Security chip upgrading method and device, computer equipment, readable storage medium and program product

By receiving and processing encrypted target upgrade data packets, the online upgrade of the security chip is achieved, which solves the problems of complexity and low efficiency in traditional security chip upgrades, and realizes simplified operation and efficient upgrade.

CN121597241APending Publication Date: 2026-03-03BEIJING HUAHONG INTEGRATED CIRCUIT DESIGN
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511607874.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-05
Publication Date
2026-03-03

AI Technical Summary

Technical Problem

Traditional security chip upgrades are complex and inefficient, requiring soldering or flying wires to the communication pins to modify the program.

Method used

By receiving target upgrade information from vehicle-side devices, determining the upgrade status, and sending target upgrade data packets, the system uses encryption algorithms for data transmission and decryption to achieve online upgrades and automatically switches to backup programs in case of upgrade anomalies.

Benefits of technology

This simplifies the operation and enables efficient upgrades of security chips, avoiding hardware replacements and improving upgrade efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121597241A_ABST
    Figure CN121597241A_ABST
Patent Text Reader

Abstract

The invention relates to a security chip upgrading method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: receiving target upgrading information sent by vehicle end equipment; upgrade state information is determined according to the target upgrade information, the upgrade state information is sent to a vehicle end device, and the upgrade state information is used for enabling the vehicle end device to send a target upgrade data packet corresponding to the target upgrade information; and receiving the target upgrading data packet sent by the vehicle end equipment, and carrying out upgrading processing based on the target upgrading data packet. By adopting the method, the upgrading efficiency of the security chip can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle networking technology, and in particular to a method, apparatus, computer device, computer-readable storage medium, and computer program product for upgrading a security chip. Background Technology

[0002] In the field of connected vehicles, when customers change their business processes, add new functions, or fix bugs, it is often necessary to modify the OS (Operating System) program of the security chip and upgrade the program of the security chips that have already been produced.

[0003] In traditional technology, security chips are usually soldered onto the vehicle. When upgrading the OS program, it is necessary to replace the chip by soldering or modify the program by flying wires to the communication pins. The operation process is complicated and the upgrade efficiency is low. Summary of the Invention

[0004] Therefore, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium, and computer program product for upgrading security chips that is simple to operate and has high upgrade efficiency, in order to address the above-mentioned technical problems.

[0005] In a first aspect, this application provides a method for upgrading a security chip, comprising:

[0006] Receive target upgrade information sent by the vehicle-side equipment;

[0007] The upgrade status information is determined based on the target upgrade information, and the upgrade status information is sent to the vehicle-side device. The upgrade status information is used to enable the vehicle-side device to send the target upgrade data packet corresponding to the target upgrade information.

[0008] Receive the target upgrade data packet sent by the vehicle-side device, and perform upgrade processing based on the target upgrade data packet.

[0009] In one embodiment, the target upgrade data packet is a data packet encrypted using an encryption algorithm; the upgrade process based on the target upgrade data packet includes:

[0010] The target upgrade data packet is decrypted based on a preset decryption algorithm to obtain a decrypted data packet;

[0011] The upgrade process is performed based on the decrypted data packet.

[0012] In one embodiment, the method further includes:

[0013] The currently used system programs are stored in a preset storage area to obtain backup programs;

[0014] After performing the upgrade process based on the target upgrade data package, if an anomaly is detected in the upgraded system program, the upgraded system program will be switched to the backup program.

[0015] In one embodiment, storing the currently used system program into a preset storage area to obtain a backup program includes:

[0016] Perform integrity verification on the target upgrade data packet sent by the vehicle-side device;

[0017] If the verification passes, the currently used system program is stored in the preset storage area to obtain the backup program.

[0018] Secondly, this application also provides a method for upgrading a security chip, the method comprising:

[0019] Obtain the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip;

[0020] Receive upgrade status information sent by the security chip, the upgrade status information being determined based on the target upgrade information;

[0021] The target upgrade data packet is sent to the security chip based on the upgrade status information, so that the security chip can perform upgrade processing based on the target upgrade data packet.

[0022] In one embodiment, sending the target upgrade data packet to the security chip based on the upgrade status information includes:

[0023] In response to the upgrade status information indicating that the upgrade is supported, the target upgrade data packet is sent to the security chip; or...

