On-board diagnostics (OBD)-based flash-proof and tamper-proof system and implementation method

By integrating national cryptographic algorithms and hardware isolation, the OBD anti-flashing and anti-tampering system solves the problems of hardware vulnerabilities, weak authentication, and data verification failure in the OBD system, achieving full-link security protection and improving vehicle safety and compliance.

CN121786840APending Publication Date: 2026-04-03JIANGXI CARBON NEUTRAL ENVIRONMENTAL PROTECTION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing OBD systems suffer from hardware vulnerabilities, weak authentication, and data verification failures, making it difficult to prevent unauthorized flashing and tampering, which affects vehicle safety and automakers' reputation.

Method used

The anti-write and anti-tampering system adopts a combination of national cryptographic algorithms, hardware isolation and dynamic multi-factor authentication. It includes a hardware protection layer, a software authentication layer and a data protection layer. It uses SM2/SM3/SM4 algorithms, optical isolation circuits, SM2 digital certificates, TOTP dynamic passwords and hash chain verification technologies to achieve full-link security protection.

Benefits of technology

It achieves 100% interception of illegal devices, 100% detection of data tampering, data recovery time of less than 5 seconds, compatibility with mainstream vehicle bus protocols, reduces vehicle failure rate by 76%, and reduces after-sales disputes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786840A_ABST
    Figure CN121786840A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of automobile electronic safety, and discloses an OBD-based flashing and tampering prevention system and an implementation method, so as to solve the problems of hardware vulnerability, weak authentication and verification failure of an existing OBD system. The system adopts a three-level protection framework, wherein a hardware protection layer integrates a national secret security chip with a PUF function and double physical protection of opto-coupler isolation and relay fusing; the software authentication layer realizes two-factor authentication through an SM2 certificate and a TOTP dynamic password, and combines space-time constraints of a time lock and a geofence; and the data protection layer constructs chain storage based on an SM3 hash chain and is matched with a data self-healing module. The implementation method comprises the steps of safe starting, dynamic authentication, data encryption storage and attack response. The actually measured illegal flash interception rate and the data tampering detection rate both reach 100%, the data recovery time is less than 5 seconds, the method is compatible with a mainstream vehicle enterprise bus protocol, the method is already applied to commercial vehicle teams and passenger vehicles, and the OBD safety is remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of automotive electronic safety technology, specifically relating to an OBD anti-flashing and anti-tampering system and implementation method that integrates national cryptographic algorithms, hardware isolation, and dynamic access control. It is applicable to various vehicles equipped with OBD interfaces, such as commercial vehicles, passenger vehicles, and new energy vehicles, and can prevent security risks such as illegal flashing of ECU data, tampering with vehicle parameters, and forging diagnostic identities, thereby ensuring vehicle driving safety and vehicle manufacturer data compliance. Background Technology

[0002] As the core interface for interaction between vehicles and external devices, OBD (On-Board Diagnostics) has expanded its functions from traditional fault diagnosis to key areas such as parameter configuration, remote monitoring, and firmware upgrades with the development of automotive electronics and connectivity, becoming an important node in the vehicle safety system. However, current mainstream OBD systems suffer from three major flaws, and their safety protection capabilities are far from meeting actual needs:

[0003] First, there's the issue of hardware vulnerabilities. The OBD interface connects directly to the vehicle's CAN bus, lacking a physical access control mechanism. Attackers can physically access the bus using simple OBD diagnostic tools or aftermarket equipment, tampering with critical information in the ECU such as engine torque, emission parameters, and mileage data. For example, criminals can use inexpensive OBD odometer tampering tools to alter passenger vehicle mileage data within 5 minutes, leading to a proliferation of "odometer-tampered cars." More seriously, hackers can inject malicious CAN messages through the OBD, directly controlling critical systems such as vehicle steering and braking. Previously, a car company experienced a batch of vehicles losing control and requiring a recall due to this type of vulnerability, resulting in direct economic losses exceeding 200 million yuan.

[0004] Secondly, the authentication mechanism is weak. Existing solutions mostly use simple password authentication based on the SAE J1939-73 standard, with password lengths typically only 4-8 characters. This makes them vulnerable to brute-force attacks like "OBD Bruteforcer," which can crack them within 10 minutes. Furthermore, the authentication information lacks a dynamic update mechanism. Once the password is leaked, attackers can illegally access the OBD system of the same vehicle model for an extended period. Tests conducted by a third-party security organization showed that OBD systems using traditional password authentication have an authentication failure rate as high as 72% in simulated real-world attack scenarios, making them completely defenseless against targeted attacks.

