Key distribution and analysis method and device
By generating a unique session key based on the device capabilities and using decryption white box code for encrypted transmission, the high risk of in-vehicle communication key leakage is solved, improving vehicle safety and production efficiency.
Patent Information
- Application Number
- CN202410374621.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-10-10
AI Technical Summary
In the existing technology, the risk of leakage of preset keys during the derivation and distribution of in-vehicle communication keys is high, which increases the risk of leakage of vehicle business keys. In addition, both the manufacturer and the vehicle manufacturer are aware of the preset keys, which makes the security insufficient.
A generation component is used to generate unique session keys based on the device capabilities of different vehicle components, encrypt the business keys for transmission, and decrypt them locally in the component through decryption white box code to ensure the security of the business keys of each component and avoid sharing session keys.
It reduces the risk of key exposure, improves the security and production efficiency of in-vehicle communications, and enhances the safety of the entire vehicle.
Smart Images

Figure CN120768535A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of secure communications, and in particular to a key distribution and analysis method and device. Background Art
[0002] In-vehicle communication typically refers to communication between in-vehicle components. Because in-vehicle communication security is a crucial component of smart cars and crucial to vehicle safety, in-vehicle components typically communicate via secure channels based on business keys to ensure secure in-vehicle communication. Therefore, each in-vehicle component must have its own business key to enable communication through secure channels based on business keys.
[0003] Currently, the derivation and distribution of keys are carried out by deriving them outside the vehicle and filling them into the vehicle on the production line. That is, a key management system (KMS) deployed outside the vehicle is used to derive business keys for vehicle components, and these keys are uniformly filled into the corresponding components in sequence on the production line. The filling process is generally as follows: the business key is encrypted using a preset key, and the encrypted business key is sent to the corresponding vehicle component. After the corresponding component receives the encrypted business key, it uses the preset key to parse the encrypted business key to obtain the business key. However, in the above scheme, many component manufacturers and vehicle manufacturers are aware of the preset key, which increases the risk of key leakage. Once the preset key is leaked, the business key of the entire vehicle is also at risk of leakage. Summary of the Invention
[0004] The present application discloses a key distribution and parsing method and device, which greatly reduces the risk of key exposure, improves the security of key distribution, and is conducive to improving the safety of vehicles.
[0005] In a first aspect, the present application provides a key distribution method, which is applied to a generation component, and the method includes: obtaining a first device capability of a first component and sending a first target key to the first component; obtaining a second device capability of a second component and sending a second target key to the second component; wherein the first device capability is used to represent the security characteristics of the first component, and the second device capability is used to represent the security characteristics of the second component, the first target key is generated by encrypting the business key of the first component using a first session key, and the second target key is generated by encrypting the business key of the second component using a second session key, the first device capability corresponds to the first session key, the second device capability corresponds to the second session key, the first device capability is different from the second device capability, and the first session key is different from the second session key.
[0006] Optionally, the generating component is a component in which the key management module in the vehicle is located, and / or the first component and the second component are respectively hung under the generating component. The generating component is, for example, a domain controller, a vehicle integrated unit (VIU), a telematics box (TBox) or an electronic control unit (ECU) in the vehicle. The domain controller includes a hardware and software integrated platform for supporting intelligent driving, namely a vehicle computing platform (vehicle computing platform), such as a mobile data center (MDC); a hardware and software integrated platform for providing vehicle multimedia services (such as head-up display, instrument panel display, entertainment audio and video, etc.), such as a cockpit domain controller (CDC); and a hardware and software integrated platform for supporting body control and chassis control, such as at least one of a vehicle domain controller (VDC).
[0007] Taking the first device capability corresponding to the first session key as an example, it is understood that the generation of the first session key is related to the first device capability, for example, affecting the determination method of the first session key and / or the value of the first session key.
[0008] The first device capability is different from the second device capability, that is, the security characteristics of the first component are different from the security characteristics of the second component.
[0009] In the above method, for components with different device capabilities, different session keys are used to generate components to encrypt and transmit the business keys of the corresponding components. Compared with using one session key for the encrypted transmission of the business keys of all components, the security of key distribution can be improved and the risk of key exposure can be effectively reduced.
[0010] Optionally, the generating component, the first component and the second component are disposed within a vehicle.
[0011] Implementing the above implementation method can improve the security of key distribution in the vehicle, which is beneficial to improving the safety of the vehicle.
[0012] Optionally, before sending the first target key to the first component, the method further includes: determining a first session key based on the first device capability, the first session key being used to generate secure communication between the component and the first component; generating a business key for the first component; and encrypting the business key of the first component using the first session key to obtain a first target key.
[0013] In this implementation, the generation component performs the generation of the first session key, the first component's business key, and the first target key. Furthermore, the generation of the first session key takes into account the component's device capabilities, enabling secure distribution of business keys. Furthermore, the derivation and distribution of business keys within the vehicle improves production efficiency compared to the current method of injecting keys into vehicles on the production line.
[0014] Similarly, before sending the second target key to the second component, the method also includes: determining a second session key based on the second device capability, the second session key being used for secure communication between the generating component and the second component; generating a business key for the second component; and encrypting the business key of the second component using the second session key to obtain a second target key.
[0015] Optionally, based on the capabilities of the first device, determining the first session key includes: the first device capabilities include secure storage capabilities, receiving the first public key and identification information of the first component sent by the first component; obtaining the first session key according to the public key of the first component, the hash value of the first component, the public key of the generating component and the private key of the generating component; wherein the public key of the generating component corresponds to the private key of the generating component, the public key of the first component is obtained based on the first public key and the second public key, the second public key is generated by the generating component for the first component, and the hash value of the first component is obtained by performing a hash operation on the identification information of the first component and the public key of the first component.
[0016] Furthermore, the first device capability also includes at least one of not supporting digital certificates and not supporting asymmetric hardware acceleration.
[0017] The first device capability includes secure storage capability, meaning that the first component has secure storage capability. This means that the first component has a hardware security module (HSM) or encrypted storage medium that can provide security at the hardware level. A hardware security module, also known as a security chip or secure microcontroller, is a hardware component specifically designed to provide security functions and protection mechanisms.
[0018] Exemplarily, the first public key, the second public key, the public key of the first component, and the private key of the first component are associated with parameters of elliptic curve cryptography.
[0019] In the implementation described above, when the first component possesses secure storage capabilities, the generation component determines the first session key using a certificateless public key protocol. The generation component participates in the generation of the first component's public-private key pair (i.e., the first component's public key and the first component's private key). Specifically, the generation of the first component's public key utilizes the second public key provided by the generation component for the first component, and the generation of the first component's private key utilizes the first public key provided by the generation component for the first component. This enables the subsequent local calculation of the first session key by the generation component to be consistent with the local calculation of the first session key by the first component. This enables the generation component and the first component to reach an agreement on the first session key without the need to transmit the first session key, thereby reducing the risk of key exposure. The use of the first session key enables secure communication between the generation component and the first component. Furthermore, as can be seen above, the first session key is also associated with the identification information of the first component. Since different components have different identification information, the generation component determines a different session key for each component. This achieves a one-component-one-session key system, improving the security of service key distribution and effectively reducing the risk of key exposure.
[0020] Optionally, the method further includes: sending a second public key, a first private key and a public key of a generating component to the first component, wherein the second public key is used to generate the public key of the first component, the first private key is used to generate the private key of the first component, and the public key of the generating component is used by the first component to parse the first target key.
[0021] Exemplarily, the first private key is also associated with parameters of elliptic curve cryptography.
[0022] By implementing the above implementation, when the first component has secure storage capabilities, the generating component sends the second public key, the first private key, and the public key of the generating component to the first component, which can assist the first component in locally generating the public-private key pair of the first component and also facilitate subsequent decryption by the first component.
[0023] Similarly, determining a second session key based on the capabilities of the second device includes: the second device capabilities include secure storage capabilities; receiving a third public key and identification information of the second component sent by the second component; and obtaining the second session key based on the public key of the second component, the hash value of the second component, the public key of the generating component, and the private key of the generating component. The generating component's public key corresponds to the generating component's private key, the second component's public key is obtained based on the third public key and a fourth public key, the fourth public key is generated by the generating component for the second component, and the hash value of the second component is obtained by hashing the identification information of the second component and the public key of the second component. Furthermore, the method further includes: sending the fourth public key, the second private key, and the public key of the generating component to the second component, the fourth public key being used for the public key of the second component, the second private key being used to generate the private key of the second component, and the public key of the generating component being used by the second component to resolve the second target key.
[0024] Optionally, the generating component is the component where the key management module in the vehicle is located, and determines the first session key based on the first device capability, including: the first device capability does not include secure storage capability, and the first session key is generated according to the identification information and master key of the first component, and the master key is generated by the generating component or comes from the network side device; the business key of the first component is generated, including: the business key of the first component is generated according to the identification information of the first component and the first session key; the method also includes: generating a decryption white box code based on the first session key, the decryption white box code includes the first session key, and the decryption white box code is used to restore the first target key to the business key of the first component; and sending the decryption white box code to the first component.
[0025] Exemplarily, when the generating component is not the component where the key management module in the vehicle is located, such as the first component does not have a secure storage capability, the generating component generates a first session key based on the business key of the generating component and the identification information of the first component.
[0026] Furthermore, the first device capability also includes at least one of not supporting digital certificates and not supporting asymmetric hardware acceleration.
[0027] Exemplarily, the first target key and / or the decryption white box code are carried in an OTA message.
[0028] Illustratively, generating the decryption white-box code based on the first session key includes: generating the decryption white-box code based on the first session key and a white-box algorithm, where the decryption white-box code is the white-box algorithm mixed with the first session key. "Mixed" here can be understood to mean, for example, that the first session key itself is inserted into the white-box algorithm as a whole, or that the first session key is split into multiple parts and the multiple parts are randomly inserted into the white-box algorithm.
[0029] By implementing the above implementation, when the first component does not have secure storage capabilities, the first session key and the algorithm code are mixed, and the decryption white-box code obtained after the mixing is sent to the first component. As a result, the first component does not locally generate the first session key but decrypts it through the decryption white-box code. In other words, secure storage of the first session key is achieved through the decryption white-box code, which increases the difficulty for attackers to obtain the first session key. Even if the first component does not have secure storage capabilities, secure storage of the key can be achieved through software.
[0030] Similarly, if the second device capability does not include secure storage capability, the generation component can also achieve secure storage of the second session key by generating a decryption white box code. For this execution process, please refer to the description of the execution steps of the generation component when the first device capability does not include secure storage capability. No further details will be given here.
[0031] Exemplarily, determining the first session key based on the first device capability includes: the first device capability includes supporting digital certificates and supporting asymmetric hardware acceleration, and using a digital certificate-based transport layer security TLS protocol to determine the first session key.
[0032] When the first component has the device capability of supporting digital certificates and asymmetric hardware acceleration, a secure distribution protocol based on digital certificates is directly used to determine a session key for secure communication between the generating component and the first component.
[0033] Optionally, the generation component includes a first generation component and a second generation component, the first component is suspended under the first generation component, and the second component is suspended under the second generation component, the first generation component is used to obtain the first device capability of the first component and send the first target key to the first component, and the first session key, the business key of the first component and the first target key are generated by the first generation component; the second generation component is used to obtain the second device capability of the second component and send the second target key to the second component, and the second session key, the business key of the second component and the second target key are generated by the second generation component.
