Method for improving credibility of asymmetric encryption algorithm of trust anchor, controller, equipment and medium
By introducing a highly reliable decryption monitoring module into the controller, the problem that the hardware resources of the MCU's HSM module do not cover the functional security mechanism is solved, and the credibility of the trust anchor's asymmetric encryption algorithm is improved, ensuring that its decryption results meet the needs of key functional security scenarios.
Patent Information
- Application Number
- CN202410104563.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-24
- Publication Date
- 2025-07-25
AI Technical Summary
In the prior art, the hardware resources of the MCU's HSM module are not developed according to functional safety standards, resulting in the decryption results of the asymmetric encryption algorithm that cannot guarantee the functional safety level and cannot be applied to critical functional safety scenarios.
By introducing a high-reliability decryption monitoring module into the controller, the decryption verification data calculated by the trust anchor based on the asymmetric encryption algorithm is received, and the data is compared with the host decryption comparison, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor and ensuring the functional security level of the decryption result.
It improves the credibility of the trust anchor's asymmetric encryption algorithm, ensures that its decryption results can meet the requirements of key functional safety scenarios, and achieves the improvement of the functional security level of the asymmetric encryption algorithm.
Smart Images

Figure CN120378128A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicles, and in particular, to a method, a controller, a device, and a medium for improving the credibility of an asymmetric encryption algorithm of a trust anchor. Background Art
[0002] With the improvement of the degree of vehicle networking, information security issues have become increasingly prominent, and the ISO21434 automotive network security standard has been officially released in 2021. In order to meet the requirements of storing controller security data (keys / root certificates), cryptographic algorithms and their hardware acceleration, security applications, and secure chip operating environments, it is necessary to be equipped with a trust anchor (such as an HSM module).
[0003] In addition, with the increasing complexity of automotive electronic control systems and the introduction of a large number of electrical and electronic components, while bringing control convenience and diversity, it also brings certain risks to vehicle safety due to inevitable systematic failures and random hardware failures. To further improve the safety design of road vehicle-related products, the ISO26262 road vehicle functional safety standard has been introduced. Based on the analysis of the risks and hazards of the vehicle under various working conditions, this standard evaluates the safety levels (Automotive Safety Integrity Level, ASIL) for different safety objectives and defines four different ASILs: ASIL A, ASIL B, ASIL C, and ASIL D. Among them, ASIL D represents the highest safety integrity, while ASIL A represents the lowest safety integrity. In addition, if the identified risk is QM, there is no corresponding safety requirement. That is, from QM, ASIL-A / B / C / D, the functional safety has gradually become one of the important requirements for the development of automotive electronic and electrical related components by each vehicle manufacturer.
[0004] With the improvement of the degree of vehicle networking, there will be more and more interactions between future functional safety and information security. On the one hand, ensuring information security is the basis for achieving functional safety; on the other hand, functional safety may also need to rely on information security mechanisms to be realized.
[0005] In related technologies, some HSM firmware has been developed in accordance with the requirements of the functional safety process, but currently, there are still a large number of HSM modules of MCUs that have not been developed according to the functional safety standard, that is, the failure of their hardware resources is not covered by corresponding functional safety mechanisms. Therefore, how to improve the functional safety level of information security mechanisms is a brand-new topic.
[0006] In the design of an MCU with an HSM, the MCU is divided into two parts: the HSM side and the HOST side. The HSM side refers to the HSM module part, and the HOST side is the other part except the HSM module.
[0007] Asymmetric encryption algorithms are currently widely used in the field of automotive information security. However, since the hardware resources on the HSM side are not currently covered by a functional safety mechanism, the decryption results obtained on it cannot guarantee the functional safety level and can only be considered as QM, and cannot be applied to functional safety critical scenarios. Summary of the Invention
[0008] An embodiment of the present invention provides a method, a controller, a device, and a medium for improving the credibility of an asymmetric encryption algorithm of a trust anchor, so as to solve the technical problem in the related art that since the hardware of the HSM module of the MCU is not developed according to the functional safety standard, that is, the failure of its hardware resources is not covered by the corresponding functional safety mechanism, the decryption result obtained on the HSM side cannot guarantee the functional safety level and can only be considered as QM, and cannot be applied to functional safety critical scenarios.
[0009] An embodiment of the present invention provides a method for improving the credibility of an asymmetric encryption algorithm of a trust anchor, which is applied to a controller. The controller includes a trust anchor and a host, and the host includes a decryption monitoring module. The credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: the decryption monitoring module receives trust anchor decryption verification data sent by the trust anchor, and the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm; the decryption monitoring module determines trust anchor decryption comparison data according to the trust anchor decryption verification data, and performs a first comparison between the trust anchor decryption comparison data and host decryption comparison data to obtain a first comparison result.
[0010] In an embodiment of the present invention, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the decryption monitoring module receives the original encrypted transmission data and sends it to the trust anchor. The data to be decrypted includes the original encrypted transmission data, and the original encrypted transmission data is obtained by encrypting the unencrypted actual data based on the public key of the sending end of the data sending end. The data sending end uses the trust anchor public key generated by the trust anchor received as the public key of the sending end; the trust anchor decrypts the original encrypted transmission data based on the trust anchor private key through the asymmetric encryption algorithm to obtain trust anchor decrypted transmission data, uses the trust anchor decrypted transmission data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
[0011] In an embodiment of the present invention, the decryption monitoring module determines trust anchor decryption comparison data according to the trust anchor decryption verification data, including: the decryption monitoring module encrypts the trust anchor decryption transmission data through the host public key to obtain the host first encrypted transmission data, and uses the host first encrypted transmission data as the trust anchor decryption comparison data. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0012] In an embodiment of the present invention, after performing a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: if the first comparison result is that the host first encrypted transmission data is the same as the original encrypted transmission data, determine at least one of the following: the trust anchor decryption transmission data is available, the asymmetric encryption algorithm is trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; if the first comparison result is that the host first encrypted transmission data is different from the original encrypted transmission data, determine that the trust anchor decryption transmission data is unavailable; wherein, the host decryption comparison data includes the original encrypted transmission data.
[0013] In an embodiment of the present invention, after the trust anchor decrypts the original encrypted transmission data through the trust anchor private key based on the asymmetric encryption algorithm to obtain the trust anchor decryption transmission data, the method further includes: sending the trust anchor decryption transmission data to the decryption data usage object.
[0014] In an embodiment of the present invention, after performing a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes: if the first comparison result is that the host first encrypted transmission data is different from the original encrypted transmission data, generate a data unavailable message and send it to the decryption data usage object.
[0015] In an embodiment of the present invention, before the decryption monitoring module receives the original encrypted transmission data, the method includes: the encryption monitoring module of the data sending end receives the trust anchor public key sent by the controller, uses the trust anchor public key as the sending end public key, encrypts the unencrypted actual data through the sending end public key to obtain the original encrypted transmission data, and sends the original encrypted transmission data to the decryption monitoring module.
[0016] In an embodiment of the present invention, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the decryption monitoring module obtains host encrypted test data, and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting initial test data with a host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with a trust anchor private key to obtain third decryption test data, uses the third decryption test data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
[0017] In an embodiment of the present invention, the method further includes: the decryption monitoring module obtains host encrypted test data, and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting initial test data with a host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with a trust anchor private key to obtain third decryption test data, uses the third decryption test data as new trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs. The decryption monitoring module uses the new trust anchor decryption verification data as new trust anchor decryption comparison data, and makes a first comparison between the new trust anchor decryption comparison data and new host decryption comparison data to obtain a first comparison result. The new host decryption comparison data is the initial test data.
[0018] In an embodiment of the present invention, after making a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: if the first comparison result is that the third decryption test data is the same as the initial test data, determine at least one of the following: the asymmetric encryption algorithm is trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; if the first comparison result is that the third decryption test data is different from the initial test data, determine at least one of the following: the asymmetric encryption algorithm is not trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is not trustworthy; wherein, the host decryption comparison data includes the initial test data, and the trust anchor decryption comparison data includes the third decryption test data.
[0019] In an embodiment of the present invention, after obtaining the first comparison result, the method further includes: counting the number of decryption exception events where the first comparison result is that the decryption comparison data of the trust anchor is different from the decryption comparison data of the host within a preset statistical period; if the number of decryption exception events is greater than a first preset number threshold, controlling the controller to enter a secure state.
[0020] In an embodiment of the present invention, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes the transmission monitoring module. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host; the trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key of the host is available, and the credibility of the transmission monitoring module is higher than the credibility of the trust anchor.
[0021] In an embodiment of the present invention, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.
[0022] In an embodiment of the present invention, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
[0023] In an embodiment of the present invention, the method further includes: if the second comparison result is that the initial test data and the first decrypted test data are the same, storing the initial test data and the host encrypted test data in the transmission monitoring module.
[0024] In an embodiment of the present invention, the transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; determines the initial test data and the host-encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.
[0025] In an embodiment of the present invention, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain trust anchor first-encrypted test data, and decrypts the trust anchor first-encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain second-decrypted test data, and determines the second-decrypted test data and the trust anchor first-encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, including: the initial test data and the second-decrypted test data are the same, and the host-encrypted test data and the trust anchor first-encrypted test data are the same.
[0026] In an embodiment of the present invention, the method further includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, storing the initial test data and the host-encrypted test data in the transmission monitoring module.
[0027] In an embodiment of the present invention, the method further includes: the encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data, the host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted with the host public key, the trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host with the trust anchor public key based on the asymmetric encryption algorithm, the host public key is the trust anchor public key sent by the trust anchor received by the host, the host further includes the encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor; the encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0028] An embodiment of the present invention further provides a method for improving the credibility of a trust anchor asymmetric encryption algorithm, which is applied to a controller. The controller includes a trust anchor and a host, and the host includes a transmission monitoring module. The credibility of the transmission monitoring module is higher than that of the trust anchor. The method includes: The transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with a host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host; The trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feeds it back to the transmission monitoring module; The transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0029] In an embodiment of the present invention, the transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain host encrypted test data; Determines the host encrypted test data as the test transmission data; Determines the initial test data as the host transmission verification data.
[0030] In an embodiment of the present invention, the trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
[0031] In an embodiment of the present invention, after the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following:
[0032] If the second comparison result is that the first decrypted test data is the same as the initial test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data; If the first comparison result is that the first decrypted test data is different from the initial test data, determine that the host public key is unavailable.
[0033] In an embodiment of the present invention, the transmission monitoring module determines host transmission verification data and test transmission data based on the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; determines the initial test data and the host-encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.
[0034] In an embodiment of the present invention, the trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor encrypts the initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data.
[0035] In an embodiment of the present invention, after the transmission monitoring module performs a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following: if the initial test data is the same as the second decrypted test data, and the host-encrypted test data is the same as the trust anchor first encrypted test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host-encrypted test data; if the initial test data is different from the second decrypted test data, determine that the trust anchor public key does not match the trust anchor private key; if the host-encrypted test data is different from the trust anchor first encrypted test data, determine that the host public key is different from the trust anchor public key and the host public key is not available.
[0036] In an embodiment of the present invention, after obtaining the second comparison result, the method includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, send the host public key to the data sending end, so that the data sending end receives the host public key as the sending end public key, and encrypts the unencrypted actual data with the sending end public key to obtain the original encrypted transmission data.
