data for the first time to obtain a first comparison result. Through the above process, the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor can be monitored based on the decryption monitoring module with higher credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor and ensuring the functional safety level of the decryption result of the trust anchor for application in functional safety critical scenarios.

[0117] The above embodiment provides a solution for improving the functional safety level of the asymmetric encryption and decryption algorithm based on HSM. This solution utilizes the characteristic that the public key can be shared, improves the functional safety level of the asymmetric encryption and decryption algorithm based on HSM, and enables the asymmetric encryption and decryption information security mechanism based on HSM to replace and supplement the existing functional safety mechanism and expand its scope of use.

[0118] Optionally, before decrypting the data to be decrypted by the trust anchor, which can be during the controller software initialization phase, verify the host public key transmitted by the trust anchor to the host, and after the verification passes, store the initial test data and the host-encrypted test data in the transmission monitoring module for use in the trust anchor asymmetric encryption algorithm credibility improvement scheme during the process of the trust anchor decrypting the data to be decrypted. This can further enhance the credibility of the trust anchor asymmetric encryption algorithm by pre-verifying the host public key during the controller software initialization phase and promptly detecting problems.

[0119] Please refer to Figure 7 as shown in Figure 7 Another flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention, which provides a functional safety improvement scheme for asymmetric public key transmission. The method includes the following steps:

[0120] Step S710, the transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor.

[0121] Among them, the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host (refer to the Figure 1 scheme). One of the host transmission verification data and the test transmission data retains the initial test data itself, and the other is obtained by encrypting the initial test data with the host public key.

[0122] The initial test data can be randomly generated or generated based on methods known to those skilled in the art.

[0123] Since the public key transmission is the preparation stage for asymmetric decryption and asymmetric encryption storage, and is generally carried out during the software initialization stage, there are no requirements for time such as the functional safety fault tolerance time interval (FTTI). Of course, the process of public key transmission can also be implemented in other stages set by those skilled in the art. For example, Figure 7 the scheme can be applied to the controller software initialization stage or can be executed before executing the Figure 4 scheme.

[0124] Step S720, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module.

[0125] The trust anchor stores the trust anchor public key and the trust anchor private key. Based on the requirements of the scenario, the trust anchor public key and / or the trust anchor private key can be used to calculate the test transmission data to obtain the trust anchor transmission verification data that can support comparison later.

[0126] Step S730, the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.

[0127] By using a transmission monitoring module with relatively high credibility to compare the data, the obtained result is also relatively credible to a certain extent, which can improve the functional safety level of the asymmetric public key transmission to a certain extent and enhance the credibility of the calculation and transmission of the asymmetric encryption algorithm.

[0128] In an embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.

[0129] Continuing with the above embodiment, the trust anchor calculates the trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor decrypts the host encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.

[0130] Continuing with the above embodiment, after the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following: if the second comparison result shows that the first decrypted test data is the same as the initial test data, determine at least one of the following, the trust anchor private key matches and is correct with the trust anchor public key, and the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data; if the first comparison result shows that the first decrypted test data is different from the initial test data, determine that the host public key is unavailable.

[0131] Taking the trust anchor as HSM as an example, please refer to Figure 8 and Figure 9 , Figure 8 which is another specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. Figure 9 For Figure 8 the data transmission schematic diagram of the method shown. As Figure 8 and Figure 9As shown, the HOST-side monitoring software generates a random challenge value, encrypts it using the uploaded public key to obtain the encrypted value e_ch, and passes e_ch to the HSM. The HSM decrypts e_ch using the private key to obtain ch’, and returns it to the HOST-side monitoring software. If the generation or transmission of the public-private key pair on the HSM side is incorrect, the monitoring software of the HOST Software will diagnose it. Combining Figure 1 's solution, first, the host monitoring software (HOST Software) sends a public-private key pair generation request to the HSM Firmware through the HSM HOSTDriver, triggering the HSM to generate a trust anchor public key and a trust anchor private key. Then, the trust anchor public key is fed back to the HOST Software through the HSM HOST Driver, enabling the host to obtain the host public key. At this time, due to the lack of a monitoring mechanism, the functional safety level of the HSM and the entire transmission link cannot be guaranteed. Continue to refer to Figure 8 and Figure 9 , after the transmission monitoring module of the host HOST obtains the public key generated by the HSM side, the HOST side generates a random value ch (an example of initial test data) and encrypts it using the public key (host public key) to obtain the host encrypted test data e_ch. Then, the host encrypted test data e_ch is sent by the transmission monitoring module (HOST Monitoring) to the HSMFirmware through the HSM HOST Driver. The HSM decrypts the host encrypted test data e_ch using the trust anchor private key based on the asymmetric encryption algorithm to obtain the first decrypted test data ch`. It is fed back to the HOST Monitoring through the HSM HOST Driver, enabling the HOST side to obtain the value ch` (the first decrypted test data) of the private key decryption of e_ch by the HSM side. Then, the transmission monitoring module checks whether the random value ch is the same as the first decrypted test data ch`. If so, the monitoring passes, the trust anchor public key and the trust anchor private key (i.e., Figure 8 's public and private keys) match and are correct, and the public key, the random value ch, and the host encrypted test data e_ch are stored in the ASIL area (such as the transmission monitoring module, etc.). Then the HOST monitoring ends.