[0034] Since the business key generator and distributor are the same for the same component, different components with different business key generators also have different business key distributors. Multiple components with key generation capabilities can generate and distribute business keys for their respective components in parallel, improving the efficiency of generating and distributing business keys for the entire vehicle.
[0035] In the second aspect, the present application provides a key parsing method, which is applied to a first component. The method includes: receiving a target key sent by a generating component; parsing the target key based on the device capability of the first component to obtain a business key of the first component; wherein the device capability of the first component is used to represent the security characteristics of the first component, and the target key is a key after the business key of the first component is encrypted by a session key.
[0036] Optionally, the generating component is a component where the key management module in the vehicle is located, and / or the first component is hung below the generating component. For details about the generating component, please refer to the description of the generating component in the first aspect above, which will not be repeated here.
[0037] Optionally, the first component and the generating component are disposed within a vehicle.
[0038] In the above method, the first component obtains the target key from the generating component and decrypts the target key to obtain the business key of the first component. The decryption of the target key is related to the device capability of the first component, which not only increases the security of the business key of the first component, but also helps to reduce the risk of leakage of the vehicle key.
[0039] Optionally, the target key is parsed based on the device capability of the first component to obtain the business key of the first component, including: the device capability of the first component includes secure storage capability, and the session key is obtained according to the private key of the first component and the public key of the generating component; the target key is parsed using the session key to obtain the business key of the first component; wherein the private key of the first component is obtained based on the first private key and the hash value of the first component, the hash value of the first component is obtained by hashing the identification information of the first component and the public key of the first component, the public key of the first component is obtained based on the first public key and the second public key, the first public key is generated by the first component, the second public key and the first private key correspond to the first component, the first private key, the second public key and the public key of the generating component come from the generating component, and the first private key is associated with the private key of the first component and the hash value of the first component.
[0040] When the above implementation method is implemented and the first component has a secure storage capability, the first component can also locally determine a session key based on the stored second public key, the first private key, and the public key of the generating component, and the second public key and the first private key are provided by the generating component. If the target key is successfully decrypted using the session key to obtain the business key of the first component, it means that the first component has achieved authenticity verification of the session key without relying on a digital certificate.
[0041] Exemplarily, the method also includes: receiving the public key of the second component and the identification information of the second component sent by the second component; obtaining a negotiated key based on the public key of the second component, the hash value of the second component, the private key of the first component and the public key of the generating component, and the negotiated key is used for secure communication between the first component and the second component; wherein the device capability of the second component includes secure storage capability, the second component is attached to the generating component, and the hash value of the second component is obtained by performing a hash operation based on the public key of the second component and the identification information of the second component.
[0042] When implementing the above implementation method, when the first component and the second component are not the generators of each other's business keys, if there is a communication need between the first component and the second component, the first component can locally calculate a session key based on the information provided by the second component (for example, the public key of the second component and the identification information of the second component). The session key is used for encryption and decryption of subsequent communications between the first component and the second component. Secure communication between the first component and the second component can be achieved through the session key.
[0043] Optionally, the target key is parsed based on the device capability of the first component to obtain the business key of the first component, including: the device capability of the first component does not include secure storage capability, the decryption white box code is locally flashed, the decryption white box code comes from the generation component, and the decryption white box code includes the session key; the target key is parsed using the decryption white box code to obtain the business key of the first component; wherein the business key of the first component is associated with the session key and the identification information of the first component, and the session key is associated with the identification information of the first component.
[0044] By implementing the above implementation, when the first component does not have the secure storage capability, secure storage of the session key is achieved by decrypting the white-box code. Therefore, the first component does not generate the session key locally, but instead decrypts the target key using the decryption white-box code pre-acquired from the generation component to obtain the business key of the first component. This increases the difficulty for an attacker to obtain the session key, and improves the security of the key even if the first component does not have the secure storage capability.
[0045] In a third aspect, the present application provides a key distribution device, which is a generating component, and the device includes: an acquisition unit, used to acquire a first device capability of a first component and a device capability of a second component; a sending unit, used to send a first target key to the first component and a second target key to the second component; wherein the first device capability is used to represent the security characteristics of the first component, and the second device capability is used to represent the security characteristics of the second component, the first target key is generated by encrypting the business key of the first component using a first session key by the processing unit, and the second target key is generated by encrypting the business key of the second component by the processing unit using a second session key, the first device capability corresponds to the first session key, the second device capability corresponds to the second session key, the first device capability is different from the second device capability, and the first session key is different from the second session key.
[0046] Optionally, the generating component, the first component and the second component are disposed within a vehicle.
[0047] Optionally, the generating component is the component where the key management module in the vehicle is located, and / or the first component and the second component are respectively hung below the generating component.
[0048] Optionally, the processing unit is used to: determine a first session key based on the first device capability, the first session key being used for secure communication between the generating component and the first component; generate a business key for the first component; and encrypt the business key of the first component using the first session key to obtain a first target key.
[0049] Similarly, the processing unit is used to: determine a second session key based on the second device capability, the second session key is used to generate secure communication between the component and the second component; generate a business key for the second component; use the second session key to encrypt the business key of the second component to obtain a second target key.
[0050] Optionally, the processing unit is specifically used to: the first device capability includes secure storage capability, receive the first public key and identification information of the first component sent by the first component; obtain the first session key according to the public key of the first component, the hash value of the first component, the public key of the generating component and the private key of the generating component; wherein the public key of the generating component corresponds to the private key of the generating component, the public key of the first component is obtained by the processing unit based on the first public key and the second public key, the second public key is generated by the generating component for the first component, and the hash value of the first component is obtained by the processing unit performing a hash operation on the identification information of the first component and the public key of the first component.
[0051] For example, the first public key, the second public key, the public key of the first component, and the private key of the first component are all associated with parameters of elliptic curve cryptography.
[0052] Optionally, the sending unit is further used to: send the second public key, the first private key and the public key of the generating component to the first component, the second public key is used to generate the public key of the first component, the first private key is used to generate the private key of the first component, and the public key of the generating component is used by the first component to parse the first target key.
[0053] Similarly, the processing unit is specifically configured to: receive the third public key and identification information of the second component sent by the second component, wherein the second device capability includes secure storage capability; obtain the second session key based on the public key of the second component, the hash value of the second component, the public key of the generating component, and the private key of the generating component; wherein the public key of the generating component corresponds to the private key of the generating component, the public key of the second component is obtained by the processing unit based on the third public key and the fourth public key, the fourth public key is generated by the generating component for the second component, and the hash value of the second component is obtained by the processing unit performing a hash operation on the identification information of the second component and the public key of the second component. Furthermore, the method further includes: sending the fourth public key, the second private key, and the public key of the generating component to the second component, wherein the fourth public key is used for the public key of the second component, the second private key is used to generate the private key of the second component, and the public key of the generating component is used by the second component to parse the second target key.
[0054] Optionally, the generating component is the component where the key management module in the vehicle is located, and the processing unit is specifically used to: if the first device capability does not include secure storage capability, generate a first session key based on the identification information and the master key of the first component, the master key is generated by the generating component or comes from the network side device; generate a business key of the first component based on the identification information of the first component and the first session key; generate a decryption white box code based on the first session key, the decryption white box code includes the first session key, and the decryption white box code is used to restore the first target key to the business key of the first component; the sending unit is also used to send the decryption white box code to the first component.
[0055] Optionally, the generating component includes a first generating component and a second generating component, the first component is suspended under the first generating component, and the second component is suspended under the second generating component, the above-mentioned acquisition unit includes a first acquisition unit of the first generating component and a second acquisition unit of the second generating component, and the above-mentioned sending unit includes a first sending unit of the first generating component and a second sending unit of the second generating component; the first acquisition unit is used to obtain the first device capability of the first component; the first sending unit is used to send the first target key to the first component; the second acquisition unit is used to obtain the second device capability of the second component; the second sending unit is used to send the second target key to the second component; the above-mentioned processing unit includes a first processing unit of the first generating component and a second processing unit of the second generating component, wherein the first session key, the business key of the first component and the first target key are generated by the first processing unit; the second session key, the business key of the second component and the second target key are generated by the second processing unit.
[0056] In a fourth aspect, the present application provides a key parsing device, which is a first component and includes: a receiving unit for receiving a target key sent by a generating component, where the target key is a key obtained by encrypting the business key of the first component with a session key; a processing unit for parsing the target key based on the device capability of the first component to obtain the business key of the first component; wherein the device capability of the first component is used to represent the security characteristics of the first component.
[0057] Optionally, the first component and the generating component are disposed within a vehicle.
[0058] Optionally, the generating component is a component in which the key management module in the vehicle is located, and / or the first component is hung below the generating component.
[0059] Optionally, the processing unit is specifically used to: obtain a session key based on the private key of the first component and the public key of the generating component according to the device capability of the first component including secure storage capability; and obtain a business key of the first component by parsing the target key using the session key; wherein the private key of the first component is obtained based on the first private key and the hash value of the first component, the hash value of the first component is obtained by the processing unit performing a hash operation on the identification information of the first component and the public key of the first component, the public key of the first component is obtained by the processing unit based on the first public key and the second public key, the first public key is generated by the first component, the second public key and the first private key correspond to the first component, the first private key, the second public key and the public key of the generating component come from the generating component, and the first private key is associated with the private key of the first component and the hash value of the first component.
[0060] For example, the first public key, the second public key, the first private key, the public key of the first component, and the private key of the first component are all associated with parameters of elliptic curve cryptography.
[0061] Exemplarily, the receiving unit is further used to receive the public key of the second component and the identification information of the second component sent by the second component; the processing unit is further used to obtain a negotiated key based on the public key of the second component, the hash value of the second component, the private key of the first component and the public key of the generating component, and the negotiated key is used for secure communication between the first component and the second component; wherein the device capability of the second component includes secure storage capability, the second component is hung under the generating component, and the hash value of the second component is obtained by performing a hash operation by the processing unit based on the public key of the second component and the identification information of the second component.
[0062] Optionally, the processing unit is specifically used to: if the device capability of the first component does not include secure storage capability, locally flash the decryption white box code, the decryption white box code comes from the generation component, and the decryption white box code includes the session key; use the decryption white box code to parse the target key to obtain the business key of the first component; wherein the business key of the first component is associated with the session key and the identification information of the first component, and the session key is associated with the identification information of the first component.
[0063] In a fifth aspect, the present application provides a chip comprising a processor and a memory, wherein the memory is used to store program instructions; the processor calls the program instructions in the memory so that the chip executes the method in the first aspect or any possible implementation of the first aspect.
[0064] In a sixth aspect, the present application provides an electronic control unit, which includes a processor and a memory, wherein the memory is used to store program instructions; the processor calls the program instructions in the memory so that the electronic control unit executes the method in the second aspect or any possible implementation of the second aspect.
[0065] In the seventh aspect, the present application provides a key distribution system, which includes a first device and a second device, wherein the first device is used to implement the method in the above-mentioned first aspect or any possible implementation of the first aspect, and the second device is used to implement the method in the above-mentioned second aspect or any possible implementation of the second aspect.
[0066] Exemplarily, the first device is the device of the third aspect or any possible implementation of the third aspect, or the first device is the chip described in the fifth aspect; the second device is the device of the fourth aspect or any possible implementation of the fourth aspect, or the second device is the electronic control unit described in the sixth aspect.
