Vehicle-mounted safety diagnosis data management method and device and electronic equipment

By introducing an independent diagnostic encryption module into the vehicle system, the problem that the existing vehicle diagnostic management system cannot adapt to diverse security needs is solved. This enables secure encrypted storage of data and flexible system expansion, thereby improving the system's security level and ease of maintenance.

CN121711364APending Publication Date: 2026-03-20CHINA AUTOMOTIVE INNOVATION CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511720686.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-21
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

Existing vehicle diagnostic management systems are ill-suited to diverse security needs and regulatory requirements, and cannot flexibly integrate new encryption algorithms or services, thus limiting the system's scalability and security level improvement.

Method used

An independent diagnostic encryption module is introduced into the vehicle system to encrypt diagnostic data and store it in the storage module. This decouples the diagnostic management module from the encryption module, ensuring data security and flexibility.

Benefits of technology

By decoupling the diagnostic management module and the encryption module, secure encrypted storage of diagnostic data is achieved, improving the system's scalability and ease of maintenance, and adapting to diverse security needs and regulatory requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121711364A_ABST
    Figure CN121711364A_ABST
Patent Text Reader

Abstract

The invention discloses a vehicle-mounted safety diagnosis data management method and device and electronic equipment. The method comprises the steps that a diagnosis data management request and diagnosis data sent by a diagnosis application module of a vehicle end are received; the diagnostic data management request is generated by the diagnostic application module based on the generation of the diagnostic data; sending a data encryption request and diagnosis data to a diagnosis encryption module; the diagnosis encryption module is used for encrypting diagnosis data based on the data encryption request to obtain encrypted diagnosis data; receiving encrypted diagnosis data returned by the diagnosis encryption module; sending a storage request and encrypted diagnosis data to a storage module; the storage module is used for storing the encrypted diagnosis data; receiving a storage response returned by the storage module; and sending a diagnosis management response to the diagnosis application module. In the embodiment of the application, the service-oriented diagnosis encryption module is used to realize decoupling with the diagnosis management module, and maintenance and expansion are easier.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle safety technology, and in particular to a method, apparatus and electronic device for vehicle safety diagnostic data management. Background Technology

[0002] As the automotive industry rapidly evolves towards autonomous driving and intelligent connectivity, the complexity of in-vehicle systems and the volume of data interaction have significantly increased, placing higher demands on the safety, reliability, and flexibility of in-vehicle diagnostic management. In the diagnostic management system architecture of the Adaptive Platform Automotive Open System Architecture (APAUTOSAR), the Diagnostic Management (DM) module serves as the core hub, providing crucial data support for vehicle maintenance and displaying important vehicle fault information in real time. It acts as a vital bridge connecting the in-vehicle system and the maintenance process.

[0003] However, in existing solutions, the encryption, signing, decryption, and signature verification of diagnostic data and diagnostic sessions rely on the diagnostic management module to implement them based on fixed encryption algorithms. This makes it difficult for the system to adapt to diverse security needs and regulatory requirements. It also limits the system's scalability, making it impossible to flexibly access new encryption algorithms or encryption services, and making it difficult to adapt to the ever-increasing security level requirements and technology iteration needs of in-vehicle systems. Summary of the Invention

[0004] To address the existing technical problems, this invention provides a method, device, and electronic device for managing vehicle safety diagnostic data. By adding an additional diagnostic encryption module, independent of the diagnostic management module, which only handles data relay and request functions, the diagnostic data is encrypted and stored in the storage module, effectively protecting the security of the diagnostic data. The use of a service-oriented diagnostic encryption module decouples it from the diagnostic management module, making it easier to maintain and expand.

[0005] In a first aspect, embodiments of this application provide an in-vehicle safety diagnostic data management method, applied to a diagnostic management module on the vehicle side, including: Receives diagnostic data management requests and diagnostic data sent by the vehicle-side diagnostic application module; the diagnostic data management requests are generated by the diagnostic application module based on the generation of diagnostic data. Send a data encryption request and diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data. Receive encrypted diagnostic data returned by the diagnostic encryption module; Sends a storage request and encrypted diagnostic data to the storage module; the storage module is used to store the encrypted diagnostic data. Receive the storage response returned by the storage module; Send a diagnostic management response to the diagnostic application module.

[0006] In an optional embodiment, after sending the diagnostic management response to the diagnostic application module, the method further includes: In response to the diagnostic data read request sent by the diagnostic instrument, a read request is sent to the storage module; The receiving and storage module returns encrypted diagnostic data based on the read request; Send encrypted diagnostic data and a data decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic data based on the data decryption request to obtain the diagnostic data. In response to the diagnostic data returned by the diagnostic encryption module, a diagnostic data read response and diagnostic data are sent to the diagnostic instrument.

