A domain control electrical architecture vehicle OTA information security protection method and system

By employing an OTA information security protection method based on a domain-controlled electrical architecture, and utilizing certificate management and encrypted channels, the problems of high cost and insufficient security in OTA upgrades for intelligent connected vehicles are solved, enabling efficient and secure software package downloads and upgrades.

CN121509122BActive Publication Date: 2026-04-10ZHIZI AUTOMOTIVE TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-14
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing OTA upgrade solutions suffer from high costs, high hardware requirements, and insufficient security protection capabilities. This is especially true in intelligent connected vehicles, where the information security attack surface is wide and the risks of data tampering and malicious code injection are high.

Method used

Adopting a domain-controlled electrical architecture, the OTA platform and the vehicle-side OTAmaster apply for certificates from the PKI/CA system and generate upgrade packages. They use KMS and a cryptographic machine to sign hash values, transmit data through the CDN platform, and verify the data between the vehicle-side OTAmaster and OTAslave. A two-way TLS encrypted channel is established to ensure identity authentication and data integrity.

Benefits of technology

It simplifies the certificate management process, improves security and efficiency, reduces system complexity and construction costs, enhances system concurrency processing capabilities and software package download speed, and strengthens the overall security protection level.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509122B_ABST
    Figure CN121509122B_ABST
Patent Text Reader

Abstract

The application discloses a kind of domain control electrical architecture vehicle OTA information security protection method and system, it is related to automobile information security protection technical field, can solve the problems of high cost, high hardware requirement and insufficient security protection capability in the OTA upgrading process in prior art.Therein, specific technical solutions are as follows: OTA platform and vehicle end OTA master respectively apply platform SSL server certificate, device certificate and OTA signature certificate to PKI / CA system;OTA platform generates upgrade package, and requests PKI / CA system to sign the hash value of upgrade package, then distributes upgrade package, hash value and corresponding signature value to content distribution network CDN platform;OTA platform further pushes OTA service to user terminal and receives the upgrade instruction of user;Finally, vehicle end OTA master and vehicle end OTA slave download corresponding upgrade package, hash value and signature value from CDN platform according to upgrade instruction, and use OTA signature certificate to verify signature value, and execute upgrade operation after verification is passed.The application is used for OTA information security protection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of automobile information security protection, in particular to a domain control electrical architecture vehicle OTA information security protection method and system. BACKGROUND

[0002] With the popularization of intelligent networked vehicles, the number of vehicle external communication interfaces has increased significantly, and the information security attack surface has expanded continuously. As the core means of vehicle software update, the security of OTA (Over-the-Air Technology) technology is crucial. Currently, the mainstream OTA solution has obvious deficiencies in information security protection, and faces serious risks such as data tampering and malicious code injection during the upgrade process.

[0003] In the prior art, the invention patent CN 112713999 B provides a secure update scheme based on two-way authentication, but still has the following defects: first, the system architecture is complex, and requires each controller vendor to provide a cloud platform, resulting in vehicle gateway communication with multiple parties and high implementation cost; second, the certificate management is complicated, and the vehicle end needs to maintain multiple source certificates, requiring high performance of the hardware security module; third, the security mechanism is weak, using HTTPS 1.1 protocol and unverified private algorithms, and the security protection capability is insufficient. SUMMARY

[0004] In order to solve the problems of high cost, high hardware requirement and insufficient security protection capability in the OTA upgrade process in the prior art, the present application provides a domain control electrical architecture vehicle OTA information security protection method and system. The technical solution is as follows:

[0005] According to the first aspect of the present application, a domain control electrical architecture vehicle OTA information security protection method is provided, which comprises:

[0006] The OTA platform and the vehicle end OTAmaster apply for platform SSL server certificates, device certificates and OTA signature certificates to the PKI / CA system respectively;

[0007] The OTA platform generates an upgrade package and requests the PKI / CA system to sign the hash value of the upgrade package, and then distributes the upgrade package, hash value and corresponding signature value to the content distribution network CDN platform; wherein the upgrade package at least includes: a first upgrade package corresponding to the vehicle end OTAmaster, a second upgrade package corresponding to the vehicle end OTAslave, and a third upgrade package corresponding to other controllers to be upgraded on the vehicle except OTAmaster and OTAslave;

[0008] The OTA platform pushes the OTA service to the user terminal and receives the upgrade instruction of the user;

[0009] The vehicle-side OTA master and the vehicle-side OTA slave download corresponding upgrade packages, hash values and signature values from the CDN platform according to the upgrade instruction, and check the signature values using the OTA signature certificate, and perform an upgrade operation after the check is passed;

[0010] The vehicle-side OTA master is responsible for downloading the first upgrade package and the third upgrade package, and the vehicle-side OTA slave is responsible for downloading the second upgrade package; the OTA slave sends corresponding hash values and signature values to the OTA master during the check, and returns the result after the check of the OTA master is completed.