[0037] An embodiment of the present invention further provides a controller, which includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. Specifically: the decryption monitoring module is configured to receive the trust anchor decryption verification data sent by the trust anchor, where the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on an asymmetric encryption algorithm; the decryption monitoring module is further configured to determine trust anchor decryption comparison data according to the trust anchor decryption verification data, and perform a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
[0038] In an embodiment of the present invention, the controller further includes at least one of a transmission monitoring module and an encryption monitoring module. The credibility of the transmission monitoring module is higher than that of the trust anchor, and the credibility of the encryption monitoring module is higher than that of the trust anchor. Specifically: if the controller includes the transmission monitoring module, the transmission monitoring module is configured to obtain initial test data, and determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host; the trust anchor is further configured to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feedback it to the transmission monitoring module; the transmission monitoring module is further configured to perform a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the controller includes the encryption monitoring module, the encryption monitoring module is configured to obtain host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted with the host public key, and the trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host with the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host, and perform a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0039] An embodiment of the present invention further provides a controller, which includes a trust anchor and a host. The host includes a transmission monitoring module, and the credibility of the transmission monitoring module is higher than that of the trust anchor. Wherein: the transmission monitoring module is used to obtain initial test data, determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host; the trust anchor is used to calculate trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm and feedback it to the transmission monitoring module; the transmission monitoring module is further used to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0040] An embodiment of the present invention further provides an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method of any of the above embodiments is implemented.
[0041] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method of any of the above embodiments is implemented.
[0042] In the solution implemented by the above-provided method for improving the credibility of the asymmetric encryption algorithm of the trust anchor, the controller, the device, and the medium, in the decryption stage of the trust anchor, the decryption monitoring module with higher credibility receives the trust anchor decryption verification data calculated by the trust anchor with lower credibility based on the asymmetric encryption algorithm, determines the trust anchor decryption comparison data, and performs a first comparison on the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result. Through the above process, it is possible to monitor the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor based on the decryption monitoring module with higher credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor and ensuring the functional safety level of the decryption result of the trust anchor for application in functional safety critical scenarios. Description of the Drawings
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0044] Figure 1 Flow schematic diagram of an implementation method for transmitting the public key of asymmetric encryption based on HSM provided for an invention embodiment;
[0045] Figure 2 Flow schematic diagram of an implementation method for decrypting asymmetric data based on HSM provided for an invention embodiment;
[0046] Figure 3 Flow schematic diagram of an implementation method for storing asymmetric encrypted data based on HSM provided for an invention embodiment;
[0047] Figure 4 A flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0048] Figure 5 A specific flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0049] Figure 6 A specific flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0050] Figure 7 Another flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0051] Figure 8 Another specific flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0052] Figure 9 For Figure 8 Data transmission schematic diagram of the method shown;
[0053] Figure 10 Another specific flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0054] Figure 11 For Figure 10 Data transmission schematic diagram of the method shown;
[0055] Figure 12 Another flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0056] Figure 13 Another specific flow schematic diagram of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided for an embodiment of the present invention;
[0057] Figure 14Another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention;
[0058] Figure 15 A structural schematic diagram of the controller provided by the embodiment of the present invention;
[0059] Figure 16 Another structural schematic diagram of the controller provided by the embodiment of the present invention;
[0060] Figure 17 Another structural schematic diagram of the controller provided by the embodiment of the present invention;
[0061] Figure 18 A structural schematic diagram of an electronic device in an embodiment of the present invention;
[0062] Figure 19 Another structural schematic diagram of an electronic device in an embodiment of the present invention. Detailed implementation manners
[0063] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts shall fall within the protection scope of the present invention.
[0064] To enable those skilled in the art to better understand the improvements of the technical solutions provided by the present disclosure, the present disclosure briefly introduces the implementation method of the asymmetric encryption algorithm based on HSM and related information in the related art.
[0065] A Trust Anchor is a module required to meet the requirements for storing secure data (keys / root certificates) of a controller, cryptographic algorithms and their hardware acceleration, secure applications, and a secure operating environment for the chip. The implementation methods of Trust Anchor in MCU applications include Secure Hardware Extension (SHE), Hardware Security Module (HSM), Secure Element (SE), etc. Among them, HSM is a specification proposed by the E-safetyVehicle Intrusion proTected Applications (EVITA, 2008 - 2011), a research project on vehicle communication security for Vehicle to Everything (V2X) in the European Union, which is divided into three levels: Light, Medium, and Full. Currently, the mainstream automotive-grade MCUs are configured with Hardware Security Modules (HSM), and the Full level has become a trend to meet the information security requirements of vehicle controllers.
[0066] An asymmetric encryption algorithm is an algorithm that uses different keys during the encryption and decryption processes. For example, when two communication parties (such as A and B) exchange data, A and B first exchange their public keys. Then, when exchanging data, A can use B's public key to encrypt the data to be exchanged, and B can use its own private key to decrypt the encrypted data after receiving it. Therefore, an asymmetric encryption algorithm is also called a public key encryption algorithm.
[0067] Asymmetric encryption algorithms are currently widely used in the field of automotive information security, such as the transfer of public keys of controllers, encrypted communication, and encrypted data storage. Asymmetric encryption and decryption algorithms can ensure the confidentiality of data. Even if a third party obtains the data encrypted by an asymmetric algorithm, they still cannot know the meaning of the data. Encryption and decryption generally use international standard algorithms, such as the RSA algorithm (an asymmetric encryption algorithm based on the problem of factoring large numbers) and the Elliptic Curve Cryptography (ECC) algorithm. In an asymmetric encryption algorithm, the number of controllers determines the number of public-private key pairs. The controllers receiving the messages need to distribute their public keys to other controllers in advance, and only the controllers with the private keys can decrypt the data encrypted with the public keys.
[0068] As an example, the application of the asymmetric encryption and decryption algorithm based on HSM in public key transfer, encrypted communication, and encrypted data storage is as Figure 1 、 Figure 2 and Figure 3 shown.
[0069] When the controller is used as a data receiving end, the controller includes a host end and a trust anchor end. Taking the trust anchor as HSM, the host end includes a software monitoring module HOST Software and a trust anchor host driver module HSM HOST Driver, and the HSM end includes a hardware security module firmware HSM Firmware as an example. Please refer to Figure 1 , Figure 1 FIG. is a schematic flow chart of an implementation method for transmitting an asymmetric encryption public key based on HSM provided by an invention embodiment, such as Figure 1 shown, the data receiving end HOST Software first calls the driver (HSM HOST Driver) function of HSM located at the HOST end to request the generation of a public-private key pair, that is, HOSTSoftware sends a public-private key pair generation request 1, 2 to HSM Firmware through HSM HOST Driver. After the HSM firmware (HSM Firmware) at the HSM end generates the key pair, it records the private key and the public key, and returns the public key to the HOST end, that is, Figure 1 in 3, 4, HSM Firmware sends the public key to HOST Software through HSM HOST Driver. HOST Software sends the public key to the data sending end, that is, Figure 1 in the public key sending step 5, the data sending end injects the public key of the data receiving end into the controller acting as the data sending end.
[0070] When the controller is used as a data receiving end, the controller includes a host end and a trust anchor end. Taking the trust anchor as HSM, the host end includes a software monitoring module HOST Software and a trust anchor host driver module HSM HOST Driver, and the HSM end includes a hardware security module firmware HSM Firmware as an example. Please refer to Figure 2 , Figure 2 FIG. is a schematic flow chart of an implementation method for asymmetric data decryption based on HSM provided by an invention embodiment, such as Figure 2 shown, after the HOST Software at the data receiving end receives the encrypted data sent by the data sending end (that is, Figure 2 in the encrypted data reception 1), it first calls the driver (HSM HOST Driver) function of HSM located at the HOST end to request the HSM end to decrypt the encrypted data, that is, Figure 2 in the transmission process of the encrypted data 2, 3, the HSM firmware (HSM Firmware) at the HSM end decrypts the data with the private key and returns the data to HOST Software through the HSM HOSTDriver at the HOST end, that is, Figure 2The original data decrypted with the private key as represented by 4 and 5 in []. The private key used in the decryption process is derived from Figure 1 The generated public-private key pair.
[0071] When the controller serves as the data storage end (data sending end), the controller includes a host end and a trust anchor end. Taking the trust anchor as the HSM, the host end includes a software monitoring module HOST Software and a trust anchor host driver module HSM HOSTDriver, and the HSM end includes a hardware security module firmware HSM Firmware as an example. Please refer to Figure 3 , Figure 3 It is a schematic flowchart of an implementation method for asymmetric encryption data storage based on HSM provided for an invention embodiment. As Figure 3 shown, the HOST Software at the data storage end first calls the driver (HSM HOST Driver) function of the HSM located at the HOST end to request encryption of the data to be stored ( Figure 3 The original data 1 and 2 in []) with the public key. After the HSM firmware (HSM Firmware) at the HSM end encrypts the data, it returns the data to the HOST Software through the driver HSM HOST Driver at the HOST end, that is, Figure 3 The data encrypted with the public key as represented by 3 and 4 in []. The public key used in the encryption process is derived from Figure 1 The generated public-private key pair. Then, perform Figure 3 The encrypted data storage in []. The stored encrypted data can also be sent to the data receiving end.
[0072] Since the hardware resources at the HSM end are currently not covered by a functional safety mechanism, the encryption or decryption results obtained on it cannot guarantee the functional safety level and can only be considered as QM and cannot be applied to functional safety critical scenarios.
[0073] For current mainstream MCUs, the host end has a perfect functional safety mechanism to ensure that the diagnostic coverage rate of its hardware failures can meet the requirements of the highest ASIL-D; and, it has at least one secure core with a lockstep mechanism, and the lockstep mechanism can make the diagnostic coverage rate of the MCU core meet the requirements of ASIL-D.
[0074] In asymmetric encryption, the public key is a public key that can be externally distributed, while the private key is a key that must be securely stored in the HSM. Therefore, the inventor designed a solution for improving the functional safety level of the asymmetric encryption and decryption algorithm based on the HSM by utilizing the characteristic of public key sharing.
[0075] The MCU hardware resources used to generate public-private key pairs and perform asymmetric encryption and decryption from the HSM side mainly include: the CPU, storage, bus, clock, power supply on the HSM side, and the information security algorithm hardware acceleration unit (asymmetric encryption and decryption algorithm). Among them, the clock, power supply are the same as those on the HOST side and can be overridden by the HOST side, but additional functional safety mechanisms need to be designed to cover the failures of other resources.
[0076] The method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiments of the present application can be applied to the controller MCU. The controller includes a trust anchor Trust Anchor and a host HOST. The host includes a software monitoring module, and the software monitoring module includes at least one of a transmission monitoring module, an encryption monitoring module, and a decryption monitoring module. The credibility of the transmission monitoring module, the encryption monitoring module, and the decryption monitoring module is higher than the credibility of the trust anchor Trust Anchor. At least two of the transmission monitoring module, the encryption monitoring module, and the decryption monitoring module can be integrated into one module or can be separated, and no limitation is made in this regard.
[0077] The credibility in this embodiment can be evaluated by the above-mentioned automotive safety integrity level ASIL, or can also be implemented by other trust rules set by those skilled in the art for the field of functional safety. Functional safety can be understood as the absence of unreasonable risks caused by hazards resulting from abnormal functional manifestations of electronic / electrical systems. For example, as exemplified in the above embodiments, the credibility of the trust anchor is QM, and the credibility of the host is ASIL D. It should be noted that the encryption (decryption) monitoring module can be a "symmetric encryption (decryption) monitoring software" designed in the security core on the HOST side. In order to achieve the integrity check success flag bit to reach the corresponding ASIL level, the software development process of this part and the MCU hardware resources involved need to meet the development requirements of the corresponding ASIL level, and need to be immune from interference (Freedom From Interference, FFI) with other ASIL / QM level software. The encryption monitoring module and the decryption monitoring module can be the same entity module or different entity modules.
[0078] In another embodiment, the credibility can be understood as the degree of trust that can actually be achieved in an actual application scenario, even if there may be software interference, rather than only referring to the degree of trust calculated when the software or module is designed.
[0079] This method can be applied to application scenarios such as public key transfer, encrypted communication, and encrypted data storage in the field of automotive information security.