[0005] Finally, data verification fails. Traditional solutions rely on CRC checks to detect data transmission errors, but the CRC algorithm can only identify random transmission interference and is completely ineffective against carefully crafted malicious data injections by attackers. Tests show that the detection rate of malicious data injection tampering by forging CRC check values ​​is less than 30%. In recent years, with the popularization of open-source CAN bus tools (such as CANinjector and CANoe), the threshold for attackers to launch data tampering attacks has been greatly reduced. In 2023, the number of vehicle power abnormalities and emission exceedances caused by OBD tampering in the domestic freight market increased by 45% year-on-year. A logistics company's 50 heavy trucks collectively experienced a surge in fuel consumption and abnormal urea consumption due to ECU parameter tampering, directly affecting operational efficiency.

[0006] Furthermore, existing OBD protection solutions often focus on a single aspect (such as strengthening only software authentication), lacking a comprehensive hardware-software-data protection approach. This results in weaknesses in protection—for example, although some solutions use digital certificate authentication, attackers can still bypass authentication and directly physically tamper with bus data because the hardware is not isolated. These shortcomings not only threaten vehicle safety but also lead to increased after-sales disputes and damage to brand reputation for automakers, necessitating a comprehensive and robust OBD security protection technology. Summary of the Invention

[0007] The purpose of this invention is to address the shortcomings of existing OBD systems, such as hardware vulnerabilities, weak authentication, and verification failures, by providing a system and implementation method that integrates national cryptographic algorithms (SM2 / SM3 / SM4), hardware isolation, dynamic multi-factor authentication, spatiotemporal constraint access control, hash chain verification, and data self-healing technology to prevent unauthorized devices from being written to and to prevent data tampering. This system achieves 100% interception of illegal devices, 100% detection and rapid recovery of data tampering, compatibility with mainstream automotive bus protocols, and ensures vehicle driving safety and data compliance.

[0008] To achieve the above objectives, the present invention provides the following technical solution:

[0009] An OBD-based anti-write and anti-tampering system includes a three-level protection module: a hardware protection layer, a software authentication layer, and a data protection layer;

[0010] The hardware protection layer integrates a national cryptographic security chip and an optocoupler isolation circuit that conform to the GM / T 0008L2 standard. The national cryptographic security chip has a built-in SM4 encryption engine and a PUF physically unclonable module. The software authentication layer is configured with a two-factor authentication module of SM2 digital certificate and TOTP dynamic password, as well as a spatiotemporal constraint module that binds the effective time and GPS geofence. The data protection layer uses SM3 hash chain to construct a data block verification structure, with each block containing the hash value of the previous block, and is configured with a data self-healing module.

[0011] Furthermore, the optocoupler isolation circuit includes a relay array, which can melt down the OBD-CAN communication path when authentication fails, with an attack response time of <100ms.

[0012] Furthermore, the TOTP dynamic password is synchronously distributed to the authorized diagnostic device by the cloud-based TSP platform, and the spatiotemporal constraint module is based on the RBAC model extension, with maintenance authorization validity period ≤ 2 hours.

[0013] Furthermore, when the data self-healing module detects a break in the SM3 hash chain, it restores backup data from the encrypted area of ​​the national cryptographic security chip.

[0014] A method for preventing write operations based on the system according to any one of claims 1-4, comprising the following steps:

[0015] Step 1: After the OBD is powered on, the security chip verifies the firmware SM2 signature. If it fails, the communication circuit is blown off.

[0016] Step 2: The diagnostic device submits its ID, SM2 certificate, and TOTP dynamic password. After verification by the cloud-based TSP platform, it obtains an authorization token containing a list of operable PIDs.

[0017] Step 3: When writing data, calculate the SM3 hash value and sign it with SM2, then encrypt and store it before updating the hash chain.

[0018] Furthermore, in step 2, after the cloud-based TSP platform verifies the information, it returns the permission level and time lock parameters to the OBD system; if the verification fails, it refuses to generate an authorization token.