[0067] In an eighth aspect, the present application provides a vehicle comprising an apparatus as described in the third or fifth aspect above, or an apparatus of any possible implementation of the third or fifth aspect above, or an apparatus as described in the fourth or sixth aspect above, or an apparatus of any possible implementation of the fourth or sixth aspect above, or a key distribution system as described in the seventh aspect.
[0068] In a ninth aspect, the present application provides a computer-readable storage medium comprising computer instructions, which, when executed by a processor, implement the method of the above-mentioned first aspect or any possible implementation of the first aspect, or implement the method of the above-mentioned second aspect or any possible implementation of the second aspect.
[0069] In the tenth aspect, the present application provides a computer program product, which, when executed by a processor, implements the method in the above-mentioned first aspect or any possible embodiment of the first aspect, or implements the method in the above-mentioned second aspect or any possible embodiment of the second aspect.
[0070] Exemplarily, the computer program product is a software installation package. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] Figure 1 This is a schematic diagram of the architecture of a key management system provided in an embodiment of the present application;
[0072] Figure 2 This is a schematic structural diagram of a vehicle provided in an embodiment of the present application;
[0073] Figure 3 This is a flowchart of a key distribution method provided by an embodiment of the present application;
[0074] Figure 4 This is a flowchart of a business key derivation method provided by an embodiment of the present application;
[0075] Figure 5 This is a flowchart of a method for generating a public and private key pair of a component provided in an embodiment of the present application;
[0076] Figure 6 This is a schematic diagram of the structure of a key generation device provided in an embodiment of the present application;
[0077] Figure 7 This is a schematic diagram of the structure of a key parsing device provided in an embodiment of the present application;
[0078] Figure 8 It is a structural diagram of a key processing device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0079] It should be noted that the prefixes such as "first" and "second" used in this application are only for distinguishing different description objects, and do not have any limiting effect on the position, order, priority, quantity or content of the described objects. For example, if the described object is a "field", then the ordinal number before the "field" in the "first field" and the "second field" does not limit the position or order between the "fields", and "first" and "second" do not limit whether the "fields" they modify are in the same message, nor do they limit the order of the "first field" and the "second field". For another example, if the described object is a "level", then the ordinal number before the "level" in the "first level" and the "second level" does not limit the priority between the "levels". For another example, the number of described objects is not limited by the prefix and can be one or more. Taking "first device" as an example, the number of "devices" can be one or more. In addition, the objects modified by different prefixes can be the same or different. For example, if the described object is a "device," then the "first device" and the "second device" can be the same device, the same type of device, or different types of devices. For another example, if the described object is "information," then the "first information" and the "second information" can be information of the same content or information of different contents. In short, the use of prefixes to distinguish the described objects in the embodiments of this application does not constitute a limitation on the described objects. For the description of the described objects, please refer to the description in the context of the claims or embodiments, and the use of such prefixes should not constitute an unnecessary limitation.
[0080] It should be noted that the descriptions used in the embodiments of the present application, such as "at least one of a1, a2, ..., and an" and the like, include any one of a1, a2, ..., and an existing alone, and any combination of any multiple of a1, a2, ..., and an, each of which can exist alone. For example, the description "at least one of a, b, and c" includes a alone, b alone, c alone, a combination of a and b, a combination of a and c, a combination of b and c, or a combination of ab and c.
[0081] For ease of understanding, the related terms that the embodiments of the present application may involve are introduced first.
[0082] (1) Hardware security module
[0083] A hardware security module (HSM) is a specialized hardware device used to protect and manage sensitive data, session keys, and perform cryptographic operations. EVITA (E-safety vehicle intrusion protected applications) is a safety standard designed to ensure the security and protection capabilities of vehicle electronic systems. EVITA divides HSM into three levels: EVITA full HSM, EVITA medium HSM, and EVITA light HSM (or EVITA small HSM), where EVITA full HSM is used for V2X communication, EVITA medium HSM is used for on-board electronic control unit (ECU) intercommunication, and EVITA light HSM is used for communication between sensors and actuators.
[0084] Hardware security modules provide additional security at the hardware level, making it more difficult for attackers to obtain or tamper with sensitive information stored in the device.
[0085] (2) Certificateless public key cryptography
[0086] Certificateless public key cryptography (CL-PKC) is a cryptographic scheme designed to address some of the issues with certificate management in traditional public key infrastructure (PKI). In traditional PKI, a trusted certificate authority (CA) is needed to verify the authenticity of public keys, which increases the complexity of management and maintenance.
[0087] CL-PKC enables parties to establish secure communication without relying on digital certificates issued by traditional certificate authorities through negotiation, exchange of information, and verification.
[0088] (3) Key derivation
[0089] Key derivation refers to the process of deriving other keys from one or more initial keys. The initial key is also known as the master key.
[0090] Key derivation is usually achieved by using a derivation function or a key derivation function (KDF), such as PBKDF2, HKDF, scrypt, Argon2, etc.
[0091] In order to reduce the risk of exposure of the entire vehicle's keys, an embodiment of the present application provides a key management system that can determine a session key for each component in the vehicle, and use the session key corresponding to the component to ensure that the business key of the component is securely transmitted to the corresponding component. In addition, the generation of the session key is related to the device capabilities of the component. The device capabilities of the component are used to describe the security characteristics of the device. Different device capabilities of the component have different corresponding session keys. In this way, all components in the vehicle no longer share a single session key. The business keys of different components are encrypted and transmitted using different session keys, which helps to reduce the risk of key exposure and improve the security of key transmission.
[0092] See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of a key management system provided by an embodiment of the present application. Figure 1 As shown, the key management system includes a terminal 10 and a network-side device 20, wherein the terminal 10 and the network-side device 20 communicate with each other in a wireless manner.
[0093] Terminal 10 is, for example, an intelligent terminal or IoT device with key management requirements, such as a vehicle, robot, drone, ship, or boat. Vehicles are vehicles in a broad sense and can be transportation vehicles (such as commercial vehicles, passenger cars, motorcycles, flying cars, trains, etc.), industrial vehicles (such as forklifts, trailers, tractors, etc.), engineering vehicles (such as excavators, bulldozers, cranes, etc.), agricultural equipment (such as mowers, harvesters, etc.), etc. For another example, a robot can be an intelligent transport robot (automated guided vehicle, AGV), a walking conversational robot, a service robot, or other robots. It can be understood that all terminals involving secure communication between internal components belong to terminal 10.
[0094] For example, the vehicle can be an autonomous vehicle or a non-autonomous vehicle. Here, autonomous driving is not limited to fully autonomous driving, highly autonomous driving, conditionally autonomous driving, or partially autonomous driving. Those skilled in the art will appreciate that any non-fully manual driving that provides intelligent driving can be covered by this concept. Furthermore, the embodiments of this application do not limit the vehicle's power source, such as a new energy vehicle or a traditional fuel vehicle.
[0095] The network-side device 20 can be a computing device or a computing device cluster, where the computing device includes a bare metal server (BMS), a virtual machine, a container, or an edge computing device. A BMS refers to a general-purpose physical server, such as an ARM server or an X86 server; a virtual machine refers to a complete computer system with complete hardware system functions that is simulated by software and runs in a completely isolated environment. Any work that can be completed in a physical computer can be implemented in a virtual machine. When creating a virtual machine in a computing device, part of the hard disk and memory capacity of the physical machine needs to be used as the hard disk and memory capacity of the virtual machine. Each virtual machine has an independent basic input / output system (BIOS), hard disk, and operating system, and can be operated like a physical machine. A container is a virtualization software that can combine an application and all its dependencies into a single software package that is not restricted by the underlying host operating system. This eliminates the need to build a complex environment and simplifies the process from application development to deployment. An edge computing device refers to a device that is closer to the data source and end user and has low latency and high bandwidth characteristics, such as smart routing, edge servers, etc. A computing device cluster may include multiple of the above-mentioned computing devices, such as a data center, which is not specifically limited in this application. The network-side device 20 can be deployed in a cloud environment or an edge environment. The network-side device 20 can be an integrated device or multiple distributed devices, without specific limitation. The network-side device 20 can also be a component in a computing device, such as a chip or integrated circuit.
[0096] Among them, a key management system (KMS) is deployed on the terminal 10, and a key management system is also deployed on the network-side device 20. The key management system, also known as the cryptographic key management system (CKMS), includes the functions of generating, distributing, and managing keys for devices and applications. To distinguish the key management system deployed on the network-side device 20 from the key management system deployed on the terminal 10, it is also called the key management module (KeyM). The KeyM on the terminal 10 can be used to generate and distribute relevant keys for various components in the vehicle, and the KMS on the network-side device 20 can assist the KeyM on the terminal 10 in performing the generation of relevant keys.
[0097] above Figure 1 This is just an example architecture diagram of the key management system, and does not limit the key management system to only Figure 1In some possible embodiments, the generation of the relevant keys of the components of the terminal 10 does not require the participation of the network side device 20. In this case, Figure 1 The key management system shown may also not include the network-side device 20 .
[0098] The following will Figure 1 The terminal 10 in the example is a vehicle, and the vehicle components included in the vehicle are introduced in detail. Figure 2 , Figure 2 It is a structural schematic diagram of a vehicle provided in an embodiment of the present application.
[0099] exist Figure 2 In the vehicle, the in-vehicle components include at least one domain controller (DC), at least one vehicle integrated unit (VIU), an electronic control unit (ECU), and a telematics box (TBox). The DC and VIU, as well as the VIUs themselves, are connected and communicated via a high-speed Ethernet network, making the vehicle network highly efficient and reliable. The TBOX communicates with the VIU and / or DC via Ethernet, for example, to transmit information or instructions, including vehicle status information, key status information, control instructions, and the like.
[0100] The VIU manages the electronic control units (ECUs) within its area. It provides close access to the corresponding sensors, actuators, or ECUs, enabling power supply, electronic fuses, I / O port isolation, and other functions. Furthermore, the VIU performs some or all of the functions of a gateway, such as protocol conversion, protocol encapsulation and forwarding, and data format conversion. When the VIU integrates the ECU functions within certain vehicle components, it also provides electronic control capabilities for controlling those components.
[0101] exist Figure 2 In the embodiment, at least one VIU includes VIU0, VIU1, VIU2, and VIU3, wherein the key management module KeyM is deployed only on VIU0. In some possible embodiments, the number of KeyMs deployed in the vehicle is not limited. The KeyMs may be deployed, for example, on VIUs, DCs, or other certificate-capable devices within the vehicle. As an example, VIU0, VIU1, VIU2, and VIU3 are each deployed with a KeyM.
[0102] Each functional domain in the vehicle can have an independent domain controller. The domain controller can be understood as a general term for the system including domain master hardware, operating system, algorithm and application software. Figure 2 In the embodiment, at least one DC includes a hardware and software integrated platform for supporting intelligent driving, namely a vehicle computing platform (vehicle computing platform), such as a mobile data center (MDC); and includes a hardware and software integrated platform for providing vehicle multimedia services (such as at least one of a head-up display, an instrument panel display, and entertainment audio and video), such as a cockpit domain controller (CDC). In some possible embodiments, at least one DC also includes a hardware and software integrated platform for supporting body control and chassis control, such as a vehicle domain controller (VDC). In some possible embodiments, MDC can also be called an advanced driving assistance system domain controller (ADASDC) or an automatic drive domain controller (AD DC).