[0132] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data using the host public key to obtain the host encrypted test data; determines the initial test data and the host encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.

[0133] Continuing with the above embodiments, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data.

[0134] Continuing with the above embodiments, after the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following:

[0135] If the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data;

[0136] If the initial test data is different from the second decrypted test data, determine that the trust anchor public key does not match the trust anchor private key;

[0137] If the host encrypted test data is different from the trust anchor first encrypted test data, determine that the host public key is different from the trust anchor public key and the host public key is not available.

[0138] Continuing with the above embodiments, after obtaining the second comparison result, the method includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, send the host public key to the data sender for the data sender to receive the host public key as the sender public key and encrypt the unencrypted actual data using the sender public key to obtain the original encrypted transmission data. At this time, it shows that the host public key is available and can be sent out, avoiding problems with the public key sent out due to issues such as the trust anchor algorithm problem and transmission problem of the controller, which may cause failures.

[0139] Taking the trust anchor as an HSM as an example, please refer to Figure 10 and Figure 11 , Figure 10 which is another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiments of the present invention. Figure 11 is Figure 10 the data transmission schematic diagram of the method shown. As Figure 10 and Figure 11 ​As shown, the HOST-side monitoring software generates a random challenge value and directly sends it to the HSM. At the same time, the HOST-side encrypts ch with the public key to obtain e_ch. The HSM encrypts the challenge value with the public key to obtain e_ch', and decrypts e_ch' with the private key to obtain ch'. The HSM also returns e_ch' and ch' to the HOST-side monitoring software. If there is an error in generating the public and private key pair on the HSM side or a transmission error, the monitoring software on the HOST side can diagnose it and be detected by subsequent monitoring. Moreover, this scheme can distinguish whether the failure is caused by an incorrect upload of the public key or a mismatch between the public and private keys. Combining Figure 1 's scheme, first, the host monitoring software (HOST Software) will send a public and private key pair generation request to the HSM Firmware through the HSM HOST Driver, triggering the HSM to generate a trust anchor public key and a trust anchor private key. Then, the trust anchor public key is fed back to the HOST Software through the HSM HOST Driver, enabling the host to obtain the host public key. At this time, due to the lack of a monitoring mechanism, the functional security level of the HSM and the entire transmission link cannot be guaranteed. Continue to refer to Figure 10 and Figure 11 , after the transmission monitoring module (HOST Monitoring) of the host HOST obtains the public key generated by the HSM side, the HOST side (HOST Monitoring) generates a random value ch (an example of initial test data) and encrypts it with the public key (host public key) to obtain the host encrypted test data e_ch. The random value ch is sent to the HSM Firmware through the HSM HOST Driver for transmission to the HSM. The HSM encrypts the random value ch with the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor first encrypted test data e_ch`. Then, the trust anchor private key decrypts the trust anchor first encrypted test data e_ch` based on the asymmetric encryption algorithm to obtain the second decrypted test data ch`. The first encrypted test data e_ch` and the second decrypted test data ch` are fed back to the HOST Monitoring through the HSM HOST Driver, enabling the HOST side to obtain the value of ch encrypted with the public key by the HSM side, that is, the trust anchor first encrypted test data e_ch` and the second decrypted test data ch`. The transmission monitoring module compares the random value ch with the second decrypted test data ch`. If they are different (no), the monitoring fails, and the trust anchor public key and the trust anchor private key on the HSM side (that is, the public and private keys in Figure 10 ) do not match. If they are the same (yes), the monitoring is successful. The host encrypted test data e_ch is compared with the trust anchor first encrypted test data e_ch`. If they are the same, the monitoring passes, and the trust anchor public key and the trust anchor private key on the HSM side (that is, the public and private keys in Figure 10If they match (the public and private keys in it), store the public key, random value ch, and host encrypted test data e_ch in the ASIL area (such as the transmission monitoring module, etc.). Then the HOST monitoring ends. If they do not match, the monitoring fails, indicating that the public key on the HOST side is different from that on the HSM side.

[0140] Through the above method, not only can we know whether the calculation and transmission link of the asymmetric encryption algorithm at the trust anchor end is trustworthy, but also we can know specifically which part has problems, which is convenient for subsequent fault handling.

