一种基于外部安全芯片的文件签名方法及系统

By using a file signing method based on an external security chip, a random key pair is generated and signed by a public ECU, and the target ECU verifies the signature, forming a closed-loop security process. This solves the problems of insufficient security and high development cost of existing automotive file signing schemes, and achieves end-to-end security and trustworthiness for vehicle software flashing.

CN120614122BActive Publication Date: 2026-07-17HEFEI JUYI POWER SYST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HEFEI JUYI POWER SYST CO LTD
Filing Date
2025-06-30
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing vehicle document signing schemes have insufficient security, especially during data transmission where they are vulnerable to attacks. Furthermore, existing technologies are costly to develop and difficult to maintain, and cannot effectively guarantee information integrity and identity verification.

Method used

A file signing method based on an external security chip is adopted. A random key pair is generated through a public ECU, and the private key is used to sign and combine the packets. The target ECU verifies the signature, forming a closed-loop security process. Hardware-level isolation and dynamic generation mechanisms are used to ensure the security of the private key and prevent key leakage.

Benefits of technology

It achieves secure and reliable end-to-end vehicle software flashing, eliminates the risk of key leakage, ensures the integrity and authenticity of information transmission, reduces development costs, and improves system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120614122B_ABST
    Figure CN120614122B_ABST
Patent Text Reader

Abstract

本发明公开了一种基于外部安全芯片的文件签名方法及系统,包括公共机ECU生成随机密钥对;上位机将待刷写文件传输至公共机ECU;公共机ECU使用私钥对待刷写文件进行数字签名,生成签名值;公共机ECU向上位机导出签名值及公钥;上位机将待刷写文件与签名值合包封装,并以特定格式存储公钥;上位机将合包后的待刷写文件刷写至目标ECU;目标ECU将存储于安全芯片SE中的公钥、签名值,以及待刷写文件进行写入操作;目标ECU调用安全芯片SE的验签功能,使用公钥验证签名值;目标ECU将验签结果经微控制器返回至上位机。本发明通过硬件级隔离的私钥动态生成机制和链式验签架构,从根本上杜绝密钥泄露风险,确保车载软件刷写全链路的安全可信。
Need to check novelty before this filing date? Find Prior Art

Citation Information

Patent Citations

  • Method and device for detecting cracking risk of digital certificate

    CN109450883A

  • Security information configuration method, security verification method, and related chip

    US20170244562A1