Controller authentication method, system, and vehicle
Patent Information
- Application Number
- CN202511574826.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-31
- Publication Date
- 2026-09-11
- Estimated Expiration
- 2045-10-31
AI Technical Summary
[0003]本申请实施例提供一种控制器认证方法、系统及车辆,以解决相关技术中车辆的控制器被随意更换为第三方控制器或者被随意拆除,可能导致车辆稳定性不佳,甚至影响行车安全、威胁用户权益,亟需对车辆控制器进行认证的方案的技术问题
Smart Images

Figure CN121037133B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle control technology, and in particular to a controller authentication method, system, and vehicle. Background Technology
[0002] Vehicle safety has always been a major concern. With the increasing intelligence of automobiles, controllers play a crucial role in ensuring vehicle safety and performance. Recently, some vehicles have seen official components replaced with third-party samples, or even removed altogether. If a vehicle's controller is arbitrarily replaced with another third-party controller, or if it is removed and used directly as a third-party sample, or if the vehicle is driven without a portion of its controller, it may lead to poor vehicle stability, even affecting driving safety and threatening user rights. Therefore, there is an urgent need for a solution that can certify vehicle controllers. Summary of the Invention
[0003] This application provides a controller authentication method, system, and vehicle to address the technical problem in the related art where the vehicle controller is arbitrarily replaced with a third-party controller or arbitrarily removed, which may lead to poor vehicle stability, or even affect driving safety and threaten user rights, thus necessitating a solution for authenticating the vehicle controller.
[0004] This application provides a controller authentication method, the method comprising: after a vehicle is powered on, an authentication server interacts with the controller to be authenticated of the vehicle via message exchange of authentication-related data; if the controller to be authenticated determines first vehicle-side verification data and second vehicle-side verification data based on the authentication-related data, the vehicle's vehicle safety module determines a vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data; and the authentication server determines a server-side verification result based on the second vehicle-side verification data and the second server-side verification data, wherein the first server-side verification data and the second server-side verification data are obtained by the authentication server based on the authentication-related data; and the authentication result of the controller to be authenticated is determined based on the vehicle-side verification result and the server-side verification result.
[0005] In one embodiment of this application, the method further includes: if the vehicle safety module does not obtain the first vehicle-side verification data and / or the second vehicle-side verification data, determining the vehicle-side verification result as a vehicle-side verification failure.
[0006] In one embodiment of this application, the determination of the first vehicle-side verification data, the second vehicle-side verification data, the first server-side verification data, and the second server-side verification data includes: the controller security module of the controller to be authenticated determines the first vehicle-side verification data based on the vehicle-side key and the first authentication sub-data; the controller security module determines the second vehicle-side verification data based on the vehicle-side key and the second authentication sub-data; the authentication server determines the first server-side verification data based on the server-side key and the first authentication sub-data; the authentication server determines the second server-side verification data based on the server-side key and the second authentication sub-data; wherein, the authentication-related data includes the first authentication sub-data and the second authentication sub-data, and the vehicle-side key is stored in the controller security module.
[0007] In one embodiment of this application, before the vehicle security module of the vehicle determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data, the method further includes: the authentication server sending the first server-side verification data to the vehicle; before the authentication server determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data, the method further includes: the vehicle sending the second vehicle-side verification data to the authentication server.
[0008] In one embodiment of this application, the authentication server interacts with the vehicle's controller to be authenticated via message exchange of authentication-related data, including: the controller to be authenticated sending an authentication request, the authentication request including first controller data; the authentication server responding to the authentication request generating a first random number and a second random number, and feeding back the first random number and the second random number to the vehicle, the first authentication sub-data including the first random number and the first controller data to be authenticated, and the second authentication sub-data including the second random number and the random number timestamp of the second random number.
[0009] In one embodiment of this application, before the authentication server interacts with the controller to be authenticated of the vehicle to exchange authentication-related data, the method further includes: when the vehicle is off the production line, the authentication server obtains the key seed data of the controller to be authenticated in the production line system, generates an initial vehicle key based on the key seed data, and sends the initial vehicle key to the vehicle; the initial vehicle key is recorded as a vehicle-side key and written into the controller security module corresponding to the controller to be authenticated when the vehicle is off the production line; the authentication server generates evidence storage data based on the initial vehicle key and the controller identifier, and sends the evidence storage data to the blockchain to store the evidence storage data through the blockchain, and records the initial vehicle key in the evidence storage data as a server-side key.
[0010] In one embodiment of this application, after determining the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result, the method further includes, if the authentication result is authentication failure, triggering the execution of a controller authentication failure control strategy; wherein, the controller authentication failure control strategy includes at least one of the following: controlling the vehicle to self-destruct the stored vehicle-side key; locking the controller to be authenticated; generating authentication failure data based on the authentication failure time identifier, authentication result, vehicle-side key fingerprint, vehicle identifier and current location, generating an evidence hash based on the authentication failure data, uploading the authentication failure data and the evidence hash to the blockchain, and generating the vehicle-side key fingerprint based on the vehicle-side key.
[0011] In one embodiment of this application, the vehicle-side key is stored in the controller security module, and the method further includes: acquiring removal monitoring data of the controller to be authenticated; determining the removal status of the controller to be authenticated based on the removal monitoring data; if the removal status is removal, self-destructing the vehicle-side key stored in the controller security module by means of voltage overload or overwriting; wherein, the removal monitoring data includes the outer shell pressure value and / or the inner shell light intensity value, the outer shell pressure value is collected by a pressure sensor disposed on the outer shell of the controller to be authenticated, and the inner shell light intensity value is collected by a photosensitive sensor disposed on the inner side of the outer shell of the controller to be authenticated.