[0141] The method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in the above embodiment, in the public key transmission stage, obtains the initial test data through a transmission monitoring module with relatively high credibility, encrypts the initial test data with the host public key to obtain host transmission verification data or test transmission data, then sends the test transmission data to the trust anchor, and the trust anchor with relatively low credibility calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm, and then the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result. Through the above process, it is possible to monitor the calculation and public key transmission process of the asymmetric encryption algorithm of the trust anchor based on a transmission monitoring module with relatively high credibility, thereby improving the credibility of the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor, ensuring the functional safety level of the host public key, and applying the host public key to functional safety critical scenarios.

[0142] The above embodiment provides a solution for improving the functional safety level of the asymmetric encryption and decryption algorithm based on HSM. This solution utilizes the characteristic that the public key can be shared, improves the functional safety level of the asymmetric encryption and decryption algorithm based on HSM, and enables the asymmetric encryption and decryption information security mechanism based on HSM to replace and supplement the existing functional safety mechanism and expand its application scope.

[0143] The execution of this method can also be in the controller software initialization stage, etc. Before the trust anchor starts to execute real encryption and decryption tasks, verify the host public key transmitted by the trust anchor to the host, and after the verification passes, store the initial test data and host encrypted test data in the transmission monitoring module for use in the trust anchor asymmetric encryption algorithm credibility improvement solution for the decryption process of the data to be decrypted by the trust anchor. It can further improve the credibility of the trust anchor asymmetric encryption algorithm, verify the host public key in advance in the controller software initialization stage, and discover problems in a timely manner. Of course, the execution of this method can also be set at other times according to the needs of those skilled in the art, such as during the process of the trust anchor executing real encryption and decryption tasks. Here, the controller software initialization stage is only an example and is not a limitation on the execution time of this method.

[0144] Please refer to Figure 12 as shownFigure 12 Another flowchart diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention provides a functional safety improvement scheme for asymmetric data encryption storage. The method includes the following steps:

[0145] Step S1210, the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data.

[0146] Among them, the host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host.

[0147] Step S1220, the encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0148] The data to be encrypted can be sent by other controllers to the current controller, or can be local data of the controller, or data set by those skilled in the art.

[0149] The obtaining method of the host public key can refer to Figure 1 the provided solution and the relevant description of the foregoing embodiment, which will not be elaborated here. Figure 4 、 Figure 7 and Figure 12 The provided solution can be executed by one controller, or can be executed by different controllers respectively, or a certain controller selects Figure 4 、 Figure 7 and Figure 12 Two of the provided solutions can also be executed. The specific combination method will not be elaborated.

[0150] In an embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: the host obtains the initial actual data; determines the expected host encryption time of the initial actual data; if the expected host encryption time is less than the preset time threshold, determines the initial actual data as the data to be encrypted; if the expected host encryption time is greater than or equal to the preset time threshold, determines the initial test data as the data to be encrypted, determines the host encryption test data as the host encryption verification data, the expected host encryption time of the initial test data is less than the preset time threshold, and the host encryption test data is obtained by encrypting the initial test data through the host public key. It should be noted that the preset time threshold in this embodiment and the preset time threshold in the decryption stage can be the same or different. The expected host encryption time is the expected time-consuming for the host to encrypt the initial actual data, which can be determined by pre-calibration or other methods known to those skilled in the art.

[0151] Certainly, if it is predicted that the host encryption time is less than the preset time threshold, it is also possible to select the initial test data as the data to be encrypted, determine the host encrypted test data as the host encryption verification data to execute this solution, and run it as a timed periodic task. Compared with the solution of executing this method only when there is initial actual data, the method of using the initial test data to execute the timed task can avoid the encryption task without initial actual data for a long time, resulting in the problem that the failure of the trust anchor encryption cannot be detected in time (similar to the decryption solution, which can be mutually reflected and will not be elaborated).

[0152] If the computing overhead of directly performing public key encryption on the HOST-side security core is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST side. That is, as mentioned in the above embodiments, public key encryption can also be directly performed on the HOST side using the host public key. However, the calculation speed of the HSM side (trust anchor) is relatively faster. In a scenario where efficiency is prioritized, the solution of using the public key of the HSM for encryption is more advantageous. Reference can be made to the relevant description in the decryption stage of the above embodiments. An example method is that after the trust anchor obtains the trust anchor encrypted transmission data, as long as the controller does not enter the secure state, the trust anchor encrypted transmission data is stored or sent to the data user. When the controller enters the secure state, the action of storing or sending the trust anchor encrypted transmission data to the data user is stopped. Another example method is that after the trust anchor obtains the trust anchor encrypted transmission data, the steps of storage and sending to the data user are performed. Subsequently, after obtaining the third comparison result, if it is proved that the trust anchor encrypted transmission data is untrustworthy (not storable), at this time, a data exception reminder message can be generated and sent to the corresponding storage space control party or data user to discard the trust anchor encrypted transmission data or the result obtained from the trust anchor encrypted transmission data. Since the situation of controller exception is a minority case, by using such a method, the data transmission and processing efficiency can be effectively improved.