[0011] The domain control electrical architecture vehicle OTA information security protection method provided by the application first applies platform SSL server certificates, device certificates and OTA signature certificates to the PKI / CA system by the OTA platform and the vehicle-side OTA master; then the OTA platform generates an upgrade package, and requests the PKI / CA system to sign the hash value of the upgrade package, and then distributes the upgrade package, the hash value and the corresponding signature value to the content distribution network CDN platform; wherein the upgrade package at least includes: a first upgrade package corresponding to the vehicle-side OTA master, a second upgrade package corresponding to the vehicle-side OTA slave, and a third upgrade package corresponding to other controllers to be upgraded on the vehicle except the OTA master and the OTA slave; the OTA platform further pushes the OTA service to the user terminal and receives the upgrade instruction of the user; finally, the vehicle-side OTA master and the vehicle-side OTA slave download corresponding upgrade packages, hash values and signature values from the CDN platform according to the upgrade instruction, and check the signature values using the OTA signature certificate, and perform an upgrade operation after the check is passed; wherein the vehicle-side OTA master is responsible for downloading the first upgrade package and the third upgrade package, and the vehicle-side OTA slave is responsible for downloading the second upgrade package; the OTA slave sends corresponding hash values and signature values to the OTA master during the check, and returns the result after the check of the OTA master is completed. The method of the application cooperates between multiple platforms and domain controllers, adopts a separate transmission mechanism of data packet distribution and vehicle cloud confirmation communication content, ensures vehicle cloud identity authentication, data encryption and integrity check, and significantly improves system concurrent processing capability, software package download speed and overall security protection level.

[0012] As a further scheme of the application, the step of applying platform SSL server certificates to the PKI / CA system by the OTA platform specifically includes:

[0013] The OTA platform applies for the platform SSL server certificate through a certificate signing request (CSR) to a PKI / CA system;

[0014] After the PKI / CA system issues the platform SSL server certificate, the OTA platform deploys the platform SSL server certificate to the platform SSL gateway.

[0015] The method of the present application lays a foundation for subsequent establishment of a high-security encrypted communication channel with a vehicle end by applying for and deploying a specific SSL server certificate for an OTA platform, and ensures the legality of the identity of the cloud platform from the source.

[0016] As a further scheme of the present application, the step of applying for a device certificate by the vehicle end OTA master to the PKI / CA system specifically comprises:

[0017] The vehicle end OTA master generates a certificate signing request (CSR) and sends the CSR assembled into a SCEP certificate application message to the PKI / CA system, wherein the CSR at least includes a vehicle identification number (VIN);

[0018] The PKI / CA system analyzes the SCEP certificate application message, extracts the vehicle identification number (VIN) information, and sends it to the OTA platform to authenticate the identity of the vehicle end OTA master;

[0019] After authentication, the certificate authority (CA) in the PKI / CA system issues the device certificate to the vehicle end OTA master;

[0020] The vehicle end OTA master receives the device certificate and verifies the legality of the device certificate according to a pre-stored PKI certificate chain, and stores it after verification.

[0021] The method of the present application ensures that only a legal vehicle can access the upgrade system by standardizing the SCEP protocol and combining vehicle VIN code to authenticate and issue a certificate for the vehicle end domain controller (OTA master), effectively preventing the access of illegal devices.

[0022] As a further scheme of the present application, the step of applying for an OTA signature certificate by the vehicle end OTA master to the PKI / CA system specifically comprises:

[0023] The vehicle end OTA master initiates an OTA signature certificate request to the PKI / CA system;

[0024] The PKI / CA system issues the OTA signature certificate to the vehicle-side OTA master when inquiring the state of the device certificate acquired by the OTA master.

[0025] The vehicle-side OTA master receives the OTA signature certificate and stores the OTA signature certificate after verifying the legality of the OTA signature certificate.

[0026] The method of the present application issues the OTA signature certificate for signature verification to the vehicle-side on the basis of the verification of the device certificate. This step-by-step and dependent certificate issuance mechanism simplifies the process and improves the security and efficiency of certificate management.

[0027] As a further scheme of the present application, the step of requesting the PKI / CA system to sign the hash value of the upgrade package specifically includes:

[0028] The OTA platform sends a signature request for the hash values of the first, second and third upgrade packages to a key management system KMS in the PKI / CA system.

[0029] The KMS calls a cryptographic machine connected thereto to sign the hash values, and sends the signature values to the OTA platform, wherein the cryptographic machine interacts with the KMS through an intranet or a whitelist mechanism.

[0030] The method of the present application performs the signature operation of the upgrade package by a special key management system KMS and a protected cryptographic machine, realizes hardware-level security protection, greatly enhances the anti-attack ability of the signature compared with pure software signature, and prevents the leakage of signature keys.

[0031] As a further scheme of the present application, the step of downloading the corresponding upgrade package, hash value and signature value from the CDN platform specifically includes:

[0032] The CDN platform sends a CDN digital certificate to the vehicle-side OTA master and the vehicle-side OTA slave, respectively.

[0033] The vehicle-side OTA master and the vehicle-side OTA slave perform identity verification on the CDN digital certificate based on the CDN certificate chain deployed by each of them.

[0034] After verification, the CDN platform transmits the corresponding upgrade package, hash value and signature value to the vehicle-side OTA master and the vehicle-side OTA slave, respectively, through a preset one-way TLS encryption channel.

[0035] The method verifies the identity of the CDN platform before downloading the upgrade package, and transmits data by using a TLS encryption channel, so that data stealing or tampering in the downloading process is effectively prevented, and the downloading speed of the software package is significantly improved by means of the content distribution capability of the CDN.

[0036] As a further scheme of the present application, the step of the OTA platform pushing the OTA service to the user terminal and receiving the upgrade instruction of the user is performed in a bidirectional TLS encryption channel established between the OTA platform and the vehicle-side OTA master by using the platform SSL server certificate deployed by the OTA platform.

[0037] The method transmits the upgrade instruction and other key information by establishing a bidirectional TLS encryption channel, ensures that all instruction interactions between the vehicle and the cloud are performed in a highly secure and identity-recognized environment, and prevents eavesdropping or forgery of the instructions.