[0024] In response to the upgrade status information being an upgrade interruption, upgrade information corresponding to the upgrade data packet of the upgrade interruption is obtained. If the upgrade information is inconsistent with the target upgrade information, the target upgrade data packet is sent to the security chip. If the upgrade information is consistent with the target upgrade information, the transmission is resumed based on the breakpoint position of the target upgrade data packet.

[0025] Thirdly, this application also provides a security chip upgrade device, the device comprising:

[0026] The receiving module is used to receive target upgrade information sent by the vehicle-side equipment;

[0027] The sending module is used to determine upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-end device. The upgrade status information is used to enable the vehicle-end device to send the target upgrade data packet corresponding to the target upgrade information.

[0028] The upgrade module is used to receive the target upgrade data packet sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packet.

[0029] In one embodiment, the target upgrade data packet is a data packet encrypted using an encryption algorithm; the upgrade module is specifically used for:

[0030] The target upgrade data packet is decrypted based on a preset decryption algorithm to obtain a decrypted data packet;

[0031] The upgrade process is performed based on the decrypted data packet.

[0032] In one embodiment, the device further includes:

[0033] The storage module is used to store the currently used system programs into a preset storage area to obtain backup programs;

[0034] The switching module is used to switch the upgraded system program to the backup program if an abnormality is detected after upgrading based on the target upgrade data package.

[0035] In one embodiment, the storage module is specifically used for:

[0036] Perform integrity verification on the target upgrade data packet sent by the vehicle-side device;

[0037] If the verification passes, the currently used system program is stored in the preset storage area to obtain the backup program.

[0038] Fourthly, this application also provides a security chip upgrade device, the device comprising:

[0039] The first sending module is used to acquire the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip;

[0040] A receiving module is configured to receive upgrade status information sent by the security chip, wherein the upgrade status information is determined based on the target upgrade information;

[0041] The second sending module is used to send the target upgrade data packet to the security chip based on the upgrade status information, so that the security chip can perform upgrade processing based on the target upgrade data packet.

[0042] In one embodiment, the second sending module is specifically used for:

[0043] In response to the upgrade status information indicating that the upgrade is supported, the target upgrade data packet is sent to the security chip; or...

[0044] In response to the upgrade status information being an upgrade interruption, upgrade information corresponding to the upgrade data packet of the upgrade interruption is obtained. If the upgrade information is inconsistent with the target upgrade information, the target upgrade data packet is sent to the security chip. If the upgrade information is consistent with the target upgrade information, the transmission is resumed based on the breakpoint position of the target upgrade data packet.

[0045] Fifthly, this application also provides a security chip upgrade system, the system comprising a security chip and vehicle-side equipment, wherein:

[0046] The vehicle-mounted device is used to acquire the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip;

[0047] The security chip is used to receive target upgrade information sent by the vehicle-side device, determine upgrade status information based on the target upgrade information, and send the upgrade status information to the vehicle-side device.

[0048] The vehicle-mounted device is also used to receive upgrade status information sent by the security chip, and send the target upgrade data packet to the security chip based on the upgrade status information;

[0049] The security chip is also used to receive target upgrade data packets sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packets.

[0050] Sixthly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method steps of the first or second aspect:

[0051] In a seventh aspect, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method steps of the first or second aspect.

[0052] Eighthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the method steps of the first or second aspect.

[0053] The aforementioned security chip upgrade method, apparatus, computer equipment, computer-readable storage medium, and computer program product can receive target upgrade information sent by a vehicle-side device; determine upgrade status information based on the target upgrade information, and send the upgrade status information to the vehicle-side device, wherein the upgrade status information is used to enable the vehicle-side device to send a target upgrade data packet corresponding to the target upgrade information; receive the target upgrade data packet sent by the vehicle-side device, and perform upgrade processing based on the target upgrade data packet. Based on the above scheme, online upgrades of the security chip can be realized, eliminating the need for ineffective chip removal and replacement or program modification via communication pin jumpers. The operation process is simple, effectively improving the upgrade efficiency of the security chip. Attached Figure Description

[0054] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0055] Figure 1 This is an application environment diagram of a security chip upgrade method in one embodiment;

[0056] Figure 2 This is a flowchart illustrating a security chip upgrade method in one embodiment;

[0057] Figure 3 This is a flowchart illustrating a security chip upgrade method in another embodiment;