[0153] In one embodiment, if the initial actual data is determined to be the data to be encrypted, the method includes: The encryption monitoring module obtains the host encryption verification data, including that the encryption monitoring module encrypts the initial actual data with the host public key to obtain the host second encrypted transmission data, and uses the host second encrypted transmission data as the host encryption verification data; The encryption monitoring module obtains the trust anchor encryption verification data, including that the trust anchor encrypts the initial actual data with the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor encrypted transmission data, and sends the trust anchor encrypted transmission data to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor encrypted transmission data as the trust anchor encryption verification data.

[0154] Continuing with the above embodiment, after obtaining the third comparison result, the method further includes at least one of the following: If the third comparison result is that the host second encrypted transmission data is the same as the trust anchor encrypted transmission data, determine at least one of the following, the trust anchor encrypted transmission data can be stored, the asymmetric encryption algorithm of the trust anchor is trustworthy (encryption part), the data transmission link between the trust anchor and the encryption monitoring module is trustworthy; If the third comparison result is that the host second encrypted transmission data is different from the trust anchor encrypted transmission data, determine that the trust anchor encrypted transmission data cannot be stored.

[0155] In one embodiment, if the trust anchor encrypted transmission data can be stored, the method further includes storing the trust anchor encrypted transmission data.

[0156] In the above solution, only the initial actual data may be used to generate the third comparison result. Once there is no encryption requirement for the initial actual data for a long time, the state of the controller is blank. To avoid this problem, the method may further include: The encryption monitoring module sends new initial test data; The trust anchor receives the new initial test data sent by the encryption monitoring module, encrypts the new initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain the new trust anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received new trust anchor second encrypted test data as the trust anchor encryption verification data; The encryption monitoring module uses the new host encryption verification data based on the new initial test data as the new host encryption verification data, and compares the new host encryption verification data with the new trust anchor encryption verification data to obtain a new third comparison result. It should be noted that this process is the same as Figure 12The solution can be parallel or executed by either party first, which is not limited here. The solution provided in this embodiment can be executed periodically or according to certain trigger conditions. Specifically, it can be set by those skilled in the art according to needs. It should be noted that the description of "new" above does not limit that the initial test data in this process is different from the initial test in the previous process. The two can be the same, and it is only used to distinguish the relevant data obtained in different processes.

[0157] As an example, taking the trust anchor as the HSM, please refer to Figure 13 , Figure 13 which is another specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 13 shown, since the HOST-side monitoring software has obtained the public key and stored it in the ASIL area (such as the encryption monitoring module) during the public key upload phase, the encrypted data can be judged whether it is available by performing public key encryption on the original data (initial actual data) again. If the data encrypted by the HOST-side public key is the same as the data to be encrypted and stored (the second encrypted transmission data of the host is the same as the encrypted transmission data of the trust anchor), it is considered that the data encrypted by the HSM (the encrypted transmission data of the trust anchor) is available, otherwise it is not available. Continue to refer to Figure 10 , combined with Figure 1 the example, the host pre-stores the host public key. The HOST side obtains the public key (host public key) from the ASIL area such as the encryption monitoring module, and then encrypts the initial actual data through the host public key to obtain the second encrypted transmission data of the host. Combined with Figure 3 the example, the host sends the initial actual data to the trust anchor, and the trust anchor encrypts the initial actual data through the trust anchor public key to obtain the encrypted transmission data of the trust anchor and sends it back to the host. Subsequently, the encryption monitoring module judges whether the data encrypted by the public key is the same as the data encrypted by the HSM? That is, it judges whether the second encrypted transmission data of the host is the same as the encrypted transmission data of the trust anchor. If so, the monitoring passes and the encrypted data (the encrypted transmission data of the trust anchor) can be stored. If not, the monitoring fails and the encrypted data cannot be stored.

[0158] In another embodiment, if the initial test data is determined as the data to be encrypted and the host encrypted test data is determined as the host encrypted verification data, the encryption monitoring module to obtain the trust anchor encrypted verification data includes: the trust anchor receives the initial test data sent by the encryption monitoring module, encrypts the initial test data through the trust anchor public key based on the asymmetric encryption algorithm to obtain the second encrypted test data of the trust anchor, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received second encrypted test data of the trust anchor as the trust anchor encrypted verification data.

[0159] Continuing from the above embodiments, after obtaining the third comparison result, the method further includes at least one of the following: If the third comparison result is that the trust anchor's second encrypted test data is the same as the host's encrypted test data, determine at least one of the following, that the trust anchor's asymmetric encryption algorithm is trustworthy and the data transmission link between the trust anchor and the encryption monitoring module is trustworthy; If the third comparison result is that the trust anchor's second encrypted test data is different from the host's encrypted test data, determine at least one of the following, that the trust anchor's asymmetric encryption algorithm is untrustworthy and the data transmission link between the trust anchor and the encryption monitoring module is untrustworthy.