[0080] In one embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment can be applied to each process of asymmetric encryption and decryption of the trust anchor of the controller. That is, in the process of each execution of asymmetric encryption and decryption of the received data by the trust anchor, the solution of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment is executed, so as to ensure the credibility of the results of asymmetric encryption and decryption of the received data by the trust anchor each time.
[0081] In another embodiment, according to the needs of those skilled in the art, the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in this embodiment can also be triggered randomly, or at intervals of a preset detection duration, or at intervals of a preset number of data transmissions, etc., to verify whether the results of asymmetric encryption and decryption of the trust anchor are credible.
[0082] The transmission monitoring module, the encryption monitoring module, and the decryption monitoring module can be hardware units with computing capabilities that meet the requirements of functional safety levels, such as: hardware acceleration units, at least one secure core with a Lockstep mechanism, etc.
[0083] The implementation methods of the trust anchor include but are not limited to SHE, HSM, SE, etc. known to those skilled in the art. In the design of an MCU with a trust anchor, the MCU can be divided into a trust anchor end (hereinafter referred to as the trust anchor) and a host end (hereinafter referred to as the host). The host is other parts except for modules such as the trust anchor like HSM, and the trust anchor is the module part such as HSM.
[0084] In another embodiment, credibility can be understood as the credible degree that can actually be achieved in an actual application scenario, even if there may be software interference, rather than only referring to the credible degree calculated during the design of the software or module.
[0085] Please refer to Figure 4 as shown in Figure 4 FIG. is a schematic flowchart of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by an embodiment of the present invention, providing a functional safety improvement solution for asymmetric data decryption. The method includes the following steps:
[0086] Step S410, the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor.
[0087] Among them, the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm.
[0088] Before step S410, continue to refer to Figure 1, the trust anchor generates a trust anchor public key and a trust anchor private key. The trust anchor sends the trust anchor public key to the decryption monitoring module of the host, and the decryption monitoring module uses the received trust anchor public key as the host public key. The data to be decrypted can be obtained by the decryption monitoring module encrypting the initial test data in advance according to the host public key, or the data sender can receive the trust anchor public key sent by the controller in advance as the sender public key and encrypt the unencrypted actual data based on this sender public key to obtain it.
[0089] Step S420, the decryption monitoring module determines the trust anchor decryption comparison data according to the trust anchor decryption verification data, and makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
[0090] Among them, depending on the determination method of the trust anchor decryption verification data, the trust anchor decryption comparison data can be directly the trust anchor decryption verification data, or the decryption monitoring module processes the trust anchor decryption verification data to obtain the trust anchor decryption comparison data. Correspondingly, based on the different selected trust anchor decryption comparison data, the host decryption comparison data also needs to be adjusted accordingly. The host decryption comparison data can be the data to be decrypted itself, or the data to be decrypted and the original data corresponding to the data to be decrypted.
[0091] In one embodiment, before the decryption monitoring module receives the original encrypted transmission data, the method includes: the encryption monitoring module of the data sender receives the trust anchor public key sent by the controller, uses the trust anchor public key as the sender public key, encrypts the unencrypted actual data through the sender public key to obtain the original encrypted transmission data, and sends the original encrypted transmission data to the decryption monitoring module.
[0092] Taking the controller's actual processing of the data to be decrypted sent by the data sender as an example, in one embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the decryption monitoring module receives the original encrypted transmission data and sends it to the trust anchor. The data to be decrypted includes the original encrypted transmission data, and the original encrypted transmission data is obtained by encrypting the unencrypted actual data based on the sender public key of the data sender. The data sender uses the trust anchor public key generated by the received trust anchor as the sender public key; the trust anchor decrypts the original encrypted transmission data through the trust anchor private key based on the asymmetric encryption algorithm to obtain the trust anchor decrypted transmission data, uses the trust anchor decrypted transmission data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
[0093] Continuing with the above embodiments, the decryption monitoring module determines the trust anchor decryption comparison data by decrypting and verifying the data based on the trust anchor, including: the decryption monitoring module encrypts the trust anchor decryption transmission data through the host public key to obtain the first host encrypted transmission data, and uses the first host encrypted transmission data as the trust anchor decryption comparison data. The host public key is the trust anchor public key sent by the trust anchor received by the host. At this time, the method further includes: determining the original encrypted transmission data as the host decryption comparison data.
[0094] As described in the above embodiments, it can be understood that first, the data sender (similar to Figure 1 the object sent by the 5 public key shown) uses the received public key (trust anchor public key) as the sender public key, and encrypts the unencrypted actual data through the sender public key to obtain the original encrypted transmission data. For reference, Figure 2 in the solution of, the data sender sends the original encrypted transmission data to the controller, which is received by the decryption monitoring module. The decryption monitoring module sends the original encrypted transmission data (similar to Figure 2 the encrypted data in) to the trust anchor, triggering the trust anchor to decrypt the original encrypted transmission data through the trust anchor private key based on the asymmetric encryption algorithm to obtain the trust anchor decryption transmission data (similar to Figure 2 the original data decrypted with the private key in), and feeds back the trust anchor decryption transmission data to the decryption monitoring module. Then, the decryption monitoring module encrypts the trust anchor decryption transmission data through the host public key to obtain the first host encrypted transmission data, and compares the first host encrypted transmission data with the originally received original encrypted transmission data for the first time to obtain the first comparison result.
[0095] In one embodiment, after comparing the trust anchor decryption comparison data with the host decryption comparison data for the first time to obtain the first comparison result, the method further includes at least one of the following: if the first comparison result is that the first host encrypted transmission data is the same as the original encrypted transmission data, the monitoring is successful, and at least one of the following is determined: the trust anchor decryption transmission data is available, the asymmetric encryption algorithm is trustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; if the first comparison result is that the first host encrypted transmission data is different from the original encrypted transmission data, the monitoring fails, and at least one of the following is determined: the trust anchor decryption transmission data is unavailable, the asymmetric encryption algorithm is untrustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is untrustworthy; wherein, the host decryption comparison data includes the original encrypted transmission data.
[0096] If the computing power overhead of directly performing public key encryption on the HOST-side security core is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST side. Since the HOST-side monitoring software has obtained the public key during the public key upload phase (the host receives the trust anchor public key sent by the trust anchor and uses it as the host public key) and stores it in the ASIL area (such as the aforementioned decryption monitoring module), the decrypted original data (trust anchor decrypted transmission data) can be encrypted again with the public key (host public key). If the data after public key encryption (host first encrypted transmission data) is the same as the received encrypted data (original encrypted transmission data), it is considered that the decrypted original data (trust anchor decrypted transmission data) is available; otherwise, it is not available.
[0097] Taking the trust anchor as the HSM as an example, please refer to Figure 5 , Figure 5 which is a specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 5 shown, if the computing power overhead of directly performing public key encryption on the HOST-side security core is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST side. Since the HOST-side monitoring software has obtained the public key and stored it in the ASIL area during the public key upload phase, the decrypted original data can be encrypted again with the public key. If the data after public key encryption is the same as the received encrypted data, it is considered that the decrypted original data is available; otherwise, it is not available. Combining Figure 1 and Figure 2 's solutions, after the generation and transmission of the key pair are completed, the host side will receive the encrypted data (original encrypted transmission data, which is obtained by encrypting the unencrypted actual data with the externally issued public key, i.e., the sender's public key), and send it to the HSM for decryption with the trust anchor private key to obtain the trust anchor decrypted transmission data. After the host side starts the process of monitoring the credibility of the asymmetric encryption algorithm of the trust anchor, first, the host side ( Figure 5The HOST side (in the above) will obtain the public key (i.e., the host public key) from the secure area (ASIL area, such as the decryption monitoring module with the decryption monitoring software set above), and then the HOST side receives the decrypted original data decrypted by the HSM (i.e., the trust anchor decrypted transmission data), and encrypts the decrypted original data with the host public key to obtain the first encrypted transmission data of the host. It is judged whether the data is consistent after public key encryption, that is, it is judged whether the first encrypted transmission data of the host is consistent with the original encrypted transmission data. If so, that is, the two are consistent, it means that the monitoring passes and the decrypted original data (trust anchor decrypted transmission data) is available. Otherwise, if the two are inconsistent, it means that the decrypted original data is unavailable.
[0098] Through the above method, if the first encrypted transmission data of the host is the same as the original encrypted transmission data, it means that the decryption result of the HSM side is credible, that is, the trust anchor decrypted transmission data is available. Correspondingly, the asymmetric encryption algorithm of the trust anchor is credible, and the data transmission link between the trust anchor and the host is also credible. On the contrary, if the first encrypted transmission data of the host is different from the original encrypted transmission data, then at least the following two situations exist: 1. There is a problem with the data transmission link between the trust anchor and the host; 2. There is a problem with the asymmetric encryption algorithm of the trust anchor. Since there is no further way to judge which part or all of them have problems, it can be determined that the trust anchor decrypted transmission data decrypted by the HSM at this time is problematic and unavailable. At this time, the trust anchor decrypted transmission data can be sent to the decryption data usage object for its use.
[0099] In an embodiment, after the trust anchor decrypts the original encrypted transmission data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the trust anchor decrypted transmission data, the method further includes: sending the trust anchor decrypted transmission data to the decryption data usage object. Since the speed of the asymmetric encryption calculation of the HSM is faster than that of the HOST side, therefore, in order to further improve the data processing speed of the entire system, after the HSM calculates the trust anchor decrypted transmission data, without waiting for the monitoring result of the host, the trust anchor decrypted transmission data can be directly sent to the decryption data usage object. Since the overall calculation credibility probability of the trust anchor is generally higher than the non-credible probability, through this method, the overall processing efficiency of the system can be effectively improved.
[0100] Continuing from the above embodiments, after performing the first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain the first comparison result, the method further includes: If the first comparison result indicates that the host's first encrypted transmission data is different from the original encrypted transmission data, a data unavailable message is generated and sent to the decryption data usage object. That is, although the trust anchor decrypted transmission data has been sent to the decryption data usage object, once it is found that the trust anchor decrypted transmission data is unavailable and there is a problem, the host generates a data unavailable message and sends it to the decryption data usage object for remedy. If the first comparison result indicates that the host's first encrypted transmission data is the same as the original encrypted transmission data, subsequent steps can be executed according to the settings of those skilled in the art. For example, a data available message is generated and sent to the decryption data usage object. After the decryption data usage object processes the trust anchor decrypted transmission data to obtain a data processing result, it waits or, upon receiving the already received data available message, will then apply the data processing result in the next step. This can synchronize the process of the decryption data usage object processing the trust anchor decrypted transmission data with the host's monitoring of the trust anchor asymmetric encryption algorithm, not only improving the processing efficiency but also ensuring the reliability of the data result. Another example is that no message may be generated at all. As long as the decryption data usage object does not receive a data unavailable message, it is defaulted that the previously received trust anchor decrypted transmission data is available.
[0101] The above embodiments provide a solution for the host to monitor the trust anchor asymmetric encryption algorithm after receiving the original encrypted transmission data sent by the data sender. As mentioned in the above embodiments, this process can be executed once for each received original encrypted transmission data, or it can be executed once. If the first comparison result is the same, the execution can be paused for a certain period of time or the monitoring of subsequent several original encrypted transmission data can be temporarily not executed, and the result of the trust anchor decryption is defaulted to be available. The specific implementation method can be selected by those skilled in the art according to needs.
[0102] In another embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: The decryption monitoring module obtains the host encrypted test data, sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting the initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decryption test data, and uses the third decryption test data as the trust anchor decryption verification data and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
[0103] The initial test data can be random values generated randomly, data pre-configured by those skilled in the art, or achieved through other technical solutions known to those skilled in the art. The host-encrypted test data can be obtained by encrypting the initial test data with the host public key. The host can pre-store the initial test data and encrypt the initial test data with the host public key when needed to obtain the host-encrypted test data. It can also be that the initial test data and the host-encrypted test data corresponding to the initial test data are pre-stored. It should be noted that the host can store a set of initial test data and the host-encrypted test data corresponding to the initial test data, or multiple sets of initial test data and the host-encrypted test data corresponding to the initial test data. When in use, the currently used initial test data can be switched randomly or sequentially.
