Vehicle key rotation method, vehicle and storage medium

By acquiring the vehicle's real-time risk index and operating parameters, dynamically adjusting the key rotation conditions, and utilizing a quantum random number generator and a dual-channel communication mechanism for key updates, the problem of inflexible key management in vehicle communication systems is solved, thereby improving communication security and reliability.

CN121968095APending Publication Date: 2026-05-01ANHUI KAIYANG TECHNOLOGY CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
ANHUI KAIYANG TECHNOLOGY CO LTD
Filing Date
2026-01-21
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

In existing technologies, the key management of vehicle communication systems adopts a fixed-cycle rotation, which cannot be flexibly adjusted according to the risk changes in the actual operating environment. This results in poor communication security and reliability, and the traditional key generation method is easy to predict and crack, posing a risk of physical tampering.

Method used

By acquiring the vehicle's real-time risk index and operating parameters, the key rotation conditions are dynamically adjusted to generate key update data. The key is then updated using a quantum random number generator and a dual-channel communication mechanism, ensuring the integrity and reliability of the key update process.

Benefits of technology

It enables intelligent and efficient rotation of vehicle network keys, which can respond to changes in vehicle risks in real time, improve communication security and reliability, and effectively resist network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968095A_ABST
    Figure CN121968095A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a vehicle key rotation method, a vehicle and a storage medium, and the method comprises the steps that a real-time risk index and vehicle operation parameters of the vehicle are obtained, the real-time risk index is used for determining the key rotation condition of the vehicle, and the vehicle operation parameters comprise the mileage or operation time of the vehicle; in response to the condition that the vehicle operation parameters meet the key rotation condition, rotation event data are obtained, and the rotation event data are used for representing event metadata corresponding to a key rotation event; secret key updating data are generated based on the rotation event data, and the secret key updating data are used for conducting communication verification on vehicle-mounted network data of the vehicle; and sending the key update data to the vehicle electronic control unit, so that the vehicle electronic control unit performs a key rotation operation based on the key update data. According to the method and the device, the technical problem of poor communication security and reliability caused by the fact that a vehicle-mounted network adopts a fixed period to alternate a vehicle-mounted key in the related technology is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the fields of information security and vehicle networking technology, specifically to a vehicle key rotation method, a vehicle, and a storage medium. Background Technology

[0002] With the rapid development of vehicle-to-everything (V2X) technology, vehicle information security faces unprecedented challenges. Key management in in-vehicle communication systems, in particular, has become crucial for protecting vehicle networks from attacks. Most in-vehicle key update mechanisms in related technologies employ fixed-cycle rotation, failing to flexibly adjust to changes in the actual operating environment's risks, thus creating a conflict between security and efficiency. Furthermore, traditional key generation methods rely on pseudo-random numbers, which are easily predicted and cracked, and the lack of key digest protection makes physical tampering possible, seriously impacting the security and reliability of in-vehicle networks.

[0003] There is currently no good solution to the above problems. Summary of the Invention

[0004] This application provides a vehicle key rotation method, a vehicle, and a storage medium to at least solve the technical problem of poor communication security and reliability caused by the use of fixed-period rotation of vehicle keys in in-vehicle networks in related technologies.

[0005] According to one aspect of the embodiments of this application, a vehicle key rotation method is provided, comprising: acquiring a real-time risk index and vehicle operating parameters of a vehicle, wherein the real-time risk index is used to determine the key rotation conditions of the vehicle, and the vehicle operating parameters include the vehicle's mileage or operating time; in response to the vehicle operating parameters meeting the key rotation conditions, acquiring rotation event data, wherein the rotation event data is used to represent event metadata corresponding to the key rotation event; generating key update data based on the rotation event data, wherein the key update data is used to perform communication verification on the vehicle's in-vehicle network data; and sending the key update data to a vehicle electronic control unit, so that the vehicle electronic control unit performs a key rotation operation based on the key update data.