[0007] In one alternative embodiment, the method further includes: Receive data read / write requests sent by the diagnostic instrument; Obtain encrypted diagnostic messages based on data read / write requests; Sends an encrypted diagnostic message and a session decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic message based on the session decryption request to obtain the diagnostic message. Receive diagnostic messages returned by the diagnostic encryption module; Verify the diagnostic message and obtain the verification result; If the verification result is successful, obtain the diagnostic data; Send diagnostic data and a data encryption request to the diagnostic encryption module; Receive encrypted diagnostic data returned by the diagnostic encryption module; Send data read / write responses to the diagnostic instrument.

[0008] In one optional embodiment, the data read / write request is a target identifier read / write request; The diagnostic message is verified to obtain the verification results, including: Retrieve the configuration list; the configuration list includes multiple data identifiers; If the target identifier exists in the configuration list, the verification is considered successful; otherwise, if the target identifier does not exist in the configuration list, the verification is considered unsuccessful.

[0009] In one optional embodiment, if the verification result is successful, diagnostic data is obtained, including: If the verification result is successful, the corresponding target diagnostic application is determined based on the data read and write requests; The target diagnostic application generates and sends a verification command to the service registry center; the service registry center uses the verification command to query whether the target diagnostic application has been registered and generates the query results. Receive the query results returned by the service registry center; If the query results indicate that the target diagnostic application has been registered, call the read / write callback function of the target diagnostic application; Receive diagnostic data sent by the target diagnostic application.

[0010] In an optional embodiment, before receiving the diagnostic data management request and diagnostic data sent by the vehicle-side diagnostic application module, the method further includes: Receive algorithm configuration instructions sent by the host computer; the algorithm configuration instructions are generated by the host computer based on the user's selection of at least one target algorithm from the algorithm list; The algorithm configuration command is sent to the diagnostic encryption module; the diagnostic encryption module encrypts the data based on at least one target algorithm. Receive the algorithm configuration response returned by the diagnostic encryption module; Send the algorithm configuration response to the host computer.

[0011] In one optional embodiment, there are multiple algorithm configuration instructions, each including encryption scenario information and having a corresponding algorithm combination. Send a data encryption request and diagnostic data to the diagnostic encryption module, including: The target encryption scenario is determined based on the diagnostic management request; If the target encryption scenario exists among multiple encryption scenario information, a data encryption request is generated based on the target encryption scenario; or; if the target encryption scenario does not exist among multiple encryption scenario information, a data encryption request is generated based on a preset algorithm combination. Send a data encryption request and diagnostic data to the diagnostic encryption module.

[0012] In one optional embodiment, the diagnostic management module and the diagnostic application module are located on the first host, and the diagnostic encryption module is located on the second host.

[0013] Secondly, embodiments of this application provide an in-vehicle safety diagnostic data management device, applied to a diagnostic management module on the vehicle side, comprising: The first receiving module is used to receive diagnostic data management requests and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management requests are generated by the diagnostic application module based on the generation of diagnostic data; The first sending module is used to send a data encryption request and diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data. The second receiving module is used to receive encrypted diagnostic data returned by the diagnostic encryption module; The second sending module is used to send storage requests and encrypted diagnostic data to the storage module; the storage module is used to store the encrypted diagnostic data. The third receiving module is used to receive the storage response returned by the storage module; The third sending module is used to send diagnostic management responses to the diagnostic application module.

[0014] Thirdly, embodiments of this application provide an electronic device, which includes a processor and a memory. The memory stores at least one instruction, at least one program, code set, or instruction set. The at least one instruction, at least one program, code set, or instruction set is loaded and executed by the processor to implement the vehicle safety diagnostic data management method of the first aspect.

[0015] Fourthly, embodiments of this application provide a computer-readable storage medium storing at least one instruction or at least one program, wherein the at least one instruction or at least one program is loaded and executed by a processor to implement the vehicle safety diagnostic data management method of the first aspect.

[0016] Fifthly, embodiments of this application provide a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the vehicle safety diagnostic data management method of the first aspect.

[0017] The vehicle safety diagnostic data management method, apparatus, and electronic device provided in this application have the following technical effects: The system receives diagnostic data management requests and diagnostic data from the vehicle-side diagnostic application module; the diagnostic data management requests are generated by the diagnostic application module based on the generated diagnostic data; it sends data encryption requests and diagnostic data to the diagnostic encryption module; the diagnostic encryption module encrypts the diagnostic data based on the data encryption requests to obtain encrypted diagnostic data; it receives the encrypted diagnostic data returned by the diagnostic encryption module; it sends storage requests and encrypted diagnostic data to the storage module; the storage module stores the encrypted diagnostic data; it receives the storage response returned by the storage module; and it sends a diagnostic management response to the diagnostic application module. In this embodiment, by additionally setting up a diagnostic encryption module, independent of the diagnostic management module, which only serves as a data and request relay, and encrypting the diagnostic data before storing it in the storage module, the security of the diagnostic data is effectively protected. Using a service-oriented diagnostic encryption module achieves decoupling from the diagnostic management module, making it easier to maintain and expand. Attached Figure Description

[0018] To more clearly illustrate the technical solutions and advantages in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application. Figure 1 ; Figure 2 This is a schematic diagram of an application environment provided in an embodiment of this application. Figure 2 ; Figure 3 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 1 ; Figure 4 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 2 ; Figure 5 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 3 ; Figure 6 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 4 ; Figure 7 This is a flowchart illustrating an algorithm configuration method provided in an embodiment of this application; Figure 8 This is a flowchart illustrating a request encryption method provided in an embodiment of this application; Figure 9 This is a schematic diagram of the structure of an in-vehicle safety diagnostic data management device provided in an embodiment of this application; Figure 10 This is a hardware structure block diagram of a server for a vehicle safety diagnostic data management method provided in an embodiment of this application. Detailed Implementation

[0020] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0021] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or server that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.