[0012] This application embodiment also provides a controller authentication system, the system including a vehicle, an authentication server, and an authentication result determination module. The vehicle includes a controller to be authenticated and a vehicle safety module, wherein: the authentication server and the controller to be authenticated are used to exchange messages for authentication-related data after the vehicle is powered on; the vehicle safety module is used to determine a vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data if the controller to be authenticated determines first vehicle-side verification data and second vehicle-side verification data according to the authentication-related data; the authentication server is used to determine a server-side verification result based on the second vehicle-side verification data and the second server-side verification data, wherein the first server-side verification data and the second server-side verification data are determined by the authentication server based on the authentication-related data; the authentication result determination module is used to determine the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result.
[0013] This application embodiment also provides a vehicle, the vehicle including a controller to be authenticated, a vehicle security module, and an authentication result execution module, wherein: the controller to be authenticated is used to perform message interaction with an authentication server on authentication-related data after the vehicle is powered on; the vehicle security module is used to determine a vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data if the controller to be authenticated determines first vehicle-side verification data and second vehicle-side verification data according to the authentication-related data; the authentication result execution module is used to control the controller to be authenticated according to the authentication result, the authentication result being determined based on the vehicle-side verification result and the server-side verification result, the server-side verification result being determined by the authentication server based on the second vehicle-side verification data and the second server-side verification data, and the first server-side verification data and the second server-side verification data being obtained by the authentication server based on the authentication-related data.
[0014] This application also provides an electronic device, including: a memory storing a computer program thereon; and a processor for executing the computer program in the memory to implement the steps of the method described in any of the above embodiments.
[0015] This invention also provides a computer-readable storage medium having a computer program stored thereon, the computer program being used to cause a computer to perform the method provided in any of the above embodiments.
[0016] The beneficial effects of this application are as follows: The controller authentication method, system, and vehicle proposed in this application involve message interaction between the authentication server and the controller to be authenticated in the vehicle after the vehicle is powered on. If the controller to be authenticated determines the first vehicle-side verification data and the second vehicle-side verification data based on the authentication-related data, the vehicle's vehicle safety module determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data. Furthermore, the authentication server determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data. The first and second server-side verification data are obtained by the authentication server based on the authentication-related data. The authentication result of the controller to be authenticated is determined based on the vehicle-side verification result and the server-side verification result. This provides a two-way authentication method between the controller to be authenticated and the authentication server, ensuring the reliability of the authentication. It can promptly and accurately detect situations where the controller has been removed or replaced. This provides a method for authenticating the controller before the vehicle is driven. The authentication result allows for the execution of corresponding control strategies on the vehicle, improving driving safety, enhancing vehicle stability, and protecting user rights. Attached Figure Description
[0017] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application. It is obvious that the drawings described below are merely some embodiments of this application, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0018] In the attached diagram: Figure 1 This is a schematic diagram illustrating an application scenario for controller authentication provided in an embodiment of this application; Figure 2 A schematic flowchart of a controller authentication method provided in one embodiment of this application; Figure 3 A system architecture diagram of a controller authentication system provided in an embodiment of the present invention; Figure 4 A system diagram illustrating an example of a controller authentication method provided in an embodiment of this application; Figure 5 A schematic flowchart illustrating a controller authentication method provided in an embodiment of this application; Figure 6 A schematic diagram illustrating a specific process of data uploading to the blockchain in a controller authentication method provided in an embodiment of this application; Figure 7 A schematic diagram of the controller authentication system provided in one embodiment of this application; Figure 8 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] The following specific examples illustrate the implementation of this application. Those skilled in the art can easily understand other advantages and effects of this application from the content disclosed in this specification. This application can also be implemented or applied through other different specific embodiments. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this application. In the absence of conflict, the following embodiments and features in the embodiments can be combined with each other.
[0020] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this application. The drawings only show the components related to this application and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the shape, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0021] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the present application. However, it will be apparent to those skilled in the art that embodiments of the present application may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the present application.
[0022] With the increasing intelligence of automobiles, many official components have been forcibly removed, and third-party samples have been arbitrarily installed, leading to decreased vehicle stability, affecting driving safety, and threatening user rights. Ensuring that components are official has become an urgent issue to be addressed. In some vehicles, the original controller has been removed or replaced with a third-party controller. The relevant technology often does not certify the controller, and it is directly powered on and used. Driving without proper certification may result in a poor driving experience or even affect driving safety.
[0023] In view of this, a controller authentication method, system, and vehicle are proposed. This method involves the authentication server exchanging authentication-related data with the controller to be authenticated after the vehicle is powered on. If the controller to be authenticated determines first vehicle-side verification data and second vehicle-side verification data based on the authentication-related data, the vehicle's safety module determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data. Furthermore, the authentication server determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data. The first and second server-side verification data are obtained by the authentication server based on the authentication-related data. The authentication result of the controller to be authenticated is determined based on the vehicle-side verification result and the server-side verification result. This provides a two-way authentication method between the controller to be authenticated and the authentication server, ensuring authentication reliability and enabling timely and accurate detection of controller removal or replacement. It provides a method for authenticating the controller before vehicle operation. The authentication result allows for the execution of corresponding control strategies on the vehicle, improving driving safety, vehicle stability, and protecting user rights.
[0024] Please see Figure 1 , Figure 1 This is a schematic diagram illustrating an application scenario for controller authentication provided in an embodiment of this application. For example... Figure 1As shown, vehicle 110 includes a controller 111 and a vehicle safety module 112. Vehicle 110 can communicate with authentication server 120. When vehicle 110 is powered on, the controller and authentication server exchange a series of authentication-related data messages. During this process, if the controller is illegally replaced, either the controller cannot provide the first and second vehicle-side verification data, in which case the authentication result can be directly determined as authentication failure; or the first and second vehicle-side verification data provided by the controller are incorrect, so the vehicle safety module can determine the vehicle-side verification result and perform verification. To further ensure the reliability of the authentication result, server-side verification can also be performed through the authentication server to obtain the server-side verification result. Then, the vehicle-side verification result and the server-side verification result are comprehensively evaluated to obtain the authentication result. This two-way authentication method between the controller and the authentication server ensures the reliability of the authentication, can promptly and accurately detect situations where the controller has been removed or replaced, and provides a method for authenticating the controller before the vehicle is driven. Based on the authentication result, corresponding control strategies can be executed on the vehicle, which can improve driving safety, improve vehicle stability, and protect user rights.