[0058] Figure 4 This is a flowchart illustrating an example of a security chip upgrade method in another embodiment;

[0059] Figure 5 This is a structural block diagram of a security chip upgrade device in one embodiment;

[0060] Figure 6 This is a structural block diagram of a security chip upgrade device in another embodiment;

[0061] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation

[0062] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0063] This application provides a method for upgrading a security chip, which can be applied to a security chip upgrade system. For example... Figure 1 The diagram illustrates an application environment for a security chip upgrade method provided in this embodiment of the application. It includes a security chip and vehicle-side equipment. The security chip can be a Security Element (SE), which has functions such as secure storage, data encryption / decryption, and digital authentication, and is widely used in fields such as vehicle networking. The security chip can be fixed to the vehicle by soldering. An Operating System (OS) program can be installed in the security chip to manage the SE system, applications, security, and other functions. The vehicle-side equipment can be a vehicle-side Microcontroller Unit (MCU). The security chip can interact and transmit instructions to the vehicle-side MCU through a communication module. Specific interaction instructions are transparently transmitted to relevant modules for processing. The security chip can be equipped with a program upgrade module and a preset storage area (which can also be called an OS program backup area). The program upgrade module of the security chip can be used to handle upgrade functions. During the upgrade process, data is backed up in the OS program backup area, and the program is switched after the download is completed. The vehicle-side MCU can be equipped with an SDK (Software Development Kit) module. The SDK module can include a program upgrade interface and a business processing module. The program upgrade interface allows for upgrades to be completed without hardware operations, significantly reducing costs while retaining user data. The business processing module can be used to implement the relevant business processes of the SDK module.

[0064] The upgrade method for the security chip provided in this application will be described in detail below, with specific implementation details. For example... Figure 2 As shown, taking the application of this method to a security chip as an example, the steps include:

[0065] Step 202: Receive the target upgrade information sent by the vehicle-side device.

[0066] In this embodiment, the vehicle-mounted device can establish a secure communication channel with the security chip based on a preset algorithm when a preset trigger condition is met. The preset algorithm can be a national cryptographic algorithm or other secure communication algorithms, which are not limited in this embodiment. Then, the vehicle-mounted device can obtain the target upgrade data package from the target platform. Optionally, the user can activate the human-machine interface of the vehicle-mounted device to perform an upgrade trigger operation. In response to the user's upgrade trigger operation, the vehicle-mounted device establishes a secure communication channel with the security chip and then obtains the target upgrade data package from the target platform. Alternatively, the vehicle-mounted device can actively monitor whether a new upgrade data package has been released on the target platform. When an update to the target upgrade data package is detected on the target platform, a secure communication channel is established with the security chip, and the updated target upgrade data package is downloaded from the target platform. The vehicle-mounted device can obtain the target upgrade information of the target upgrade data package. The target upgrade information can include at least a description of the target upgrade data package, such as a version identifier (version number) and data package size. Then, the vehicle-mounted device can send the target upgrade information corresponding to the target upgrade data package to the security chip.

[0067] In one example, the vehicle-side device's SDK module includes a program upgrade interface, comprising an init interface, a load interface, and a complete interface. After obtaining the target upgrade information, the vehicle-side device can call the init interface to initialize the security chip, and the init interface sends the target upgrade information to the security chip via the communication interface. The security chip can receive the target upgrade information sent by the vehicle-side device through the communication interface and transmit it to the program upgrade module.

[0068] Step 204: Determine the upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-side device. The upgrade status information is used to enable the vehicle-side device to send the target upgrade data packet corresponding to the target upgrade information.

[0069] In this embodiment, the security chip can determine upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-side device. The upgrade status information indicates whether the security chip supports the upgrade. The vehicle-side device can determine whether to send target upgrade data to the security chip and the specific content of the target upgrade data to be sent based on the upgrade status information.