[0022] In one possible embodiment, Figure 1 This is a schematic diagram of an application environment provided in an embodiment of this application. Figure 1 This includes the diagnostic instrument 101 and the vehicle end 102.

[0023] The vehicle-side 102 includes a diagnostic application module, a diagnostic management module, a diagnostic encryption module, and a storage module.

[0024] In other words, the diagnostic encryption module, diagnostic management module, and diagnostic application module are all located on the same host.

[0025] In this embodiment, the Diagnostic Application (DA) module is a vehicle-side module that generates diagnostic data based on the occurrence and recovery of faults. It monitors the abnormal status and recovery status of vehicle systems such as electronic control units, sensors, and actuators in real time, and converts these statuses into standardized diagnostic data, such as conforming to the standardized format of Unified Diagnostic Services (UDS), to provide raw data support for subsequent fault storage and diagnostic tool interaction.

[0026] The Diagnostic Management (DM) module specifically includes the Diagnostic Communication Manager (DCM) component, the Diagnostic Event Manager (DEM) component, and the Diagnostics over Internet Protocol (DoIP) component.

[0027] The DCM component is responsible for diagnostic communication, primarily managing the network connection between the electronic control unit and the diagnostic instrument. The DEM component is responsible for diagnostic event management, collecting the status of monitored events reported by the adaptive application. The DoIP component receives DoIP protocol messages sent by the diagnostic instrument and then passes the UDS data packet payload to the DCM.

[0028] In this application embodiment, the diagnostic encryption module is specifically a cryptography (CRYPTO) module under the service-oriented architecture (SOA), which provides SOA application services and adaptive platforms with a variety of encryption algorithms such as symmetric encryption, asymmetric encryption, key negotiation, digital signature, hash calculation, and message authentication, and supports cross-domain encryption operations.

[0029] In this embodiment, the storage module is specifically the Persistency module under SOA, which provides unified storage for persistent diagnostic data for SOA application services and adaptive platforms.

[0030] In another optional embodiment, the diagnostic management module and the diagnostic application module are located on the first host, and the diagnostic encryption module is located on the second host. Figure 2 This is a schematic diagram of an application environment provided in an embodiment of this application. Figure 2 It includes a diagnostic instrument 101, a vehicle terminal 102, and an encryption host 103.

[0031] The vehicle-side unit 102 is the first host, which includes a diagnostic application module, a diagnostic management module, and a storage module. The diagnostic encryption module is independently located on the second host.

[0032] In one possible embodiment, the diagnostic management module of vehicle terminal 102 receives a diagnostic data management request and diagnostic data sent by the diagnostic application module of vehicle terminal; the diagnostic data management request is generated by the diagnostic application module based on the generation of diagnostic data; a data encryption request and diagnostic data are sent to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data; the encrypted diagnostic data returned by the diagnostic encryption module is received; a storage request and encrypted diagnostic data are sent to the storage module; the storage module is used to store the encrypted diagnostic data; a storage response is received from the storage module; and a diagnostic management response is sent to the diagnostic application module.

[0033] In this embodiment, an additional diagnostic encryption module is set up, independent of the diagnostic management module. The diagnostic management module only undertakes the function of relaying data and requests. The diagnostic data is encrypted and stored in the storage module, which effectively protects the security of the diagnostic data. The use of a service-oriented diagnostic encryption module achieves decoupling from the diagnostic management module, making it easier to maintain and expand.

[0034] The following describes a specific embodiment of an on-board safety diagnostic data management method according to this application. Figure 3 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 1 This specification provides method operation steps as shown in the embodiments or flowcharts, but based on conventional or non-inventive labor, more or fewer operation steps may be included. The order of steps listed in the embodiments is merely one possible execution order among many and does not represent the only execution order. In actual system or server products, the methods shown in the embodiments or drawings can be executed sequentially or in parallel (e.g., in a parallel processor or multi-threaded processing environment). Specifically, as shown in the embodiments or drawings... Figure 3 As shown, this method, applied to the vehicle-side diagnostic management module, may include: S201: Receive diagnostic data management request and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management request is generated by the diagnostic application module based on the generation of diagnostic data.

[0035] S202: Send a data encryption request and diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data.

[0036] S203: Receive encrypted diagnostic data returned by the diagnostic encryption module.

[0037] S204: Send a storage request and encrypted diagnostic data to the storage module; the storage module is used to store the encrypted diagnostic data.