[0006] Optionally, obtaining the real-time risk index of a vehicle includes: obtaining environmental perception data and vehicle status data of the vehicle, wherein the environmental perception data is used to determine the vehicle's operating scenario and the vehicle status data is used to represent the vehicle's operating condition; and performing risk assessment processing on the environmental perception data and vehicle status data to obtain the real-time risk index.

[0007] Optionally, the rotation event data includes: random seed data, preceding communication key, control unit identification data, and rotation counter data. The random seed data is used to randomly derive key update data, the preceding communication key is used to indicate the communication key currently used by the vehicle electronic control unit, the control unit identification data is used to establish the association between the key update data and the vehicle electronic control unit, and the rotation counter data is used to indicate the number of key rotation events.

[0008] Optionally, the vehicle key rotation method in this application embodiment further includes: generating a wake-up request instruction based on a key rotation event, wherein the wake-up request instruction is used to request the quantum random number generator to generate random seed data according to a preset bit length within a preset time; sending the wake-up request instruction to the quantum random number generator using a serial peripheral interface; and receiving the random seed data returned by the quantum random number generator based on the wake-up request instruction.

[0009] Optionally, generating key update data based on rotation event data includes: generating an updated communication key based on the rotation event data, wherein the updated communication key is uncorrelated with the previous communication key; performing a hash operation on the updated communication key to obtain an updated key digest, wherein the updated key digest is used to verify the updated communication key in the vehicle electronic control unit; and determining key update data based on the updated communication key and the updated key digest.

[0010] Optionally, sending key update data to the vehicle electronic control unit includes: encrypting the update communication key to obtain a key encryption result; broadcasting the key encryption result to the vehicle electronic control unit using a first communication channel; and broadcasting the update key digest to the vehicle electronic control unit using a second communication channel.

[0011] According to another aspect of the embodiments of this application, a vehicle key rotation method is also provided, comprising: receiving key update data sent by a gateway electronic control unit of a vehicle, wherein the key update data is generated based on rotation event data, the rotation event data is used to represent event metadata corresponding to the key rotation event, the rotation event data is acquired when the vehicle operating parameters meet the key rotation conditions, the vehicle operating parameters include the vehicle's mileage or operating time, and the key rotation conditions are determined based on the vehicle's real-time risk index; performing verification processing on the key update data to obtain a key verification result, wherein the key verification result is used to determine whether there is a transmission anomaly in the key update data; and, in response to the key verification result being successful, using the key update data to perform communication verification on the vehicle's in-vehicle network data.

[0012] Optionally, the key update data is verified to obtain a key verification result, including: in response to the key update data meeting the preset verification conditions, the key verification result is determined to be successful, wherein the preset verification conditions are used to compare the consistency between the key update data and the preset cache data, and the preset cache data is used to represent the key cache data in the gateway electronic control unit.

[0013] According to another aspect of the embodiments of this application, a vehicle key rotation device is also provided, comprising: a first acquisition module, configured to acquire a real-time risk index and vehicle operating parameters of a vehicle, wherein the real-time risk index is used to determine the key rotation conditions of the vehicle, and the vehicle operating parameters include the vehicle's mileage or operating time; a second acquisition module, configured to acquire rotation event data in response to the vehicle operating parameters meeting the key rotation conditions, wherein the rotation event data is used to represent event metadata corresponding to the key rotation event; a generation module, configured to generate key update data based on the rotation event data, wherein the key update data is used to perform communication verification on the vehicle's in-vehicle network data; and a sending module, configured to send the key update data to a vehicle electronic control unit, so that the vehicle electronic control unit performs a key rotation operation based on the key update data.

[0014] Optionally, the first acquisition module is further configured to: acquire environmental perception data and vehicle status data of the vehicle, wherein the environmental perception data is used to determine the vehicle's operating scenario and the vehicle status data is used to represent the vehicle's operating condition; and perform risk assessment processing on the environmental perception data and vehicle status data to obtain a real-time risk index.