[0103] Among them, MDC is used to provide services for vehicle components that realize autonomous driving functions. Vehicle components that realize autonomous driving functions include monocular cameras, binocular cameras, millimeter-wave radars, lidars, ultrasonic radars, etc.
[0104] The CDC is used to provide services for vehicle components within the cockpit domain, where the vehicle components within the cockpit domain include head-up display (HUD), instrument display, radio, navigation, camera, etc.
[0105] VDC is used to provide services for vehicle components within the body domain and vehicle components within the chassis domain. Vehicle components within the body domain include door and window lift controllers, electric rearview mirrors, air conditioning, central door locks, etc.; vehicle components within the chassis domain include vehicle components in the braking system, vehicle components in the steering system, and vehicle components in the acceleration system, such as the accelerator.
[0106] The components in the vehicle are divided into three types based on their equipment capabilities. See the description of the first to third types of components below:
[0107] 1) Category I components
[0108] Device capabilities of the first category of components include support for digital certificates and support for asymmetric hardware acceleration.
[0109] A digital certificate is a security tool used to verify the identities of both parties communicating on a network. It's typically based on the Public Key Infrastructure (PKI) framework, such as the SSL / TLS certificates used for authentication. Devices that support digital certificates are those equipped with the necessary functionality and security protocols to process, verify, and generate digital certificates.
[0110] Devices that support asymmetric hardware acceleration are equipped with specialized hardware modules or accelerators for accelerating asymmetric encryption algorithms. Asymmetric encryption algorithms, also known as public-key encryption algorithms, are cryptographic algorithms that use public and private keys for encryption and decryption. Examples include RSA, the Digital Signature Algorithm (DSA), and elliptic-curve cryptography (ECC).
[0111] For example, in Figure 2 Among them, VIUx (including VIU0, VIU1, VIU2 and VIU3), TBox, CDC, MDC and other Ethernet-connected devices belong to the first category of components.
[0112] 2) Category II components
[0113] The device capabilities of the second category components include secure storage capabilities. In some possible embodiments, the device capabilities of the second category components further satisfy at least one of not supporting digital certificates and not supporting asymmetric hardware acceleration.
[0114] Here, "a component possessing secure storage capability" means that the component incorporates a hardware security module (HSM) or encrypted storage medium, providing security at the hardware level. A HSM, also known as a security chip or secure microcontroller, is a hardware component specifically designed to provide security functions and protection mechanisms. They typically integrate functions such as cryptographic engines, random number generators, secure storage, and identity authentication modules to perform security tasks such as encryption, key storage, and identity verification.
[0115] For example, in Figure 2 In the example, devices with secure storage capabilities such as ECU01 and ECU02 belong to the second category of components. For example, the second category of components are connected to a controller area network (CAN) bus or a CAN-FD (CAN With Flexible Data-Rate) bus.
[0116] In some possible embodiments, the second category of components further includes an intelligent key module (IKM), a microcontroller unit (MCU), and a battery management system (BMS).
[0117] 3) Category III components
[0118] The device capabilities of the third category components do not include secure storage capabilities. In some possible embodiments, the device capabilities of the third category components further satisfy at least one of not supporting digital certificates and not supporting asymmetric hardware acceleration.
[0119] For example, the third category of components includes sensor components without secure storage capabilities, which are primarily used to collect data such as vehicle operating status and environmental information to support the vehicle's control, monitoring, and decision-making systems. Such sensor components include, for example, global positioning systems (GPS), inertial measurement units (IMUs), vehicle speed sensors, steering angle sensors, lidars, cameras, ultrasonic sensors, atmospheric pressure sensors, temperature sensors, and other sensor components used to provide vehicle status and surrounding environment data.
[0120] Assumptions Figure 2 If the equipment capability of ECU11, the equipment capability of ECU12 and the equipment capability of ECU12 meet the judgment conditions of the equipment capability of the third category components, then ECU11, ECU12 and ECU12 all belong to the third category components. Figure 2 In the embodiment, ECU11, ECU12, and ECU12 are connected to VIU1 through an in-vehicle signal bus (such as a CAN bus or a Lin bus).
[0121] above Figure 2 An example of the internal structure of a vehicle, but not limited to Figure 2 The system shown includes the number of network elements. Figure 2 Not shown, but Figure 2 In addition to the functional entities shown, Figure 2 Other functional entities may also be included. In addition, the method provided in the embodiment of the present application can be applied to Figure 2 Of course, the method provided in the embodiment of the present application can also be applied to other vehicle structures. For example, in some implementations, Figure 2The MDC and CDC in the VDC are logically integrated to form a fused domain controller, that is, the MDC and CDC are combined into one. Of course, other fusion methods may also be used for multiple items of the above VDC, MDC and CDC, which are not specifically limited here.
[0122] For the sake of convenience, the terminal 10 below is described using a vehicle as an example, but the embodiment of the present application does not limit the terminal 10 to being only a vehicle.
[0123] The following combines the above Figure 1 、 Figure 2 The structure shown introduces a key distribution method provided in an embodiment of the present application.
[0124] See also Figure 3 , Figure 3 This is a flowchart of a key distribution method provided by an embodiment of the present application. The method is applied to a communication system composed of a generating component and a first component, wherein the generating component is the generator of the business key of the first component and also the sender of the business key of the first component. The generating component and the first component are both deployed in Figure 1 On terminal 10 or Figure 2 On the vehicle shown.
[0125] Figure 3 The method shown in the embodiment includes but is not limited to the following steps S301-S305.
[0126] S301: The generating component generates a service key of the first component.
[0127] Here, for any component (eg, the first component), the service key of the first component is associated with a specific service requirement (eg, a diagnostic service), an application, or a service.
[0128] There are two main ways to generate business keys for vehicle components: centralized derivation and distributed derivation.
[0129] The first type: centralized derivation
[0130] Centralized derivation means that a key management module (KeyM) within the vehicle is responsible for deriving the business keys for each component within the vehicle. Centralized derivation generates business keys for the entire vehicle, with a single key management module responsible for generating business keys. This centralized management of business keys reduces deployment costs and facilitates maintenance.
[0131] For example, the process of centralized derivation of business keys can be found in Figure 4 Description of embodiments. Figure 4This is a flowchart of a business key derivation method provided by an embodiment of the present application. The method is applied to a communication system consisting of a generating component, a first component, and a network side device, wherein the generating component is the component where the key management module KeyM is located, and the first component is any component in the vehicle that requires a business key. The network side device is, for example, the above-mentioned Figure 1 The network side device 20 in the vehicle is Figure 1 An example of the terminal 10.
[0132] For example, the generating component and the first component are both deployed in the vehicle, and the network side device is deployed outside the vehicle. Figure 2 For the vehicle shown, the generated parts are Figure 2 In VIU0, the first component can be Figure 2 In this case, the derivation of the component's business key occurs inside the vehicle.
[0133] Figure 4 The illustrated embodiment includes but is not limited to the following steps S401 - S403 .
[0134] S401: The generating component obtains the master key from the network side device.
[0135] As an example, the generation component obtains the master key from the network side device, including: after the vehicle is assembled and powered on, the KeyM in the generation component triggers the key derivation process, and the KeyM sends a first request to the network side device, and the first request is used to request to obtain the master key; in response to the first request, the network side device sends the master key to the generation component, so that the KeyM in the generation component obtains the master key.
[0136] Exemplarily, the master key is provided by a user of the network-side device or generated by a key management system KMS deployed on the network-side device.
[0137] To ensure the security of the master key, the network-side device can use encryption to securely transmit the master key to the generation component.
[0138] S402: The generating component obtains identification information of the first component from the first component.
[0139] The identification information of the first component is used to identify the first component, and the identification information of the first component is, for example, the component serial number of the first component, the component ID of the first component, or the IP address of the first component.
[0140] Exemplarily, the generating component obtains identification information of the first component from the first component, including: KeyM in the generating component sends identification request information to the first component; in response to the identification request information, the first component sends the identification information of the first component to the generating component, so that KeyM in the generating component obtains the identification information of the first component.
[0141] In another implementation, the generating component pre-stores the identification information of the first component, and the KeyM in the generating component directly obtains the identification information of the first component locally.
[0142] S403: The generating component generates a service key of the first component based on the master key and the identification information of the first component.
[0143] In one implementation, a generation component generates a business key for the first component based on a master key and identification information of the first component, including: KeyM in the generation component uses the master key and the identification information of the first component as inputs to a key derivation function to obtain the business key of the first component, wherein the business key of the first component is a result output by the key derivation function based on the master key and the identification information of the first component.
[0144] Exemplarily, the generation of the service key of the first component satisfies the following formula (1):
[0145] KEY x =KDF(MK, ID_ECU x ||Salt_ECU x ) Formula (1)
[0146] Among them, KEY x Indicates the business key of the first component, which can be any component in the vehicle. KDF() represents the key derivation function, MK represents the master key, and ID_ECU x Indicates the identification information of the first component. Salt_ECU x For example, it is a 256-bit number, Salt_ECU x The service key of the first component is increased by 1 each time the service key of the first component is updated. The above formula (1) is only an example, and the service key of the first component can also be generated by a modified formula based on formula (1).
[0147] In some possible embodiments, S401 may not be executed, and the master key is locally generated by KeyM in the generating component.
[0148] Second: Distributed Derivation
[0149] Distributed derivation means that the key management module KeyM in the vehicle (multiple) is first used to derive the key of the components on the Ethernet ring (for example, Figure 1Components on the Ethernet ring then derive service keys for their own components, and so on, until every component in the vehicle has its own service key. This distributed derivation approach allows multiple components with key generation capabilities to generate service keys for their respective components in parallel, improving the efficiency of generating service keys for the entire vehicle.
[0150] exist Figure 2 In the structure shown, it is assumed that VIUx (ie, VIU0, VIU1, VIU2, and VIU3) are all deployed with KeyM, and VIUx, TBox, CDC, and MDC are all on the Ethernet ring. The process of using the service key of the distributed derived component includes the following steps Step 1 and Step 2.
[0151] Step 1: KeyM on VIU0 generates business keys for VIU0, TBox, CDC and MDC based on the master key. VIU1 generates business keys for VIU1, VIU2 generates business keys for VIU2, and VIU3 generates business keys for VIU3.
[0152] Here, the master key is generated by KeyM on VIU0 or comes from a network-side device. This master key comes from the network-side device, allowing it to centrally manage the vehicle's master keys. Each vehicle has a corresponding master key. When a component from vehicle A is replaced in vehicle B, vehicle B can use vehicle A's master key to request the network-side device to verify the legitimacy of vehicle A. The master key is generated locally by KeyM and never leaves the vehicle, reducing the risk of key exposure.
[0153] Taking the example of KeyM on VIU0 generating a service key for the TBox based on the master key, the KeyM on VIU0 generating a service key for the TBox based on the master key includes: KeyM on VIU0 generating the service key for the TBox based on the master key and the identification information of the TBox. This implementation method is described in the above-mentioned S403 and will not be repeated here.
[0154] Step 2: VIUx, TBox, CDC, and MDC derive service keys for their own components that are not configured with service keys.
[0155] Assuming that ECU001 is connected to MDC, and taking MDC deriving the business key of its own component ECU001 as an example, MDC generates the business key of ECU001 based on the business key of MDC and the identification information of ECU001.