[0104] Continuing with the above embodiment, when only the above-provided scheme for initial test data is adopted to improve the trust anchor asymmetric encryption algorithm, the method further includes, after obtaining the first comparison result, sending the original encrypted transmission data to the trust anchor, decrypting the original encrypted transmission data by the trust anchor to obtain the trust anchor decrypted transmission data. At this time, it can be defaulted that the trust anchor decrypted transmission data is available, and the original encrypted transmission data is no longer used as the data to be decrypted for Figure 4 the credibility improvement scheme shown. Of course, it can also be determined whether to directly default to using the trust anchor decrypted transmission data as available data or to execute the credibility improvement scheme shown again with the original encrypted transmission data as the data to be decrypted based on the magnitude relationship between the first estimated host encryption time consumption of the original encrypted transmission data and the preset time threshold, and determine whether the trust anchor decrypted transmission data is available based on the execution result. It can also be based on the monitoring interval principle set by those skilled in the art. For example, every time a monitoring is performed and the first comparison result is the same, the next several original encrypted transmission data are paused, or the execution of the credibility improvement scheme shown is paused for a certain pause duration. Figure 4 Figure 4 Figure 4 the credibility improvement scheme shown.
[0105] In another embodiment, if the original encrypted transmission data is used as the data to be encrypted and the host decryption comparison data, and the host first encrypted transmission data is used as the trust anchor decryption comparison data, before, during, or after using the above data to improve the credibility of the trust anchor asymmetric encryption algorithm, the following scheme can also be executed to further improve the credibility of the trust anchor asymmetric encryption algorithm. For example, the following monitoring scheme is used as a periodic task, and the following process is executed at preset interval times regardless of whether the original encrypted transmission data is received.
[0106] The specific monitoring solution is as follows: The decryption monitoring module obtains the host encrypted test data and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting the initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decrypted test data, uses the third decrypted test data as the new trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs. The decryption monitoring module uses the new trust anchor decryption verification data as the new trust anchor decryption comparison data, and makes a first comparison between the new trust anchor decryption comparison data and the new host decryption comparison data to obtain a first comparison result. The new host decryption comparison data is the initial test data.
[0107] Different from the foregoing embodiment, the foregoing embodiment is a simple scheme that executes once to improve the credibility using the host encrypted test data and the initial test data. In this embodiment, the controller not only executes the scheme to improve the credibility using the host encrypted test data and the initial test data, but also executes the scheme to improve the credibility of the trust anchor asymmetric encryption algorithm by using the original encrypted transmission data as the data to be encrypted and the host decryption comparison data, and using the host first encrypted transmission data as the trust anchor decryption comparison data. The executions of the two are independent, and the execution order can be limited according to the needs of those skilled in the art.
[0108] In these two embodiments, after making a first comparison between the (new) trust anchor decryption comparison data and the (new) host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: If the first comparison result is that the third decrypted test data is the same as the initial test data, determine at least one of the following, the asymmetric encryption algorithm is trustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; If the first comparison result is that the third decrypted test data is different from the initial test data, determine at least one of the following, the asymmetric encryption algorithm is not trustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is not trustworthy; Among them, the host decryption comparison data includes the initial test data, and the trust anchor decryption comparison data includes the third decrypted test data.
[0109] Although the actually used calculation data is not the data provided by the data sender, the above method can also be used to verify whether the asymmetric encryption algorithm and the data transmission link between the trust anchor and the decryption monitoring module are trustworthy.
[0110] For example, if the computing power overhead of directly performing public key encryption on the HOST - side security core is large and the calculation cannot be completed or the normal function of the controller will be affected within the time required by the Fault Tolerant Time Interval (FTTI) and other requirements, the HOST - side monitoring software does not directly participate in decrypting the received encrypted data. Instead, it additionally triggers the HSM to decrypt in the periodic task, and judges whether the HSM and the data transfer link are invalid through the value after HSM decryption. Since the HOST - side monitoring software has obtained the ch and e_ch values and stored them in the ASIL area during the public key upload phase, the HSM can be triggered to decrypt the e_ch value once. If the decrypted value ch’ is consistent with ch, it is considered that the private key decryption and the data transfer link after decryption are available; otherwise, they are unavailable.
[0111] Taking the trust anchor as the HSM as an example, please refer to Figure 6 , Figure 6 which is a specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 6 shown, if the computing power overhead of directly performing public key encryption on the HOST - side security core is large and the calculation cannot be completed or the normal function of the controller will be affected within the time required by the Fault Tolerant Time Interval (FTTI) and other requirements, the HOST - side monitoring software does not directly participate in decrypting the received encrypted data. Instead, it additionally triggers the HSM to decrypt in the periodic task, and judges whether the HSM and the data transfer link are invalid through the value after HSM decryption. Since the HOST - side monitoring software has obtained the ch and e_ch values and stored them in the ASIL area during the public key upload phase, the HSM can be triggered to decrypt the e_ch value once. If the decrypted value ch’ is consistent with ch, it is considered that the private key decryption and the data transfer link after decryption are available; otherwise, they are unavailable. Combining Figure 1 and Figure 2 's solution, after the generation and transmission of the key pair are completed, the host side will receive encrypted data (the original encrypted transmission data, which is obtained by encrypting the unencrypted actual data with the external public key, that is, the sender's public key). Estimate the first estimated host encryption time of the original encrypted transmission data. If the first estimated host encryption time is less than the preset time threshold, then Figure 5Decryption is performed in the manner shown. If the encryption time of the first estimated host is greater than or equal to the preset time threshold, a solution for improving the credibility can be adopted using the host-encrypted test data and the initial test data. Specifically, the host side, i.e., the HOST side, first obtains the initial encrypted data ch and the host-encrypted test data e_ch from the secure area (ASIL area, such as the decryption monitoring module with the decryption monitoring software set above). Then, the host-encrypted test data e_ch is sent to the HSM. The HSM decrypts the host-encrypted test data e_ch using the trust anchor private key to obtain the trust anchor decrypted transmission data ch`. The trust anchor decrypted transmission data ch` is sent back to the host. Then, the decryption monitoring module of the host will perform a first comparison between the trust anchor decrypted transmission data ch` and the above-mentioned initial encrypted data ch. If the trust anchor decrypted transmission data ch` is the same as the above-mentioned initial encrypted data ch, it indicates that the monitoring is successful, the decryption of the trust anchor private key and the data transmission link after decryption are not invalidated, and the calculation result of the trust anchor asymmetric encryption algorithm is available. Otherwise, it is determined that the monitoring fails, which to a certain extent means that the decryption of the trust anchor private key and the data transmission link after decryption are invalidated, and the calculation result of the trust anchor asymmetric encryption algorithm is unavailable.
[0112] In one embodiment, before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method includes: the decryption monitoring module receives the original encrypted transmission data and determines the first estimated host encryption time for receiving the original encrypted transmission data; if the first estimated host encryption time is less than the preset time threshold, the original encrypted transmission data is determined as the data to be decrypted and sent to the trust anchor.
[0113] Continuing with the above embodiment, if the first estimated host encryption time is greater than or equal to the preset time threshold, the host-encrypted test data is determined as the data to be decrypted and sent to the trust anchor, and the initial test data is determined as the host decryption comparison data. The host-encrypted test data is obtained by encrypting the initial test data using the host public key, where the second estimated host encryption time of the host-encrypted test data is less than the preset time threshold.
[0114] The preset time threshold can be a threshold set by those skilled in the art based on the Fault Tolerant Time Interval (FTTI), and can be greater than or equal to the Fault Tolerant Time Interval.
[0115] For example, if the currently received original encrypted transmission data is data that requires a cycle to improve the credibility of the trust anchor asymmetric encryption algorithm, at this time, first estimate the time required for the host to encrypt the unencrypted actual data corresponding to the original encrypted transmission data, and obtain the first estimated host encryption time. The estimation method can be achieved by recording the encryption time of the original encrypted transmission data, or other methods known to those skilled in the art, which are not limited herein. If the first estimated host encryption time is less than the preset time threshold, it indicates that the host can complete the re-encryption of the data decrypted by the trust anchor without affecting its own functions. At this time, the original encrypted transmission data can be determined as the data to be decrypted, the original encrypted transmission data can be used as the data to be encrypted and the host decryption comparison data, and the host's first encrypted transmission data can be used as the trust anchor decryption comparison data to implement the solution for improving the credibility of the trust anchor asymmetric encryption algorithm. In scenarios with high requirements for data processing efficiency, without waiting for the first comparison result, after obtaining the trust anchor decrypted transmission data, it can be sent to the decryption data user to improve the processing efficiency. In addition, this solution also supports directly decrypting the original encrypted transmission data by the host without passing through the trust anchor when the first estimated host encryption time is less than the preset time threshold. When the first estimated host encryption time is greater than or equal to the preset time threshold, at this time, the host cannot encrypt the data decrypted by the trust anchor, otherwise it may affect the implementation of the host's own functions. Therefore, a solution for improving the credibility by using the host encryption test data and the initial test data can be adopted for auxiliary verification, and then the original encrypted transmission data is sent to the trust anchor for decryption. For the solution with security status monitoring, as long as the controller does not enter the security state, it supports the trust anchor to continue decrypting the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decryption data user. When the controller enters the security state, the step of the trust anchor continuing to decrypt the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decryption data user is stopped. For the solution without security status monitoring, it can be that the previous monitoring fails, and the step of the trust anchor continuing to decrypt the original encrypted transmission data and sending the decrypted trust anchor decrypted transmission data to the decryption data user is stopped, or other solutions set by those skilled in the art.
[0116] In one embodiment, after obtaining the first comparison result, the method further includes: counting the number of decryption exception events where the first comparison result shows that the trust anchor decryption comparison data is different from the host decryption comparison data within a preset statistical period; if the number of decryption exception events is greater than the first preset number threshold, controlling the controller to enter the security state.
[0117] The preset statistical period can be a limitation in dimensions such as the time dimension set by those skilled in the art or the number of executions of the method for improving the credibility of the trust anchor asymmetric encryption algorithm. The first preset number threshold can be set by those skilled in the art according to needs. The entry method of the secure state can be implemented in a manner known to those skilled in the art, which will not be elaborated here. As an example, within the preset statistical period, each time a new first comparison result is generated, the current number of decryption exception events is updated once to enter the secure state in a timely manner.
[0118] In one embodiment, the method further includes a solution for pre-verifying whether the host key received by the host is available. The relevant limitations of the specific solution can refer to the Figure 8 - Figure 11 solution of the method for improving the credibility of the trust anchor asymmetric encryption algorithm shown below, which will not be elaborated here specifically.
[0119] Before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: the transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes a transmission monitoring module; the trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the second comparison result shows that the host transmission verification data is the same as the trust anchor transmission verification data, it is determined that the host key of the host is available. Among them, the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host. At this time, it shows that the host public key stored on the host side is consistent with the trust anchor public key generated by the trust anchor. It should be noted that the credibility of the transmission monitoring module is higher than that of the trust anchor.
[0120] Continuing with the above embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.
[0121] Continuing with the above embodiment, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
[0122] Continuing from the above embodiments, the method further includes: if the second comparison result indicates that the initial test data is the same as the first decrypted test data, storing the initial test data and the host encrypted test data in the transmission monitoring module.
[0123] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data based on the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the initial test data and the host encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.
[0124] Continuing from the above embodiments, the trust anchor calculates the trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data with the trust anchor public key based on the asymmetric encryption algorithm to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain the second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result indicates that the host transmission verification data is the same as the trust anchor transmission verification data, including: the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data.