[0019] Furthermore, it also includes attack response steps: when the same device MAC address is detected to have failed authentication 3 times in total, the device will be permanently blocked and added to the blacklist.

[0020] Furthermore, the attack response steps also include: sending an attack alert to the cloud-based TSP platform and broadcasting attack device information to surrounding vehicles via V2X communication.

[0021] Furthermore, in step 3, the list of operable PIDs is limited by the RBAC permission matrix, allowing only authorized devices to modify compliant parameters and prohibiting unauthorized modification of key parameters such as VIN codes and engine torque.

[0022] Furthermore, in step 1, the security chip pre-programs a private key to verify the firmware SM2 signature. If the verification fails, the OBD system enters a hardware lock-up state and triggers a local alarm.

[0023] The beneficial effects of this invention are:

[0024] 1. Thorough security protection: The rate of interception of illegal devices and the detection rate of data tampering both reach 100%, and the data recovery time is less than 5 seconds, eliminating the risk of parameter tampering and illegal flashing;

[0025] 2. Excellent performance: Device authentication latency ≤50ms, peak CPU utilization only 8%, without affecting the vehicle's original diagnostic and operational functions;

[0026] 3. Wide compatibility: Adaptable to commercial vehicles, passenger vehicles, and new energy vehicles, supporting bus protocols of 12 mainstream automakers, with low deployment costs;

[0027] 4. Outstanding practical value: The spatiotemporal access control is adaptable to the needs of multiple scenarios, reducing vehicle failure rate by 76%, reducing after-sales disputes, and has significant industrialization prospects. Attached Figure Description

[0028] Figure 1 This is a schematic diagram of the system architecture of the OBD-based anti-write and anti-tampering system in this invention;

[0029] Figure 2 This is a schematic diagram illustrating the implementation process of the anti-write method in this invention;

[0030] Figure 3 This is a flowchart of the dynamic authentication and data writing process in this invention;

[0031] Figure 4 This is a schematic diagram of the SM3 hash chain data storage structure in this invention;

[0032] Figure 5 This is an example of the spatiotemporal access control matrix representation in this invention. Detailed Implementation

[0033] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0034] This invention proposes an OBD-based anti-write and anti-tampering system and implementation method, characterized in that:

[0035] (I) System Architecture

[0036] The OBD-based anti-write and anti-tampering system provided by this invention adopts a three-level protection architecture, with each level working together to achieve end-to-end security protection, as shown in the following architecture:

[0037] 1. Hardware protection layer

[0038] Security chip module: Selects Huada Electronics CIU98 series national cryptographic security chip, which complies with GM / T 0008L2 standard, and has a built-in SM4 symmetric encryption engine to achieve high-speed encrypted data storage; at the same time, it integrates a PUF (Physically Unclonable Function) module, which uses physical differences in the chip manufacturing process to generate a unique "physical fingerprint key". This key cannot be copied or exported, eliminating the risk of key leakage from the root.

[0039] Dynamic isolation module: Composed of optocoupler isolators and relay array. Optocoupler isolators provide electrical isolation between the OBD interface and the CAN bus, preventing attackers from damaging the bus through voltage injection. The relay array is controlled by the authentication result. When the device is authenticated, the relay closes to connect the OBD-CAN path. When authentication fails or an attack is detected, the relay immediately opens the fuse path. The attack response time is <100ms, which blocks unauthorized access at the physical level.

[0040] 2. Software Authentication Layer

[0041] Multi-factor authentication module: It integrates SM2 asymmetric digital certificates and TOTP (time-based one-time password) to form a dual identity verification mechanism: the SM2 certificate is issued by the car manufacturer's CA center and contains unique identification information of the diagnostic device, which can prevent certificate forgery; the TOTP dynamic password is generated based on the RFC 6238 standard and is synchronized to the authorized device in real time by the cloud TSP platform, and is updated every 30 seconds. Even if the certificate is leaked, attackers cannot obtain a valid password.

[0042] The spatiotemporal permission module is an extension of the RBAC (Role-Based Access Control) model, constructing a three-dimensional permission matrix of roles, permissions, and spatiotemporal permissions. Permissions are bound to an effective time (e.g., the validity period of a single repair authorization is ≤2 hours, and it will automatically expire after the time limit) and GPS geofencing (e.g., only allowing operation within 4S stores or designated repair shops). The vehicle's GPS module verifies the location in real time, and operations outside the scope are directly rejected to prevent authorized devices from being taken out of compliance scenarios and abused.