[0038] As a further scheme of the present application, the step of verifying the signature value by using the OTA signature certificate specifically includes:

[0039] The vehicle-side OTA master verifies the signature value corresponding to the downloaded upgrade package by using the OTA signature certificate, and verifies the signature value sent by the vehicle-side OTA slave.

[0040] The method unifies the signature verification work of the vehicle-side core domain controller OTA master and other controllers, realizes centralized processing of the signature verification task, simplifies the system architecture, reduces the computing power requirement for multiple controllers, and ensures the consistency of the verification standard.

[0041] According to a second aspect of the present application, an electrical architecture vehicle OTA information security protection system is provided, which includes a PKI / CA system, an OTA platform, a content distribution network CDN platform, a vehicle-side OTA master and a vehicle-side OTA slave.

[0042] The PKI / CA system is configured to issue platform SSL server certificates, device certificates and OTA signature certificates for the OTA platform and the vehicle-side OTA master, and to sign the upgrade package hash value.

[0043] The OTA platform is in communication connection with the PKI / CA system, and is configured to manage the platform SSL server certificates, generate the upgrade package, request signature of the upgrade package hash value, distribute the upgrade package, the hash value and the signature value to the CDN platform, and push the OTA service to the user terminal and receive the upgrade instruction.

[0044] The CDN platform is in communication connection with the OTA platform, and is configured to store and distribute the upgrade package, the hash value and the corresponding signature value to the vehicle-side OTA master and the vehicle-side OTA slave;

[0045] The vehicle-side OTA master is in communication connection with the OTA platform and the CDN platform, and is configured to apply for and load the device certificate and the OTA signature certificate, download the upgrade package, the hash value and the signature value of itself and other controllers to be upgraded from the CDN platform, and use the OTA signature certificate to verify the signature values of itself, other controllers to be upgraded and the vehicle-side OTA slave;

[0046] The vehicle-side OTA slave is in communication connection with the CDN platform and the vehicle-side OTA master, and is configured to download the upgrade package, the hash value and the signature value of itself from the CDN platform, and send the hash value and the signature value to the vehicle-side OTA master for verification.

[0047] The domain control electrical architecture vehicle OTA information security protection system provided by the application comprises a PKI / CA system, an OTA platform, a content distribution network CDN platform, a vehicle end OTA master and a vehicle end OTA slave; the PKI / CA system is used for issuing platform SSL server certificates, device certificates and OTA signature certificates for the OTA platform and the vehicle end OTA master, and signing upgrade package hash values; the OTA platform is in communication connection with the PKI / CA system, and is used for managing platform SSL server certificates, generating upgrade packages, requesting signature of upgrade package hash values, distributing upgrade packages, hash values and signature values to the CDN platform, and pushing OTA services to user terminals and receiving upgrade instructions; the CDN platform is in communication connection with the OTA platform, and is used for storing and distributing upgrade packages, hash values and corresponding signature values to the vehicle end OTA master and the vehicle end OTA slave; the vehicle end OTA master is in communication connection with the OTA platform and the CDN platform, and is used for applying for and loading device certificates and OTA signature certificates, downloading upgrade packages, hash values and signature values of itself and other controllers to be upgraded from the CDN platform, and verifying the signature values of itself, other controllers to be upgraded and the vehicle end OTA slave by using the OTA signature certificates; the vehicle end OTA slave is in communication connection with the CDN platform and the vehicle end OTA master, and is used for downloading upgrade packages, hash values and signature values of itself from the CDN platform, and sending the hash values and the signature values to the vehicle end OTA master for verification. The system of the application simplifies the component responsibilities, reduces the system complexity and construction cost, reduces the dependence on cloud server resources, supports multi-vehicle parallel upgrade, improves the software package download efficiency and guarantees the transmission security by means of the combined architecture of multiple platforms and domain controllers, which respectively bear the certificate management, upgrade instruction and software package distribution functions, and complete the security verification by the vehicle end OTA master.

[0048] As a further scheme of the application, the PKI / CA system comprises a certificate authority CA, a key management system KMS and a cryptomachine;

[0049] The CA is used for performing issuance and management of the platform SSL server certificates, the device certificates and the OTA signature certificates;

[0050] The KMS is connected with the CA and the cryptomachine, and is used for receiving a signature request of the OTA platform for the upgrade package hash values, and sending the signature request to the cryptomachine;

[0051] The cryptomachine is connected with the KMS, and is used for performing a signature operation on the upgrade package hash values.

[0052] The application divides the PKI / CA system into three components, CA, KMS and cryptographic machine, defines the respective responsibilities, and makes the certificate issuing, key management and signature undertaken by different modules. The clear division of labor architecture is convenient for system maintenance, and since the cryptographic machine is responsible for signature operation, the stability of the overall system operation and the security of the signature process are effectively improved.

[0053] According to a third aspect of the present application, a domain control electrical architecture vehicle OTA information security protection device is provided, comprising a processor and a memory, and at least one computer instruction is stored in the memory, and the instruction is loaded and executed by the processor to realize the steps performed in the domain control electrical architecture vehicle OTA information security protection method.

[0054] According to a fourth aspect of the present application, a computer readable storage medium is provided, and at least one computer instruction is stored in the storage medium, and the instruction is loaded and executed by the processor to realize the steps performed in the domain control electrical architecture vehicle OTA information security protection method.

[0055] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF DRAWINGS

[0056] The accompanying drawings incorporated in the specification and forming a part of it, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the application.