[0025] It should be noted that the above scenario is only an example of an application scenario provided by the embodiments of this application. The embodiments of this application do not limit the actual form of various devices, components, etc. included in the scenario. In the specific application of the solution, it can be set according to actual needs. Please see Figure 2 , Figure 2 A schematic flowchart of a controller authentication method provided in one embodiment of this application is shown below. Figure 2 As shown, the method includes the following steps: In step S210, after the vehicle is powered on, the authentication server and the vehicle's controller to be authenticated exchange messages related to authentication data.
[0026] As an example, this step can be triggered after the vehicle is powered on but before it begins to drive. Alternatively, it can be triggered at a time specified by someone skilled in the art. The controller to be authenticated can be a controller in the vehicle selected by someone skilled in the art. That is, the method may not be executed on all controllers in the vehicle, but only on the controller selected by someone skilled in the art. The controller to be authenticated is configured with a corresponding controller security module, such as HSM (Hardware Security Module) hardware or eSE (embedded Secure Element) hardware.
[0027] In one embodiment, the authentication server interacts with the vehicle's controller to be authenticated via message exchange of authentication-related data, including: the controller to be authenticated sending an authentication request, the authentication request including first controller data; the authentication server responding to the authentication request generating a first random number and a second random number, and feeding back the first random number and the second random number to the vehicle, the first authentication sub-data including the first random number and the first controller data to be authenticated, and the second authentication sub-data including the second random number and the random number timestamp of the second random number.
[0028] As an example, the first controller data to be certified includes sensor data used to detect whether the controller has been disassembled. This sensor data can reveal whether the controller has been forcibly removed or modified.
[0029] As another example, the first controller data to be authenticated can also be data collected or generated by the controller itself.
[0030] As another example, the first controller data to be authenticated can also be relevant data specified by those skilled in the art.
[0031] As an example, authentication-related data characterizes the data used for controller authentication, such as an authentication request (which carries first controller data to be authenticated), a first random number, a second random number, and a random number time identifier for the second random number.
[0032] In one embodiment, if there are multiple controllers to be certified in the vehicle, they can be categorized into two types based on the ease of disassembly: detachable controllers (easier to disassemble) and non-detachable controllers (more difficult to disassemble). The specific definition of the ease of disassembly can be flexibly formulated by those skilled in the art as needed. If the controller to be certified is a detachable controller, to further ensure the reliability of data transmission, the data interaction between the controller to be certified and the certification server can be transmitted through a reliable non-detachable controller. See the following examples for further details. Figure 4The relevant description is as follows: After the vehicle is powered on, the controller to be certified senses this and sends an authentication request to the authentication server. As an example, this authentication request includes the controller identifier of the controller to be certified and the sensor status. The sensor status refers to the real-time data collected by tamper-proof sensors (such as pressure sensors or photosensitive sensors) embedded in the ECU housing. These sensor statuses are used to detect physical removal of the ECU and trigger a key self-destruct mechanism. Then, upon receiving the authentication request, the authentication server generates a first random number and a second random number based on the request, and feeds these two random numbers back to the vehicle. The first authentication sub-data includes the first random number and the first controller data to be certified, and the second authentication sub-data includes the random number timestamp of the second random number and the second random number. As an example, the controller identifier can be a unique, unalterable hardware ID (such as a serial number) written to each ECU at the factory.
[0033] As another example, the second authentication sub-data includes a first random number and first controller data to be authenticated, wherein the first authentication sub-data includes a second random number and a random number time identifier of the second random number. The specific authentication sub-data can also be selected based on the needs of those skilled in the art.
[0034] In one embodiment, before the authentication server and the vehicle's controller to be authenticated exchange messages related to authentication data, the method further includes: when the vehicle rolls off the production line, the authentication server obtains the key seed data of the controller to be authenticated in the production line system, generates an initial vehicle key based on the key seed data, and sends the initial vehicle key to the vehicle; the initial vehicle key is recorded as the vehicle-side key and written into the controller security module corresponding to the controller to be authenticated when the vehicle rolls off the production line; the authentication server generates evidence storage data based on the initial vehicle key and the controller identifier, and sends the evidence storage data to the blockchain to store the evidence storage data, and records the initial vehicle key in the evidence storage data as the server-side key. Furthermore, the encryption algorithm needs to be synchronized so that the controller and the server subsequently use the same encryption algorithm to calculate the verification data.
[0035] As an example, the blockchain also stores key fingerprints generated based on the server-side key.
[0036] As an example, the key seed can be obtained in ways including but not limited to the following: when a vehicle rolls off the production line, the electrical inspection equipment obtains the key seed through the production line PLC (Programmable Logic Controller) system. The key seed may include at least one of the following: a unique controller identifier, a production timestamp, or a unique vehicle identifier.
[0037] For example, one way to generate the initial vehicle key is to use a key seed as the controller identifier and during production. Taking the time stamp as an example, the controller identifier, production timestamp, and generated random salt value are first concatenated to obtain concatenated basic data. Based on this concatenated basic data, a one-way irreversible hash is generated. Then, the one-way irreversible hash is truncated, for example, truncated to 257 bits, to obtain the initial vehicle key.
[0038] Taking a solution where the server-side key is stored on the blockchain and the controller to be authenticated is the vehicle's ECU (Electronic Control Unit) as an example, please refer to [link to relevant documentation]. Figure 3 , Figure 3 This is a system architecture diagram of a controller authentication system provided in an embodiment of the present invention. Figure 3 As shown, the system includes a vehicle ECU, an authentication server, a BAAS gateway, and multiple blockchain nodes (the number is not limited). Figure 3 Blockchain node 1, blockchain node 2, and blockchain node 3 are just examples, along with a distributed ledger. The initial vehicle key is recorded in the distributed ledger via the blockchain node through the authentication server and the BAAS (Broker As A Service) gateway. The initial vehicle key in the authentication server is then written into the ECU's secure storage area (controller security module) via the HSM / eSE hardware encryption channel through an electronic testing device.