[0160] In one embodiment, after obtaining the third comparison result, the method further includes: counting the number of encryption anomaly events where the third comparison result is that the host's encrypted verification data is different from the trust anchor's encrypted verification data within a preset statistical period; If the number of encryption anomaly events is greater than a second preset number threshold, control the controller to enter a safe state. It should be noted that when the controller has both an encryption scheme and a decryption scheme, it can also be based on the number of encryption anomaly events and the number of decryption anomaly events to adjust the first preset number threshold or the second preset number threshold, so as to achieve that whether it is the number of encryption anomaly events or the number of decryption anomaly events is regarded as one anomaly, and when the total number of encryption anomaly events and decryption anomaly events is greater than a certain threshold, the controller also enters an abnormal state.

[0161] If the computing overhead of directly performing public key encryption on the HOST side security core is large and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) or it will affect the normal function of the controller, then the HOST side monitoring software does not directly participate in the encryption of the original data, but instead triggers HSM encryption additionally in periodic tasks, and determines whether the HSM and the data transmission link are faulty based on the value encrypted by the HSM.

[0162] As an example, taking the trust anchor as the HSM, please refer to Figure 14 , Figure 14 which is another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiments of the present invention. As Figure 14 shown, since the HOST side monitoring software has obtained the public key and stored it in the ASIL area (such as the encryption monitoring module) during the public key upload stage, and has pre-stored the initial test data and the host encrypted verification data corresponding to the initial test data (which can be obtained based on the Figure 7 scheme shown, or can also be obtained by other means). As Figure 14As shown, since the HOST - side monitoring software has obtained the ch and e_ch values during the public - key upload phase and stored them in the ASIL area, the HSM can be triggered to encrypt the ch value once. If the encrypted value e_ch’ is the same as e_ch, it is considered that the public - key decryption and the encrypted - data transfer link are available; otherwise, they are not. Continue to refer to Figure 14 , after the HOST monitoring starts, the HOST - side obtains the initial test data ch and the host encryption verification data e_ch corresponding to the initial test data from the ASIL area (such as the encryption monitoring module), transfers the initial test data ch to the HSM. Then the HSM encrypts the initial test data ch with the trust - anchor public key to obtain the trust - anchor second - encrypted test data e_ch`, and sends it back to the host. The encryption monitoring module determines whether the host encryption verification data e_ch is the same as the trust - anchor second - encrypted test data e_ch`. If so, the monitoring passes, and the HSM public - key (trust - anchor public key) encryption and the encrypted - data (trust - anchor second - encrypted test data) transfer link are not invalid. If not, the monitoring fails, and the HSM public - key encryption and the encrypted - data transfer link fail. The HOST monitoring ends.

[0163] In one embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust - anchor encryption verification data, the method further includes performing one or more embodiments of the trust - anchor asymmetric - encryption - algorithm credibility improvement method provided in Figure 7 . For the specific description and implementation, reference can be made to the description of the above - mentioned embodiments, which will not be elaborated here.

[0164] In one embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust - anchor encryption verification data, the method includes: The transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust - anchor. The host also includes a transmission monitoring module. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key; the trust - anchor calculates the trust - anchor transmission verification data based on the asymmetric - encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust - anchor transmission verification data to obtain a second comparison result; if the second comparison result is that the host transmission verification data is the same as the trust - anchor transmission verification data, it is determined that the host public key of the host is available.

[0165] Continuing with the above - mentioned embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain the host - encrypted test data; determines the host - encrypted test data as the test transmission data; determines the initial test data as the host transmission verification data.

[0166] Continuing from the above embodiments, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm, including: the trust anchor decrypts the host-encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.

[0167] Continuing from the above embodiments, the method further includes: if the second comparison result is that the initial test data and the first decrypted test data are the same, storing the initial test data and the host-encrypted test data in the transmission monitoring module.

[0168] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data based on the initial test data, including: the transmission monitoring module encrypts the initial test data using the host public key to obtain the host-encrypted test data; determines the initial test data and the host-encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.

[0169] Continuing from the above embodiments, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, including: the initial test data and the second decrypted test data are the same, and the host-encrypted test data and the trust anchor first encrypted test data are the same.

[0170] Continuing from the above embodiments, the method further includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, storing the initial test data and the host-encrypted test data in the transmission monitoring module.

[0171] In the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the above embodiments, in the solution where the trust anchor encrypts the data to be decrypted, the host encryption verification data is obtained through an encryption monitoring module with relatively high credibility, and the trust anchor encryption verification data calculated by the trust anchor based on the asymmetric encryption algorithm with relatively low credibility is received. The trust anchor encryption verification data is compared with the host encryption verification data for a third time to obtain a third comparison result. Through the above process, it is possible to monitor the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor based on an encryption monitoring module with relatively high credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor, ensuring the functional safety level of the encryption result of the trust anchor, and applying it to functional safety critical scenarios.