[0125] Continuing from the above embodiments, the method further includes: if the second comparison result indicates that the host transmission verification data is the same as the trust anchor transmission verification data, storing the initial test data and the host encrypted test data in the transmission monitoring module.
[0126] In this way, when using the scheme of the initial test data to improve the trust anchor asymmetric encryption algorithm in the foregoing embodiments, the initial test data and the host encrypted test data pre-stored by the schemes provided in this embodiment and the previous embodiment can be used.
[0127] In one embodiment, the method further includes: the encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host. The host further includes an encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor. The encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result. Through the above method, the functional safety level of the asymmetric data encryption storage of the controller can be improved. For the relevant description of this part, reference can also be made to the description content of the following Figures 12 - 14 embodiments provided, which will not be elaborated here.
[0128] It should be noted that for the same controller, it can be both a data receiver and a data storage (sender). Figure 4 、 Figure 12 The execution order of the method described is not limited, and it depends on the application requirements of the current controller to determine its execution order, or any one of them can be selectively executed.
[0129] In the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in the above embodiment, in the solution where the trust anchor decrypts the data to be decrypted, the decryption monitoring module with higher credibility receives the trust anchor decryption verification data calculated by the trust anchor with lower credibility based on the asymmetric encryption algorithm, and determines the trust anchor decryption comparison data. The trust anchor decryption comparison data is compared with the host decryption comparison data for the first time to obtain a first comparison result. Through the above process, the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor can be monitored based on the decryption monitoring module with higher credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor and ensuring the functional safety level of the decryption result of the trust anchor for application in functional safety critical scenarios.
[0130] The above embodiment provides a solution for improving the functional safety level of the asymmetric encryption and decryption algorithm based on HSM. This solution utilizes the characteristic that the public key can be shared, improves the functional safety level of the asymmetric encryption and decryption algorithm based on HSM, and enables the asymmetric encryption and decryption information security mechanism based on HSM to replace and supplement the existing functional safety mechanism and expand its scope of use.
[0131] Optionally, before decrypting the data to be decrypted by the trust anchor, which can be during the controller software initialization phase, verify the host public key transmitted by the trust anchor to the host, and after successful verification, store the initial test data and the host-encrypted test data in the transmission monitoring module for use in the trust anchor asymmetric encryption algorithm credibility improvement scheme during the process of the trust anchor decrypting the data to be decrypted. This can further enhance the credibility of the trust anchor asymmetric encryption algorithm by pre-verifying the host public key during the controller software initialization phase to promptly detect problems.
[0132] Please refer to Figure 7 as shown in Figure 7 Another flowchart diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention, which provides a functional safety improvement scheme for asymmetric public key transmission. The method includes the following steps:
[0133] Step S710, the transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data based on the initial test data, and sends the test transmission data to the trust anchor.
[0134] Among them, the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host (reference can be made to Figure 1 scheme). One of the host transmission verification data and the test transmission data retains the initial test data itself, and the other is obtained by encrypting the initial test data with the host public key.
[0135] The initial test data can be randomly generated or generated in a manner known to those skilled in the art.
[0136] Since the public key transmission is the preparation stage for asymmetric decryption and asymmetric encryption storage, generally carried out during the software initialization stage, there are no requirements for time such as the functional safety fault tolerance time interval (FTTI). Of course, the process of public key transmission can also be implemented in other stages set by those skilled in the art. For example, Figure 7 the scheme can be applied to the controller software initialization stage or can be executed before executing the Figure 4 scheme.
[0137] Step S720, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module.
[0138] The trust anchor stores the trust anchor public key and the trust anchor private key. Based on the scenario requirements, the trust anchor public key and / or the trust anchor private key can be used to calculate the test transmission data to obtain the trust anchor transmission verification data that can support comparison subsequently.
[0139] Step S730, the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0140] By using a transmission monitoring module with a relatively high credibility to compare the data, the obtained result has a relatively high credibility, which can improve the functional safety level of the asymmetric public key transmission to a certain extent and enhance the credibility of the calculation and transmission of the asymmetric encryption algorithm.
[0141] In one embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.
[0142] Continuing the above embodiment, the trust anchor calculates the trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: the trust anchor decrypts the host encrypted test data with the trust anchor private key based on the asymmetric encryption algorithm to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
[0143] Continuing the above embodiment, after the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following: if the second comparison result shows that the first decrypted test data is the same as the initial test data, determine at least one of the following, the trust anchor private key matches and is correct with the trust anchor public key, and the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data; if the first comparison result shows that the first decrypted test data is different from the initial test data, determine that the host public key is unavailable.
[0144] Taking the trust anchor as HSM as an example, please refer to Figure 8 and Figure 9 , Figure 8 which is another specific flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. Figure 9 For Figure 8 the data transmission schematic diagram of the method shown. As Figure 8 and Figure 9As shown, the HOST-side monitoring software generates a random challenge value, encrypts it using the uploaded public key to obtain the encrypted value e_ch (encrypted challenge), and passes e_ch to the HSM. The HSM decrypts e_ch using the private key to obtain ch’ (decrypted challenge) and returns it to the HOST-side monitoring software. If there is an error in generating or transmitting the public-private key pair on the HSM side, the monitoring software of the HOST Software will diagnose it. Combining Figure 1 's solution, first, the host monitoring software (HOST Software) issues a public-private key pair generation request to the HSM Firmware through the HSM HOST Driver, triggering the HSM to generate the trust anchor public key and the trust anchor private key. Then, the trust anchor public key is fed back to the HOST Software through the HSM HOST Driver, enabling the host to obtain the host public key. At this time, due to the lack of a monitoring mechanism, the functional safety level of the HSM and the entire transmission link cannot be guaranteed. Continue to refer to Figure 8 and Figure 9 , after the transmission monitoring module of the host HOST obtains the public key generated by the HSM side, the HOST side generates a random value ch (an example of initial test data) and encrypts it using the public key (host public key) to obtain the host encrypted test data e_ch. Then, the host encrypted test data e_ch is sent by the transmission monitoring module (HOST Monitoring) to the HSM Firmware through the HSM HOST Driver. The HSM decrypts the host encrypted test data e_ch using the trust anchor private key based on the asymmetric encryption algorithm to obtain the first decrypted test data ch`. It is fed back to the HOST Monitoring through the HSM HOST Driver, enabling the HOST side to obtain the value ch` (the first decrypted test data) obtained by decrypting e_ch with the private key on the HSM side. Then, the transmission monitoring module checks whether the random value ch is the same as the first decrypted test data ch`. If so, the monitoring passes, the trust anchor public key and the trust anchor private key (that is, the public-private key pair in Figure 8 ) match and are correct, and the public key, the random value ch, and the host encrypted test data e_ch are stored in the ASIL area (such as the transmission monitoring module, etc.). Then the HOST monitoring ends.
[0145] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data using the host public key to obtain the host encrypted test data; determines the initial test data and the host encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.
[0146] Continuing with the above embodiments, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data.
[0147] Continuing with the above embodiments, after the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following:
[0148] If the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, and the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data;
[0149] If the initial test data is different from the second decrypted test data, determine that the trust anchor public key does not match the trust anchor private key;
[0150] If the host encrypted test data is different from the trust anchor first encrypted test data, determine that the host public key is different from the trust anchor public key and the host public key is not available.
[0151] Continuing with the above embodiments, after obtaining the second comparison result, the method includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, send the host public key to the data sender for the data sender to receive the host public key as the sender public key, and encrypt the unencrypted actual data using the sender public key to obtain the original encrypted transmission data. At this time, it shows that the host public key is available and can be sent out, avoiding problems with the public key sent out due to issues such as the trust anchor algorithm problem or transmission problem of the controller, which may cause failures.
[0152] Taking the trust anchor as the HSM as an example, please refer to Figure 10 and Figure 11 , Figure 10 which is another specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiments of the present invention. Figure 11 For Figure 10 the data transmission schematic diagram of the method shown. As Figure 10 and Figure 11As shown, the HOST - side monitoring software generates a random challenge value and directly sends it to the HSM. At the same time, the HOST - side encrypts the ch (challenge) with the public key to obtain e_ch (encrypted challenge). The HSM encrypts the challenge value with the public key to obtain e_ch’ (decrypted challenge), and decrypts e_ch’ with the private key to obtain ch’. The HSM also returns e_ch’ and ch’ to the HOST - side monitoring software. If there is an error in generating or transmitting the public - private key pair on the HSM side, the monitoring software on the HOST side can diagnose it and be detected by subsequent monitoring. Moreover, this scheme can distinguish whether the failure is caused by an incorrect upload of the public key or a mismatch between the public and private keys. Combining Figure 1 with the scheme, first, the host monitoring software (HOSTSoftware) sends a public - private key pair generation request to the HSM Firmware through the HSM HOST Driver, triggering the HSM to generate a trust - anchor public key and a trust - anchor private key. Then, the trust - anchor public key is fed back to the HOSTSoftware through the HSM HOST Driver, enabling the host to obtain the host public key. At this time, due to the lack of a monitoring mechanism, the functional safety level of the HSM and the entire transmission link cannot be guaranteed. Continue to refer to Figure 10 and Figure 11 , after the transmission monitoring module (HOST Monitoring) of the host HOST obtains the public key generated by the HSM side, the HOST - side (HOST Monitoring) generates a random value ch (an example of initial test data) and encrypts it with the public key (host public key) to obtain the host - encrypted test data e_ch. The random value ch is sent to the HSM Firmware through the HSM HOSTDriver for transmission to the HSM. The HSM encrypts the random value ch with the trust - anchor public key based on the asymmetric encryption algorithm to obtain the trust - anchor first - encrypted test data e_ch`. Then, the trust - anchor first - encrypted test data e_ch` is decrypted with the trust - anchor private key based on the asymmetric encryption algorithm to obtain the second - decrypted test data ch`. The first - encrypted test data e_ch` and the second - decrypted test data ch` are fed back to the HOSTMonitoring through the HSM HOST Driver, enabling the HOST - side to obtain the value of the encryption of ch with the public key by the HSM side, that is, the trust - anchor first - encrypted test data e_ch` and the second - decrypted test data ch`. The transmission monitoring module compares the random value ch with the second - decrypted test data ch`. If they are different (no), the monitoring fails. The trust - anchor public key and the trust - anchor private key on the HSM side (that is, Figure 10If the public and private keys (in Figure 10 the public and private keys) do not match, if they are the same (yes), the monitoring is successful. Compare the host encrypted test data e_ch with the trusted anchor first encrypted test data e_ch`. If they are the same, the monitoring passes. The public key of the trusted anchor at the HSM end matches the private key of the trusted anchor (i.e.,
[0153] the public and private keys in). Store the public key, random value ch, and host encrypted test data e_ch in the ASIL area (such as the transmission monitoring module, etc.). Then the HOST monitoring ends. If they are different, the monitoring fails, indicating that the public key at the HOST end is different from the one at the HSM end.
[0154] Through the above method, not only can we know whether the calculation and transmission link of the asymmetric encryption algorithm at the trusted anchor end are trustworthy, but also we can know specifically which part has problems, which is convenient for subsequent fault handling.
[0155] The method for improving the credibility of the asymmetric encryption algorithm of the trusted anchor provided by the above embodiment, in the public key transmission stage, obtains the initial test data through a transmission monitoring module with relatively high credibility, encrypts the initial test data based on the host public key to obtain the host transmission verification data or test transmission data, then sends the test transmission data to the trusted anchor, and the trusted anchor with relatively low credibility calculates the trusted anchor transmission verification data based on the asymmetric encryption algorithm. Then, the transmission monitoring module makes a second comparison between the host transmission verification data and the trusted anchor transmission verification data to obtain the second comparison result. Through the above process, it is possible to monitor the calculation and public key transmission process of the asymmetric encryption algorithm of the trusted anchor based on the transmission monitoring module with relatively high credibility, thereby improving the credibility of the calculation and transmission process of the asymmetric encryption algorithm of the trusted anchor, ensuring the functional safety level of the host public key, and applying the host public key to functional safety critical scenarios.