[0156] As can be seen from Step 1 and Step 2 above, when a distributed derivation method is adopted, if the generating component is the component where KeyM is located, the generating component generates the business key of the first component based on the master key and the identification information of the first component; if the generating component is not the component where KeyM is located, the generating component generates the business key of the first component based on the business key of the generating component and the identification information of the first component.
[0157] Using a distributed derivation method, multiple components in the vehicle have the ability to generate keys. Each KeyM in the vehicle first generates a business key for the components on the Ethernet ring, and then the components on the Ethernet ring generate business keys for the components hanging below it. In this way, each component in the vehicle has a business key.
[0158] In the case of distributed derivation, the first component is attached to the generating component. Figure 2 For example, if the generating component is CDC, the first component includes the components hanging under CDC; for example, if the generating component is VIU1, the first component includes the components hanging under VIU1 (i.e., ECU11, ECU12, and ECU13); for example, if the generating component is VIU0, the first component includes the components hanging under VIU0 (including ECU11, ECU12, and ECU13), or the generating component and the first component can also be Figure 2 Other forms in .
[0159] Here, if the first component is subordinate to the generation component, the device capability of the generation component must be no less than that of the first component. For example, if the generation component belongs to the first category, then the first component belongs to the first, second, or third category; if the generation component belongs to the second category, then the first component belongs to the second or third category.
[0160] In one implementation, when the generating component generates the service key for the first component, the device capability of the first component is not distinguished.
[0161] In another implementation, when the device capability of the first component does not include secure storage capability (i.e., the first component belongs to the aforementioned third category of components), the generation component generates a business key for the first component, including: the generation component generates a root key based on the pre-key and the identification information of the first component; the generation component generates the business key for the first component based on the root key and the identification information of the first component.
[0162] For example, when the generating component is the component where KeyM is located, the pre-key is the master key; when the generating component is not the component where KeyM is located, the pre-key is the business key of the generating component. The master key can be referred to the description of the corresponding content above.
[0163] Exemplarily, the generation component generates the root key by using a first key derivation algorithm, and the generation component generates the service key of the first component by using a second key derivation algorithm, which can be the same or different from the first key derivation algorithm.
[0164] When the generation component and the first component are deployed in the vehicle, the generation of the service key is completed in the vehicle. Compared with the current line key filling process, the embodiments of the application realize that the vehicle key is not taken out of the vehicle, which is conducive to reducing the exposure risk of the key.
[0165] S302: The generation component determines the first session key based on the device capability of the first component.
[0166] Here, the execution order of S301 and S302 is not limited, for example, they can be executed simultaneously or one before the other.
[0167] The first session key is used for secure communication between the generation component and the first component. That is, the first session key corresponds to the device capability of the first component, and if the device capability of the first component changes, the first session key will also change. In this way, it is conducive to improving the security of communication between the two parties.
[0168] Exemplarily, the device capability of the first component is obtained by the generation component from the first component, or the device capability of the first component is set by the user on the generation component, or the device capability of the first component is written into the generation component by default when the component is manufactured.
[0169] The aforementioned division of components based on device capability into three types, the determination process of the first session key when the first component belongs to different types of components is described below, please refer to the following case 1-case 3.
[0170] Case 1: The first component belongs to the first type of component
[0171] In one implementation mode, the device capability of the first component includes support for digital certificates and support for asymmetric hardware acceleration, and the generation component determines the first session key based on the device capability of the first component, including: the generation component determines the first session key by using a transport layer security (TLS) protocol based on digital certificates.
[0172] Taking the generation component as KeyM and the first component as CDC as an example, the process of KeyM determining the first session key by using the TLS protocol is described, please refer to the following steps A11-A14.
[0173] A11: KeyM and CDC agree on the TLS version and encryption algorithm to be used in advance.
[0174] A12: KeyM sends a digital certificate to the CDC, the digital certificate including a public key of KeyM and signature information.
[0175] Correspondingly, the CDC uses a locally stored root certificate or a certificate of a certificate authority to verify validity and authenticity of the digital certificate sent by KeyM. The verification of the digital certificate includes checking whether the signature information in the digital certificate is valid, whether the digital certificate is within a valid period, etc. In the case that the verification of the digital certificate succeeds, the CDC encrypts the pre-master key using the public key of KeyM (an encryption algorithm in A11 is used in the encryption process), obtains an encrypted key, and sends the encrypted key to KeyM.
[0176] A13: KeyM receives the encrypted key from the CDC, and decrypts the encrypted key using a private key of KeyM to obtain the pre-master key.
[0177] A14: KeyM and the CDC determine a first session key based on the pre-master key, the first session key being used to encrypt and decrypt subsequent communications between KeyM and the CDC. Here, the process in which KeyM and the CDC determine the first session key based on the pre-master key can refer to the description of determining a session key based on a certificate in the prior art TLS protocol, and will not be described here.
[0178] When the first component has the device capability of supporting a digital certificate and asymmetric hardware acceleration, a secure distribution protocol based on a digital certificate is directly used to determine a session key used to generate a component and the first component to securely communicate.
[0179] Case 2: The first component belongs to the second type of component
[0180] In an implementation manner, the device capability of the first component includes a secure storage capability, and the generating component determines the first session key based on the device capability of the first component, including: the generating component receives a first public key and identification information of the first component sent by the first component; obtains the first session key according to the public key of the first component, a hash value of the first component, a public key of the generating component and a private key of the generating component; wherein the public key of the generating component corresponds to the private key of the generating component, the public key of the first component is obtained based on the first public key and a second public key, the second public key being generated by the generating component for the first component, and the hash value of the first component is obtained by performing a hash operation on the identification information of the first component and the public key of the first component.
[0181] Further, the device capability of the first component further satisfies at least one of not supporting a digital certificate and not supporting asymmetric hardware acceleration.
[0182] Exemplarily, the first public key, the second public key, the public key of the generating component and the private key of the generating component are obtained through elliptic curve cryptography.
[0183] Furthermore, in the process of determining the first session key, the generating component also sends the above-mentioned second public key, the first private key and the public key of the generating component to the first component, wherein the second public key is used to generate the public key of the first component, the first private key is used to generate the private key of the first component, and the public key of the generating component is used by the first component to parse and obtain the business key of the first component.
[0184] That is, when the first component belongs to the second category, the generating component uses a certificateless public key protocol to determine the first session key. This allows the first component to locally determine the first session key based on the obtained second public key, the first private key, and the generating component's public key. This allows the first component to verify the authenticity of the public key (e.g., the first session key) without relying on a digital certificate. Furthermore, the first component has secure storage capabilities, enabling it to securely store the obtained relevant keys (e.g., the second public key, the first private key, etc.).
[0185] In order to make the description of the acquisition process of the first session key in case 2 clearer, the generating component is the component where KeyM is located, the first component is ECU i For example, the generating component is the generator of the business key of the first component. i The process of determining the first session key for secure communication includes two stages, namely the following stage one and stage two.
[0186] Phase 1: KeyM needs to assist ECU first i Generate ECU i Public-private key pair
[0187] ECU i The public and private key pair includes ECU i Public key and ECU i The private key.
[0188] ECU i Please refer to the generation process of the public and private key pair Figure 5 Flow chart of the process. Figure 5 This is a flowchart of a method for generating a public and private key pair of a component provided in an embodiment of the present application. Figure 5 ECU shown i The method for generating the public and private key pair is applied to KeyM and ECU i The method includes but is not limited to the following steps S501-S505.
[0189] S501: ECU i Generate a first public key.
[0190] For example, ECU iNegotiate with KeyM in advance to use elliptic curve cryptography to configure the system parameters locally. The system parameters include Among them, ε represents the elliptic curve group, n is a prime number, G is the n-order base point of the elliptic curve, and the elliptic curve In the finite field F q In the above, H() represents a hash function. For example, H() is configured as The use of elliptic curve cryptography for system parameter configuration is conducive to lightweight implementation of public key authenticity verification and can reduce the consumption of computing power during key generation.
[0191] For example, ECU i After executing the above system parameter configuration locally, ECU i The first public key is generated by the following formula (2).
[0192] X i =x i G Formula (2)
[0193] Among them, X i Indicates ECU i The first public key, x i is a random number, The parameter G can be referred to the above description and will not be repeated here. Formula (2) is only used as the ECU i An example of generating the first public key, which does not apply to ECU i The manner in which the first public key is generated constitutes a limitation.
[0194] S502: ECU i Send the first public key and ECU to KeyM i identification information.
[0195] ECU i The identification information is used to identify the ECU i ECU i The identification information is, for example, ECU i Part serial number, ECU i Component ID or ECU i IP address, etc.
[0196] Accordingly, KeyM receives the i The first public key and ECU i identification information.
[0197] S503: KeyM is ECU i Generate a second public key and a first private key.
[0198] Exemplarily, after KeyM locally executes the system parameter configuration described above, KeyM generates a private key of KeyM and a public key of KeyM, for example, the private key of KeyM The public key PK of KeyM KM = sk KM G.
[0199] Exemplarily, after KeyM locally executes the system parameter configuration described above, KeyM generates a second public key through the following formula (3).
[0200] P i = r i G formula (3)
[0201] wherein, P i represents the second public key of ECU i , r i is a random number, The parameter G can refer to the foregoing description and will not be described here. Formula (3) is only an example of KeyM generating the second public key of ECU i , and should not limit the way KeyM generates the second public key. i
[0202] In an implementation mode, KeyM generates the first private key of ECU i , including: KeyM obtains the public key of ECU i based on the first public key of ECU i and the second public key of ECU i ; KeyM obtains the hash value of ECU i based on the public key of ECU i and the identification information of ECU i ; and KeyM obtains the first private key of ECU i based on the private key of KeyM and the hash value of ECU i .
[0203] Exemplarily, the public key of ECU i obtained based on the first public key of ECU i and the second public key of ECU i means that the public key of ECU i is the sum of the first public key of ECU i and the second public key of ECU i , or the public key of ECU i is obtained by splicing the first public key of ECU i and the second public key of ECU i .
[0204] Exemplarily, KeyM generates the first private key through the following formula (4).
[0205]
[0206] Among them, PK i Indicates ECU i The public key of X i Indicates ECU i The first public key, P i Indicates ECU i The second public key, h i Indicates ECU i Hash value, ID i Indicates ECU i Identification information, p i Indicates ECU i The first private key, sk KM Represents the private key of KeyM, H(), r i Please refer to the above description for n, which will not be repeated here. Formula (4) is only used as KeyM for ECU i Generate ECU i This is an example of the first public key and does not limit the method in which KeyM generates the first private key.
[0207] As can be seen from formula (4), the hash function uses the identification information of the first component and the public key of the first component as input parameters. Compared with the hash function using the identification information of the first component, the first public key of the first component and the second public key of the first component as input parameters, the computational efficiency of the hash function can be improved.
[0208] S504: KeyM to ECU i Send the second public key, the first private key, and the public key of KeyM.
[0209] For example, KeyM generates a second public key based on the second public key generated by itself and the public key from ECU. i The first public key is generated by ECU i The public key is stored locally on the ECU i The public key and ECU i The correspondence between the identification information.
[0210] S505: ECU i Generate ECU based on the first public key and the second public key i The public key and the ECU generated according to the first private key i The private key.
[0211] For example, ECU i The public key is based on ECU i The first public key and ECU i The second public key is obtained by: ECUi The public key is ECU i The first public key and ECU i The sum of the second public key, or, ECU i The public key of ECU i The first public key and ECU i The second public key is obtained by concatenating the two.