[0057] Figure 1 is the overall scheme diagram of the domain control electrical architecture vehicle OTA information security protection method provided by the embodiment of the present application;

[0058] Figure 2 is the flowchart of the domain control electrical architecture vehicle OTA information security protection method provided by the embodiment of the present application;

[0059] Figure 3 is the flowchart of the vehicle end OTA master device authentication and authentication, and the issuance of device certificate provided by the embodiment of the present application;

[0060] Figure 4 is the flowchart of the vehicle end OTA master obtaining OTA signature certificate provided by the embodiment of the present application;

[0061] Figure 5 is the structure diagram of the domain control electrical architecture vehicle OTA information security protection system provided by the embodiment of the present application. DETAILED DESCRIPTION

[0062] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals designate identical or similar elements in the several views. The implementations described in the following exemplary embodiments are not meant to represent all implementations consistent with the present invention.

[0063] The domain control electrical architecture vehicle OTA information security protection method provided by the embodiment of the present application. Figure 1 An exemplary system architecture using the method of the present application is shown. In the architecture, a PKI / CA system (including a CA certificate issuing system and a KMS key management system), a cryptographic machine, an OTA platform, a CDN platform, a vehicle end OTA master, a vehicle end OTA slave, and other vehicle end controllers to be upgraded are included. Figure 2 The flowchart of the domain control electrical architecture vehicle OTA information security protection method of the present application includes the following steps:

[0064] Step 101, the OTA platform and the vehicle end OTA master respectively apply to the PKI / CA system for platform SSL server certificate, device certificate, and OTA signature certificate;

[0065] In this embodiment, the vehicle end OTA master is a whole vehicle domain controller, and the vehicle end OTA slave is a cabin domain controller. The OTA platform and the PKI / CA system are both built on a vehicle enterprise server. The vehicle end OTA master obtains the device certificate and the OTA signature certificate through remote issuance, which is efficient and easy to manage.

[0066] In one embodiment, the step of the OTA platform applying to the PKI / CA system for platform SSL server certificate specifically includes:

[0067] The OTA platform applies to the PKI / CA system for platform SSL server certificate through a certificate signing request (CSR);

[0068] After the PKI / CA system issues the platform SSL server certificate, the OTA platform deploys the platform SSL server certificate to the platform SSL gateway. The OTA platform SSL gateway is configured with the SSL server certificate, the PKI certificate chain, the domain name certificate, and the domain name certificate chain, which are used to establish TLS encrypted communication with the vehicle end OTA master, the mobile phone APP, and the CDN platform.

[0069] In actual use, the platform SSL server certificate is mainly used for subsequent vehicle cloud identity authentication and data packet encryption to ensure the confidentiality of communication and the authenticity of identity.

[0070] The method of the application lays a foundation for subsequent establishment of a high-security encrypted communication channel with the vehicle end by applying and deploying a specific SSL server certificate for the OTA platform, and ensures the legality of the cloud platform identity from the source.

[0071] In one embodiment, the step of the vehicle end OTA master applying a device certificate to the PKI / CA system specifically comprises:

[0072] The vehicle end OTA master generates a certificate signing request (CSR) and assembles the CSR into an SCEP certificate application message and sends the SCEP certificate application message to the PKI / CA system, wherein the CSR at least includes a vehicle identification number (VIN);

[0073] The PKI / CA system parses the SCEP certificate application message, extracts the vehicle identification number (VIN) information, and sends the vehicle identification number (VIN) information to the OTA platform to authenticate the identity of the vehicle end OTA master;

[0074] After the authentication is passed, a certificate authority (CA) in the PKI / CA system issues a device certificate to the vehicle end OTA master;

[0075] The vehicle end OTA master receives the device certificate and verifies the legality of the device certificate according to a pre-stored PKI certificate chain, and stores the device certificate after the verification is passed.

[0076] In actual use, as shown in FIG. 6, the PKI system parses the SCEP and the CSR, extracts the VIN information, verifies the device identity in the system, encapsulates a CA certificate application request, the CA platform verifies the identity of the OTA master according to the request, issues a device certificate for the OTA master, and sends the device certificate to the OTA master. The OTA master verifies the legality of the device certificate according to the stored certificate chain, and loads the new certificate. Figure 3

[0077] The method of the application ensures that only a legal vehicle can access the upgrade system by standardizing the SCEP protocol and combining the vehicle VIN code to perform identity authentication and certificate issuance on the vehicle end domain controller (OTA master), and effectively prevents the access of illegal devices.

[0078] In one embodiment, the step of the vehicle end OTA master applying an OTA signature certificate to the PKI / CA system specifically comprises:

[0079] The vehicle end OTA master initiates an OTA signature certificate request to the PKI / CA system;

[0080] The PKI / CA system issues an OTA signature certificate to the vehicle end OTA master after querying the status of the device certificate obtained by the OTA master;

[0081] ​The vehicle end OTA master receives the OTA signature certificate, and stores the OTA signature certificate after verifying the legality of the OTA signature certificate.

[0082] In actual use, the OTA master part needs to load the OTA signature certificate in advance for signature verification of the cloud data packet, as shown in the following figure. Figure 4 The loading process diagram of the OTA signature certificate for the OTA master is shown in the figure. The OTA signature certificate is mainly used for data packet signature verification to ensure the authenticity and integrity of the software package. Generally, only the device that passes the authentication and authorization can obtain the device certificate for subsequent OTA upgrade operation to prevent illegal devices from accessing the upgrade system.