[0038] S205: Receive the storage response returned by the storage module.

[0039] S206: Send a diagnostic management response to the diagnostic application module.

[0040] Figure 4 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 2 The method may include: S301: Receives diagnostic data management requests and diagnostic data sent by the vehicle-side diagnostic application module.

[0041] In one possible embodiment, the diagnostic data management request is generated by the diagnostic application module based on the generation of diagnostic data. After a fault occurs or is recovered, the diagnostic application module sends a real-time monitoring request and generates a diagnostic data management request to invoke the DM's Application Programming Interface (API).

[0042] In the embodiments of this application, the diagnostic data management request typically includes a request type, core fault data, fault context information, and a request identifier.

[0043] The request type is used to specify the purpose of the operation. For example, the request type may include the fault data reporting type when a fault occurs, the fault recovery confirmation type when a fault is eliminated, and the diagnostic data query type when historical records need to be obtained.

[0044] The core fault data can include the fault code (DTC) in the fault occurrence scenario, the fault type indicating whether it is a current fault or a historical fault, the trigger timestamp, and the recovered fault code, recovery timestamp, and status parameters after fault recovery in the fault recovery scenario.

[0045] Fault context information can include environmental parameters related to the fault, such as vehicle speed and temperature at the time of the fault, and can also include associated ECU status, such as power supply voltage and communication link quality, to assist DM in determining fault priority or other diagnostic management.

[0046] The request identifier is a unique identifier used to match the request when the DM returns a response, ensuring a closed-loop interaction.

[0047] S302: Send a data encryption request and diagnostic data to the diagnostic encryption module.

[0048] Upon receiving a diagnostic data management request, the system determines the required encryption algorithm and generates a data encryption request based on the specific request type, core fault data, fault context information, and request identifier.

[0049] In one possible embodiment, the diagnostic encryption module is used to encrypt and sign diagnostic data based on a data encryption request, resulting in encrypted diagnostic data. The standalone diagnostic encryption module can provide various encryption algorithms, including symmetric encryption, asymmetric encryption, key negotiation, digital signature, hash calculation, and message authentication.

[0050] S303: Receive encrypted diagnostic data returned by the diagnostic encryption module.

[0051] S304: Send a storage request and encrypted diagnostic data to the storage module.

[0052] In one possible embodiment, the storage module is used to persistently store encrypted diagnostic data. DM calls the Persistency module's write diagnostic data interface to persistently store the encrypted diagnostic data.

[0053] S305: Receive the storage response returned by the storage module.

[0054] S306: Send a diagnostic management response to the diagnostic application module.

[0055] After storage is complete, DM returns the results of the API call to the diagnostic application module.

[0056] Figure 5 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 3 The method may include: S401: In response to the diagnostic data read request sent by the diagnostic instrument, a read request is sent to the storage module.

[0057] After storage is complete, the diagnostic instrument can retrieve the diagnostic data for analysis and processing. The diagnostic instrument sends a diagnostic data read request to the diagnostic management module. Upon receiving the request, the diagnostic management module sends a request to the storage module to read the data. Specifically, the DM (Distributed Diagnostic Data Center) reads the diagnostic data from the Persistency module upon receiving the request. In this embodiment, the diagnostic data read request is specifically a DTC (Distributed Clinical Trial) information read service request.

[0058] S402: Receive encrypted diagnostic data returned by the storage module based on the read request.

[0059] S403: Send encrypted diagnostic data and data decryption request to the diagnostic encryption module.

[0060] In one possible embodiment, the diagnostic encryption module is also used to decrypt encrypted diagnostic data based on a data decryption request to obtain the diagnostic data. Specifically, DM calls the API provided by the Crypto module to perform decryption and signature verification operations.

[0061] S404: Receive diagnostic data returned by the diagnostic encryption module.

[0062] S405: Sends diagnostic data read response and diagnostic data to the diagnostic instrument.

[0063] After the data reading is complete, DM returns a diagnostic data reading response and diagnostic data to the diagnostic instrument.

[0064] Figure 6 This is a flowchart illustrating a vehicle safety diagnostic data management method provided in an embodiment of this application. Figure 4 The method may include: S501: Receives data read / write requests sent by the diagnostic instrument.

[0065] S502: Obtain encrypted diagnostic messages based on data read / write requests.

[0066] The DM obtains encrypted diagnostic messages, also known as DoIP ciphertext, based on data read / write requests. After receiving the DoIP ciphertext, the DM decrypts and verifies the signature using the API provided by the Crypto module, and generates a session decryption request.

[0067] S503: Sends encrypted diagnostic messages and session decryption requests to the diagnostic encryption module.

[0068] In an optional embodiment, the diagnostic encryption module is further configured to decrypt the encrypted diagnostic message based on the session decryption request to obtain the diagnostic message.

[0069] S504: Receive the diagnostic message returned by the diagnostic encryption module.

[0070] S505: Verify the diagnostic message and obtain the verification result.

[0071] In one optional embodiment, the data read / write request is a target identifier read / write request, that is, a service request to read / write a data identifier (DID).