[0043] 3. Data Protection Layer

[0044] Chained storage module: The data blockchain structure is constructed using the SM3 hash algorithm. Each piece of OBD data (such as ECU parameters and diagnostic commands) is a "data block". In addition to the original data, each block also stores the SM3 hash value of the previous block. When new data is written, the hash value of the current block needs to be recalculated based on the hash value of the previous block, forming an irreversible verification link. Any data tampering will cause the hash chain to break, which can be detected in real time.

[0045] Self-healing module: An independent encrypted backup area is defined within the national cryptographic security chip, and key ECU parameters (such as engine control parameters and emission benchmark values) are periodically encrypted and backed up to this area; when the SM3 hash chain is detected to be broken (i.e. the data has been tampered with), the self-healing module automatically reads the data in the backup area, overwrites the tampered data, and restores the vehicle parameters to normal.

[0046] (II) Implementation Method and Flow

[0047] The anti-flashover and anti-tampering method of the present invention includes four major steps: secure boot, dynamic device authentication, data anti-tampering processing, and attack response, as shown in the following process:

[0048] 1. Safe Start

[0049] After the OBD interface is powered on, the system first executes the secure boot process: the national cryptographic security chip reads the SM2 signature built into its own firmware (this signature is pre-generated by the car manufacturer's private key, and the signature becomes invalid after the firmware is tampered with), and uses the car manufacturer's public key pre-programmed in the chip to verify the legality of the signature; if the verification is successful, the security chip releases control of the hardware isolation module, allowing subsequent device authentication; if the verification fails (such as if the firmware is tampered with), the security chip immediately triggers hardware lock-up, melts the OBD-CAN communication circuit, and issues an audible and visual alarm through the vehicle's instrument panel to prevent malicious firmware from running.

[0050] 2. Dynamic Device Authentication

[0051] When a diagnostic device initiates a connection request, it must complete the following authentication process:

[0052] The diagnostic device sends its device ID, SM2 certificate (including device identity information), and current TOTP dynamic password to the OBD system.

[0053] The OBD system encrypts and uploads the above authentication information to the cloud TSP platform, requesting certificate chain verification (verifying whether the SM2 certificate was issued by a legitimate CA center and whether it has been revoked);

[0054] The cloud-based TSP platform verifies the validity of the certificate and its consistency with the TOTP password. Once verified, it returns the corresponding permission level (e.g., read permission, write permission) and time lock parameters (e.g., authorization validity period of 2 hours) based on the device role (e.g., maintenance personnel, automotive engineers).

[0055] The OBD system generates an authorization token containing a "list of operable PIDs" (e.g., maintenance personnel can only operate the fault code clearing PID, and cannot operate the engine torque PID), and sends it to the diagnostic equipment to complete the authentication; if the verification fails, the OBD system refuses to generate the token and records the device's MAC address.

[0056] 3. Data tamper-proof processing

[0057] When an authorized device performs a data write operation, the system ensures data security through the following process:

[0058] The diagnostic equipment sends the data to be written (such as ECU parameter adjustment commands) to the OBD system;

[0059] The OBD system calls the SM3 hash algorithm to calculate a new hash value of "the hash value of the previous data block + the data to be written now", ensuring that the data is associated with the historical link;

[0060] The new hash value is signed using the SM2 private key of the national cryptographic security chip to generate an immutable digital signature;

[0061] The "data to be written + digital signature" is encrypted and stored in the encrypted area of ​​the security chip, and the SM3 hash chain is updated to the latest state to complete the data writing. When reading the data, the consistency between the signature and the hash value must be verified to prevent the data from being read after being tampered with.

[0062] 4. Attack Response Mechanism

[0063] The system monitors device access behavior and data integrity in real time. When an anomaly is detected, the following response is triggered:

[0064] If the same device MAC address fails to authenticate 3 times (e.g., entering an incorrect TOTP password or submitting a forged certificate), the system will permanently add the MAC address to the blacklist, and the relay will permanently melt down the communication path of the device, preventing it from accessing again.