[0015] Optionally, the rotation event data includes: random seed data, preceding communication key, control unit identification data, and rotation counter data. The random seed data is used to randomly derive key update data, the preceding communication key is used to indicate the communication key currently used by the vehicle electronic control unit, the control unit identification data is used to establish the association between the key update data and the vehicle electronic control unit, and the rotation counter data is used to indicate the number of key rotation events.

[0016] Optionally, the second acquisition module is further configured to: generate a wake-up request instruction based on the key rotation event, wherein the wake-up request instruction is used to request the quantum random number generator to generate random seed data according to a preset bit length within a preset time; send the wake-up request instruction to the quantum random number generator using the serial peripheral interface; and receive the random seed data returned by the quantum random number generator based on the wake-up request instruction.

[0017] Optionally, the generation module is further configured to: generate an updated communication key based on rotation event data, wherein the updated communication key is uncorrelated with the previous communication key; perform a hash operation on the updated communication key to obtain an updated key digest, wherein the updated key digest is used to verify the updated communication key in the vehicle electronic control unit; and determine key update data based on the updated communication key and the updated key digest.

[0018] Optionally, the sending module is further configured to: encrypt the updated communication key to obtain the key encryption result; broadcast the key encryption result to the vehicle electronic control unit using the first communication channel; and broadcast the updated key digest to the vehicle electronic control unit using the second communication channel.

[0019] According to another aspect of the embodiments of this application, a vehicle key rotation device is also provided, comprising: a receiving module, configured to receive key update data sent by a gateway electronic control unit of a vehicle, wherein the key update data is generated based on rotation event data, the rotation event data being used to represent event metadata corresponding to the key rotation event, the rotation event data being acquired when vehicle operating parameters meet key rotation conditions, the vehicle operating parameters including vehicle mileage or operating time, and the key rotation conditions being determined based on the vehicle's real-time risk index; a verification module, configured to verify the key update data to obtain a key verification result, wherein the key verification result is used to determine whether there is a transmission anomaly in the key update data; and a processing module, configured to, in response to a successful key verification result, perform communication verification on the vehicle's in-vehicle network data using the key update data.

[0020] Optionally, the verification module is further configured to: determine the key verification result as successful in response to the key update data meeting the preset verification conditions, wherein the preset verification conditions are used to compare the consistency between the key update data and the preset cache data, and the preset cache data is used to represent the key cache data in the gateway electronic control unit.

[0021] According to another aspect of the embodiments of this application, a vehicle is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods in various embodiments of this application when it runs.

[0022] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided, the computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0023] According to another aspect of the embodiments of this application, a computer program product is also provided, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0024] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0025] According to another aspect of the embodiments of this application, a computer program is also provided, which, when executed by a processor, implements the methods of the various embodiments of this application.

[0026] In this embodiment, by acquiring the vehicle's real-time risk index and operating parameters, and then responding to the vehicle operating parameters meeting the key rotation conditions, rotation event data is acquired. Subsequently, key update data is generated based on the rotation event data, and finally, the key update data is sent to the vehicle's electronic control unit (ECU) so that the ECU performs a key rotation operation based on the key update data. This ensures the integrity and reliability of the key update process. This embodiment, through dynamically adjusted key rotation conditions and timely generated key update data, achieves intelligent and efficient rotation of the vehicle network key. This ensures that the vehicle key is updated in real-time according to changes in the vehicle's risk status, effectively resisting potential network attacks and further improving the security and reliability of vehicle network communication. This solves the technical problem of poor communication security and reliability caused by fixed-period rotation of vehicle keys in related technologies. Attached Figure Description

[0027] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0028] Figure 1 This is a flowchart of a vehicle key rotation method according to an embodiment of this application;

[0029] Figure 2 This is a flowchart of another vehicle key rotation method according to an embodiment of this application;

[0030] Figure 3 This is a schematic diagram of a vehicle key rotation method according to an embodiment of this application;

[0031] Figure 4 This is a structural block diagram of a vehicle key switching device according to an embodiment of this application;

[0032] Figure 5 This is a structural block diagram of another vehicle key switching device according to an embodiment of this application. Detailed Implementation

[0033] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0034] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0035] According to an embodiment of this application, a method embodiment for vehicle key rotation is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.