[0039] As an example, each controller to be authenticated corresponds to a node on the blockchain. The data structure of the evidence storage data on the blockchain includes the controller identifier, the hash of the initial vehicle key, the authentication time, the operator's address, the authentication location, the authentication result, and the evidence hash. In the initial stage, the authentication time, operator's address, authentication location, authentication result, and evidence hash in the evidence storage data are blank; only the controller identifier and the hash of the initial vehicle key are recorded. This evidence storage data will be supplemented based on the authentication results after the controller to be authenticated.
[0040] As another example, the authentication server can also store the initial vehicle key along with the controller identifier. The authentication server stores the data in its local trusted storage space. When authentication is required, the server key can be obtained either by directly retrieving the initial vehicle key stored on the authentication server or by retrieving the stored data from the blockchain. Alternatively, both methods can be used to obtain the server key, which is then compared to the data to further ensure its accuracy and reliability.
[0041] In step S220, if the controller to be certified determines the first vehicle-side verification data and the second vehicle-side verification data based on the certification-related data, the vehicle's vehicle safety module determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data.
[0042] The vehicle safety module can be a trusted safety module other than the controller to be certified, which can be pre-configured by those skilled in the art.
[0043] As analyzed in the above embodiments, if the controller is not removed or replaced, then the first vehicle-side verification data and the second vehicle-side verification data will be obtained. If the controller is removed, then the first vehicle-side verification data and the second vehicle-side verification data will not be fed back to the vehicle safety module.
[0044] As an example, if the vehicle safety module does not receive the first vehicle-side verification data and the second vehicle-side verification data sent by the controller to be authenticated within a preset time after the vehicle is powered on, then the vehicle-side verification result can be directly determined as verification failure.
[0045] If the controller has not been replaced, the vehicle-side key in the controller is the same as the server-side key of the authentication server. Both use the same random number and authentication-related data, calculated using the same encryption algorithm. Therefore, the resulting first vehicle-side verification data and first server-side verification data should be identical, and the vehicle-side verification result is successful. However, if the controller has been replaced, it no longer has a vehicle-side key and / or is unaware of the specific encryption algorithm. In this case, the first vehicle-side verification data and the first server-side verification data will differ. This may indicate that the controller to be authenticated was not registered with the authentication server, or that the original controller was replaced. In this situation, the vehicle-side verification result is unsuccessful.
[0046] As another example, the authentication server may be unreliable, causing the first server-side verification data it returns to differ from the first vehicle-side verification data. In this case, the vehicle-side verification result will also be determined as verification failure.
[0047] In one embodiment, the method further includes: if the vehicle safety module does not obtain the first vehicle-side verification data and / or the second vehicle-side verification data, determining the vehicle-side verification result as a vehicle-side verification failure.
[0048] Verification at the vehicle end can quickly determine whether the controller to be certified is legitimate. However, due to the many uncontrollable situations at the vehicle end, further verification of the controller's legitimacy requires server-side authentication to ensure the reliability of the authentication results.
[0049] In one embodiment, the determination of the first vehicle-side verification data and the second vehicle-side verification data includes: the controller security module of the controller to be authenticated determines the first vehicle-side verification data based on the vehicle-side key and the first authentication sub-data; the controller security module determines the second vehicle-side verification data based on the vehicle-side key and the second authentication sub-data; wherein, the authentication-related data includes the first authentication sub-data and the second authentication sub-data, and the vehicle-side key is stored in the controller security module.
[0050] In one embodiment, before the vehicle's vehicle security module determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data, the method further includes: the authentication server sending the first server-side verification data to the vehicle.
[0051] For example, the controller security module pre-stores the vehicle-side key and encryption algorithm. Then, based on the vehicle-side key, it encrypts the first authentication sub-data and the second authentication sub-data using the encryption algorithm to obtain the first vehicle-side verification data and the second vehicle-side verification data. The second vehicle-side verification data is then sent to the authentication server for the authentication server to determine the authentication result.
[0052] In step S230, the authentication server determines the server verification result based on the second vehicle-side verification data and the second server-side verification data. The first server-side verification data and the second server-side verification data are obtained by the authentication server based on authentication-related data.
[0053] If the verification data from the second vehicle is the same as the verification data from the second server, then the server verification result is successful. Otherwise, if no verification data is received from the second vehicle, or if the verification data from the second vehicle is different from the verification data from the second server, then the verification fails.
[0054] In one embodiment, if the vehicle is powered on and no authentication request is received within a preset time threshold, the authentication result of the controller to be authenticated is also considered to be authentication failure.
[0055] In one embodiment, the determination of the first server-side verification data and the second server-side verification data includes: the authentication server determining the first server-side verification data based on the server-side key and the first authentication sub-data; and the authentication server determining the second server-side verification data based on the server-side key and the second authentication sub-data.
[0056] In one embodiment, before the authentication server determines the server verification result based on the second vehicle-side verification data and the second server-side verification data, the method further includes: the vehicle sending the second vehicle-side verification data to the authentication server.
[0057] For example, the authentication server may pre-store the vehicle-side key and encryption algorithm, or it may obtain the server-side key and encryption algorithm of the controller to be authenticated through a blockchain. Then, it may encrypt the first and second authentication sub-data based on the server-side key using the encryption algorithm to obtain the first and second server-side verification data. The first server-side verification data is then sent to the authentication server for evaluation.