[0065] Send attack alerts to the cloud-based TSP platform. The alert information includes the MAC address of the attacking device, the time of the attack, and the type of attack (such as identity spoofing or data injection), making it easier for automakers to trace the source of the attack.

[0066] If data tampering is detected (such as a broken SM3 hash chain), the data self-healing process is immediately initiated, the original data is read from the encrypted backup area of ​​the security chip, and the tampered data is overwritten. The recovery time is less than 5 seconds.

[0067] By broadcasting attack information to vehicles of the same brand within a 1-kilometer radius through the V2X (vehicle-to-everything) module, nearby vehicles are alerted to the attack device, thus achieving collaborative protection. Specific implementation examples:

[0069] To verify the effectiveness of this invention, implementation tests were conducted in two scenarios: commercial vehicle fleet management and passenger vehicle diagnostic protection, as detailed below:

[0070] Example 1: Commercial Vehicle Fleet Management Scenario

[0071] Deployment Background: A logistics company operates 500 heavy trucks (models include Dongfeng Tianlong KL and Jiefang JH6). Previously, due to the tampering of OBD parameters (such as illegally rewriting the engine fuel injection volume to increase power, resulting in excessive emissions), it has been repeatedly punished by the environmental protection department, and the abnormal power of the vehicles has caused multiple transportation delays. Therefore, it is urgent to strengthen OBD protection.

[0072] Preliminary preparations:

[0073] Hardware adaptation: For different vehicle ECU models (Bosch EDC17, Continental V54), the protocol adaptation interface of the national cryptographic security chip is used to complete the automatic matching of CAN bus baud rate (250kbps / 500kbps) to ensure that the protection system does not affect the original fault diagnosis and remote monitoring functions.

[0074] Software integration: Completed the interface development with Dongfeng Commercial Vehicle TSP platform, realizing three major functions: ① TOTP dynamic password generation and distribution (maintenance personnel receive passwords via tablet APP); ② permission parameter configuration (assigning "regional permissions" to different maintenance stations, allowing only operation of vehicles under the station's responsibility); ③ attack alarm reception and display (the platform displays information on attacking devices and the location of affected vehicles in real time).

[0075] Personnel training: Operation training was conducted for 120 maintenance personnel, clarifying the authorization process (authorization must be applied for by logging into the TSP platform with the employee ID, and a password will be obtained after approval) and time and space constraints (each authorization is valid for 1.5 hours and can only be operated within the company's 3 maintenance workshops).

[0076] Testing Methods and Duration: The testing period is 3 months, employing a combination of simulated attacks and real-world scenario monitoring.

[0077] Simulated attack: Using a modified OBD diagnostic tool (with a built-in CAN message tampering module), attempts were made to illegally rewrite key parameters such as engine fuel injection quantity and urea injection quantity, launching a total of 2000 attacks;

[0078] Real-world scenario: Statistics on the compliance of authorized operations during routine maintenance (e.g., whether operations exceeded the time limit / scope) and the number of abnormal accesses (e.g., unauthorized devices attempting to access the system).

[0079] Implementation results:

[0080] Test Project Traditional solution Invention Solution Improvement effect Illegal write interception rate 62% 100% An increase of 38 percentage points Data recovery time tampering >30 minutes <5 seconds 360 times more efficient System resource utilization CPU peak 35% CPU peak 8% 27 percentage points lower Authorization operation compliance rate 78% 100% Increased by 22 percentage points

[0081] User feedback: After deployment, the logistics company no longer experienced emission overruns or power malfunctions, and the number of environmental penalties dropped to 0; maintenance efficiency improved by 20% (no need for manual troubleshooting of parameter tampering); in 2024, the system intercepted 18,000 illegal spoofing operations, and the vehicle failure rate decreased by 76%.

[0082] Example 2: Diagnostic Protection Scenario for Passenger Vehicles

[0083] Test objective: To verify the ability of this invention to resist various attacks in passenger vehicle scenarios, and its compatibility with legitimate diagnostic functions.

[0084] Test environment:

[0085] Test vehicles: 10 mainstream passenger cars were selected (Mercedes-Benz C-Class, BMW 3 Series, Toyota Camry, BYD Han, etc.), and the OBD interface of all vehicles complies with the ISO 15031 standard;

[0086] Test site: Three scenarios were set up - 4S store repair environment (compliant scenario, inside the geofence), roadside repair shop environment (unauthorized scenario, outside the geofence), and outdoor open environment (attack scenario);

[0087] Testing tools: CANoe 11.0 (generates fake CAN messages and simulates diagnostic devices), OBDLink SX (collects OBD communication data), and a self-developed attack detection platform (statistics on interception results and system response time).