[0156] The execution of this method can also be in the controller software initialization phase, etc. Before the trust anchor starts to perform real encryption and decryption tasks, verify the host public key transmitted by the trust anchor to the host, and after the verification passes, store the initial test data and the host-encrypted test data in the transmission monitoring module for the trust anchor to use in the trust anchor asymmetric encryption algorithm credibility improvement scheme for decrypting the data to be decrypted. This can further improve the credibility of the trust anchor asymmetric encryption algorithm, verify the host public key in advance in the controller software initialization phase, and discover problems in a timely manner. Of course, the execution of this method can also be set at other times according to the needs of those skilled in the art, such as during the process of the trust anchor performing real encryption and decryption tasks. Here, the controller software initialization phase is only an example and not a limitation on the execution time of this method.
[0157] Please refer to Figure 12 as shown in Figure 12 FIG. 7 is another flowchart of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention, providing a functional safety improvement scheme for asymmetric data encryption storage. The method includes the following steps:
[0158] Step S1210, the encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data.
[0159] Among them, the host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key, and the trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0160] Step S1220, the encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0161] The data to be encrypted can be sent by other controllers to the current controller, or can be local data of the controller, or data set by those skilled in the art.
[0162] The method for obtaining the host public key can refer to Figure 1 the provided solution and the relevant description of the foregoing embodiment, which will not be elaborated here. Figure 4 、 Figure 7 and Figure 12 The provided solutions can be executed by one controller, or can be executed by different controllers respectively, or a certain controller can select Figure 4 、 Figure 7 and Figure 12 Two of the provided solutions to execute are also possible. The specific combination methods will not be elaborated.
[0163] In one embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: the host obtains initial actual data; determines the expected host encryption time of the initial actual data; if the expected host encryption time is less than a preset time threshold, determines the initial actual data as the data to be encrypted; if the expected host encryption time is greater than or equal to the preset time threshold, determines the initial test data as the data to be encrypted, determines the host encryption test data as the host encryption verification data, the expected host encryption time of the initial test data is less than the preset time threshold, and the host encryption test data is obtained by encrypting the initial test data with the host public key. It should be noted that the preset time threshold in this embodiment and the preset time threshold in the decryption stage may be the same or different. The expected host encryption time is the expected time-consuming for the host to encrypt the initial actual data, which can be determined by pre-calibration or other methods known to those skilled in the art.
[0164] Of course, if the expected host encryption time is less than the preset time threshold, it is also possible to select to determine the initial test data as the data to be encrypted and determine the host encryption test data as the host encryption verification data to execute this solution, running as a timed periodic task. Compared with the solution of executing this method only when there is initial actual data, the method of using the initial test data to execute the timed task can avoid the problem that the encryption task cannot find the trust anchor encryption failure in time due to the lack of initial actual data for a long time (similar to the decryption solution, they can be mutually reflected and will not be elaborated).
[0165] If the computing overhead of directly performing public key encryption on the HOST - side security core is small, and the calculation can be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) without affecting the normal function of the controller, then public key encryption can be directly performed on the HOST - side. That is, as mentioned in the above - mentioned embodiment, the host public key can also be directly used for encryption on the HOST - side. However, the computing speed of the HSM - side (trust anchor) is relatively faster. In a scenario where efficiency is prioritized, the solution of using the public key of the HSM for encryption is more advantageous. Reference can be made to the relevant description in the decryption stage of the above - mentioned embodiment. An example way is that after the trust anchor obtains the trust - anchor - encrypted transmission data, as long as the controller has not entered the secure state, the trust - anchor - encrypted transmission data is stored or sent to the data user. When the controller enters the secure state, the action of storing or sending the trust - anchor - encrypted transmission data to the data user is stopped. Another example way is that after the trust anchor obtains the trust - anchor - encrypted transmission data, it performs the steps of storage and sending to the data user. Subsequently, after obtaining the third comparison result, if it is proved that the trust - anchor - encrypted transmission data is untrustworthy (not storable), at this time, a data exception reminder message can be generated and sent to the corresponding storage - space control party or data user to discard the trust - anchor - encrypted transmission data or the result obtained from the trust - anchor - encrypted transmission data. Since the situation of controller exception is a minority case, by adopting such a method, the data transmission and processing efficiency can be effectively improved.
[0166] In one embodiment, if the initial actual data is determined as the data to be encrypted, the method includes: the encryption monitoring module obtains the host encryption verification data, including that the encryption monitoring module encrypts the initial actual data through the host public key to obtain the host second encrypted transmission data, and takes the host second encrypted transmission data as the host encryption verification data; the encryption monitoring module obtains the trust - anchor encryption verification data, including that the trust anchor encrypts the initial actual data through the trust - anchor public key based on the asymmetric encryption algorithm to obtain the trust - anchor encrypted transmission data, and sends the trust - anchor encrypted transmission data to the encryption monitoring module, so that the encryption monitoring module takes the received trust - anchor encrypted transmission data as the trust - anchor encryption verification data.
[0167] Continuing from the above - mentioned embodiment, after obtaining the third comparison result, the method further includes at least one of the following: if the third comparison result is that the host second encrypted transmission data is the same as the trust - anchor encrypted transmission data, determine at least one of the following: the trust - anchor encrypted transmission data is storable, the asymmetric encryption algorithm of the trust anchor is trustworthy (encryption part), the data transmission link between the trust anchor and the encryption monitoring module is trustworthy; if the third comparison result is that the host second encrypted transmission data is different from the trust - anchor encrypted transmission data, determine that the trust - anchor encrypted transmission data is not storable.
[0168] In one embodiment, if the trusted anchor encrypted transmission data can be stored, the method further includes storing the trusted anchor encrypted transmission data.
[0169] In the above solution, only the initial actual data can be used to generate the third comparison result. Once there is no encryption requirement for the initial actual data for a long time, the state of the controller is blank. To avoid this problem, the method may further include: the encryption monitoring module sends new initial test data; the trusted anchor receives the new initial test data sent by the encryption monitoring module, encrypts the new initial test data based on the asymmetric encryption algorithm using the trusted anchor public key to obtain new trusted anchor second encrypted test data, and feeds it back to the encryption monitoring module, so that the encryption monitoring module uses the received new trusted anchor second encrypted test data as the trusted anchor encryption verification data; the encryption monitoring module uses the new host encryption verification data of the new initial test data as the new host encryption verification data, and compares the new host encryption verification data with the new trusted anchor encryption verification data to obtain a new third comparison result. It should be noted that this process and Figure 12 's solution can be parallel or either party executes first, which is not limited here. The solution provided in this embodiment can be periodically executed using a periodic task, or can be executed according to certain trigger conditions, which can be specifically set by those skilled in the art according to needs. It should be noted that the above description of "new" does not limit that the initial test data in this process is different from the initial test in the previous process. The two can be the same, and are only used to distinguish the relevant data obtained in different processes.
[0170] As an example, taking the trusted anchor as an HSM, please refer to Figure 13 , Figure 13 is another specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trusted anchor provided by the embodiment of the present invention. As shown in Figure 13 , since the HOST-side monitoring software has obtained the public key and stored it in the ASIL area (such as the encryption monitoring module) during the public key upload phase, the encrypted data can be judged whether it is available by encrypting the original data (initial actual data) with the public key again. If the data encrypted by the HOST-side public key is the same as the data to be encrypted and stored (the host second encrypted transmission data is the same as the trusted anchor encrypted transmission data), it is considered that the data encrypted by the HSM (trusted anchor encrypted transmission data) is available, otherwise it is not available. Continue to refer to Figure 10 , combined with Figure 1 's example, the host pre-stores the host public key. The HOST side obtains the public key (host public key) from the ASIL area such as the encryption monitoring module, and then encrypts the initial actual data with the host public key to obtain the host second encrypted transmission data. Combined with Figure 3In an example, the host sends the initial actual data to the trust anchor. The trust anchor encrypts the initial actual data using the trust anchor public key to obtain the trust anchor encrypted transmission data and sends it back to the host. Subsequently, the encryption monitoring module determines whether the data encrypted by the public key is the same as the data encrypted by the HSM, that is, determines whether the second encrypted transmission data of the host is the same as the trust anchor encrypted transmission data. If so, the monitoring passes and the encrypted data (trust anchor encrypted transmission data) can be stored. If not, the monitoring fails and the encrypted data cannot be stored.
[0171] In another embodiment, if the initial test data is determined as the data to be encrypted and the host encrypted test data is determined as the host encrypted verification data, the encryption monitoring module obtaining the trust anchor encrypted verification data includes: the trust anchor receiving the initial test data sent by the encryption monitoring module, encrypting the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor second encrypted test data, and feeding it back to the encryption monitoring module, so that the encryption monitoring module uses the received trust anchor second encrypted test data as the trust anchor encrypted verification data.
[0172] Continuing from the above embodiment, after obtaining the third comparison result, the method further includes at least one of the following: if the third comparison result is that the trust anchor second encrypted test data is the same as the host encrypted test data, determine at least one of the following, the asymmetric encryption algorithm of the trust anchor is trustworthy, the data transmission link between the trust anchor and the encryption monitoring module is trustworthy; if the third comparison result is that the trust anchor second encrypted test data is different from the host encrypted test data, determine at least one of the following, the asymmetric encryption algorithm of the trust anchor is not trustworthy, the data transmission link between the trust anchor and the encryption monitoring module is not trustworthy.
[0173] In an embodiment, after obtaining the third comparison result, the method further includes: counting the number of encryption exception events where the third comparison result is that the host encrypted verification data is different from the trust anchor encrypted verification data within a preset statistical period; if the number of encryption exception events is greater than the second preset number threshold, control the controller to enter the safe state. It should be noted that when the controller has both an encryption scheme and a decryption scheme, it can also be to adjust the first preset number threshold or the second preset number threshold according to the number of encryption exception events and the number of decryption exception events, so as to achieve that whether it is the number of encryption exception events or the number of decryption exception events is regarded as one exception, and when the total number of encryption exception events and decryption exception events is greater than a certain threshold, the controller also enters the abnormal state.
[0174] If the computing overhead of directly performing public key encryption on the HOST-side security core is relatively large and the calculation cannot be completed within the time required by requirements such as the Fault Tolerant Time Interval (FTTI) of functional safety fault tolerance or it will affect the normal function of the controller, the HOST-side monitoring software does not directly participate in the encryption of the original data. Instead, it additionally triggers HSM encryption in periodic tasks, and determines whether the HSM and the data transfer link are invalid based on the value encrypted by the HSM.
[0175] As an example, taking the trust anchor as the HSM, please refer to Figure 14 , Figure 14 which is another specific process schematic diagram of the method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided by the embodiment of the present invention. As Figure 14 shown, since the HOST-side monitoring software has obtained the public key and stored it in the ASIL area (such as the encryption monitoring module) during the public key upload phase, and the initial test data and the host encryption verification data corresponding to the initial test data are pre-stored (which can be obtained based on the Figure 7 scheme shown, or can be obtained by other means). As Figure 14 shown, since the HOST-side monitoring software has obtained the ch and e_ch values and stored them in the ASIL area during the public key upload phase, the HSM can be triggered to encrypt the ch value once. If the encrypted value e_ch' is consistent with e_ch, it is considered that the public key decryption and the encrypted data transfer link are available; otherwise, they are unavailable. Continuing to refer to Figure 14 , after the HOST monitoring starts, the HOST-side obtains the initial test data ch and the host encryption verification data e_ch corresponding to the initial test data from the ASIL area (such as the encryption monitoring module), transfers the initial test data ch to the HSM, and then the HSM encrypts the initial test data ch with the trust anchor public key to obtain the trust anchor second encrypted test data e_ch`, and sends it back to the host. The encryption monitoring module determines whether the host encryption verification data e_ch is consistent with the trust anchor second encrypted test data e_ch`. If so, the monitoring passes and there is no failure in the HSM public key (trust anchor public key) encryption and the encrypted data (trust anchor second encrypted test data) transfer link. If not, the monitoring fails and the HSM public key encryption and the encrypted data transfer link fail. The HOST monitoring ends.