[0058] In the above embodiment, the first authentication sub-data includes a first random number and first controller data to be authenticated, and the second authentication sub-data includes a second random number and a random number time identifier of the second random number. The encryption algorithm is SM3-HMAC, and the first controller data to be authenticated is sensor data. Taking the generation of the first vehicle-side verification data as an example, the first random number is truncated, and the sensor data is truncated, for example, truncated to 32 bits each, creating a 74-bit data space. The truncated first random number and sensor data are concatenated to obtain sensor status data. Then, the sensor status data and the vehicle-side key are calculated using the encryption algorithm to obtain the first vehicle-side verification data.
[0059] Step S240: Determine the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result.
[0060] It is understandable that if the vehicle-side verification result is a verification failure, and / or the server-side verification result is a verification failure, then the authentication result is authentication failure; otherwise, if both the vehicle-side and server-side verification results are successful, then the authentication result is authentication success. If authentication is successful, a normal session can be created, the controller can be enabled according to relevant technical methods, and legitimate control commands can be executed.
[0061] Through the above methods, the server verifies the legitimacy of the ECU, the ECU verifies the authenticity of the server, and sensor data and timestamps are dynamically bound for each authentication. The first and second random numbers are also randomly generated. These methods can further enhance the reliability of authentication and prevent man-in-the-middle attacks.
[0062] In one embodiment, after determining the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result, the method further includes, if the authentication result is authentication failure, triggering the execution of a controller authentication failure control strategy; wherein, the controller authentication failure control strategy includes at least one of the following: controlling the vehicle to self-destruct the stored vehicle-side key; locking the controller to be authenticated; generating authentication failure data based on the authentication failure time identifier, authentication result, vehicle-side key fingerprint, vehicle identifier and current location, generating an evidence hash based on the authentication failure data, uploading the authentication failure data and evidence hash to the blockchain, and generating the vehicle-side key fingerprint based on the vehicle-side key.
[0063] For example, key self-destruction can be achieved by linking physical sensors. When the sensor alarms (authentication failure), the system triggers a fuse signal, causing an overload of the voltage in the controller's security module storage area (eSE storage area voltage overload), thus physically destroying the key.
[0064] For example, an ECU can be remotely locked via OTA (Over-The-Air). An exemplary security protocol stack for implementing this function is: Application layer: Lock command (0xE5) → Transport layer: TLS 1.3 encryption → Network layer: 5G slicing private network.
[0065] As an example, locking can be a way to control the function of a controller so that it does not perform relevant control operations on a controller that has failed authentication, thereby ensuring the safe operation of the vehicle.
[0066] Uploading authentication failure data and evidence hashes to the blockchain can provide reliable evidence support for subsequent troubleshooting and liability determination.
[0067] As an example, the controller authentication failure control strategy also includes notifying the vehicle owner or designated management personnel of the authentication failure. This allows them to be aware of the vehicle's security status in a timely manner and take appropriate measures. For instance, an authentication failure notification can be sent to the vehicle owner via a mobile app, SMS, or email, informing them of the reason for the failure, the time, location, and other key information.
[0068] In one embodiment, the vehicle-side key is stored in the controller security module. The method further includes: acquiring removal monitoring data of the controller to be authenticated; determining the removal status of the controller to be authenticated based on the removal monitoring data; if the removal status is removal, self-destructing the vehicle-side key stored in the controller security module by means of voltage overload or overwriting; wherein, the removal monitoring data includes the outer shell pressure value and / or the inner shell light intensity value, the outer shell pressure value is collected by a pressure sensor installed on the outer shell of the controller to be authenticated, and the inner shell light intensity value is collected by a photosensitive sensor installed on the inner side of the outer shell of the controller to be authenticated.
[0069] For example, pressure sensors and photosensors can communicate with the ECU main control chip via I2C (Inter-Integrated Circuit) or SPI (Serial Peripheral Interface) interfaces to periodically collect and monitor data. Anomalies include: pressure sensors setting thresholds, exceeding which is considered abnormal pressure on the housing (detecting changes in externally applied pressure at critical locations on the ECU housing, such as screw holes and seams); and light intensity setting thresholds, exceeding which is considered the housing being opened (installed inside the ECU housing to detect whether light is entering). Taking the use of ESE or HSM to store vehicle-side keys as an example, when a sensor triggers an anomaly, the vehicle-side key is destroyed through voltage overload or overwriting. For example, this can be done by fusing the power supply line to the storage unit in the controller's security module, or by overwriting preset or random data in the storage unit of the controller's security module.
[0070] In one embodiment, if the vehicle-side key is self-destructed, the method further includes: generating a self-destruction event and reporting it. The reported content includes the vehicle identifier, controller identifier, self-destruction timestamp, event type (self-destruction event), vehicle location information, etc. The reporting target can be at least one of a cloud server, an authentication server, or a blockchain.
[0071] The controller authentication method provided in the above embodiments involves the authentication server and the controller to be authenticated in the vehicle exchanging messages related to authentication data after the vehicle is powered on. If the controller to be authenticated determines the first vehicle-side verification data and the second vehicle-side verification data based on the authentication-related data, the vehicle's vehicle safety module determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data. The authentication server determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data. The first and second server-side verification data are determined by the authentication server based on the authentication-related data. The authentication result of the controller to be authenticated is determined based on the vehicle-side verification result and the server-side verification result. This provides a two-way authentication method between the controller to be authenticated and the authentication server, ensuring the reliability of the authentication. It can promptly and accurately detect situations where the controller has been removed or replaced, providing a method for authenticating the controller before the vehicle is driven. The authentication result allows for the execution of corresponding control strategies on the vehicle, improving driving safety, enhancing vehicle stability, and protecting user rights. This effectively solves the problem of forced removal or arbitrary installation of intelligent vehicles, guarantees the legitimate rights and interests of consumers, reduces vehicle problems caused by the replacement of unqualified parts, and ensures the user's driving experience and safety.