[0088] Attack scenario design: A total of 3 types of attacks were designed, with a total of 10,000 attack requests initiated.

[0089] Identity spoofing attack (1000 times): Use CANoe to forge the device ID and SM2 certificate of the authorized diagnostic instrument (clone the legitimate certificate information), and attempt to rewrite the VIN code and adjust the idle speed;

[0090] Data injection attack (5000 times): Inject fake CAN messages through the OBD interface to tamper with mileage data and fault code records in the ECU (such as clearing major accident fault codes);

[0091] Unauthorized operation attack (4000 times): ① Initiating operation outside the authorized time (e.g., 1 hour after the maintenance authorization expires); ② Initiating ECU firmware upgrade request outside the authorized geofence (e.g., 5 kilometers away from the 4S store).

[0092] Test results:

[0093] Identity spoofing attack: 1,000 spoofing requests were all blocked by the SM2 certificate chain verification - the cloud TSP platform detected that the certificate "issuance information does not match the device ID", refused to generate an authorization token, and the OBD system simultaneously recorded the MAC address of the attacking device;

[0094] Data injection attack: All 5,000 malicious packets were detected and tampered with by the SM3 hash chain (the newly calculated hash value was inconsistent with the stored hash value), triggering the data self-healing process with an average recovery time of 3.2 seconds. No malicious data was written to the ECU.

[0095] Unauthorized operation attack: Of the 4,000 timeout requests, 3,948 were directly blocked by the time and space permission module (interception rate of 98.7%), and the remaining 52 were "edge requests" caused by network latency (such as those initiated 1 second before the authorization expired). They were blocked twice by SM3 hash verification before the data was written, and did not pose a security risk.

[0096] Compatibility testing: During the test, a legitimate diagnostic instrument was used to perform operations such as reading fault codes, data streams, and clearing temporary faults. The response latency was ≤50ms (meeting the requirements of ISO 14229UDS protocol). There were no communication interruptions or functional failures. The average CPU utilization was 5.3%, which is lower than the design threshold of 8%.

[0097] Example 3: Supplementary Test for OBD Protection in New Energy Vehicles

[0098] To verify the adaptability of this invention to new energy vehicles, an additional 5 BYD Han EVs and 3 Tesla Model 3s were selected for testing:

[0099] Configuration adjustment: For high-voltage system parameters of new energy vehicles (such as battery SOC and motor speed), a "high-voltage parameter operation permission" has been added to the RBAC permission matrix, which can only be modified by the vehicle manufacturer's engineers in authorized scenarios;

[0100] Attack test: Simulated attackers tampering with battery SOC data via OBD (e.g., changing the actual 20% SOC to 50% to mislead users), launching a total of 500 attacks;

[0101] Results: All 500 attacks were intercepted. The SM3 hash chain detected SOC data tampering. The self-healing module restored the real SOC value from the backup area. No misjudgment problem occurred in the battery management system, proving that the present invention is suitable for new energy vehicle scenarios.

[0102] Technical effect

[0103] Safety performance has been greatly improved:

[0104] The illegal device interception rate is 100% (all 10,000 attacks were blocked in actual testing), solving the problem of "incomplete interception" in traditional solutions;

[0105] The data tampering detection rate is 100% (SM3 hash chain can identify all malicious data injections), and the data recovery time is less than 5 seconds, preventing vehicles from running abnormally for a long time.

[0106] Three authentication failures trigger a permanent circuit breaker, effectively resisting brute-force attacks. In 2024, Dongfeng Commercial Vehicle Fleet intercepted 32,000 illegal operations.

[0107] Balancing real-time performance with practicality:

[0108] The equipment certification delay is ≤50ms, which meets the requirements of the ISO 14229UDS protocol for diagnostic response speed and does not affect maintenance efficiency;

[0109] Spatiotemporal access control adapts to diverse scenarios (repair, inspection, vehicle debugging) and supports flexible configuration of access parameters;

[0110] The system resource utilization rate is low (CPU peak 8%), avoiding the occupation of vehicle electronic resources and causing other functions to lag.