[0070] Specifically, the upgrade status information can include first upgrade status information, second upgrade status information, and third upgrade status information. The first upgrade status information, "upgrade supported," indicates that the previous version of the system program has been successfully upgraded, and the security chip supports upgrading to the target upgrade data packet. The second upgrade status information, "upgrade interrupted," indicates that the previous upgrade failed. The second upgrade status information may also include the version information of the failed system program and the data interruption point at the time of the upgrade failure. The third upgrade status information, "upgrade not supported," indicates that the previous version of the system program has been successfully upgraded, but the security chip does not support upgrading to the target upgrade data packet. In response to the upgrade status information "upgrade supported," the vehicle-mounted device sends the target upgrade data packet to the security chip. In response to the upgrade status information "upgrade interrupted," the vehicle-mounted device obtains the upgrade information corresponding to the interrupted upgrade data packet. If the upgrade information is inconsistent with the target upgrade information, it sends the target upgrade data packet to the security chip. If the upgrade information is consistent with the target upgrade information, it resumes the transmission based on the interruption point of the target upgrade data packet. In response to the upgrade status information "upgrade not supported," the vehicle-mounted device stops the upgrade process.

[0071] Step 206: Receive the target upgrade data packet sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packet.

[0072] In this embodiment, after the vehicle-side device determines that it needs to send a target upgrade data packet to the security chip based on the upgrade status information, it can call the load interface to send the target upgrade data packet to the security chip. Upon receiving the target upgrade data packet, the security chip can parse and process it to obtain system program data, and then perform upgrade processing based on the system program data in the target upgrade data packet.

[0073] Based on the above solution, online upgrades of security chips can be achieved, eliminating the need for disassembling and replacing chips or using communication pin jumpers to delete or modify programs. The operation process is simple and effectively improves the upgrade efficiency of security chips.

[0074] Optionally, the target upgrade data packet is a data packet encrypted using an encryption algorithm; the upgrade process based on the target upgrade data packet includes: decrypting the target upgrade data packet using a preset decryption algorithm to obtain a decrypted data packet; and performing the upgrade process based on the decrypted data packet.

[0075] In this embodiment, the target platform in the cloud can encrypt the target upgrade data packet, for example, using the SM4 encryption algorithm. The vehicle-side device can download the encrypted target upgrade data packet from the target platform and then send it to the security chip. Upon receiving the encrypted target upgrade data packet, the security chip can decrypt it using a preset decryption algorithm through the program upgrade module to obtain a decrypted data packet, and then perform upgrade processing based on the decrypted data packet.

[0076] Based on the above scheme, encrypted transmission of the target upgrade data packet can be achieved, preventing the target upgrade data packet from being tampered with or lost, thus improving the security of the security chip upgrade.

[0077] Optionally, the method also includes: storing the currently used system program in a preset storage area to obtain a backup program; and after performing an upgrade based on the target upgrade data package, if an anomaly is detected in the upgraded system program, switching the upgraded system program to the backup program.

[0078] In this embodiment, after the program upgrade module receives the target upgrade data packet, it can store the system program currently used by the security chip in a preset storage area as a backup program. After a successful upgrade based on the target upgrade data packet, the upgraded system program can be used. During the operation of the upgraded system program, if the security chip detects an anomaly in the upgraded system program, it can switch the upgraded system program to the backup program. Optionally, during the next program update, the cached backup program can be deleted, and a new backup program can be stored.

[0079] Based on the above solution, if the system program malfunctions, it can automatically revert to the previous version, ensuring the normal execution of the security chip's OS program and improving the reliability of the security chip's operation.

[0080] Optionally, the currently used system program can be stored in a preset storage area to obtain a backup program, including: performing integrity verification on the target upgrade data packet sent by the vehicle-side device; if the verification passes, the currently used system program can be stored in the preset storage area to obtain a backup program.

[0081] In this embodiment, after the vehicle-side device sends all data packets to the security chip, it can call the `complete` interface to send an integrity verification command (or a transmission completion command) to the chip. Upon receiving the integrity verification command, the security chip can perform integrity verification on the target upgrade data packet sent by the vehicle-side device. If the verification passes, the security chip stores the currently used system program in a preset storage area to obtain a backup program, switches the current system program to the upgraded system program, and then restarts to complete the system program upgrade. The security chip can also send an upgrade success message to the vehicle-side device, which may include an upgrade success identifier and upgraded version information, facilitating the vehicle-side device's reporting to the target platform in the cloud. If the verification fails, the security chip can send a verification failure message to the vehicle-side device, causing it to re-download the target upgrade data packet and re-process the upgrade.

[0082] Based on the above solution, system program switching and backup can be performed only after the integrity verification of the new system program has passed, thus improving the success rate of the upgrade.

[0083] like Figure 3 As shown, taking the application of this method to vehicle-side equipment as an example, the steps include:

[0084] Step 302: Obtain the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip.