[0072] In one optional embodiment, the diagnostic message is verified to obtain a verification result, including: S5051: Get the configuration list, which includes multiple data identifiers.

[0073] In this embodiment, the configuration list is a predefined set of identifiers, such as the list of DIDs that can be read and written in vehicle diagnostics, stored in the security configuration area of ​​the DM module, and can be updated and expanded by the host computer.

[0074] S5052: Determine if the target identifier exists in the configuration list. If yes, execute S5053; otherwise, execute S5054.

[0075] In this embodiment of the application, the target identifier is the identifier to be verified carried in the target identifier read / write request.

[0076] S5053: Verification passed is considered the verification result.

[0077] S5054: Verification failure is determined as the verification result.

[0078] In one possible implementation, if the target identifier exists in the configuration list, the verification is considered successful as the verification result.

[0079] In automotive systems, not all identifiers are accessible to external diagnostic tools. For example, DIDs (Distributed Identifiers) related to core autonomous driving parameters require strictly restricted access. A configuration list clearly defines which data identifiers can be manipulated, preventing unauthorized access to sensitive data. Furthermore, automotive diagnostics have high real-time requirements. List matching is a lightweight verification method that requires no complex calculations, enabling rapid verification and avoiding the impact of verification time on diagnostic efficiency. In addition, the configuration list can be dynamically updated via a host computer, allowing for the addition of DIDs or the removal of obsolete DIDs without modifying the underlying code to adapt to new diagnostic needs.

[0080] In another possible embodiment, if the target identifier is not present in the configuration list, the verification failure is determined as the verification result.

[0081] For target identifiers not in the configuration list, they can be rejected directly at the beginning of message processing, so that the DM module does not need to parse the complete message content, avoid invalid requests from entering subsequent encryption, forwarding and other processes, and save system resources.

[0082] If the verification result is that the verification fails, a verification failure message can be returned to the diagnostic instrument.

[0083] S506: If the verification result is successful, obtain the diagnostic data.

[0084] In one optional embodiment, if the verification result is successful, diagnostic data is obtained, including: S5061: If the verification result is successful, determine the corresponding target diagnostic application based on the data read / write request.

[0085] S5062: Generate and send verification instructions to the service registry based on the target diagnostic application.

[0086] In one optional embodiment, the service registry is used to query whether the target diagnostic application has been registered based on the verification command, and generate query results.

[0087] S5063: Receive the query results returned by the service registry.

[0088] S5064: If the query results indicate that the target diagnostic application has been registered, call the read / write callback function of the target diagnostic application.

[0089] In this embodiment of the application, if the target diagnostic application is found to be registered, the read / write callback function of the target diagnostic application is called to obtain diagnostic data.

[0090] S5065: Receive diagnostic data sent by the target diagnostic application.

[0091] S507: Send diagnostic data and data encryption request to the diagnostic encryption module.

[0092] S508: Receive encrypted diagnostic data returned by the diagnostic encryption module.

[0093] S509: Sends data read / write responses to the diagnostic instrument.

[0094] After obtaining the diagnostic data, it is also necessary to call the API provided by the Crypto module to perform encryption and signing operations, and finally return the encrypted diagnostic data to the diagnostic instrument client to ensure the security of the entire encrypted session.

[0095] Figure 7 This is a flowchart illustrating an algorithm configuration method provided in an embodiment of this application. The method may include: S601: Receives algorithm configuration instructions sent by the host computer.

[0096] In one alternative embodiment, the algorithm configuration instructions are generated by the host computer based on the user's selection of at least one target algorithm from the algorithm list.

[0097] The host computer pre-reads all algorithms supported by the CRYPTO module and displays them in a visual list or selection box format, clearly defining the purpose and parameter range of each algorithm to provide a basis for user selection. Users can specify several target algorithms to form the required algorithm combination based on the diagnostic scenario requirements, requiring the use of the specified algorithm combination to encrypt diagnostic data or diagnostic sessions. Different users can configure different algorithm combinations due to differences in permissions and scenarios, achieving flexible customization of encryption strategies that meet both security and compliance requirements while also considering ease of use and efficiency.

[0098] S602: Send the algorithm configuration command to the diagnostic encryption module.

[0099] In one optional embodiment, after receiving the instruction, the diagnostic encryption module first verifies whether the target algorithm is in the supported list. If supported, it loads the algorithm component, initializes the encryption process according to the combinational logic, and generates a successfully configured algorithm configuration response. If the target algorithm is not supported, the encryption module generates a failed algorithm configuration response, carrying the error reason.

[0100] In one alternative embodiment, the diagnostic encryption module encrypts based on at least one target algorithm.

[0101] S603: Receive the algorithm configuration response returned by the diagnostic encryption module.

[0102] The diagnostic encryption module returns the configuration success result to the DM module, which then feeds back to the host computer so that the user is aware of the configuration status.

[0103] S604: Send algorithm configuration response to the host computer.