[0083] The method of the application issues the OTA signature certificate for signature verification for the vehicle end on the basis of the device certificate verification. This step-by-step and dependent certificate issuing mechanism simplifies the process and improves the security and efficiency of certificate management.

[0084] In step 102, the OTA platform generates an upgrade package, requests the PKI / CA system to sign the hash value of the upgrade package, and then distributes the upgrade package, the hash value and the corresponding signature value to the content distribution network (CDN) platform.

[0085] In this embodiment, the upgrade package at least includes a first upgrade package corresponding to the vehicle end OTA master, a second upgrade package corresponding to the vehicle end OTA slave, and a third upgrade package corresponding to other controllers to be upgraded on the vehicle except the OTA master and the OTA slave. The CDN platform is built on the vehicle enterprise server. The upgrade package hash value is calculated by the OTA platform.

[0086] In one embodiment, the step of requesting the PKI / CA system to sign the hash value of the upgrade package specifically includes:

[0087] The OTA platform sends a signature request for the hash values of the first upgrade package, the second upgrade package and the third upgrade package to the key management system (KMS) in the PKI / CA system.

[0088] The KMS calls a cryptomachine connected thereto to sign the hash values and sends the signature values to the OTA platform, wherein the cryptomachine interacts with the KMS through an intranet or a whitelist mechanism.

[0089] In this embodiment, a hardware-level cryptomachine is used for digital signature, and interacts with the CA (certificate authority) and KMS in the PKI (public key infrastructure) through an intranet / whitelist, ensuring the security of the communication process between the cryptomachine and the PKI. Compared with the digital signature of the OTA platform, the security of the cryptomachine is significantly improved.

[0090] The method of the application implements hardware-level security protection by performing the signature operation of the upgrade package by a special key management system KMS and a protected cryptographic machine, greatly enhances the anti-attack ability of the signature compared with pure software signature, and prevents the leakage of the signature key.

[0091] Step 103, the OTA platform pushes the OTA service to the user terminal and receives the upgrade instruction of the user.

[0092] In this embodiment, the OTA platform pushes the OTA service to the user's mobile phone APP, the user reserves the upgrade time, and issues the upgrade instruction (mobile phone end); in addition, the OTA platform pushes the OTA service to the user's mobile phone APP, the user reserves the upgrade time, and issues the upgrade instruction (vehicle end).

[0093] In one embodiment, the step of the OTA platform pushing the OTA service to the user terminal and receiving the upgrade instruction of the user is performed in the bidirectional TLS encryption channel established between the vehicle end OTA master and the platform SSL server certificate of the OTA platform.

[0094] In this embodiment, the OTA master and the OTA platform communicate securely through http+bidirectional TLS 1.2: OTA service pushing and upgrade time reservation, vehicle owner upgrade instruction issuing and other operations are performed in the encryption channel.

[0095] The method of the application transmits the upgrade instruction and other key information through the establishment of a bidirectional TLS encryption channel, ensures that all instruction interactions between the vehicle and the cloud are performed in a highly secure and identity-recognized environment, and prevents the instructions from being eavesdropped or forged.

[0096] Step 104, the vehicle end OTA master and the vehicle end OTA slave download the corresponding upgrade package, hash value and signature value from the CDN platform according to the upgrade instruction, and verify the signature value using the OTA signature certificate, and perform the upgrade operation after the verification is passed.

[0097] In this embodiment, the vehicle end OTA master is responsible for downloading the first upgrade package and the third upgrade package, and the vehicle end OTA slave is responsible for downloading the second upgrade package; the OTA slave sends the corresponding hash value and signature value to the OTA master during verification, and returns the result after the OTA master completes the verification.

[0098] In one embodiment, the step of downloading the corresponding upgrade package, hash value and signature value from the CDN platform specifically includes:

[0099] The CDN platform sends the CDN digital certificate to the vehicle end OTA master and the vehicle end OTA slave, respectively;

[0100] The vehicle-side OTA master and the vehicle-side OTA slave verify the CDN digital certificate based on the CDN certificate chain deployed respectively;

[0101] After verification, the CDN platform transmits the corresponding upgrade package, hash value and signature value to the vehicle-side OTA master and the vehicle-side OTA slave respectively through a preset one-way TLS encryption channel.

[0102] In actual use, before the CDN platform transmits the prepared upgrade package to the vehicle, the CDN digital certificate is first sent, which is used for the OTA master and the OTA slave to verify the authenticity of the CDN identity. After the CDN identity authenticity verification is passed, the CDN platform transmits the signed data package to the vehicle through the TLS protocol.

[0103] The method of the present application verifies the identity of the CDN platform before downloading the upgrade package, and transmits data using the TLS encryption channel, which protects the integrity, authenticity and confidentiality of the upgrade package and its digital signature when transmitted from the CDN server to the vehicle, effectively preventing data from being stolen or tampered with during the download process. At the same time, with the help of the content distribution capability of the CDN, the speed of downloading software package by a single vehicle is improved by more than 50%.

[0104] In one embodiment, the step of verifying the signature value using the OTA signature certificate specifically includes:

[0105] The vehicle-side OTA master uses the OTA signature certificate to verify the signature value corresponding to the upgrade package downloaded by itself, and to verify the signature value sent by the vehicle-side OTA slave.

[0106] In this embodiment, after downloading the upgrade package for itself, the OTA master verifies the received software package using the OTA signature certificate, and executes the upgrade process after verification. After downloading the upgrade package for itself, the OTA slave completes the signature package verification with the assistance of the OTA master, and executes the upgrade after verification.