[0085] In this embodiment, the vehicle-mounted device can establish a secure communication channel with the security chip based on a preset algorithm when a preset trigger condition is met. The preset algorithm can be a national cryptographic algorithm or other secure communication algorithms; this embodiment does not limit the specific algorithm. Then, the vehicle-mounted device can obtain a target upgrade data packet from the target platform and send the target upgrade information corresponding to the target upgrade packet to the security chip.

[0086] In one example, the vehicle-side device's SDK module includes a program upgrade interface, comprising an init interface, a load interface, and a complete interface. After obtaining the target upgrade information, the vehicle-side device can call the init interface to initialize the security chip, and the init interface sends the target upgrade information to the security chip via the communication interface. The security chip can receive the target upgrade information sent by the vehicle-side device through the communication interface and transmit it to the program upgrade module.

[0087] Step 304: Receive upgrade status information sent by the security chip. The upgrade status information is determined based on the target upgrade information.

[0088] In this embodiment, the security chip can determine upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-side device. The upgrade status information indicates whether the security chip supports the upgrade. The vehicle-side device can determine whether to send target upgrade data to the security chip and the specific content of the target upgrade data to be sent based on the upgrade status information.

[0089] Step 306: Send the target upgrade data packet to the security chip based on the upgrade status information, so that the security chip can perform upgrade processing based on the target upgrade data packet.

[0090] In this embodiment, after the vehicle-side device determines to send a target upgrade data packet to the security chip based on the upgrade status information, it can call the load interface to send the target upgrade data packet to the security chip. Upon receiving the target upgrade data packet, the security chip can parse and process it to obtain system program data, and then perform upgrade processing based on the system program data in the target upgrade data packet. It can be understood that the vehicle-side device can establish a secure communication channel with the security chip before downloading the target upgrade data packet to improve data transmission efficiency and reduce upgrade time; alternatively, the vehicle-side device can also download the target upgrade data packet after determining to send it to the security chip based on the upgrade status information to save network resources.

[0091] Based on the above solution, online upgrades of security chips can be achieved, eliminating the need for disassembling and replacing chips or using communication pin jumpers to delete or modify programs. The operation process is simple and effectively improves the upgrade efficiency of security chips.

[0092] Optionally, sending a target upgrade data packet to the security chip based on the upgrade status information includes: in response to the upgrade status information indicating that the upgrade is supported, sending a target upgrade data packet to the security chip; or, in response to the upgrade status information indicating that the upgrade is interrupted, obtaining the upgrade information corresponding to the upgrade data packet of the interrupted upgrade, and if the upgrade information is inconsistent with the target upgrade information, sending the target upgrade data packet to the security chip; if the upgrade information is consistent with the target upgrade information, resuming the transmission based on the breakpoint position of the target upgrade data packet.

[0093] In this embodiment, the upgrade status information may include first upgrade status information, second upgrade status information, and third upgrade status information. The first upgrade status information indicates "upgrade supported," signifying that the historical version of the system program has been successfully upgraded, and the security chip supports upgrading to the target upgrade data packet. The second upgrade status information indicates "upgrade interrupted," signifying that the previous upgrade failed. The second upgrade status information may also include the version information of the failed system program and the data interruption point at the time of the upgrade failure. The third upgrade status information indicates "upgrade not supported," signifying that the historical version of the system program has been successfully upgraded, and the security chip does not support upgrading to the target upgrade data packet. In response to the upgrade status information indicating "upgrade supported," the vehicle-side device sends the target upgrade data packet to the security chip. In response to the upgrade status information indicating "upgrade interrupted," the vehicle-side device obtains the upgrade information corresponding to the interrupted upgrade data packet. If the upgrade information is inconsistent with the target upgrade information, it sends the target upgrade data packet to the security chip. If the upgrade information is consistent with the target upgrade information, it resumes transmission based on the breakpoint position of the target upgrade data packet. In response to the upgrade status information indicating "upgrade not supported," the vehicle-side device stops the upgrade process.

[0094] Based on the above solution, the vehicle-side equipment can perform different processing according to the different upgrade statuses of the security chip, so as to improve upgrade efficiency and upgrade success rate.