[0176] In an embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method further includes performing one or more embodiments of the method for improving the credibility of the trust anchor asymmetric encryption algorithm provided by Figure 7 . For the specific description and implementation manner, reference can be made to the description of the above embodiments, which will not be elaborated here.
[0177] In one embodiment, before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, the method includes: the transmission monitoring module obtains initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host further includes a transmission monitoring module, and the host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key; the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feeds it back to the transmission monitoring module; the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key of the host is available.
[0178] Continuing with the above embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the host encrypted test data as the test transmission data; and determines the initial test data as the host transmission verification data.
[0179] Continuing with the above embodiment, the trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: the trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
[0180] Continuing with the above embodiment, the method further includes: if the second comparison result is that the initial test data and the first decrypted test data are the same, storing the initial test data and the host encrypted test data in the transmission monitoring module.
[0181] In another embodiment, the transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: the transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; determines the initial test data and the host encrypted test data as the host transmission verification data; and determines the initial test data as the test transmission data.
[0182] Continuing with the above embodiments, the trust anchor calculates trust anchor transmission verification data for the test transmission data based on an asymmetric encryption algorithm, including: the trust anchor encrypts the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; at this time, the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, including: the initial test data and the second decrypted test data are the same, and the host encrypted test data and the trust anchor first encrypted test data are the same.
[0183] Continuing with the above embodiments, the method further includes: if the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, storing the initial test data and the host encrypted test data in the transmission monitoring module.
[0184] The method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in the above embodiments, in the scheme where the trust anchor encrypts the data to be decrypted, obtains the host encryption verification data through the encryption monitoring module with higher credibility and receives the trust anchor encryption verification data calculated by the trust anchor with lower credibility based on the asymmetric encryption algorithm, compares the trust anchor encryption verification data with the host encryption verification data to obtain the third comparison result. Through the above process, it is possible to monitor the calculation and transmission process of the asymmetric encryption algorithm of the trust anchor based on the encryption monitoring module with higher credibility, thereby improving the credibility of the asymmetric encryption algorithm of the trust anchor, ensuring the functional safety level of the encryption result of the trust anchor, and applying it to functional safety critical scenarios.
[0185] In one embodiment, a controller is provided, and this controller is used to implement the above Figure 4 shown method for improving the credibility of the asymmetric encryption algorithm of the trust anchor. Please refer to Figure 15 , Figure 15 which is a schematic structural diagram of the controller provided in the embodiments of the present invention. As Figure 15 shown, the controller 1500 includes a trust anchor 1510 and a host 1520. The host 1520 includes a decryption monitoring module 1521, and the credibility of the decryption monitoring module 1521 is higher than that of the trust anchor 1510. The detailed description of each functional module is as follows:
[0186] The decryption monitoring module 1521 is used to receive the trust anchor decryption verification data sent by the trust anchor 1510, and the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm;
[0187] The decryption monitoring module 1521 is further configured to determine trust anchor decryption comparison data according to the trust anchor decrypted verification data, and perform a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
[0188] In one embodiment, the host further includes a trust anchor driver function module, which is configured to receive the data to be decrypted sent by the decryption monitoring module and send it to the trust anchor, and receive the trust anchor decrypted verification data fed back by the trust anchor and send it to the host.
[0189] In one embodiment, the decryption monitoring module may be disposed in the trust anchor driver function module.
[0190] In one embodiment, the host further includes a mode switching module, which is configured to enable the decryption monitoring module to receive the original encrypted transmission data and determine a first estimated host encryption time for receiving the original encrypted transmission data; if the first estimated host encryption time is less than a preset time threshold, determine the original encrypted transmission data as the data to be decrypted and send it to the trust anchor, or decrypt the original encrypted transmission data through the decryption monitoring module. If the first estimated host encryption time is greater than or equal to the preset time threshold, determine the host encryption test data as the data to be decrypted and send it to the trust anchor, and determine the initial test data as the host decryption comparison data, where the host encryption test data is obtained by encrypting the initial test data with the host public key, and the second estimated host encryption time of the host encryption test data is less than the preset time threshold.
[0191] In one embodiment, the encryption monitoring module is disposed in the security core of the host, and the security core includes a hardware acceleration unit or at least one locked-step module.
[0192] In one embodiment, the controller further includes a statistics module, which is configured to count the number of decryption exception events where the first comparison result is that the trust anchor decryption comparison data is different from the host decryption comparison data within a preset statistical period; if the number of decryption exception events is greater than a first preset number threshold, control the controller to enter a secure state.
[0193] For the specific limitations of the controller, reference may be made to the limitations on the method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor in the electronic device in hardware form or be independent of it, or be stored in the memory in the electronic device in software form, so as to facilitate the processor to call and execute the operations corresponding to the above modules. Figure 4 In this embodiment, the controller essentially sets multiple modules to execute any one of the above embodiments
[0194] In this embodiment, the controller essentially sets multiple modules to execute any one of the above embodiments Figure 4The method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor, for the specific functions and technical effects, please refer to the above embodiments, which will not be elaborated here.
[0195] In one embodiment, a controller is provided, which is used to implement the above Figure 7 The method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in any one of the corresponding embodiments. Please refer to Figure 13 , Figure 16 Another structural schematic diagram of the controller provided by the embodiment of the present invention is shown in Figure 16 As shown, the controller 1600 includes a trust anchor 1610 and a host 1620. The host 1620 includes a transmission monitoring module 1616, and the credibility of the transmission monitoring module 1616 is higher than that of the trust anchor 1610. The detailed description of each functional module is as follows:
[0196] The transmission monitoring module 1616 is used to obtain initial test data, determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor 1610. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor 1610 received by the host;
[0197] The trust anchor 1610 is used to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feedback it to the transmission monitoring module 1616;
[0198] The transmission monitoring module 1616 is further used to make a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0199] In one embodiment, Figure 16 The host and the trust anchor in Figure 15 are similar in structure to the host and the trust anchor in the controller in
[0200] They can be the same structure or similar structures in different controllers. Figure 7 For the specific limitations of the controller, please refer to the limitations of the method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor in the above text, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0201] In this embodiment, the controller essentially sets multiple modules to execute any one of the above embodiments Figure 7The method for improving the credibility of the asymmetric encryption algorithm of the corresponding trust anchor, the specific functions and technical effects can be referred to the above embodiments, and will not be elaborated here.
[0202] In one embodiment, a controller is further provided. The host of the controller includes the transmission monitoring module and the decryption monitoring module provided in the above embodiments. The relevant descriptions can be referred to the above embodiments and will not be elaborated here.
[0203] In one embodiment, a controller is provided, which is used to implement the Figure 12 method for improving the credibility of the asymmetric encryption algorithm of the trust anchor provided in any one of the corresponding embodiments above. Please refer to Figure 17 , Figure 17 which is another structural schematic diagram of the controller provided in the embodiment of the present invention. As Figure 17 shown, the controller 1700 includes a trust anchor 1710 and a host 1720. The host 1720 includes an encryption monitoring module 1712, and the credibility of the transmission monitoring module 1712 is higher than that of the trust anchor 1710. The detailed description of each functional module is as follows:
[0204] The encryption monitoring module 1712 is used to obtain the host encryption verification data and the trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module 1712 encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor 1710 encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor 1710 received by the host;
[0205] The encryption monitoring module 1712 is further used to perform a third comparison on the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0206] In one embodiment, Figure 17 the host and the trust anchor in Figure 15 , Figure 16 are similar in structure to the host and the trust anchor in the controller in
[0207] In an embodiment of the present invention, the controller further includes an early warning module, which is used to, after obtaining the third comparison result, count the number of encryption exception events where the third comparison result is that the host encryption verification data is different from the trust anchor encryption verification data within a preset statistical period; if the number of encryption exception events is greater than the second preset number threshold, control the controller to enter a safe state.
[0208] In an embodiment of the present invention, the controller further includes a transmission monitoring module. The transmission monitoring module is configured to obtain initial test data before the encryption monitoring module obtains the host encryption verification data and the trust anchor encryption verification data, determine the host transmission verification data and the test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key. The credibility of the transmission monitoring module is higher than that of the trust anchor. The trust anchor is further configured to calculate the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feedback it to the transmission monitoring module. The transmission monitoring module is further configured to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result. If the second comparison result shows that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key of the host is available.
[0209] For the specific limitations of the controller, reference can be made to the limitations on the Figure 12 corresponding method for improving the credibility of the asymmetric encryption algorithm of the trust anchor described above, which will not be elaborated here. Each module in the above controller can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the electronic device in hardware form or independent of it, or stored in the memory of the electronic device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0210] In this embodiment, the controller essentially sets up multiple modules to execute the Figure 12 corresponding method for improving the credibility of the asymmetric encryption algorithm of the trust anchor in any of the above embodiments. The specific functions and technical effects can be referred to the above embodiments, and will not be elaborated here.
[0211] In one embodiment, an electronic device is provided. The electronic device can be a server, and its internal structure diagram can be as Figure 18 shown. The electronic device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the server side of a method for improving the credibility of the asymmetric encryption algorithm of the trust anchor.
[0212] In one embodiment, an electronic device is provided. The electronic device can be a client, and its internal structure diagram can be as Figure 19As shown in the figure. The electronic device includes a processor, a memory, a network interface, a display screen, and an input device connected by a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the electronic device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it realizes the functions or steps on the client side of a method for improving the credibility of a trust anchor asymmetric encryption algorithm.
[0213] In one embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0214] Control the transmission monitoring module to obtain initial test data, and determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0215] Control the trust anchor to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feedback it to the transmission monitoring module.
[0216] Control the transmission monitoring module to perform a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0217] In another embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0218] Control the decryption monitoring module to receive the trust anchor decryption verification data sent by the trust anchor. The trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm.
[0219] Control the decryption monitoring module to determine trust anchor decryption comparison data according to the trust anchor decryption verification data, and perform a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
[0220] In another embodiment, an electronic device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0221] The control encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host through the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0222] The control encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0223] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0224] The control transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data through the host public key. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0225] The control trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module.
[0226] The control transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
[0227] In another embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0228] The control decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor. The trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm.
[0229] The control decryption monitoring module determines trust anchor decryption comparison data according to the trust anchor decryption verification data, makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
[0230] In another embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0231] The control encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted with the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host with the trust anchor public key based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host.
[0232] The control encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
[0233] It should be noted that for the functions or steps that the above computer-readable storage medium or electronic device can achieve, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described in detail here.
[0234] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The above computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to the memory, storage, database or other media used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0235] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the above division of each functional unit and module is used as an example. In practical applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the above device, system, and controller can be divided into different functional units or modules to complete all or part of the functions described above.
[0236] The embodiments provided above are only used to illustrate the technical solutions of the present invention, rather than to limit it; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for improving the credibility of a trust anchor asymmetric encryption algorithm, characterized in that, Applied to a controller, the controller includes a trust anchor and a host, the host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor. The method includes: The decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, and the trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on an asymmetric encryption algorithm; The decryption monitoring module determines trust anchor decryption comparison data according to the trust anchor decryption verification data, and makes a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
2. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 1, wherein, Before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: The decryption monitoring module receives the original encrypted transmission data and sends it to the trust anchor. The data to be decrypted includes the original encrypted transmission data, and the original encrypted transmission data is encrypted based on the public key of the data sender of the data sending end for the unencrypted actual data. The data sending end uses the trust anchor public key generated by the trust anchor received as the public key of the data sender; The trust anchor decrypts the original encrypted transmission data based on the asymmetric encryption algorithm using the trust anchor private key to obtain trust anchor decrypted transmission data, uses the trust anchor decrypted transmission data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
3. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 2, wherein The decryption monitoring module determining trust anchor decryption comparison data according to the trust anchor decryption verification data includes: The decryption monitoring module encrypts the trust anchor decrypted transmission data through the host public key to obtain host first encrypted transmission data, and uses the host first encrypted transmission data as the trust anchor decryption comparison data. The host public key is the trust anchor public key sent by the trust anchor received by the host.
4. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 3, wherein After making a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: If the first comparison result is that the host first encrypted transmission data is the same as the original encrypted transmission data, determine at least one of the following: the trust anchor decrypted transmission data is available, the asymmetric encryption algorithm is trustworthy, and the data transmission link between the trust anchor and the decryption monitoring module is trustworthy; If the first comparison result is that the host first encrypted transmission data is different from the original encrypted transmission data, determine that the trust anchor decrypted transmission data is unavailable; Wherein, the host decryption comparison data includes the original encrypted transmission data.
5. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 3, wherein After the trust anchor decrypts the original encrypted transmission data based on the asymmetric encryption algorithm using the trust anchor private key to obtain trust anchor decrypted transmission data, the method further includes: Sending the trust anchor decrypted transmission data to the decryption data usage object.
6. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 5, characterized in that, After making a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes: If the first comparison result indicates that the first encrypted transmission data of the host is different from the original encrypted transmission data, a data unavailable message is generated and sent to the decryption data usage object.
7. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 2, wherein Before the decryption monitoring module receives the original encrypted transmission data, the method includes: The encryption monitoring module of the data sender receives the trust anchor public key sent by the controller, uses the trust anchor public key as the sender public key, encrypts the unencrypted actual data with the sender public key to obtain the original encrypted transmission data, and sends the original encrypted transmission data to the decryption monitoring module.
8. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 1, wherein, Before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: The decryption monitoring module obtains host encrypted test data, and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decryption test data, uses the third decryption test data as the trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs.
9. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 3, wherein The method further includes: The decryption monitoring module obtains host encrypted test data, and sends the host encrypted test data to the trust anchor. The host encrypted test data is obtained by encrypting initial test data with the host public key. The data to be decrypted includes the host encrypted test data, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the third decryption test data, uses the third decryption test data as the new trust anchor decryption verification data, and sends it to the decryption monitoring module. The trust anchor private key and the trust anchor public key are a pair of key pairs. The decryption monitoring module uses the new trust anchor decryption verification data as the new trust anchor decryption comparison data, and makes a first comparison between the new trust anchor decryption comparison data and the new host decryption comparison data to obtain a first comparison result. The new host decryption comparison data is the initial test data.
10. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 8 or 9, characterized in that, After making a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result, the method further includes at least one of the following: If the first comparison result indicates that the third decryption test data is the same as the initial test data, determine at least one of the following: the asymmetric encryption algorithm is trustworthy, the data transmission link between the trust anchor and the decryption monitoring module is trustworthy. If the first comparison result indicates that the third decryption test data is different from the initial test data, determine at least one of the following: the asymmetric encryption algorithm is untrustworthy, the data transmission link between the trust anchor and the decryption monitoring module is untrustworthy. Among them, the host decryption comparison data includes the initial test data, and the trust anchor decryption comparison data includes the third decryption test data.
11. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 1-9, characterized in that, After obtaining the first comparison result, the method further includes: Counting the number of decryption anomaly events where the first comparison result is that the trust anchor decryption comparison data is different from the host decryption comparison data within a preset statistical period; If the number of decryption anomaly events is greater than a first preset number threshold, controlling the controller to enter a safe state.
12. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 1-9, characterized in that, Before the decryption monitoring module receives the trust anchor decryption verification data sent by the trust anchor, the method further includes: The transmission monitoring module obtains the initial test data, determines the host transmission verification data and the test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host also includes the transmission monitoring module. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key. The host public key is the trust anchor public key sent by the trust anchor received by the host, and the credibility of the transmission monitoring module is higher than that of the trust anchor; The trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data and feeds it back to the transmission monitoring module; The transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result; If the second comparison result is that the host transmission verification data and the trust anchor transmission verification data are the same, it is determined that the host public key of the host is available.
13. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 12, wherein The transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; Determining the host encrypted test data as the test transmission data; Determining the initial test data as the host transmission verification data.
14. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 13, characterized in that, The trust anchor calculates the trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: The trust anchor decrypts the host encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain the first decryption test data, and determines the first decryption test data as the trust anchor transmission verification data.
15. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 14, characterized in that, The method further includes: If the second comparison result is that the initial test data and the first decryption test data are the same, storing the initial test data and the host encrypted test data in the transmission monitoring module.
16. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 12, wherein The transmission monitoring module determines the host transmission verification data and the test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain the host encrypted test data; Determining the initial test data and the host encrypted test data as the host transmission verification data; Determining the initial test data as the test transmission data.
17. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 16, wherein The trust anchor calculates trust anchor transmission verification data for the test transmission data based on the asymmetric encryption algorithm, including: The trust anchor encrypts the initial test data based on the asymmetric encryption algorithm through the trust anchor public key to obtain trust anchor first encrypted test data, and decrypts the trust anchor first encrypted test data based on the asymmetric encryption algorithm through the trust anchor private key to obtain second decrypted test data, and determines the second decrypted test data and the trust anchor first encrypted test data as the trust anchor transmission verification data; At this time, the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, including: the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor first encrypted test data.
18. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 17, characterized in that, The method further includes: If the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, store the initial test data and the host encrypted test data in the transmission monitoring module.
19. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 1-9, characterized in that, The method further includes: The encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host based on the asymmetric encryption algorithm through the trust anchor public key. The host public key is the trust anchor public key sent by the trust anchor received by the host. The host further includes the encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor; The encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
20. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 12, wherein The method further includes: The encryption monitoring module obtains host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by the encryption monitoring module encrypting the data to be encrypted through the host public key. The trust anchor encryption verification data is obtained by the trust anchor encrypting the data to be encrypted sent by the host based on the asymmetric encryption algorithm through the trust anchor public key. The host public key is the trust anchor public key sent by the trust anchor received by the host. The host further includes the encryption monitoring module, and the credibility of the encryption monitoring module is higher than that of the trust anchor; The encryption monitoring module makes a third comparison between the host encryption verification data and the trust anchor encryption verification data to obtain a third comparison result.
21. A method for improving the credibility of a trust anchor asymmetric encryption algorithm, characterized in that Applied to a controller, the controller includes a trust anchor and a host, the host includes a transmission monitoring module, and the credibility of the transmission monitoring module is higher than that of the trust anchor. The method includes: The transmission monitoring module obtains initial test data, determines host transmission verification data and test transmission data according to the initial test data, and sends the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host; The trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feeds it back to the transmission monitoring module; The transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
22. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 21, wherein, The transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; Determine the host-encrypted test data as the test transmission data; Determine the initial test data as the host transmission verification data.
23. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 22, wherein The trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: The trust anchor decrypts the host-encrypted test data based on the asymmetric encryption algorithm with the trust anchor private key to obtain first decrypted test data, and determines the first decrypted test data as the trust anchor transmission verification data.
24. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 23, wherein After the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following: If the second comparison result is that the first decrypted test data is the same as the initial test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host-encrypted test data; If the first comparison result is that the first decrypted test data is different from the initial test data, determine that the host public key is unavailable.
25. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 21, characterized in that The transmission monitoring module determines host transmission verification data and test transmission data according to the initial test data, including: The transmission monitoring module encrypts the initial test data with the host public key to obtain host-encrypted test data; Determine the initial test data and the host-encrypted test data as the host transmission verification data; Determine the initial test data as the test transmission data.
26. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 25, characterized in that, The trust anchor calculates trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, including: The trust anchor encrypts the initial test data based on the asymmetric encryption algorithm using the trust anchor public key to obtain the trust anchor's first encrypted test data, and decrypts the trust anchor's first encrypted test data based on the asymmetric encryption algorithm using the trust anchor private key to obtain the second decrypted test data. The second decrypted test data and the trust anchor's first encrypted test data are determined as the trust anchor transmission verification data.
27. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to claim 26, wherein After the transmission monitoring module makes a second comparison between the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result, the method further includes at least one of the following: If the initial test data is the same as the second decrypted test data, and the host encrypted test data is the same as the trust anchor's first encrypted test data, determine at least one of the following: the trust anchor private key matches and is correct with the trust anchor public key, the host public key is available, and trigger the transmission monitoring module to store the host public key, the initial test data, and the host encrypted test data; If the initial test data is different from the second decrypted test data, determine that the trust anchor public key does not match the trust anchor private key; If the host encrypted test data is different from the trust anchor's first encrypted test data, determine that the host public key is different from the trust anchor public key and the host public key is not available.
28. The method for improving the credibility of the trust anchor asymmetric encryption algorithm according to any one of claims 21-27, characterized in that, After obtaining the second comparison result, the method includes: If the second comparison result is that the host transmission verification data is the same as the trust anchor transmission verification data, send the host public key to the data sender, so that the data sender receives the host public key as the sender public key and encrypts the unencrypted actual data using the sender public key to obtain the original encrypted transmission data.
29. A controller, characterized in that, The controller includes a trust anchor and a host. The host includes a decryption monitoring module, and the credibility of the decryption monitoring module is higher than that of the trust anchor, where: The decryption monitoring module is used to receive the trust anchor decryption verification data sent by the trust anchor. The trust anchor decryption verification data is obtained by the trust anchor decrypting the data to be decrypted sent by the host based on the asymmetric encryption algorithm; The decryption monitoring module is further used to determine the trust anchor decryption comparison data based on the trust anchor decryption verification data, and make a first comparison between the trust anchor decryption comparison data and the host decryption comparison data to obtain a first comparison result.
30. The controller according to claim 29, wherein, The controller further includes at least one of a transmission monitoring module and an encryption monitoring module. The credibility of the transmission monitoring module is higher than that of the trust anchor, and the credibility of the encryption monitoring module is higher than that of the trust anchor, where: If the controller includes the transmission monitoring module, the transmission monitoring module is used to obtain initial test data, determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor is further used to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feedback it to the transmission monitoring module. The transmission monitoring module is further used to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result. If the controller includes the encryption monitoring module, the encryption monitoring module is used to obtain host encryption verification data and trust anchor encryption verification data. The host encryption verification data is obtained by encrypting the data to be encrypted with the host public key by the encryption monitoring module. The trust anchor encryption verification data is obtained by encrypting the data to be encrypted sent by the host with the trust anchor public key by the trust anchor based on the asymmetric encryption algorithm. The host public key is the trust anchor public key sent by the trust anchor received by the host. The host encryption verification data and the trust anchor encryption verification data are compared for the third time to obtain a third comparison result.
31. A controller, characterized in that, The controller includes a trust anchor and a host, and the host includes a transmission monitoring module, and the credibility of the transmission monitoring module is higher than that of the trust anchor, where: The transmission monitoring module is used to obtain initial test data, determine host transmission verification data and test transmission data according to the initial test data, and send the test transmission data to the trust anchor. The host transmission verification data or the test transmission data is obtained by encrypting the initial test data with the host public key, and the host public key is the trust anchor public key sent by the trust anchor received by the host. The trust anchor is used to calculate trust anchor transmission verification data based on the asymmetric encryption algorithm for the test transmission data, and feedback it to the transmission monitoring module. The transmission monitoring module is further used to perform a second comparison on the host transmission verification data and the trust anchor transmission verification data to obtain a second comparison result.
32. An electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, the method according to any one of claims 1 to 28 is implemented.
33. A computer-readable storage medium stores a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 28 is implemented.