[0107] The method of the present application realizes centralized processing of the verification task by the vehicle-side core domain controller OTA master being responsible for the verification of the upgrade package of itself and other controllers, simplifies the system architecture, reduces the computing power requirement for multiple controllers, and ensures the consistency of the verification standard.

[0108] The domain control electrical architecture vehicle OTA information security protection method provided by the embodiment of the application first applies for platform SSL server certificates, device certificates and OTA signature certificates from a PKI / CA system by an OTA platform and a vehicle end OTA master respectively; then the OTA platform generates an upgrade package, requests the PKI / CA system to sign a hash value of the upgrade package, and then distributes the upgrade package, the hash value and the corresponding signature value to a content distribution network CDN platform; wherein the upgrade package at least includes a first upgrade package corresponding to the vehicle end OTA master, a second upgrade package corresponding to a vehicle end OTA slave, and a third upgrade package corresponding to other controllers to be upgraded on the vehicle except the OTA master and the OTA slave; the OTA platform further pushes an OTA service to a user terminal and receives an upgrade instruction of the user; finally, the vehicle end OTA master and the vehicle end OTA slave download the corresponding upgrade package, hash value and signature value from the CDN platform according to the upgrade instruction, and verify the signature value using the OTA signature certificate, and perform an upgrade operation after the verification is passed; wherein the vehicle end OTA master is responsible for downloading the first upgrade package and the third upgrade package, and the vehicle end OTA slave is responsible for downloading the second upgrade package; the OTA slave sends the corresponding hash value and signature value to the OTA master during verification, and returns the result after the verification of the OTA master is completed. The method of the application improves the system concurrent processing capability, software package download speed and overall security protection level by the collaborative work between multiple platforms and domain controllers, and the independent transmission mechanism of data packet distribution and vehicle cloud confirmation communication content, while ensuring vehicle cloud identity authentication, data encryption and integrity verification.

[0109] Based on the above Figure 1 The domain control electrical architecture vehicle OTA information security protection method described in the corresponding embodiment, the following is a system embodiment of the application, which can be used to execute the method embodiment of the application.

[0110] The domain control electrical architecture vehicle OTA information security protection system provided by the embodiment of the application, as shown in Figure 5 The system includes: a PKI / CA system 201, an OTA platform 202, a content distribution network CDN platform 203, a vehicle end OTA master 204 and a vehicle end OTA slave 205.

[0111] The PKI / CA system 201 is configured to issue platform SSL server certificates, device certificates and OTA signature certificates for the OTA platform 202 and the vehicle end OTA master 204, and to sign the hash value of the upgrade package.

[0112] The OTA platform 202 is connected in communication with the PKI / CA system 201, and is configured to manage platform SSL server certificates, generate upgrade packages, request signature of upgrade package hash values, distribute upgrade packages, hash values and signature values to the CDN platform 203, and push OTA services to user terminals and receive upgrade instructions;

[0113] The CDN platform 203 is connected in communication with the OTA platform 202, and is configured to store and distribute upgrade packages, hash values and corresponding signature values to the vehicle-side OTA master 204 and the vehicle-side OTA slave 205.

[0114] The vehicle-side OTA master 204 is connected in communication with the OTA platform 202 and the CDN platform 203, and is configured to apply for and load device certificates and OTA signature certificates, download upgrade packages, hash values and signature values of itself and other controllers to be upgraded from the CDN platform 203, and use the OTA signature certificates to verify the signature values of itself, other controllers to be upgraded and the vehicle-side OTA slave 205.

[0115] The vehicle-side OTA slave 205 is connected in communication with the CDN platform 203 and the vehicle-side OTA master 204, and is configured to download upgrade packages, hash values and signature values of itself from the CDN platform 203, and send the hash values and signature values to the vehicle-side OTA master 204 for verification.

[0116] Specifically, the OTA platform is responsible for managing OTA signature certificates, requesting signature of upgrade packages from the KMS, and pushing OTA services and upgrade time reservations, owner upgrade instructions and the like to vehicle terminals. The CDN platform stores upgrade data packages and CDN digital certificates, and provides download services for upgrade data packages for the OTA slave and the OTA master. The OTA platform SSL gateway establishes an ssl encrypted channel, is configured with multiple certificates, and guarantees the security of data transmission. The vehicle-side OTA slave is responsible for downloading OTA slave upgrade packages and digital signatures from the CDN platform, performing certificate verification and installation package download, and interacting with the OTA master to complete self-upgrade package verification. The vehicle-side OTA master communicates with the OTA platform through a TLS encrypted channel, receives upgrade instructions, and interacts with a software development kit (SDK) to complete verification and the like, and is responsible for downloading OTA master upgrade packages and other controller upgrade packages to be upgraded on the vehicle from the CDN platform.