[0172] In one embodiment, a controller is provided, which is used to implement the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor shown above. Please refer to Figure 4 ., Figure 15 , Figure 15 FIG. is a schematic structural diagram of the controller provided by an embodiment of the present invention. As Figure 15 shown, the controller 1500 includes a trust anchor 1510 and a host 1520. The host 1520 includes a decryption monitoring module 1521, and the credibility of the decryption monitoring module 1521 is higher than that of the trust anchor 1510. The detailed description of each functional module is as follows:

[0173] The decryption monitoring module 1521 is configured to receive the trust anchor decryption verification data sent by the trust anchor 1510, and the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm;

[0174] The decryption monitoring module 1521 is further configured to determine the trust anchor decryption comparison data according to the trust anchor decryption verification data, and perform a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.

[0175] In one embodiment, the host further includes a trust anchor driver function module, which is configured to receive the data to be decrypted sent by the decryption monitoring module and send it to the trust anchor, and receive the trust anchor decryption verification data fed back by the trust anchor and send it to the host.

[0176] In one embodiment, the decryption monitoring module may be disposed in the trust anchor driver function module.

[0177] In one embodiment, the host further includes a mode switching module, which is configured to receive the original encrypted transmission data by the decryption monitoring module and determine the first estimated host encryption time for receiving the original encrypted transmission data; if the first estimated host encryption time is less than a preset time threshold, determine the original encrypted transmission data as the data to be decrypted and send it to the trust anchor, or decrypt the original encrypted transmission data through the decryption monitoring module. If the first estimated host encryption time is greater than or equal to the preset time threshold, determine the host encryption test data as the data to be decrypted and send it to the trust anchor, and determine the initial test data as the host decryption comparison data. The host encryption test data is obtained by encrypting the initial test data with the host public key, wherein the second estimated host encryption time of the host encryption test data is less than the preset time threshold.

[0178] In one embodiment, the encryption monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one lockstep module.

[0179] In one embodiment, the controller further includes a statistics module, which is configured to count the number of decryption exception events where the first comparison result indicates that the decryption comparison data of the trust anchor is different from the decryption comparison data of the host within a preset statistical period; if the number of decryption exception events is greater than a first preset number threshold, the controller is controlled to enter a secure state.

[0180] For the specific limitations of the controller, reference can be made to the limitations of the asymmetric encryption algorithm credibility improvement method for the corresponding trust anchor described above, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or be independent of it, or be stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to each of the above modules. Figure 4 In this embodiment, the controller essentially sets multiple modules to execute the asymmetric encryption algorithm credibility improvement method for the corresponding trust anchor in any of the above embodiments. The specific functions and technical effects can be referred to the above embodiments, which will not be elaborated here.

[0181] In one embodiment, a controller is provided, and the controller is used to implement the asymmetric encryption algorithm credibility improvement method provided in any of the above Figure 4 corresponding embodiments. Please refer to

[0182] FIG. Figure 7 Another structural schematic diagram of the controller provided in the embodiment of the present invention is shown in Figure 13 , Figure 16 As shown in Figure 16 , the controller 1600 includes a trust anchor 1610 and a host 1620. The host 1620 includes a transmission monitoring module 1616, and the credibility of the transmission monitoring module 1616 is higher than that of the trust anchor 1610. The detailed description of each functional module is as follows:

[0183] The transmission monitoring module 1616 is configured to obtain initial test data, determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor 1610. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor 1610 received by the host;

[0184] The trust anchor 1610 is configured to calculate trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm and feedback it to the transmission monitoring module 1616;

[0185] The transmission monitoring module 1616 is further configured to perform a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.

[0186] In one embodiment, Figure 16 The host, trust anchor in Figure 15 and the host and trust anchor structures in the controller in

[0187] are similar, and can be the same structure, or similar structures in different controllers. Figure 7 For specific limitations on the controller, reference can be made to the limitations on the method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in or independent of the processor in the electronic device in hardware form, or stored in the memory in the electronic device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0188] In this embodiment, the controller essentially sets multiple modules to execute the Figure 7 method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor in any of the above embodiments. For the specific functions and technical effects, reference can be made to the above embodiments, which will not be elaborated here.

[0189] In one embodiment, a controller is further provided. The host of the controller includes the transmission monitoring module and decryption monitoring module provided in the above embodiment. For relevant descriptions, reference can be made to the above embodiment, which will not be elaborated here.

[0190] In one embodiment, a controller is provided. The controller is used to implement the Figure 12 method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in any of the corresponding embodiments above. Please refer to Figure 17 , Figure 17 which is another structural schematic diagram of the controller provided in the embodiment of the present invention. As shown in Figure 17 , the controller 1700 includes a trust anchor 1710 and a host 1720. The host 1720 includes an encryption monitoring module 1712, and the credibility of the transmission monitoring module 1712 is higher than that of the trust anchor 1710. The detailed description of each functional module is as follows:

[0191] The encryption monitoring module 1712 is used to obtain host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module 1712 encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor 1710 encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor 1710 received by the host;

[0192] The encryption monitoring module 1712 is further used to perform a third comparison on the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0193] In one embodiment, Figure 17 Hosts, trust anchors and Figure 15 , Figure 16 The host and trust anchor structures in the controller are similar, and can be the same structure, or similar structures in different controllers.