[0072] As an example, see Figure 4 and Figure 5 , Figure 4 A system diagram illustrating an example of a controller authentication method provided in an embodiment of this application. Figure 5 This is a schematic flowchart of a controller authentication method provided in an embodiment of this application. Figure 4 The document illustrates detachable controllers (detachable ECUs, ECU3, ECU4, ECU5) and non-detachable controllers (ECU1, ECU2), where ECU2 can be considered an example of a non-certified controller. ECU1, ECU3, ECU4, and ECU5 are all controllers awaiting certification. Figure 4 and Figure 5As shown, the first step involves the order system entering order information. When a vehicle rolls off the production line, the electrical inspection equipment obtains a key seed, including the vehicle's unique identifier and production timestamp, through the production line PLC system. This key seed (vehicle unique identifier and production timestamp) is then transmitted from the order system to the authentication server. The authentication server generates encrypted information (the initial vehicle key) based on the key seed. The second step involves synchronizing this encrypted information to the electrical inspection server. The electrical inspection server then synchronizes this encrypted information to the electrical inspection equipment. The third step involves the electrical inspection equipment writing the key to the secure storage area of each of the ECUs (ECU1, ECU3, ECU4, and ECU5) via the HSM / eSE hardware encryption channel. Additionally, the authentication server records the mapping between the VIN (Vehicle Unique Identifier) and Key_Hash (initial vehicle key hash value), and the blockchain BAAS system stores the key fingerprint, completing the synchronization. For the fourth step, please refer to [link to relevant documentation]. Figure 5 After the vehicle starts, a two-way challenge-response protocol is triggered. The ECU to be certified sends an authentication request (if the ECU is ECU1, it is sent directly to the authentication server via the relevant communication link; if the ECU is ECU3, ECU4, or ECU5, the authentication request is sent to ECU1, which then sends it to the authentication server via the relevant communication link). The authentication server responds to the authentication request by issuing a first random number R1 and a second random number R2 (if the ECU is ECU1, the authentication server sends it directly to ECU1 via the relevant communication link; if the ECU is ECU3, ECU4, or ECU5, the server sends the first random number R1 and the second random number R2 to ECU1, which then sends them to ECU3, ECU4, or ECU5 via the relevant communication link). The ECU calculates first vehicle-side verification data S1 using a first random number, sensor data, and vehicle-side key; and calculates second vehicle-side verification data S2 using a second random number, the timestamp of the second random number, and the vehicle-side key. The authentication server also calculates first server-side verification data S3 using the first random number, sensor data, and server-side key; and calculates second server-side verification data S4 using a second random number, the timestamp of the second random number, and the server-side key. The vehicle verifies S1 and S3 to obtain the vehicle-side verification result, and the authentication server verifies S2 and S4 to obtain the server-side verification result. Based on the vehicle-side verification result and the server-side verification result, the authentication result of the controller to be authenticated is determined. If authentication is successful, a session key is generated, and step five is executed to execute a valid control command. If authentication fails, a three-level response is triggered, including key self-destruction, blockchain storage, and OTA locking.
[0073] As an example, the verification data for the first vehicle and the verification data for the second vehicle are determined as follows: S1=HMAC (Key1, R1‖Sensor Data) formula (1), S2=HMAC (Key1, R2‖Timerstamp) formula (2), Wherein, S1 is the first vehicle-side verification data, S2 is the second vehicle-side verification data, Key1 is the vehicle-side key, R1 is the first random number, R2 is the second random number, Sensor Data is the sensor data, and Timerstamp is the timestamp of the second random number.
[0074] As an example, the methods for determining the first server-side verification data and the second server-side verification data are as follows: S3=HMAC (Key2, R1‖Sensor Data) formula (3), S4=HMAC (Key2, R2‖Timerstamp) formula (4), Wherein, S3 is the first server verification data, S4 is the second server verification data, Key2 is the server key, R1 is the first random number, R2 is the second random number, Sensor Data is the sensor data, and Timerstamp is the timestamp of the second random number.
[0075] It should be noted that, Figure 4 Taking ECU1, ECU2, ECU3, ECU4, and ECU5 in a vehicle as an example, with ECU1 being the ECU to be certified, this example illustrates the types and number of controllers mentioned above. Figure 4 The connection relationships described are merely an exemplary example provided in this embodiment and are not intended to limit the application environment of this controller authentication method.
[0076] Please see Figure 6 , Figure 6 A specific flowchart illustrating the data uplink process in the controller authentication method provided in an embodiment of this application is shown below. Figure 6 As shown, the ECU to be certified sends an authentication request to the certification server. The authentication request includes the vehicle identification number (VIN). The authentication result is obtained. If the authentication result is authentication failure, a data packet containing the evidence storage data is generated. The data packet is encapsulated into a transaction request and broadcast to the blockchain via the gateway Geteway. The evidence storage data is then stored on the blockchain.
[0077] As an example, the blockchain stores the controller's authentication records, and hash verification (e.g., the `verify_record` function can be used to implement hash verification) to ensure the integrity of the records. Any modification to the stored data (such as the VIN (Vehicle Identification Number), key hash, controller identifier, etc. in the `CertificationRecord` structure) will cause a change in the hash value, triggering an alarm; the verification process is based on the vehicle VIN code (unique identifier), allowing traceability of the authentication history of all controllers. If a third party illegally replaces the controller, a matching record will be missing or a hash anomaly will occur in the blockchain; when physical sensors (such as the pressure sensor and light sensor mentioned above) detect illegal dismantling, self-destruct events (such as logs generated by the `report_self_destruct_event` function) will be stored on the blockchain using the same hash rules, forming a complete chain of evidence against tampering.
[0078] As an example, the evidence storage data includes, but is not limited to, the vehicle's unique identifier, the SM3 key hash, the authentication time, the operator's address, the authentication location [latitude, longitude], the authentication result (0 = success, 1 = failure), and the hash of associated evidence.