[0104] In one optional embodiment, there are multiple algorithm configuration instructions, each including encryption scenario information and a corresponding algorithm combination.

[0105] For example, encrypted scenario information can include ordinary maintenance scenarios, sensitive operation scenarios, and export compliance scenarios. Ordinary maintenance scenarios correspond to the more efficient Algorithm A combination, sensitive operation scenarios to the more secure Algorithm B combination, and export compliance scenarios to the more compliant Algorithm C combination.

[0106] Figure 8 This is a flowchart illustrating a request encryption method provided in an embodiment of this application. Sending a data encryption request and diagnostic data to a diagnostic encryption module may include: S701: Determine the target encryption scenario based on the diagnostic management request.

[0107] The diagnostic management request is the source that triggers encryption and contains key information that can be used to determine the scenario.

[0108] In one possible implementation, the target encryption scenario can be determined by parsing the operation type, data sensitivity, and geographic information in the request through matching. For example, if the request is to read a DID of the ordinary category, the target encryption scenario is a normal maintenance scenario; if the request is to write a DID of the security category, the target encryption scenario is a sensitive operation scenario; if the request carries a vehicle sales region identifier, the target encryption scenario is an export compliance scenario.

[0109] In another possible embodiment, the target encryption scenario required can be determined by parsing the fault context information of the request and using a preset big oracle model.

[0110] S702: Determine if the target encrypted scenario exists among multiple encrypted scenario information. If yes, execute S703; otherwise, execute S704.

[0111] S703: Generate a data encryption request based on the target encryption scenario.

[0112] When a target encryption scenario exists among multiple encryption scenario information, the algorithm combination bound to that scenario is automatically retrieved, and a data encryption request containing that algorithm combination is generated.

[0113] S704: Generates a data encryption request based on a preset algorithm combination.

[0114] When the target encryption scenario is not found among multiple encryption scenario information, a data encryption request is generated by combining basic preset algorithms.

[0115] S705: Sends a data encryption request and diagnostic data to the diagnostic encryption module.

[0116] By dynamically selecting algorithm combinations based on scenario matching, different encryption scenarios correspond to different algorithm combinations in terms of efficiency, compliance, and security. This avoids situations where over-encryption affects efficiency or under-encryption leads to risks, achieving a balance between security and efficiency. The system can automatically determine scenarios and match algorithms by parsing diagnostic management requests, improving the efficiency and accuracy of the encryption process. When scenarios are not preset, default algorithm combinations ensure uninterrupted encryption, avoiding data security vulnerabilities caused by incomplete scenario coverage.

[0117] This application also provides an on-board safety diagnostic data management device. Figure 9 This is a schematic diagram of the structure of an on-board safety diagnostic data management device provided in an embodiment of this application, as shown below. Figure 9 As shown, the device 800 includes: The first receiving module 801 is used to receive diagnostic data management requests and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management requests are generated by the diagnostic application module based on the generation of diagnostic data; The first sending module 802 is used to send a data encryption request and diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data. The second receiving module 803 is used to receive encrypted diagnostic data returned by the diagnostic encryption module; The second sending module 804 is used to send a storage request and encrypted diagnostic data to the storage module; the storage module is used to store the encrypted diagnostic data. The third receiving module 805 is used to receive the storage response returned by the storage module; The third sending module 806 is used to send a diagnostic management response to the diagnostic application module.

[0118] In an optional embodiment, it further includes: In response to the diagnostic data read request sent by the diagnostic instrument, a read request is sent to the storage module; The receiving and storage module returns encrypted diagnostic data based on the read request; Send encrypted diagnostic data and a data decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic data based on the data decryption request to obtain the diagnostic data. In response to the diagnostic data returned by the diagnostic encryption module, a diagnostic data read response and diagnostic data are sent to the diagnostic instrument.

[0119] In an optional embodiment, it further includes: Receive data read / write requests sent by the diagnostic instrument; Obtain encrypted diagnostic messages based on data read / write requests; Sends an encrypted diagnostic message and a session decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic message based on the session decryption request to obtain the diagnostic message. Receive diagnostic messages returned by the diagnostic encryption module; Verify the diagnostic message and obtain the verification result; If the verification result is successful, obtain the diagnostic data; Send diagnostic data and a data encryption request to the diagnostic encryption module; Receive encrypted diagnostic data returned by the diagnostic encryption module; Send data read / write responses to the diagnostic instrument.

[0120] In an optional embodiment, the data read / write request is a target identifier read / write request; it also includes: Retrieve the configuration list; the configuration list includes multiple data identifiers; If the target identifier exists in the configuration list, the verification is considered successful; otherwise, if the target identifier does not exist in the configuration list, the verification is considered unsuccessful.

[0121] In an optional embodiment, it further includes: If the verification result is successful, the corresponding target diagnostic application is determined based on the data read and write requests; The target diagnostic application generates and sends a verification command to the service registry center; the service registry center uses the verification command to query whether the target diagnostic application has been registered and generates the query results. Receive the query results returned by the service registry center; If the query results indicate that the target diagnostic application has been registered, call the read / write callback function of the target diagnostic application; Receive diagnostic data sent by the target diagnostic application.