[0095] Optionally, obtaining the target upgrade data packet includes: obtaining the target upgrade data packet in response to an upgrade trigger operation by the target user; or, obtaining the updated target upgrade data packet when an update to the target upgrade data packet is detected in the target platform.

[0096] In this embodiment, the user can use the human-machine interface of the vehicle-mounted device to execute an upgrade trigger operation. In response to the user's upgrade trigger operation, the vehicle-mounted device establishes a secure communication channel with the security chip and then obtains the target upgrade data package from the target platform. Alternatively, the vehicle-mounted device can actively monitor whether a new upgrade data package has been released on the target platform. When an update to the target upgrade data package is detected, it establishes a secure communication channel with the security chip and then downloads the updated target upgrade data package from the target platform. The vehicle-mounted device can obtain the target upgrade information from the target upgrade data package. This target upgrade information may include at least a description of the target upgrade data package, such as a version identifier (version number) and data package size. The vehicle-mounted device can then send the target upgrade information corresponding to the target upgrade data package to the security chip.

[0097] Based on the above scheme, multiple upgrade trigger conditions are provided, which improves the flexibility of the upgrade and makes the security chip upgrade method of this application applicable to different scenarios, thereby improving the user experience.

[0098] like Figure 4As shown in the figure, this application embodiment provides an example of a security chip upgrade method, including the following steps:

[0099] Step 401: The vehicle-side MCU establishes a communication connection with the security chip.

[0100] Step 402: The vehicle-side MCU sends the target upgrade information to the security chip.

[0101] Step 403: The security chip determines the upgrade status information based on the target upgrade information and sends the upgrade status information to the vehicle-side MCU.

[0102] Step 404: The vehicle-side MCU sends the target upgrade data packet to the security chip based on the upgrade status information until the transmission is complete.

[0103] Step 405: The vehicle-side MCU sends an integrity verification command to the security chip.

[0104] Step 406: The security chip performs an integrity check. If the integrity check is successful, proceed to step 407; otherwise, proceed to step 409.

[0105] In step 407, the security chip stores the old version of the system program in the backup area and installs the new version of the system program based on the target upgrade data package.

[0106] Step 408: The security chip returns an upgrade success message to the vehicle-side MCU.

[0107] Step 409: The security chip returns a verification failure message to the vehicle-side MCU.

[0108] It should be understood that although the steps in the flowcharts of the above embodiments are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0109] Based on the same inventive concept, this application also provides an upgrade apparatus for a security chip to implement the aforementioned upgrade method for a security chip. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations of one or more security chip upgrade apparatus embodiments provided below can be found in the limitations of the security chip upgrade method described above, and will not be repeated here.

[0110] In one exemplary embodiment, such as Figure 5 As shown, a security chip upgrade device is provided, comprising:

[0111] The receiving module 510 is used to receive target upgrade information sent by the vehicle-end device;

[0112] The sending module 520 is used to determine upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-end device. The upgrade status information is used to enable the vehicle-end device to send the target upgrade data packet corresponding to the target upgrade information.

[0113] The upgrade module 530 is used to receive the target upgrade data packet sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packet.

[0114] In one embodiment, the target upgrade data packet is a data packet encrypted using an encryption algorithm; the upgrade module is specifically used for:

[0115] The target upgrade data packet is decrypted based on a preset decryption algorithm to obtain a decrypted data packet;

[0116] The upgrade process is performed based on the decrypted data packet.

[0117] In one embodiment, the device further includes:

[0118] The storage module is used to store the currently used system programs into a preset storage area to obtain backup programs;

[0119] The switching module is used to switch the upgraded system program to the backup program if an abnormality is detected after upgrading based on the target upgrade data package.

[0120] In one embodiment, the storage module is specifically used for:

[0121] Perform integrity verification on the target upgrade data packet sent by the vehicle-side device;

[0122] If the verification passes, the currently used system program is stored in the preset storage area to obtain the backup program.

[0123] In one exemplary embodiment, such as Figure 6 As shown, a security chip upgrade device is provided, comprising:

[0124] The first sending module 610 is used to acquire the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip.

[0125] The receiving module 620 is used to receive upgrade status information sent by the security chip, wherein the upgrade status information is determined based on the target upgrade information;

[0126] The second sending module 630 is used to send the target upgrade data packet to the security chip based on the upgrade status information, so that the security chip can perform upgrade processing based on the target upgrade data packet.