[0079] In one embodiment, a controller authentication system is provided for performing the controller authentication method provided in any of the above embodiments. See also... Figure 7 , Figure 7 A schematic diagram of the controller authentication system provided in one embodiment of this application is shown below. Figure 7 As shown, the controller authentication system 700 includes a vehicle 710, an authentication server 720, and an authentication result determination module 730. The vehicle 710 includes a controller to be authenticated 711 and a vehicle safety module 712. Specifically: the authentication server 720 and the controller to be authenticated 711 exchange messages related to authentication data after the vehicle is powered on; the vehicle safety module 712 determines the vehicle-side verification result based on the first vehicle-side verification data and the second vehicle-side verification data obtained by the controller to be authenticated according to the authentication-related data; the authentication server 720 determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data, wherein the first server-side verification data and the second server-side verification data are obtained by the authentication server 720 based on the authentication-related data; and the authentication result determination module 730 determines the authentication result of the controller to be authenticated 711 based on the vehicle-side verification result and the server-side verification result.
[0080] As an example, the authentication result determination module can be integrated into the authentication server or set up in other trusted objects selected by those skilled in the art.
[0081] As an example, the system also includes blockchain, electrical inspection server, electrical inspection equipment, etc. For specific details, please refer to the relevant descriptions in the above embodiments, which will not be repeated here.
[0082] For specific limitations regarding the controller authentication system, please refer to the limitations on the controller authentication method above, which will not be repeated here. Each module in the aforementioned controller authentication system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware within or independently of the processor in the electronic device, or stored in software within the memory of the electronic device, so that the processor can call and execute the corresponding operations of each module.
[0083] In this embodiment, the controller authentication system is essentially configured with multiple modules to execute the controller authentication method in any of the above embodiments. The specific functions and technical effects can be referred to in the above embodiments, and will not be repeated here.
[0084] In one embodiment, a vehicle is provided, comprising a controller to be authenticated, a vehicle security module, and an authentication result execution module, wherein: the controller to be authenticated is used to perform message interaction with an authentication server on authentication-related data after the vehicle is powered on; the vehicle security module is used to determine a vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data if the controller to be authenticated determines first vehicle-side verification data and second vehicle-side verification data according to the authentication-related data; the authentication result execution module is used to control the controller to be authenticated according to the authentication result, wherein the authentication result is determined based on the vehicle-side verification result and the server-side verification result, and the server-side verification result is determined by the authentication server based on the second vehicle-side verification data and the second server-side verification data, and the first server-side verification data and the second server-side verification data are obtained by the authentication server based on the authentication-related data.
[0085] Specific limitations regarding the vehicle can be found in the controller authentication method section above, and will not be repeated here. Each module in the vehicle described above can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in hardware or independently of the processor in the electronic device, or stored in software in the memory of the electronic device, so that the processor can call and execute the corresponding operations of each module.
[0086] In this embodiment, the vehicle is essentially equipped with multiple modules to execute the vehicle-side execution method in the controller authentication method of any of the above embodiments. The specific functions and technical effects can be referred to in the above embodiments, and will not be repeated here.
[0087] See Figure 8 , Figure 8A schematic diagram of the structure of an electronic device provided in an embodiment of this application is shown below. Figure 8 As shown, this embodiment of the invention also provides an electronic device 800, including a processor 801, a memory 802, and a communication bus 803; the communication bus 803 is used to connect the processor 801 and the memory 802; the processor 801 is used to execute a computer program stored in the memory 802 to implement the method described in any of the above embodiments.
[0088] This invention also provides a computer-readable storage medium having a computer program stored thereon, the computer program being used to cause a computer to perform the method provided in any of the above embodiments.
[0089] This application also provides a non-volatile readable storage medium storing one or more modules (programs) that, when applied to a device, enable the device to execute the instructions included in the steps provided in this application.
[0090] This application also provides a computer program product, including a computer program that, when executed by a processor, can implement the steps and corresponding content of the aforementioned method embodiments.
[0091] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0092] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0093] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of methods and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0095] It should be understood that the terms "first," "second," etc., used in this application are used to distinguish similar objects and do not necessarily indicate a specific order or sequence. The technical features to which these terms are used can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in a sequence other than that shown in the figures or text.
[0096] It should be understood that although the flowcharts provided in the embodiments of this application indicate the various steps with arrows, the order indicated by the arrows does not necessarily limit the implementation order of these steps. Those skilled in the art can perform these steps in other orders according to different implementation scenarios and requirements.
[0097] The above embodiments are merely illustrative of the principles and effects of this application and are not intended to limit this application. Any person skilled in the art can modify or alter the above embodiments without departing from the spirit and scope of this application. Therefore, all equivalent modifications or alterations made by those skilled in the art without departing from the spirit and technical concept disclosed in this application should still be covered by the claims of this application.
Claims
1. A controller authentication method, characterized in that, The method includes: After the vehicle is powered on, the authentication server interacts with the vehicle's controller to be authenticated via message exchange of authentication-related data. This interaction includes: the controller to be authenticated sending an authentication request, which includes first controller data; the authentication server responding to the authentication request generating a first random number and a second random number, and feeding these two random numbers back to the vehicle. The authentication-related data includes first authentication sub-data and second authentication sub-data. The first authentication sub-data includes the first random number and the first controller data to be authenticated. The second authentication sub-data includes the second random number and a random number timestamp. The first controller data to be authenticated includes sensor data used to detect whether the controller to be authenticated has been disassembled. If the controller to be certified determines the first vehicle-side verification data and the second vehicle-side verification data based on the certification-related data, the vehicle safety module of the vehicle determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data. Furthermore, the authentication server determines the server-side verification result based on the second vehicle-side verification data and the second server-side verification data, wherein the first server-side verification data and the second server-side verification data are obtained by the authentication server based on the authentication-related data; The authentication result of the controller to be authenticated is determined based on the vehicle-side verification result and the server-side verification result. Obtain the removal monitoring data of the controller to be certified; The removal status of the controller to be certified is determined based on the removal monitoring data. If the removal status is removal, the vehicle-side key stored in the controller security module will be self-destructed by means of voltage overload or overwriting. The dismantling monitoring data includes the outer shell pressure value and / or the inner shell light intensity value. The outer shell pressure value is collected by a pressure sensor installed on the outer shell of the controller to be certified, and the inner shell light intensity value is collected by a photosensitive sensor installed on the inner side of the outer shell of the controller to be certified. If the controller to be authenticated is a detachable controller, the data interaction between the controller to be authenticated and the authentication server is transmitted through a non-detachable controller.