[0117] The domain control electrical architecture vehicle OTA information security protection system provided by the embodiment of the application comprises: a PKI / CA system 201, an OTA platform 202, a content distribution network (CDN) platform 203, a vehicle end OTA master 204 and a vehicle end OTA slave 205; the PKI / CA system 201 is configured to issue platform SSL server certificates, device certificates and OTA signature certificates for the OTA platform 202 and the vehicle end OTA master 204, and to sign an upgrade package hash value; the OTA platform 202 is in communication connection with the PKI / CA system 201, and is configured to manage platform SSL server certificates, generate an upgrade package, request signing of an upgrade package hash value, distribute the upgrade package, the hash value and a signature value to the CDN platform 203, and push an OTA service to a user terminal and receive an upgrade instruction; the CDN platform 203 is in communication connection with the OTA platform 202, and is configured to store and distribute the upgrade package, the hash value and the corresponding signature value to the vehicle end OTA master 204 and the vehicle end OTA slave 205; the vehicle end OTA master 204 is in communication connection with the OTA platform 202 and the CDN platform 203, and is configured to apply for and load device certificates and OTA signature certificates, to download, from the CDN platform 203, an upgrade package, a hash value and a signature value of the vehicle end OTA master 204 and other controllers to be upgraded, and to use the OTA signature certificates to verify the signature values of the vehicle end OTA master 204, the other controllers to be upgraded and the vehicle end OTA slave 205; and the vehicle end OTA slave 205 is in communication connection with the CDN platform 203 and the vehicle end OTA master 204, and is configured to download, from the CDN platform 203, an upgrade package, a hash value and a signature value of the vehicle end OTA slave 205, and to send the hash value and the signature value to the vehicle end OTA master 204 for verification. The system of the application is combined by multiple platforms and domain controllers, the functions of certificate management, upgrade instructions and software package distribution are borne by different components respectively, and the security verification is completed by the vehicle end OTA master 204, so that the component responsibilities are simplified, the system complexity and construction cost are reduced, the dependence on cloud server resources is reduced, and the system can support multiple vehicle parallel upgrades, improve software package download efficiency and ensure transmission security.

[0118] In one embodiment, the PKI / CA system 201 comprises a certificate authority (CA), a key management system (KMS) and a cryptomachine;

[0119] The CA is configured to perform issuance and management of platform SSL server certificates, device certificates and OTA signature certificates;

[0120] The KMS is connected with the CA and the cryptomachine, and is configured to receive a signature request for an upgrade package hash value sent by the OTA platform 202, and to send the signature request to the cryptomachine;

[0121] The cryptographic machine is connected with the KMS, and is used for performing a signature operation on the upgrade package hash value.

[0122] In the embodiment, the CA mainly performs certificate cloud platform certificate and vehicle terminal device certificate issuing and management, the KMS performs signature on the upgrade package hash value through the cryptographic machine and returns to the OTA platform. The cryptographic machine interacts with the PKI system through an intranet / white list, and provides encryption and authentication support.

[0123] The application divides the PKI / CA system into three components of CA, KMS and cryptographic machine, and defines the respective responsibilities, so that certificate issuing, key management and signature are borne by different modules. The clear division of labor architecture facilitates system maintenance, and effectively improves the stability of the overall operation of the system and the security of the signature process.

[0124] Based on the above Figure 1 According to the vehicle OTA information security protection method of the domain control electrical architecture described in the corresponding embodiment, another embodiment of the application further provides a vehicle OTA information security protection device of a domain control electrical architecture, which comprises a processor and a memory, and at least one computer instruction is stored in the memory, and the instruction is loaded and executed by the processor to realize the above Figure 1 The vehicle OTA information security protection method of the domain control electrical architecture described in the corresponding embodiment.

[0125] Based on the above Figure 1 According to the vehicle OTA information security protection method of the domain control electrical architecture described in the corresponding embodiment, an embodiment of the application further provides a computer readable storage medium, for example, a non-transitory computer readable storage medium can be a read only memory (English: Read Only Memory, ROM), a random access memory (English: Random Access Memory, RAM), a CD-ROM, a magnetic tape, a floppy disk and an optical data storage system, etc. The storage medium stores at least one computer instruction for executing the above Figure 1 The vehicle OTA information security protection method of the domain control electrical architecture described in the corresponding embodiment, which will not be repeated here.

[0126] Other embodiments of the application will be apparent to those skilled in the art from consideration of the specification and practice of the application disclosed herein. This application is intended to cover any variations, uses or adaptive changes of the application following the general principles thereof and including those expressly stated or implied herein. The specification and examples are to be regarded as exemplary only, and the true scope and spirit of the application are indicated by the claims.

[0127] It should be understood that the application is not limited to the precise construction which has been described above and which shown in the drawings, and that various modifications and changes can be made by those skilled in the art without departing from the scope of the application. The scope of the application should be limited only by the appended claims.

Claims

1. A method for protecting vehicle OTA information security of a domain control electrical architecture, characterized in that, The method comprises: The OTA platform applies for a platform SSL server certificate to a PKI / CA system, the OTA platform comprising a platform SSL gateway; a vehicle-side OTA master applies for a device certificate and an OTA signature certificate to the PKI / CA system; The OTA platform generates an upgrade package and requests the PKI / CA system to sign a hash value of the upgrade package, and then distributes the upgrade package, the hash value and a corresponding signature value to a content distribution network (CDN) platform; wherein the upgrade package at least comprises a first upgrade package corresponding to the vehicle-side OTA master, a second upgrade package corresponding to the vehicle-side OTA slave, and a third upgrade package corresponding to other controllers to be upgraded on the vehicle except the OTA master and the OTA slave; The OTA platform pushes an OTA service to a user terminal and receives an upgrade instruction of the user; The vehicle-side OTA master and the vehicle-side OTA slave download corresponding upgrade packages, hash values and signature values from the CDN platform according to the upgrade instruction, and verify the signature values using the OTA signature certificate, and perform an upgrade operation after verification is passed; The vehicle-side OTA master is responsible for downloading the first upgrade package and the third upgrade package, and the vehicle-side OTA slave is responsible for downloading the second upgrade package; the OTA slave sends corresponding hash values and signature values to the OTA master when verifying, and returns the result to the OTA master after the OTA master completes verification.

2. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of the OTA platform applying for a platform SSL server certificate to a PKI / CA system specifically comprises: The OTA platform applies for the platform SSL server certificate to the PKI / CA system through a certificate signing request (CSR); After the PKI / CA system issues the platform SSL server certificate, the OTA platform deploys the platform SSL server certificate to the platform SSL gateway.

3. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of the vehicle-side OTA master applying for a device certificate to the PKI / CA system specifically comprises: The vehicle-side OTA master generates a certificate signing request (CSR) and sends the SCEP certificate application message to the PKI / CA system, the CSR at least comprising a vehicle identification number (VIN); The PKI / CA system analyzes the SCEP certificate application message, extracts the vehicle identification number (VIN) information, and sends it to the OTA platform to authenticate the identity of the vehicle-side OTA master; After authentication, the certificate authority (CA) in the PKI / CA system issues the device certificate to the vehicle-side OTA master; The vehicle-side OTA master receives the device certificate and verifies the legality of the device certificate according to a pre-stored PKI certificate chain, and stores it after verification is passed.

4. The domain control electrical architecture vehicle OTA information security protection method according to claim 3, characterized in that, The step of the vehicle-side OTA master applying for an OTA signature certificate to the PKI / CA system specifically comprises: The vehicle end OTA master initiates an OTA signature certificate request to the PKI / CA system; The PKI / CA system issues the OTA signature certificate to the vehicle end OTA master in a state of querying that the OTA master has acquired the device certificate; The vehicle end OTA master receives the OTA signature certificate and stores it after verifying the legality of the OTA signature certificate.

5. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of requesting the PKI / CA system to sign the hash value of the upgrade package specifically includes: The OTA platform sends a signature request for the hash values of the first, second and third upgrade packages to a key management system KMS in the PKI / CA system; The KMS calls a cryptomachine connected thereto to sign the hash values, and sends the signature values to the OTA platform, wherein the cryptomachine interacts with the KMS through an intranet or a whitelist mechanism.

6. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of downloading the corresponding upgrade package, hash value and signature value from the CDN platform specifically includes: The CDN platform sends a CDN digital certificate to the vehicle end OTA master and the vehicle end OTA slave respectively; The vehicle end OTA master and the vehicle end OTA slave perform identity verification on the CDN digital certificate based on the CDN certificate chain deployed by each of them; After verification, the CDN platform transmits the corresponding upgrade package, hash value and signature value to the vehicle end OTA master and the vehicle end OTA slave respectively through a preset one-way TLS encryption channel.

7. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of the OTA platform pushing an OTA service to a user terminal and receiving an upgrade instruction of the user is performed in a two-way TLS encryption channel established between the OTA platform and the vehicle end OTA master using the platform SSL server certificate already deployed by the OTA platform.

8. The domain control electrical architecture vehicle OTA information security protection method according to claim 1, characterized in that, The step of verifying the signature value using the OTA signature certificate specifically includes: The vehicle end OTA master uses the OTA signature certificate to verify the signature value corresponding to the upgrade package downloaded by itself, and to verify the signature value sent by the vehicle end OTA slave.

9. A domain control electrical architecture vehicle OTA information security protection system, characterized in that, It includes: A PKI / CA system, an OTA platform, a content distribution network CDN platform, a vehicle end OTA master and a vehicle end OTA slave; The PKI / CA system is configured to issue a platform SSL server certificate for the OTA platform, issue a device certificate and an OTA signature certificate for the vehicle end OTA master, and sign an upgrade package hash value; The OTA platform includes a platform SSL gateway, which is in communication connection with the PKI / CA system, and is configured to manage the platform SSL server certificate, generate an upgrade package, request signature of an upgrade package hash value, distribute the upgrade package, hash value and signature value to the CDN platform, and push an OTA service to a user terminal and receive an upgrade instruction; The CDN platform is in communication connection with the OTA platform, and is configured to store and distribute the upgrade package, the hash value and the corresponding signature value to the vehicle-side OTA master and the vehicle-side OTA slave; The vehicle-side OTA master is in communication connection with the OTA platform and the CDN platform, and is configured to apply for and load the device certificate and the OTA signature certificate, download the upgrade package, the hash value and the signature value of itself and other controllers to be upgraded from the CDN platform, and use the OTA signature certificate to verify the signature values of itself, other controllers to be upgraded and the vehicle-side OTA slave; The vehicle-side OTA slave is in communication connection with the CDN platform and the vehicle-side OTA master, and is configured to download the upgrade package, the hash value and the signature value of itself from the CDN platform, and send the hash value and the signature value to the vehicle-side OTA master for verification.

10. The domain control electrical architecture vehicle OTA information security protection system according to claim 9, characterized in that, The PKI / CA system comprises a certificate authority (CA), a key management system (KMS) and a cryptomachine; The CA is configured to perform issuance and management of the platform SSL server certificate, the device certificate and the OTA signature certificate; The KMS is connected with the CA and the cryptomachine, and is configured to receive a signature request for an upgrade package hash value sent by the OTA platform, and send the signature request to the cryptomachine; The cryptomachine is connected with the KMS, and is configured to perform a signature operation on the upgrade package hash value.

Citation Information

Patent Citations

  • Vehicle software upgrading method and device and storage medium

    CN115022092A

  • OTA upgrading method, device and equipment, storage medium and vehicle

    CN116419206A