[0194] In one embodiment of the present invention, the controller also includes an early warning module, which is used to count the number of encryption abnormality events in which the third comparison result is different between the host encryption verification data and the trust anchor encryption verification data within a preset statistical period after obtaining the third comparison result; if the number of encryption abnormality events is greater than a second preset number threshold, the controller is controlled to enter a safe state.

[0195] In one embodiment of the present invention, the controller further includes a transmission monitoring module, which is used to obtain initial test data before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, and determine the host transmission verification data and the test transmission data according to the initial test data, and send the test transmission data to the trust anchor, the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the credibility of the transmission monitoring module is higher than the credibility of the trust anchor; the trust anchor is also used to calculate the test transmission data based on an asymmetric encryption algorithm to obtain the trust anchor transmission verification data, and feed it back to the transmission monitoring module; the transmission monitoring module is also used to perform a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, and if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key of the host is available.

[0196] For specific limitations on controllers, please refer to the above Figure 12 The definition of the corresponding trust anchor asymmetric encryption algorithm credibility enhancement method is not repeated here. Each module in the above controller can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above modules can be embedded in or independent of the processor in the electronic device in the form of hardware, or can be stored in the memory of the electronic device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0197] In this embodiment, the controller is essentially provided with multiple modules for executing any of the above embodiments. Figure 12 The corresponding trust anchor asymmetric encryption algorithm credibility enhancement method, the specific functions and technical effects can refer to the above embodiments, and will not be repeated here. In one embodiment, an electronic device is provided, which can be a server, and its internal structure diagram can be as follows Figure 18As shown in the figure. The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the server side of a method for improving the credibility of a trust anchor asymmetric encryption algorithm.

[0198] In one embodiment, an electronic device is provided. The electronic device can be a client, and its internal structure diagram can be as Figure 19 shown. The electronic device includes a processor, a memory, a network interface, a display screen, and an input device connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a method for improving the credibility of a trust anchor asymmetric encryption algorithm.

[0199] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0200] Control the transmission monitoring module to obtain initial test data, and determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key. The host public key is the trust anchor public key sent by the trust anchor received by the host;

[0201] Control the trust anchor to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feedback it to the transmission monitoring module;

[0202] Control the transmission monitoring module to make a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.

[0203] In another embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0204] The control decryption monitoring module receives the trust anchor decryption verification data, which is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm;

[0205] The control decryption monitoring module determines the trust anchor decryption comparison data according to the trust anchor decryption verification data, and makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.

[0206] In another embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0207] The control encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key, and the trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host;

[0208] The control encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0209] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0210] The control transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data through the host public key. The host public key is the trust anchor public key sent by the trust anchor received by the host;

[0211] The control trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module;

[0212] The control transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.

[0213] In another embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0214] The control decryption monitoring module receives the trust anchor decryption verification data, which is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm;

[0215] The control decryption monitoring module determines the trust anchor decryption comparison data according to the trust anchor decryption verification data, and makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.

[0216] In another embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:

[0217] The control encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key, and the trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host;

[0218] The control encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

[0219] It should be noted that for the functions or steps that the above computer-readable storage medium or electronic device can implement, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0220] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0221] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device, system, and controller can be divided into different functional units or modules to complete all or part of the functions described above.

[0222] The embodiments provided above are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention and should all be included in the protection scope of the present invention.

Claims

1. A method for improving the credibility of a trust anchor asymmetric encryption algorithm, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. The method includes: The encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by encrypting the data to be encrypted by the host public key through the encryption monitoring module. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on an asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host; The encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

2. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 1, wherein, Before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: The host obtains initial actual data; Determine the expected host encryption time of the initial actual data; If the expected host encryption time is less than a preset time threshold, determine the initial actual data as the data to be encrypted; If the expected host encryption time is greater than or equal to the preset time threshold, determine the initial test data as the data to be encrypted, determine the host encryption test data as the host encryption verification data. The expected host encryption time of the initial test data is less than the preset time threshold, and the host encryption test data is obtained by encrypting the initial test data through the host public key.

3. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 2, wherein If the initial actual data is determined as the data to be encrypted, the method includes: When the encryption monitoring module obtains the host encryption verification data, the encryption monitoring module encrypts the initial actual data through the host public key to obtain host second encrypted transmission data, and uses the host second encrypted transmission data as the host encryption verification data; When the encryption monitoring module obtains the trust anchor encryption verification data, the trust anchor encrypts the initial actual data through the trust anchor public key based on an asymmetric encryption algorithm to obtain trust anchor encrypted transmission data, and sends the trust anchor encrypted transmission data to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor encrypted transmission data as the trust anchor encryption verification data.

4. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 3, wherein After obtaining the third comparison result, the method further includes at least one of the following: If the third comparison result is that the host second encrypted transmission data is the same as the trust anchor encrypted transmission data, determine at least one of the following: the trust anchor encrypted transmission data can be stored, the asymmetric encryption algorithm of the trust anchor is credible, and the data transmission link between the trust anchor and the encryption monitoring module is credible; If the third comparison result is that the host second encrypted transmission data is different from the trust anchor encrypted transmission data, determine that the trust anchor encrypted transmission data cannot be stored.

5. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 2, characterized in that If the initial test data is determined as the data to be encrypted and the host encryption test data is determined as the host encryption verification data, when the encryption monitoring module obtains the trust anchor encryption verification data, it includes: The trust anchor receives the initial test data sent by the encryption monitoring module, encrypts the initial test data based on an asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor second encrypted test data as the trust anchor encrypted verification data.

6. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 5, wherein After obtaining the third comparison result, the method further includes at least one of the following: If the third comparison result is that the trust anchor second encrypted test data is the same as the host encrypted test data, determine at least one of the following: the asymmetric encryption algorithm of the trust anchor is trustworthy, and the data transmission link between the trust anchor and the encryption monitoring module is trustworthy; If the third comparison result is that the trust anchor second encrypted test data is different from the host encrypted test data, determine at least one of the following: the asymmetric encryption algorithm of the trust anchor is not trustworthy, and the data transmission link between the trust anchor and the encryption monitoring module is not trustworthy.

7. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 4, wherein The method further includes: The encryption monitoring module sends new initial test data; The trust anchor receives the new initial test data sent by the encryption monitoring module, encrypts the new initial test data based on an asymmetric encryption algorithm using the trust anchor public key to obtain the new trust anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received new trust anchor second encrypted test data as the trust anchor encrypted verification data; The encryption monitoring module uses the new host encrypted verification data of the new initial test data as the new host encrypted verification data, and performs a third comparison between the new host encrypted verification data and the new trust anchor encrypted verification data to obtain a new third comparison result.

8. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 1-7, characterized in that, After obtaining the third comparison result, the method further includes: Count the number of encryption anomaly events where the third comparison result is that the host encrypted verification data is different from the trust anchor encrypted verification data within a preset statistical period; If the number of encryption anomaly events is greater than a second preset number threshold, control the controller to enter a secure state.

9. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 1-7, characterized in that, Before the encryption monitoring module obtains the host encrypted verification data and the trust anchor encrypted verification data, the method includes: The transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes the transmission monitoring module. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data using the host public key; The trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; The transmission monitoring module performs a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; If the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, determine that the host public key of the host is available.

10. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 9, characterized in that, The transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; Determine the host-encrypted test data as the test transmission data; Determine the initial test data as the host transmission verification data.

11. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 10, characterized in that, The trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: The trust anchor decrypts the host-encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.

12. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 11, wherein The method further includes: If the second comparison result is that the initial test data is the same as the first decrypted test data, store the initial test data and the host-encrypted test data in the transmission monitoring module.

13. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 9, characterized in that The transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; Determine the initial test data and the host-encrypted test data as the host transmission verification data; Determine the initial test data as the test transmission data.

14. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 13, wherein, The trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: The trust anchor encrypts the initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; At this time, the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, including: the initial test data is the same as the second decrypted test data, and the host-encrypted test data is the same as the trust anchor first encrypted test data.

15. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 14, wherein, The method further includes: If the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, store the initial test data and the host-encrypted test data in the transmission monitoring module.

16. A controller, characterized in that, The controller includes a trust anchor and a host, the host includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor, where: The encryption monitoring module is used to obtain host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by encrypting the data to be encrypted through the host public key by the encryption monitoring module. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host; The encryption monitoring module is further used to perform a third comparison on the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.

17. The controller according to claim 16, wherein, The controller further includes an early warning module, which is used to, after obtaining the third comparison result, count the number of encryption anomaly events where the third comparison result is that the host encryption verification data is different from the trust anchor encryption verification data within a preset statistical period; If the number of encryption anomaly events is greater than a second preset number threshold, control the controller to enter a secure state.

18. The controller according to any one of claims 16 or 17, characterized in that, The controller further includes a transmission monitoring module. The transmission monitoring module is used to obtain initial test data before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, and determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data through the host public key. The credibility of the transmission monitoring module is higher than that of the trust anchor; The trust anchor is further used to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feedback it to the transmission monitoring module; The transmission monitoring module is further used to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result. If the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, it is determined that the host public key of the host is available.

19. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor implements the method according to any one of claims 1 to 15 when executing the computer program.

20. A computer-readable storage medium stores a computer program, characterized in that, The computer program implements the method according to any one of claims 1 to 15 when executed by the processor.