2. The controller authentication method as described in claim 1, characterized in that, The method further includes: If the vehicle safety module fails to obtain the first vehicle-side verification data and / or the second vehicle-side verification data, the vehicle-side verification result will be determined as a vehicle-side verification failure.
3. The controller authentication method as described in claim 1, characterized in that, The methods for determining the first vehicle-side verification data, the second vehicle-side verification data, the first server-side verification data, and the second server-side verification data include: The controller security module of the controller to be authenticated determines the first vehicle-side verification data based on the vehicle-side key and the first authentication sub-data; The controller security module determines the second vehicle-side verification data based on the vehicle-side key and the second authentication sub-data. The authentication server determines the first server verification data based on the server key and the first authentication sub-data. The authentication server determines the second server verification data based on the server key and the second authentication sub-data; The vehicle-side key is stored in the controller security module.
4. The controller authentication method as described in claim 1, characterized in that, Before the vehicle safety module of the vehicle determines the vehicle-side verification result based on the first vehicle-side verification data and the first server-side verification data, the method further includes: the authentication server sending the first server-side verification data to the vehicle; Before the authentication server determines the server verification result based on the second vehicle-side verification data and the second server-side verification data, the method further includes: the vehicle sending the second vehicle-side verification data to the authentication server.
5. The controller authentication method according to any one of claims 1-4, characterized in that, Before the authentication server exchanges authentication-related data messages with the vehicle's controller to be authenticated, the method further includes: When the vehicle rolls off the production line, the authentication server obtains the key seed data of the controller to be authenticated in the production line system, generates an initial vehicle key based on the key seed data, and sends the initial vehicle key to the vehicle. The initial vehicle key is recorded as the vehicle-side key and written into the controller security module corresponding to the controller to be authenticated when the vehicle is taken off the production line; The authentication server generates evidence storage data based on the initial vehicle key and controller identifier, and sends the evidence storage data to the blockchain to store the evidence storage data through the blockchain, and records the initial vehicle key in the evidence storage data as the server key.
6. The controller authentication method according to any one of claims 1-4, characterized in that, After determining the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result, the method further includes, if the authentication result is authentication failure, triggering the execution of the controller authentication failure control strategy; The controller authentication failure control strategy includes at least one of the following: Control the vehicle to self-destruct the stored vehicle-side key; Lock the controller to be authenticated; Authentication failure data is generated based on the authentication failure time identifier, authentication result, vehicle key fingerprint, vehicle identifier, and current location. An evidence hash is generated based on the authentication failure data. The authentication failure data and the evidence hash are uploaded to the blockchain. The vehicle key fingerprint is generated based on the vehicle key.
7. A controller authentication system, characterized in that, The system, applied to the controller authentication method as described in any one of claims 1-6, comprises a vehicle, an authentication server, and an authentication result determination module, wherein the vehicle includes a controller to be authenticated and a vehicle security module, wherein: The authentication server and the controller to be authenticated are used to exchange authentication-related data messages after the vehicle is powered on. The authentication server and the controller to be authenticated of the vehicle exchange authentication-related data messages include: the controller to be authenticated sending an authentication request, the authentication request including first controller data; the authentication server responding to the authentication request generating a first random number and a second random number, and feeding back the first random number and the second random number to the vehicle. The first authentication sub-data includes the first random number and the first controller data to be authenticated, and the second authentication sub-data includes the second random number and the random number timestamp of the second random number. The vehicle safety module is used to determine the vehicle verification result based on the first vehicle verification data and the first server verification data if the controller to be certified determines the first vehicle verification data and the second vehicle verification data according to the certification-related data. The authentication server is used to determine the server verification result based on the second vehicle-side verification data and the second server-side verification data. The first server-side verification data and the second server-side verification data are obtained by the authentication server based on the authentication-related data. The authentication result determination module is used to determine the authentication result of the controller to be authenticated based on the vehicle-side verification result and the server-side verification result.
8. A vehicle, characterized in that, Applied to the controller authentication method as described in any one of claims 1-6, the vehicle includes a controller to be authenticated, a vehicle safety module, and an authentication result execution module, wherein: The controller to be authenticated is used to exchange authentication-related data with the authentication server after the vehicle is powered on. The authentication server exchanges authentication-related data with the controller to be authenticated of the vehicle, which includes: the controller to be authenticated sending an authentication request, the authentication request including first controller data; the authentication server responding to the authentication request generating a first random number and a second random number, and feeding the first random number and the second random number back to the vehicle. The first authentication sub-data includes the first random number and the first controller data to be authenticated, and the second authentication sub-data includes the second random number and the random number timestamp of the second random number. The vehicle safety module is used to determine the vehicle verification result based on the first vehicle verification data and the first server verification data if the controller to be certified determines the first vehicle verification data and the second vehicle verification data according to the certification-related data. The authentication result execution module is used to control the controller to be authenticated according to the authentication result. The authentication result is determined based on the vehicle-side verification result and the server-side verification result. The server-side verification result is determined by the authentication server based on the second vehicle-side verification data and the second server-side verification data. The first server-side verification data and the second server-side verification data are obtained by the authentication server based on the authentication-related data.
Citation Information
Patent Citations
Lightweight car networking safety communication method
CN107204850A
Data evidence storage method and data evidence storage platform based on blockchain
CN111884811A
Vehicle key controller tamper authentication method and system and vehicle
CN120856341A