[0212] In one implementation, the ECU i Generate ECU based on the first private key i Private key, including: ECU i According to ECU i Identification information and ECU i Get the public key of ECU i Hash value of ECU i According to the first private key and ECU i The hash value of ECU i The private key.
[0213] Here, ECU i Get ECU i The hash value is obtained by the hash algorithm and KeyM i The hash algorithm used when calculating the hash value is the same as that used when calculating the hash value, such as the above-mentioned H().
[0214] For example, ECU i Generate ECU by the following formula (5) i The private key.
[0215]
[0216] Among them, PK i Indicates ECU i The public key of X i Indicates ECU i The first public key, P i Indicates ECU i The second public key, h i Indicates ECU i Hash value, ID i Indicates ECU i Identification information, s i Indicates ECU i The private key, p i Indicates ECU i The first private key, x i Please refer to the relevant description of formula (2), which will not be repeated here. Formula (5) is only used as the ECU i Generate ECU i An example of a private key that does not correspond to ECUi The manner in which the private key is generated constitutes a limitation.
[0217] Accordingly, ECU i Locally save ECU i The public and private key pair, that is, the above (PK i , s i ).
[0218] From the above S501-S505, we can see that KeyM participates in ECU i Generation of public and private key pairs, ECU i Generate ECU i The public key of ECU is the second public key provided by KeyM. i Generate ECU i The private key of ECU is the first private key provided by KeyM. i The generation of public and private key pairs can enhance the security and credibility of communication between the two parties.
[0219] Phase 2: KeyM, ECU i Each locally determines a first session key
[0220] KeyM locally determines the first session key, including: KeyM determines the first session key according to the private key of KeyM, the public key of KeyM, and the ECU i Hash value and ECU i The public key of is used to obtain the first session key.
[0221] From the above, we can see that ECU i The public key is based on ECU i The first public key and ECU i The second public key, ECU i The hash value is based on the ECU i Public key and ECU i The identification information of ECU is obtained. i The first public key and ECU i The identification information comes from ECU i , ECU i The second public key is KeyM for ECU i generate.
[0222] Exemplarily, KeyM determines the first session key by the following formula (6).
[0223]
[0224] Among them, K Mi The key determined by KeyM for communication with ECU i First session key for secure communication, sk KMis a private key of KeyM, PK KM is a public key of KeyM, h i is a hash value of ECU i , PK i is a public key of ECU i , other parameters in formula (6) refer to the description of the corresponding parameters in the foregoing formula, and will not be described here.
[0225] ECU i locally determines a first session key, including: ECU i obtains the first session key according to a private key of ECU i and a public key of KeyM. Wherein, the public key of KeyM is from KeyM.
[0226] Exemplarily, ECU i determines the first session key through the following formula (7).
[0227] K iM = s i PK KM Formula (7)
[0228] Wherein, K iM is the first session key determined by ECU i for secure communication with KeyM, s i is a private key of ECU i , and PK KM is a public key of KeyM.
[0229] Based on the foregoing formula (6) and formula (7), from the foregoing PK KM = sk KM G, the expression of p i in formula (2), formula (3), formula (4), and the expression of s i in formula (5), the K Mi in formula (6) and the K iM in formula (7) are respectively deduced, and it can be known that K Mi = K iM = sk KM s i G.
[0230] The foregoing formula (6) and formula (7) are only an example of KeyM and ECU i each determining a first session key for communication between KeyM and ECU i , and a formula after deformation of formula (6) and formula (7) can also be used to determine the first session key for communication between KeyM and ECU iThe first session key of the communication between the two parties, no matter how the formula (6) and formula (7) are transformed, satisfies the K calculated locally by KeyM Mi With ECU i Locally calculated K iM equal.
[0231] From the above, it can be seen that KeyM does not need to transmit the first session key to ECU i , ECU i The first session key can be generated locally based on the information obtained from KeyM (ie, the second public key, the first private key and the public key of KeyM), and the first session key determined by KeyM is used by the ECU i The first session key determined locally is the same, so KeyM and ECU i The two parties have completed the negotiation of the first session key, which is used for KeyM and ECU i The encryption and decryption of subsequent communications between KeyM and ECU can be achieved through the first session key i secure communications.
[0232] In some possible embodiments, for two components within a vehicle that need to communicate, such as ECU_A and ECU_B, KeyM is the generator of both ECU_A's and ECU_B's service keys. ECU_A and ECU_B are not the generators of the corresponding service keys. In this case, if ECU_A and ECU_B need to communicate, they must also negotiate a first session key. This first session key is used for secure communication between ECU_A and ECU_B. The process for ECU_A and ECU_B to negotiate the first session key is described in steps B11-B14 below.
[0233] B11: ECU_A sends ECU_A's public key and ECU_A's identification information to ECU_B.
[0234] For example, the public key of ECU_A is Figure 5 The method shown in the embodiment is generated. Please refer to the aforementioned ECU for the identification information of ECU_A i The description of the identification information will not be repeated here.
[0235] B12: ECU_B sends ECU_B's public key and ECU_B's identification information to ECU_A.
[0236] For example, the public key of ECU_B is Figure 5 The method shown in the embodiment is generated. Please refer to the aforementioned ECU for the identification information of ECU_B iThe description of the identification information will not be repeated here.
[0237] B13: ECU_A generates a first session key based on ECU_A's private key, KeyM's public key, ECU_B's hash value, and ECU_B's public key. ECU_B's hash value is obtained by ECU_A based on ECU_B's public key and ECU_B's identification information.
[0238] Exemplarily, ECU_A determines the first session key using the following formula (8).
[0239]
[0240] Among them, h B is the hash value of ECU_B, ID B PK is the identification information of ECU_B B is the public key of ECU_B, K AB The first session key determined for ECU_A to communicate securely with ECU_B, s A ECU_A's private key, PK KM is the public key of KeyM.
[0241] B14: ECU_B generates a first session key based on ECU_B's private key, KeyM's public key, ECU_A's hash value, and ECU_A's public key. ECU_A's hash value is obtained by ECU_B based on ECU_A's public key and ECU_A's identification information.
[0242] Exemplarily, ECU_B determines the first session key using the following formula (9).
[0243]
[0244] Among them, h A is the hash value of ECU_A, ID A PK is the identification information of ECU_A A is the public key of ECU_A, K BA The first session key determined for ECU_B to communicate securely with ECU_A, s B ECU_B's private key, PK KM is the public key of KeyM.
[0245] The above formula (8) generates h B The hash algorithm used when generating h is the same as that in the above formula (9) A The hash algorithm used is the same as that used in the above formula (6). Mi The same derivation method is used to calculate K in formula (8): AB and K in formula (9)BA By deducing separately, we can know that K AB =K BA =s A s B G.
[0246] The above formula (8) and formula (9) are only used as an example for ECU_A and ECU_B to determine the first session key for communication between ECU_A and ECU_B. The first session key for communication between ECU_A and ECU_B can also be determined by using the modified formulas of formula (8) and formula (9). No matter how the formulas (8) and (9) are modified, the K calculated locally by ECU_A is satisfied. AB K calculated locally by ECU_B BA equal.
[0247] In some possible embodiments, for two components in a vehicle that have communication needs (for example, ECU_A and ECU_B), the generator of the business key of ECU_A and the generator of the business key of ECU_B may also be different. For example, the business key of ECU_A is generated by generating component 1 and the business key of ECU_B is generated by generating component 2. In this case, ECU_A and ECU_B may also locally negotiate the session key through the methods shown in B11-B14 above. In this case, the public-private key pair of KeyM used by generating component 1 to assist ECU_A in generating the public-private key pair of ECU_A is the same as the public-private key pair of KeyM used by generating component 2 to assist ECU_B in generating the public-private key pair of ECU_B.
[0248] Case 3: The first component belongs to the third category above
[0249] That is, the device capability of the first component does not have the secure storage capability. Further, the device capability of the first component also satisfies at least one of not supporting digital certificates and not supporting asymmetric hardware acceleration.
[0250] In scenario 3, in one implementation, the generation component determines the first session key based on the device capabilities of the first component, including generating a root key based on the prekey and identification information of the first component, and using the root key as the first session key. For details on the prekey and root key, please refer to the description of the root key in S301 above and will not be repeated here.
[0251] Exemplarily, the master key originates from a network-side device, or the master key is generated by a generating component.
[0252] In case 3, in another implementation, the generating component determines the first session key based on the device capability of the first component, including:
[0253] The generating component uses the master key as the first session key.
[0254] Furthermore, in case 3, the generation component also generates a decryption white-box code based on the first session key, and the generation component sends the decryption white-box code to the first component, wherein the decryption white-box code includes the first session key, and the decryption white-box code is used by the first component to parse and obtain the business key of the first component.
[0255] Illustratively, generating the decryption white-box code based on the first session key includes: generating the decryption white-box code based on the first session key and a white-box algorithm, where the decryption white-box code is the white-box algorithm mixed with the first session key. "Mixed" here can be understood to mean, for example, that the first session key itself is inserted into the white-box algorithm as a whole, or that the first session key is split into multiple parts and randomly inserted into the white-box algorithm.
[0256] The mixing method may be, for example, mixing the first session key and the white-box algorithm using internal obfuscation technology, or mixing the first session key and the execution process of the white-box algorithm using algebraic technology and transformation, etc., which are not specifically limited here. The white-box algorithm may be, for example, a dynamic white-box algorithm or a static white-box algorithm.
[0257] When the first component does not have a secure storage capability, the first session key and the algorithm code are obfuscated, and the decrypted white-box code obtained after the obfuscation is sent to the first component. The first component does not generate the first session key locally but decrypts it through the decryption white-box code. The decryption white-box code achieves secure storage of the first session key, thereby increasing the difficulty for an attacker to obtain the first session key. Even if the first component does not have a secure storage capability, the security of the key is improved.
[0258] Exemplarily, the generating component sends the decrypted white box code to the first component via the OTA upgrade channel. In other words, the decrypted white box code is carried in the OTA message.
[0259] S303: The generating component encrypts the service key of the first component using the first session key to obtain a first target key.
[0260] The first session key is used to encrypt the service key of the first component, thereby protecting the privacy and integrity of the service key. The first session key helps to achieve the secure distribution of the service key of the first component, thereby improving the security of the key.
[0261] S304: The generating component sends the first target key to the first component.
[0262] S305: The first component parses the first target key based on the device capability of the first component to obtain the service key of the first component.
[0263] In one implementation, the device capability of the first component includes support of digital certificate and support of asymmetric hardware acceleration (i.e., the first component belongs to the first type of component), and the first component obtains the service key of the first component based on the device capability of the first component by: the first component decrypts the first target key using a local first session key to obtain the service key of the first component. The first session key local to the first component is, for example, the pre-master key described in the "Case 1" of the foregoing S402.
[0264] In one implementation, the device capability of the first component includes support of secure storage (i.e., the first component belongs to the second type of component), and the first component obtains the service key of the first component based on the device capability of the first component by: the first component obtains a first session key according to a private key of the first component and a public key of the generation component; and the first component decrypts the first target key using the first session key to obtain the service key of the first component. Further, in this implementation, the device capability of the first component further satisfies at least one of not supporting digital certificate and not supporting asymmetric hardware acceleration.