[0111] Wide compatibility:

[0112] Supports CAN / FlexRay bus protocols from 12 mainstream automakers (Mercedes-Benz, BMW, Toyota, Dongfeng, BYD, etc.), with 100% test coverage;

[0113] It is compatible with various vehicle types, including commercial vehicles, passenger vehicles, and new energy vehicles, without requiring large-scale modifications to vehicle hardware, resulting in low deployment costs.

[0114] Significant industrialization value:

[0115] It has been successfully applied to the Dongfeng Commercial Vehicle fleet and a certain car manufacturer's 4S store network, resulting in a 76% reduction in vehicle failure rate and a 60% reduction in after-sales disputes;

[0116] This creates a technological barrier through the synergy of hardware, software, and algorithms, which can be extended to fleets in industries such as logistics, taxis, and ride-hailing, with broad market prospects.

[0117] The present invention and its embodiments have been described above. This description is not restrictive, and the accompanying drawings are only one embodiment of the present invention; the actual structure is not limited thereto. In conclusion, if those skilled in the art are inspired by this description and design similar structures and embodiments without departing from the spirit of the invention, such designs should fall within the protection scope of the present invention.

Claims

1. An OBD-based anti-write and anti-tampering system, characterized in that: It includes a three-tiered protection module: a hardware protection layer, a software authentication layer, and a data protection layer; The hardware protection layer integrates a national cryptographic security chip and an optocoupler isolation circuit that conform to the GM / T 0008L2 standard. The national cryptographic security chip has a built-in SM4 encryption engine and a PUF physically unclonable module. The software authentication layer is configured with a two-factor authentication module of SM2 digital certificate and TOTP dynamic password, as well as a spatiotemporal constraint module that binds the effective time and GPS geofence. The data protection layer uses SM3 hash chain to construct a data block verification structure, with each block containing the hash value of the previous block, and is configured with a data self-healing module.

2. The OBD-based anti-write and anti-tampering system according to claim 1, characterized in that: The optocoupler isolation circuit includes a relay array, which can melt down the OBD-CAN communication path when authentication fails, with an attack response time of <100ms.

3. The OBD-based anti-write and anti-tampering system according to claim 1, characterized in that: The TOTP dynamic password is synchronously issued to the authorized diagnostic equipment by the cloud-based TSP platform. The spatiotemporal constraint module is based on the RBAC model extension, and the maintenance permission validity period is ≤2 hours.

4. The OBD-based anti-write and anti-tampering system according to claim 1, characterized in that: When the data self-healing module detects a break in the SM3 hash chain, it restores backup data from the encrypted area of ​​the national cryptographic security chip.

5. A method for preventing write operations based on the system described in any one of claims 1-4, characterized in that, Includes the following steps: Step 1: After the OBD is powered on, the security chip verifies the firmware SM2 signature. If it fails, the communication circuit is blown off. Step 2: The diagnostic device submits its ID, SM2 certificate, and TOTP dynamic password. After verification by the cloud-based TSP platform, it obtains an authorization token containing a list of operable PIDs. Step 3: When writing data, calculate the SM3 hash value and sign it with SM2, then encrypt and store it before updating the hash chain.

6. The anti-write method according to claim 5, characterized in that: In step 2, after the cloud-based TSP platform verifies the information, it returns the permission level and time lock parameters to the OBD system. If the verification fails, it refuses to generate an authorization token.

7. The anti-write method according to claim 5, characterized in that: It also includes attack response steps: when the same device MAC address is detected to have failed authentication 3 times, the device will be permanently blocked and added to the blacklist.

8. The anti-write method according to claim 7, characterized in that: The attack response steps also include: sending an attack alert to the cloud-based TSP platform and broadcasting information about the attacking device to surrounding vehicles via V2X communication.

9. The anti-write method according to claim 5, characterized in that: In step 3, the list of operable PIDs is limited by the RBAC permission matrix, allowing only authorized devices to modify compliant parameters and prohibiting unauthorized modification of key parameters such as VIN codes and engine torque.

10. The anti-write method according to claim 5, characterized in that: In step 1, the security chip pre-programs a private key to verify the firmware SM2 signature. If the verification fails, the OBD system enters a hardware lock-up state and triggers a local alarm.