[0036] This method embodiment can be executed in an electronic device or similar computing device that includes memory and a processor. Taking operation on a computer terminal as an example, the computer terminal may include one or more processors (processors may include, but are not limited to, central processing units (CPUs), graphics processing units (GPUs), digital signal processing (DSP) chips, microcontroller units (MCUs), field-programmable gate arrays (FPGAs), neural network processors (NPUs), tensor processors (TPUs), artificial intelligence (AI) type processors, etc.) and memory for storing data. Optionally, the computer terminal may also include transmission devices, input / output devices, and display devices for communication functions. Those skilled in the art will understand that the above structural description is merely illustrative and does not limit the structure of the computer terminal. For example, the computer terminal may include more or fewer components than described above, or have a different configuration than described above.

[0037] The memory can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the vehicle key rotation method in this embodiment. The processor executes various functional applications and data processing by running the computer program stored in the memory, thereby implementing the aforementioned vehicle key rotation method. The memory may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include memory remotely located relative to the processor, and these remote memories can be connected to the mobile terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0038] The transmission device is used to receive or send data via a network. Specific examples of the network mentioned above may include a wireless network provided by the mobile terminal's communication provider. In one example, the transmission device includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device may be a Radio Frequency (RF) module, used for wireless communication with the Internet.

[0039] Display devices can be, for example, touchscreen liquid crystal displays (LCDs) and touch displays (also referred to as "touchscreens" or "touch displays"). The LCD allows users to interact with the user interface of the mobile terminal. In some embodiments, the mobile terminal has a graphical user interface (GUI), which allows users to interact with the GUI through finger contact and / or gestures on a touch-sensitive surface. Optional human-computer interaction functions include: creating web pages, drawing, word processing, creating electronic documents, playing games, video conferencing, instant messaging, sending and receiving emails, call interfaces, playing digital video, playing digital music, and / or web browsing, etc. Executable instructions for performing the above human-computer interaction functions are configured / stored in one or more processor-executable computer program products or readable storage media.

[0040] This embodiment provides a vehicle key rotation method. Figure 1 This is a flowchart of a vehicle key rotation method according to an embodiment of this application, such as... Figure 1 As shown, the process includes the following steps:

[0041] Step S11: Obtain the vehicle's real-time risk index and vehicle operating parameters. The real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time.

[0042] Step S12: In response to the vehicle operating parameters meeting the key rotation conditions, obtain rotation event data, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event.

[0043] Step S13: Generate key update data based on rotation event data, wherein the key update data is used to perform communication verification on the vehicle's in-vehicle network data.

[0044] Step S14: Send key update data to the vehicle electronic control unit so that the vehicle electronic control unit can perform a key rotation operation based on the key update data.

[0045] The aforementioned real-time risk index is a quantitative indicator reflecting the current security risk level of a vehicle, calculated by the vehicle's Intrusion Detection System (IDS) using a preset algorithm based on multi-dimensional data such as real-time monitoring of the vehicle's internal and external environment, network traffic, and abnormal access requests. The real-time risk index can be dynamically updated, providing a trigger for key rotation and ensuring that the key update frequency matches the risk level. Specifically, the real-time risk index can be a score from 0 to 100, where 0 represents the lowest risk and 100 represents the highest risk. The real-time risk index can also be a risk label output by the IDS, such as a high-risk label, a medium-risk label, and a low-risk label.

[0046] The aforementioned vehicle operating parameters, including mileage and operating time, serve as important references for assessing the vehicle's communication security status. Combined with a real-time risk index, they determine the timing of key rotation. Consideration of mileage and operating time covers the vehicle's security needs in different usage scenarios, such as long-distance highway driving and frequent start-stop operations in urban environments.