[0127] In one embodiment, the second sending module is specifically used for:

[0128] In response to the upgrade status information indicating that the upgrade is supported, the target upgrade data packet is sent to the security chip; or...

[0129] In response to the upgrade status information being an upgrade interruption, upgrade information corresponding to the upgrade data packet of the upgrade interruption is obtained. If the upgrade information is inconsistent with the target upgrade information, the target upgrade data packet is sent to the security chip. If the upgrade information is consistent with the target upgrade information, the transmission is resumed based on the breakpoint position of the target upgrade data packet.

[0130] The modules in the aforementioned security chip upgrade device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.

[0131] In one exemplary embodiment, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 7As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When the computer program is executed by the processor, it implements a method for upgrading a security chip. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.

[0132] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0133] In one exemplary embodiment, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the above-described method steps.

[0134] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the above-described method steps.

[0135] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the above-described method steps.

[0136] It should be noted that the user information (including but not limited to user device identifiers, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.

[0137] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.

[0138] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0139] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A method for upgrading a security chip, characterized in that, The method includes: Receive target upgrade information sent by the vehicle-side equipment; The upgrade status information is determined based on the target upgrade information, and the upgrade status information is sent to the vehicle-side device. The upgrade status information is used to enable the vehicle-side device to send the target upgrade data packet corresponding to the target upgrade information. Receive the target upgrade data packet sent by the vehicle-side device, and perform upgrade processing based on the target upgrade data packet.

2. The method according to claim 1, characterized in that, The target upgrade data packet is a data packet encrypted using an encryption algorithm; the upgrade process based on the target upgrade data packet includes: The target upgrade data packet is decrypted based on a preset decryption algorithm to obtain a decrypted data packet; The upgrade process is performed based on the decrypted data packet.

3. The method according to claim 1, characterized in that, The method further includes: The currently used system programs are stored in a preset storage area to obtain backup programs; After performing the upgrade process based on the target upgrade data package, if an anomaly is detected in the upgraded system program, the upgraded system program will be switched to the backup program.

4. The method according to claim 3, characterized in that, The step of storing the currently used system program into a preset storage area to obtain a backup program includes: Perform integrity verification on the target upgrade data packet sent by the vehicle-side device; If the verification passes, the currently used system program is stored in the preset storage area to obtain the backup program.

5. A method for upgrading a security chip, characterized in that, The method includes: Obtain the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip; Receive upgrade status information sent by the security chip, the upgrade status information being determined based on the target upgrade information; The target upgrade data packet is sent to the security chip based on the upgrade status information, so that the security chip can perform upgrade processing based on the target upgrade data packet.

6. The method according to claim 5, characterized in that, Sending the target upgrade data packet to the security chip based on the upgrade status information includes: In response to the upgrade status information indicating that the upgrade is supported, the target upgrade data packet is sent to the security chip; or... In response to the upgrade status information being an upgrade interruption, upgrade information corresponding to the upgrade data packet of the upgrade interruption is obtained. If the upgrade information is inconsistent with the target upgrade information, the target upgrade data packet is sent to the security chip. If the upgrade information is consistent with the target upgrade information, the transmission is resumed based on the breakpoint position of the target upgrade data packet.

7. An upgrade device for a security chip, characterized in that, The device includes: The receiving module is used to receive target upgrade information sent by the vehicle-side equipment; The sending module is used to determine upgrade status information based on the target upgrade information and send the upgrade status information to the vehicle-end device. The upgrade status information is used to enable the vehicle-end device to send the target upgrade data packet corresponding to the target upgrade information. The upgrade module is used to receive the target upgrade data packet sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packet.

8. An upgrade system for a security chip, characterized in that, The system includes a security chip and vehicle-mounted equipment, wherein: The vehicle-mounted device is used to acquire the target upgrade data packet and send the target upgrade information corresponding to the target upgrade data packet to the security chip; The security chip is used to receive target upgrade information sent by the vehicle-side device, determine upgrade status information based on the target upgrade information, and send the upgrade status information to the vehicle-side device. The vehicle-mounted device is also used to receive upgrade status information sent by the security chip, and send the target upgrade data packet to the security chip based on the upgrade status information; The security chip is also used to receive target upgrade data packets sent by the vehicle-side device and perform upgrade processing based on the target upgrade data packets.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4 or claims 5 to 6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4 or claims 5 to 6.