[0122] In an optional embodiment, it further includes: Receive algorithm configuration instructions sent by the host computer; the algorithm configuration instructions are generated by the host computer based on the user's selection of at least one target algorithm from the algorithm list; The algorithm configuration command is sent to the diagnostic encryption module; the diagnostic encryption module encrypts the data based on at least one target algorithm. Receive the algorithm configuration response returned by the diagnostic encryption module; Send the algorithm configuration response to the host computer.

[0123] In one optional embodiment, the number of algorithm configuration instructions is multiple, each algorithm configuration instruction including encryption scenario information, the encryption scenario information having a corresponding algorithm combination; and further includes: The target encryption scenario is determined based on the diagnostic management request; If the target encryption scenario exists among multiple encryption scenario information, a data encryption request is generated based on the target encryption scenario; or; if the target encryption scenario does not exist among multiple encryption scenario information, a data encryption request is generated based on a preset algorithm combination. Send a data encryption request and diagnostic data to the diagnostic encryption module.

[0124] In one optional embodiment, the diagnostic management module and the diagnostic application module are located on the first host, and the diagnostic encryption module is located on the second host.

[0125] The apparatus and method embodiments in this application are based on the same application concept.

[0126] The methods and embodiments provided in this application can be executed on a computer terminal, server, or similar computing device. Taking running on a server as an example, Figure 10 This is a hardware structure block diagram of a server for a vehicle safety diagnostic data management method provided in an embodiment of this application. For example... Figure 10 As shown, the server 900 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 910 (CPUs 910 may include, but are not limited to, microprocessors such as MCUs or programmable logic devices such as FPGAs), a memory 930 for storing data, and one or more storage media 920 (e.g., one or more mass storage devices) for storing application programs 923 or data 922. The memory 930 and storage media 920 may be temporary or persistent storage. The program stored in the storage media 920 may include one or more modules, each module may include a series of instruction operations on the server. Furthermore, the CPU 910 may be configured to communicate with the storage media 920 and execute the series of instruction operations stored in the storage media 920 on the server 900. Server 900 may also include one or more power supplies 960, one or more wired or wireless network interfaces 950, one or more input / output interfaces 940, and / or one or more operating systems 921, such as Windows Server™, Mac OS X™, Unix™, Linux™, FreeBSD™, etc.

[0127] The input / output interface 940 can be used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of server 900. In one example, the input / output interface 940 includes a network interface controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the input / output interface 940 may be a radio frequency (RF) module used for wireless communication with the Internet.

[0128] Those skilled in the art will understand that Figure 10 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, server 900 may also include... Figure 10 The more or fewer components shown, or having the same Figure 10 The different configurations shown.

[0129] This application provides an electronic device, which includes a processor and a memory. The memory stores at least one instruction, at least one program, code set, or instruction set. The processor loads and executes the at least one instruction, at least one program, code set, or instruction set to implement the above-described data processing method.

[0130] Embodiments of this application also provide a computer-readable storage medium, which can be disposed in a server to store at least one instruction, at least one program, code set, or instruction set related to implementing a vehicle safety diagnostic data management method in the method embodiment. The at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the above-described vehicle safety diagnostic data management method.

[0131] Optionally, in this embodiment, the storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0132] As can be seen from the embodiments of the vehicle-mounted safety diagnostic data management method, apparatus, electronic device, or storage medium provided in this application, this application receives diagnostic data management requests and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management request is generated by the diagnostic application module based on the generation of diagnostic data; a data encryption request and diagnostic data are sent to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data; the encrypted diagnostic data returned by the diagnostic encryption module is received; a storage request and encrypted diagnostic data are sent to the storage module; the storage module is used to store the encrypted diagnostic data; a storage response is received from the storage module; and a diagnostic management response is sent to the diagnostic application module. In the embodiments of this application, by additionally setting a diagnostic encryption module, independent of the diagnostic management module, the diagnostic management module only undertakes the function of relaying data and requests, and storing the encrypted diagnostic data in the storage module, the security of the diagnostic data is effectively protected. Using a service-oriented diagnostic encryption module, decoupling from the diagnostic management module is achieved, making it easier to maintain and expand.

[0133] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, specific embodiments have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps described in the claims can be performed in a different order than that shown in the embodiments and still achieve the desired result. Additionally, the processes depicted in the drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0134] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the device embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0135] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.

[0136] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A method for managing vehicle-mounted safety diagnostic data, characterized in that, The diagnostic management module applied to the vehicle includes: The system receives a diagnostic data management request and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management request is generated by the diagnostic application module based on the diagnostic data. The diagnostic encryption module sends a data encryption request and the diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data. Receive the encrypted diagnostic data returned by the diagnostic encryption module; A storage request and the encrypted diagnostic data are sent to the storage module; the storage module is used to store the encrypted diagnostic data. Receive the storage response returned by the storage module; Send a diagnostic management response to the diagnostic application module.