[0265] The private key of the first component is obtained based on the first private key and a hash value of the first component, the hash value of the first component is obtained by hashing the identification information of the first component and the public key of the first component, the public key of the first component is obtained based on the first public key and the second public key, the first public key is generated by the first component, the second public key and the first private key correspond to the first component, the first private key, the second public key and the public key of the generation component are from the generation component, and the first private key is associated with the private key of the generation component and the hash value of the first component. The generation of the public-private key pair of the first component (i.e., the public key of the first component and the private key of the first component) is described in the foregoing Figure 5 The related descriptions of the embodiments are not repeated here.
[0266] In one implementation, the device capability of the first component does not include support of secure storage (i.e., the first component belongs to the third type of component), and the first component further receives a decrypted white-box code from the generation component, and the first component obtains the service key of the first component based on the device capability of the first component by: the first component locally flashes the decrypted white-box code; and the first component parses the first target key using the decrypted white-box code to obtain the service key of the first component. Further, in this implementation, the device capability of the first component further satisfies at least one of not supporting digital certificate and not supporting asymmetric hardware acceleration.
[0267] The decrypted white-box code is associated with the first session key, which is associated with the identification information of the first component. The business key of the first component is associated with the first session key and the identification information of the first component. For details on the decrypted white-box code and the first session key, refer to the description of "Case 3" in S402. For details on the generation of the business key of the first component, refer to the description of S301.
[0268] The above embodiment shows the process of the generation component generating the service key of the first component and the generation component securely distributing the service key of the first component. In some possible embodiments, the generation component can be responsible for the generation and secure distribution of service keys of multiple components.
[0269] As an example, the generation component generates a business key for the second component; the generation component determines a second session key based on the device capabilities of the second component; the generation component encrypts the business key of the second component using the second session key to obtain a second target key; and the generation component sends the second target key to the second component. Accordingly, the second component receives the second target key and parses the second target key based on the device capabilities of the second component to obtain the business key of the second component. The generation process of the business key of the second component refers to the description of the generation process of the business key of the first component, and the generation process of the second session key refers to the description of the generation process of the first session key, and will not be repeated here.
[0270] Among them, the first session key corresponds to the device capability of the first component, and the second session key corresponds to the device capability of the second component. If the device capability of the first component is different from the device capability of the second component (for example, the component type to which the first component belongs is different from the component type to which the second component belongs), the first session key and the second session key are also different.
[0271] In some possible embodiments, for different components of the same component type, if both the first component and the second component belong to the second category, the generation of the session key for the second category component is not only related to the device capabilities of the component but also to the component's identification information. Since the identification information of the first component is different from the identification information of the second component, the first session key and the second session key are also different. Therefore, different components also have different corresponding session keys.
[0272] above Figure 4In an embodiment, the generator of the business key of a component can determine a session key for each component of the vehicle, and use the session key corresponding to the component to encrypt and transmit the business key of the component to the corresponding component. The generator determines the session key based on the device capability of the component. The device capability of the component is used to describe the security characteristics of the device, which is beneficial to improving the security of key distribution. The device capabilities of the components are different, and the session keys corresponding to the components are different. Compared with the current production line key filling process, all components in the vehicle no longer share a session key. The business keys of different components are encrypted and transmitted using different session keys, which is beneficial to reducing the risk of key exposure and improving the security of key transmission. In addition, the generation of the business key of the component and the generation of the session key are both performed in the vehicle, so that the key does not leave the vehicle, which is also beneficial to improving the efficiency of key distribution in the vehicle.
[0273] See also Figure 6 , Figure 6 3 is a schematic diagram of the structure of a key generation device provided in an embodiment of the present application, wherein the key generation device 30 includes an acquisition unit 310, a processing unit 312, and a sending unit 314. The key generation device 30 can be implemented by hardware, software, or a combination of hardware and software.
[0274] The acquisition unit 310 is configured to acquire a first device capability of a first component, where the first device capability represents the security characteristics of the first component. The sending unit 314 is configured to send a first target key to the first component, where the first target key is generated by encrypting the first component's service key using the first session key by the processing unit 312, and the first session key corresponds to the first device capability. In some possible embodiments, the acquisition unit 310 is further configured to acquire a second device capability of a second component, where the second device capability represents the security characteristics of the second component. The sending unit 314 is further configured to send a second target key to the second component, where the second target key is generated by encrypting the second component's service key using the second session key by the processing unit 312, and the second session key corresponds to the second device capability. When the first device capability is different from the second device capability, the first session key is different from the second session key.
[0275] The key generating device 30 is used to implement, for example Figure 3 The method for generating the component side described in the embodiment. Figure 3 In the embodiment, the acquiring unit 310 and the processing unit 312 are used to execute S301 to S303 , and the sending unit 314 is used to execute S304 .
[0276] In some possible embodiments, the key generation device 30 is also used to implement Figure 4 The method for generating the component side described in the embodiment and Figure 5For the sake of brevity, the method on the KeyM side described in the embodiment will not be repeated here.
[0277] See also Figure 7 , Figure 7 4 is a schematic diagram of the structure of a key parsing device provided in an embodiment of the present application, wherein the key parsing device 40 includes a receiving unit 410 and a processing unit 412. The key parsing device 40 can be implemented by hardware, software, or a combination of hardware and software.
[0278] The receiving unit 410 is configured to receive a target key sent by the generating component, where the target key is a key obtained by encrypting the business key of the first component with the session key; the processing unit 412 is configured to parse the target key based on the device capability of the first component to obtain the business key of the first component; wherein the device capability of the first component is used to indicate the security characteristics of the first component.
[0279] The key analysis device 40 is used to implement, for example Figure 3 The method of the first component side is described in the embodiment. Figure 3 In the embodiment, the receiving unit 410 is used to execute S304 , and the processing unit 412 is used to execute S305 .
[0280] In some possible embodiments, the key parsing device 40 is also used to implement Figure 4 The method of the first component side described in the embodiment and Figure 5 ECU described in the embodiment i For the sake of brevity of the description, the method of the side is not described here.
[0281] It should be understood that the division of each unit in the above device (for example, the key generation device 30 and the key resolution device 40) is only a logical division of functions, and in actual implementation, all or part of the units can be integrated into one physical entity, or can be physically separated. In addition, the units in the device can be implemented in the form of processor calling software; for example, the device includes a processor, the processor is connected with a memory, the memory stores instructions, and the processor calls the instructions stored in the memory to implement any one of the above methods or to implement the functions of the units of the device, wherein the processor is, for example, a general-purpose processor such as a central processing unit (CPU) or a microprocessor, and the memory is a memory in the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuit, and the functions of part or all of the units can be implemented through the design of the hardware circuit, which can be understood as one or more processors; for example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC), and the functions of part or all of the units are implemented through the design of the logical relationship between the elements in the circuit; for example, in another implementation, the hardware circuit is a programmable logic device (PLD), and taking a field programmable gate array (FPGA) as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured through a configuration file, so as to implement the functions of part or all of the units. All units of the above device can be implemented in the form of processor calling software, or all units can be implemented in the form of hardware circuit, or part of the units can be implemented in the form of processor calling software, and the remaining part can be implemented in the form of hardware circuit.
[0282] In an embodiment of the present application, a processor is a circuit with a signal processing capability. In one implementation, the processor can be a circuit with instruction reading and execution capability, such as a central processing unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationship of a hardware circuit. The logical relationship of the hardware circuit is fixed or reconfigurable, such as a hardware circuit implemented by a processor as an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the processor loads a configuration document to implement the process of hardware circuit configuration, which can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a neural network processing unit (NPU), a tensor processing unit (TPU), a deep learning processing unit (DPU), etc.
[0283] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above method, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.
[0284] In addition, the various units in the above devices can be fully or partially integrated together, or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of a system-on-a-chip (SOC). The SOC may include at least one processor for implementing any of the above methods or implementing the functions of the various units of the device. The type of the at least one processor can be different, for example, including a CPU and FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.
[0285] See also Figure 8 , Figure 8 This is a schematic diagram of the structure of a key processing device provided in an embodiment of the present application. Figure 8As shown, the key processing device 50 includes a processor 501, a communication interface 502, a memory 503, and a bus 504. The processor 501, the memory 503, and the communication interface 502 communicate with each other via the bus 504. It should be understood that the present application does not limit the number of processors and memories in the key processing device 50.
[0286] In one implementation, the key processing device 50 is a network-side device, such as a computing device, a computing device cluster, or a terminal device. The network-side device can be deployed in a cloud environment or an edge environment. Figure 1 The relevant description of the network side device 20 is omitted here.
[0287] In one implementation, the key processing device 50 is a terminal or a component within a terminal. Taking the terminal as a vehicle as an example, the component within the vehicle is, for example, a domain controller DC, a vehicle integrated unit VIU, an electronic control unit ECU, or a telematics processor TBox. In some possible embodiments, the key processing device 50 may also be a component within a component, such as a chip or an integrated circuit. For terminal, please refer to Figure 1 The description of the terminal 10 will not be repeated here.
[0288] The bus 504 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 The bus 504 may include a path for transmitting information between various components of the key processing device 50 (eg, the memory 503, the processor 501, and the communication interface 502).
[0289] The processor 501 can refer to the relevant description of the processor in the above embodiment, which will not be repeated here.
[0290] Memory 503 is used to provide storage space for storing data such as the operating system and computer programs. Memory 503 can be one or a combination of random access memory (RAM), erasable programmable read-only memory (EPROM), read-only memory (ROM), or compact disc read-only memory (CD-ROM). Memory 503 can exist independently or be integrated into processor 501.
[0291] The communication interface 502 can be used to provide information input or output for the processor 501. Alternatively, the communication interface 502 can be used to receive data transmitted externally and / or transmit data externally. It can be a wired link interface such as an Ethernet cable, or a wireless link interface (such as Wi-Fi, Bluetooth, general wireless transmission, etc.). Alternatively, the communication interface 502 can also include a transmitter (such as a radio frequency transmitter, antenna, etc.) or a receiver coupled to the interface.
[0292] The processor 501 in the key processing device 50 is used to read the computer program stored in the memory 503 to execute the above method, for example Figure 3 、 Figure 4 or Figure 5 Methods for either side are described.
[0293] In a possible design, the key processing device 50 may be a device for executing Figure 3 One or more modules in the execution body (e.g., generating component) of the method shown, the processor 501 can be used to read one or more computer programs stored in the memory to perform the following operations:
[0294] Acquiring, by the acquisition unit 310, a first device capability of the first component, where the first device capability is used to represent a security feature of the first component;
[0295] Sending a first target key to the first component through the sending unit 314, where the first target key is generated by encrypting the service key of the first component using the first session key;
[0296] Acquiring, by the acquiring unit 310, a second device capability of the second component, where the second device capability is used to represent a security feature of the second component;
[0297] Sending a second target key to the second component through the sending unit 314, where the second target key is generated by encrypting the service key of the second component using the second session key;
[0298] The first device capability corresponds to the first session key, the second device capability corresponds to the second session key, the first device capability is different from the second device capability, and the first session key is different from the second session key. The business key of the first component, the first session key, the business key of the second component, and the second session key are generated by the processing unit 312.
[0299] In a possible design, the key processing device 50 may be a device for executing Figure 3 One or more modules in the execution body (e.g., the first component) of the method shown, the processor 501 can be used to read one or more computer programs stored in the memory to perform the following operations:
[0300] Receive the target key sent by the generating component through the receiving unit 410, where the target key is a key obtained by encrypting the service key of the first component with the session key;
[0301] The target key is parsed based on the device capability of the first component to obtain the service key of the first component; wherein the device capability of the first component is used to represent the security characteristics of the first component.