2. The method for managing vehicle-mounted safety diagnostic data according to claim 1, characterized in that, After sending the diagnostic management response to the diagnostic application module, the method further includes: In response to a diagnostic data read request sent by the diagnostic instrument, a read request is sent to the storage module; Receive the encrypted diagnostic data returned by the storage module based on the read request; The diagnostic encryption module sends the encrypted diagnostic data and a data decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic data based on the data decryption request to obtain the diagnostic data. In response to the diagnostic data returned by the diagnostic encryption module, a diagnostic data read response and the diagnostic data are sent to the diagnostic instrument.

3. The method for managing vehicle-mounted safety diagnostic data according to claim 1, characterized in that, The method further includes: Receive data read / write requests sent by the diagnostic instrument; Obtain encrypted diagnostic messages based on the data read / write request; The diagnostic encryption module sends the encrypted diagnostic message and a session decryption request to the diagnostic encryption module; the diagnostic encryption module is also used to decrypt the encrypted diagnostic message based on the session decryption request to obtain a diagnostic message. Receive the diagnostic message returned by the diagnostic encryption module; The diagnostic message was verified to obtain the verification result; If the verification result is successful, obtain the diagnostic data; Send the diagnostic data and the data encryption request to the diagnostic encryption module; Receive the encrypted diagnostic data returned by the diagnostic encryption module; Send a data read / write response to the diagnostic instrument.

4. The vehicle-mounted safety diagnostic data management method according to claim 3, characterized in that, The data read / write request is a target identifier read / write request; The verification of the diagnostic message to obtain the verification result includes: Obtain the configuration list; the configuration list includes multiple data identifiers; If the target identifier exists in the configuration list, the verification is determined to be successful; or, if the target identifier does not exist in the configuration list, the verification is determined to be unsuccessful.

5. The vehicle-mounted safety diagnostic data management method according to claim 3, characterized in that, If the verification result is successful, the diagnostic data is obtained, including: If the verification result is successful, the corresponding target diagnostic application is determined based on the data read / write request; A verification command is generated based on the target diagnostic application and sent to the service registry center; the service registry center is used to query whether the target diagnostic application has been registered based on the verification command and generate query results; Receive the query results returned by the service registry; If the query result indicates that the target diagnostic application has been registered, the read / write callback function of the target diagnostic application is invoked; Receive the diagnostic data sent by the target diagnostic application.

6. The vehicle-mounted safety diagnostic data management method according to claim 1, characterized in that, Before receiving the diagnostic data management request and diagnostic data sent by the diagnostic application module on the vehicle, the method further includes: Receive algorithm configuration instructions sent by the host computer; the algorithm configuration instructions are generated by the host computer based on the user's selection of at least one target algorithm from the algorithm list; The algorithm configuration command is sent to the diagnostic encryption module; the diagnostic encryption module performs encryption based on the at least one target algorithm. Receive the algorithm configuration response returned by the diagnostic encryption module; Send the algorithm configuration response to the host computer.

7. The vehicle-mounted safety diagnostic data management method according to claim 6, characterized in that, The number of algorithm configuration instructions is multiple, and each algorithm configuration instruction includes encryption scenario information, and the encryption scenario information has a corresponding algorithm combination; Sending the data encryption request and the diagnostic data to the diagnostic encryption module includes: The target encryption scenario is determined based on the diagnostic management request; If the target encryption scenario exists among the multiple encryption scenario information, the data encryption request is generated based on the target encryption scenario; or, if the target encryption scenario does not exist among the multiple encryption scenario information, the data encryption request is generated based on a preset algorithm combination. Send the data encryption request and the diagnostic data to the diagnostic encryption module.

8. The method for managing vehicle-mounted safety diagnostic data according to claim 1, characterized in that, The diagnostic management module and diagnostic application module are located on the first host, and the diagnostic encryption module is located on the second host.

9. A vehicle-mounted safety diagnostic data management device, characterized in that, The diagnostic management module applied to the vehicle includes: The first receiving module is used to receive a diagnostic data management request and diagnostic data sent by the diagnostic application module on the vehicle side; the diagnostic data management request is generated by the diagnostic application module based on the generation of the diagnostic data; The first sending module is used to send a data encryption request and the diagnostic data to the diagnostic encryption module; the diagnostic encryption module is used to encrypt the diagnostic data based on the data encryption request to obtain encrypted diagnostic data. The second receiving module is used to receive the encrypted diagnostic data returned by the diagnostic encryption module; The second sending module is used to send a storage request and the encrypted diagnostic data to the storage module; the storage module is used to store the encrypted diagnostic data. The third receiving module is used to receive the storage response returned by the storage module; The third sending module is used to send a diagnostic management response to the diagnostic application module.

10. An electronic device, characterized in that, The electronic device includes a processor and a memory, wherein the memory stores at least one instruction, at least one program, a code set, or an instruction set, and the at least one instruction, the at least one program, the code set, or the instruction set is loaded and executed by the processor to implement the vehicle safety diagnostic data management method as described in any one of claims 1-8.