[0302] In the embodiments described above, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a particular embodiment, please refer to the relevant descriptions of other embodiments. In addition, in the various embodiments of this application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between the various embodiments are consistent and can be referenced to each other. The technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.
[0303] It should be noted that, those skilled in the art can see that all or part of the steps in the various methods of the above embodiments can be completed by a program to instruct relevant hardware. The program can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.
[0304] The technical solution of the present application may essentially or contribute to the part or all or part of the technical solution in the form of a software product. The computer program product is stored in a storage medium and includes a number of instructions for enabling a device (which may be a personal computer, a server, or a network device, a robot, a single-chip microcomputer, a chip, a robot, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
Claims
1. A key distribution method, characterized in that: Applied to generating a component, the method includes: Obtaining a first device capability of a first component, where the first device capability is used to represent a security feature of the first component; Sending a first target key to the first component, wherein the first target key is generated by encrypting a service key of the first component using a first session key; Obtaining a second device capability of the second component, where the second device capability is used to represent a security feature of the second component; Sending a second target key to the second component, wherein the second target key is generated by encrypting the service key of the second component using the second session key; The first device capability corresponds to the first session key, the second device capability corresponds to the second session key, the first device capability is different from the second device capability, and the first session key is different from the second session key.
2. The method according to claim 1, characterized in that The generating component, the first component, and the second component are disposed within a vehicle.
3. The method according to claim 2, characterized in that The generating component is the component where the key management module in the vehicle is located, and / or the first component and the second component are respectively hung below the generating component.
4. The method according to any one of claims 1 to 3, characterized in that Before sending the first target key to the first component, the method further includes: determining, based on the first device capability, a first session key, where the first session key is used for secure communication between the generating component and the first component; generating a service key for the first component; The service key of the first component is encrypted using the first session key to obtain the first target key.
5. The method according to claim 4, characterized in that Determining the first session key based on the first device capability includes: The first device capability includes a secure storage capability, and receives the first public key and identification information of the first component sent by the first component; Obtaining the first session key according to the public key of the first component, the hash value of the first component, the public key of the generating component, and the private key of the generating component; The public key of the generating component corresponds to the private key of the generating component, the public key of the first component is obtained based on the first public key and the second public key, the second public key is generated by the generating component for the first component, and the hash value of the first component is obtained by performing a hash operation on the identification information of the first component and the public key of the first component.
6. The method according to claim 5, characterized in that The method further comprises: The second public key, the first private key and the public key of the generating component are sent to the first component, the second public key is used to generate the public key of the first component, the first private key is used to generate the private key of the first component, and the public key of the generating component is used by the first component to parse the first target key.
7. The method according to claim 4, characterized in that The generating component is the component where the key management module in the vehicle is located. Determining the first session key based on the first device capability includes: The first device capability does not include secure storage capability, and the first session key is generated according to the identification information of the first component and a master key, where the master key is generated by the generating component or comes from a network-side device; Generating the service key of the first component includes: generating a service key of the first component according to the identification information of the first component and the first session key; The method further comprises: generating a decryption white-box code based on the first session key, the decryption white-box code including the first session key, the decryption white-box code being used to restore the first target key to the business key of the first component; The decrypted white-box code is sent to the first component.
8. The method according to any one of claims 1 to 7, characterized in that The generating component includes a first generating component and a second generating component, wherein the first generating component is hung below the first generating component and the second generating component is hung below the second generating component. The acquiring of the first device capability of the first component and the sending of the first target key to the first component are performed by the first generating component, and the first session key, the service key of the first component and the first target key are generated by the first generating component; The acquiring of the second device capability of the second component and the sending of the second target key to the second component are performed by the second generating component, and the second session key, the service key of the second component and the second target key are generated by the second generating component.
9. A key analysis method, characterized in that: Applied to the first component, the method comprises: receiving a target key sent by a generating component, wherein the target key is a key obtained by encrypting the service key of the first component with a session key; parsing the target key based on the device capability of the first component to obtain a service key of the first component; The device capability of the first component is used to represent the security characteristics of the first component.
10. The method according to claim 9, characterized in that The first component and the generating component are disposed within a vehicle.
11. The method according to claim 10, characterized in that The generating component is the component where the key management module in the vehicle is located, and / or the first component is hung below the generating component.
12. The method according to any one of claims 9 to 11, characterized in that: The parsing the target key based on the device capability of the first component to obtain the service key of the first component includes: The device capability of the first component includes a secure storage capability, and the session key is obtained based on the private key of the first component and the public key of the generating component; parsing the target key using the session key to obtain the service key of the first component; The private key of the first component is obtained based on the first private key and the hash value of the first component, the hash value of the first component is obtained by performing a hash operation on the identification information of the first component and the public key of the first component, the public key of the first component is obtained based on the first public key and the second public key, the first public key is generated by the first component, the second public key and the first private key correspond to the first component, the first private key, the second public key and the public key of the generating component come from the generating component, and the first private key is associated with the private key of the first component and the hash value of the first component.
13. The method according to any one of claims 9 to 11, characterized in that: The parsing the target key based on the device capability of the first component to obtain the service key of the first component includes: The device capability of the first component does not include secure storage capability, and a decryption white box code is locally flashed, the decryption white box code comes from the generating component, and the decryption white box code includes the session key; parsing the target key using the decryption white box code to obtain the business key of the first component; The service key of the first component is associated with the session key and the identification information of the first component, and the session key is associated with the identification information of the first component.
14. A key distribution device, characterized in that: The device is a generating component, and the device includes: an acquiring unit, configured to acquire a first device capability of a first component, where the first device capability is used to represent a security feature of the first component; A sending unit, configured to send a first target key to the first component, wherein the first target key is generated by encrypting a service key of the first component using a first session key by a processing unit; The acquiring unit is further configured to acquire a second device capability of the second component, where the second device capability is used to represent a security feature of the second component; The sending unit is further configured to send a second target key to the second component, wherein the second target key is generated by encrypting the service key of the second component by the processing unit using the second session key; The first device capability corresponds to the first session key, the second device capability corresponds to the second session key, the first device capability is different from the second device capability, and the first session key is different from the second session key.
15. The device according to claim 14, characterized in that The generating component, the first component, and the second component are disposed within a vehicle.
16. The device according to claim 15, characterized in that The generating component is the component where the key management module in the vehicle is located, and / or the first component and the second component are respectively hung below the generating component.
17. The device according to any one of claims 14 to 16, characterized in that The processing unit is used for: determining, based on the first device capability, a first session key, where the first session key is used for secure communication between the generating component and the first component; generating a service key for the first component; The service key of the first component is encrypted using the first session key to obtain the first target key.
18. The device according to claim 17, characterized in that The processing unit is specifically configured to: The first device capability includes a secure storage capability, and receives the first public key and identification information of the first component sent by the first component; Obtaining the first session key according to the public key of the first component, the hash value of the first component, the public key of the generating component, and the private key of the generating component; The public key of the generating component corresponds to the private key of the generating component, the public key of the first component is obtained based on the first public key and the second public key, the second public key is generated by the generating component for the first component, and the hash value of the first component is obtained by performing a hash operation on the identification information of the first component and the public key of the first component.
19. The device according to claim 18, characterized in that The sending unit is further configured to: The second public key, the first private key and the public key of the generating component are sent to the first component, the second public key is used to generate the public key of the first component, the first private key is used to generate the private key of the first component, and the public key of the generating component is used by the first component to parse the first target key.
20. The device according to claim 17, wherein The generating component is the component where the key management module in the vehicle is located, and the processing unit is specifically used to: The first device capability does not include secure storage capability, and the first session key is generated according to the identification information of the first component and a master key, where the master key is generated by the generating component or comes from a network-side device; generating a service key of the first component according to the identification information of the first component and the first session key; generating a decryption white-box code based on the first session key, the decryption white-box code including the first session key, the decryption white-box code being used to restore the first target key to the business key of the first component; The sending unit is further configured to send the decrypted white-box code to the first component.
21. The device according to any one of claims 14 to 20, characterized in that The generating component includes a first generating component and a second generating component, the first component is hung below the first generating component, and the second component is hung below the second generating component, the acquiring unit includes a first acquiring unit of the first generating component and a second acquiring unit of the second generating component, and the sending unit includes a first sending unit of the first generating component and a second sending unit of the second generating component; The first acquiring unit is configured to acquire the first device capability of the first component; The first sending unit is configured to send the first target key to the first component; The second acquiring unit is configured to acquire the second device capability of the second component; The second sending unit is configured to send the second target key to the second component; The processing unit includes a first processing unit of the first generating component and a second processing unit of the second generating component, wherein: The first session key, the service key of the first component, and the first target key are generated by the first processing unit; The second session key, the service key of the second component, and the second target key are generated by the second processing unit.
22. A key analysis device, characterized in that: The device is a first component, and the device includes: A receiving unit, configured to receive a target key sent by the generating component, wherein the target key is a key obtained by encrypting the service key of the first component with the session key; a processing unit, configured to parse the target key based on the device capability of the first component to obtain a service key of the first component; The device capability of the first component is used to represent the security characteristics of the first component.
23. The device according to claim 22, characterized in that The first component and the generating component are disposed within a vehicle.
24. The device according to claim 23, characterized in that The generating component is the component where the key management module in the vehicle is located, and / or the first component is hung below the generating component.
25. The device according to any one of claims 22 to 24, characterized in that The processing unit is specifically configured to: The device capability of the first component includes a secure storage capability, and the session key is obtained based on the private key of the first component and the public key of the generating component; parsing the target key using the session key to obtain the service key of the first component; The private key of the first component is obtained by the processing unit based on the first private key and the hash value of the first component. The hash value of the first component is obtained by the processing unit performing a hash operation on the identification information of the first component and the public key of the first component. The public key of the first component is obtained by the processing unit based on the first public key and the second public key. The first public key is generated by the first component, the second public key and the first private key correspond to the first component, the first private key, the second public key and the public key of the generating component come from the generating component, and the first private key is associated with the private key of the first component and the hash value of the first component.
26. The device according to any one of claims 22 to 24, characterized in that The processing unit is specifically configured to: The device capability of the first component does not include secure storage capability, and a decryption white box code is locally flashed, the decryption white box code comes from the generating component, and the decryption white box code includes the session key; parsing the target key using the decryption white box code to obtain the business key of the first component; The service key of the first component is associated with the session key and the identification information of the first component, and the session key is associated with the identification information of the first component.
27. A chip, characterized in that: The chip includes a memory and at least one processor, the memory stores computer program instructions, and the at least one processor executes the computer program instructions to enable the chip to perform the method according to any one of claims 1 to 8.
28. An electronic control unit, characterized in that: The chip includes a memory and at least one processor, the memory stores computer program instructions, and the at least one processor executes the computer program instructions to enable the chip to perform the method according to any one of claims 9 to 13.
29. A key distribution system, characterized in that: The system includes a first device and a second device, wherein the first device is used to implement the method according to any one of claims 1 to 8, and the second device is used to implement the method according to any one of claims 9 to 13.
30. A vehicle, characterized in that: The vehicle comprises the apparatus according to any one of claims 14 to 28, or comprises the system according to claim 29.
31. A computer-readable storage medium, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the method according to any one of claims 1 to 8, or implement the method according to any one of claims 9 to 13.