[0047] The aforementioned key rotation conditions can be a set of rules based on real-time risk indices and vehicle operating parameters to determine when key rotation should be triggered. The key rotation conditions aim to balance communication security and system resource consumption, ensuring timely key updates when risk increases, while avoiding unnecessary frequent updates. The key rotation conditions are closely related to the real-time risk index; when the risk index rises, the key update frequency increases accordingly, and vice versa. This allows the key rotation strategy to be matched in real-time to the specific security environment of the vehicle, improving the security of the in-vehicle communication system.

[0048] For example, when a vehicle is traveling at 120 km / h on a highway, due to the relatively simple network environment on highways and the limited communication between the vehicle and other vehicles or roadside infrastructure, the IDS can output a low real-time risk index, such as 20. In this case, to reduce the computational and communication overhead caused by key rotation, a longer key rotation cycle can be set, such as rotating every 100 km or every 2 hours of operation.

[0049] Vehicles frequently start and stop in urban environments, constantly communicating with roadside infrastructure, other vehicles, and mobile devices. Simultaneously, the abundance of wireless network hotspots in urban environments increases the risk of cyberattacks. In this scenario, an IDS (Intrusion Detection System) can output a high real-time risk index, such as 80. To address this increased security risk, the key rotation cycle needs to be shortened, for example, triggering a key rotation every 25 km or every 30 minutes of operation, thereby increasing the difficulty for attackers to crack the keys.

[0050] When a vehicle is parked overnight, although it is not in use, it may still be in an environment vulnerable to physical intrusion or cyberattacks. Based on historical data analysis, the IDS can output a medium-risk index, such as 50. In this case, even though the vehicle is not in use, the key will still be updated according to preset key rotation conditions, such as every 15 km of parking or every 4 hours, ensuring that the vehicle network is secure when the vehicle restarts.

[0051] By continuously monitoring vehicle mileage and operating time, a key rotation event can be triggered when vehicle operating parameters meet pre-set thresholds in the key rotation conditions, thereby enabling the acquisition of rotation event data. This rotation event data may include metadata related to the key rotation event. The rotation event data forms the basis for generating key update data, ensuring the traceability of the key update process.

[0052] Furthermore, key update data is generated based on the key rotation event data. This key update data can be a set of data generated by the system when a key rotation event occurs, used to update the keys in the vehicular network. The key update data may include the newly generated key and its digest.

[0053] After generating key update data, it is sent to the vehicle's electronic control unit (ECU) so that the ECU can perform a key rotation operation based on the key update data. The ECU is an intelligent control module within the vehicle, responsible for performing specific functions such as power control, navigation, and safety systems. Upon receiving the key update data, the ECU can perform a key rotation operation based on the information contained therein, updating its local key to enhance communication security.

[0054] Based on steps S11 to S14 above, by acquiring the vehicle's real-time risk index and vehicle operating parameters, and then responding to the vehicle operating parameters meeting the key rotation conditions, rotation event data is acquired. Subsequently, key update data is generated based on the rotation event data, and finally, the key update data is sent to the vehicle's electronic control unit (ECU) so that the ECU can perform a key rotation operation based on the key update data. This ensures the integrity and reliability of the key update process. This embodiment of the application achieves intelligent and efficient rotation of the vehicle network key through dynamically adjusted key rotation conditions and timely generated key update data. This ensures that the vehicle key is updated in real time according to changes in the vehicle's risk status, effectively resisting potential network attacks, further improving the security and reliability of vehicle network communication, and thus solving the technical problem of poor communication security and reliability caused by fixed-period rotation of vehicle keys in related technologies.

[0055] The vehicle key rotation method in the embodiments of this application will be further described below.

[0056] In an optional embodiment, step S11, obtaining the vehicle's real-time risk index includes:

[0057] Step S111: Obtain the vehicle's environmental perception data and vehicle status data, wherein the environmental perception data is used to determine the vehicle's operating scenario and the vehicle status data is used to represent the vehicle's operating conditions.

[0058] Step S112: Perform risk assessment processing on the environmental perception data and vehicle status data to obtain the real-time risk index.

[0059] The aforementioned environmental perception data can be external environmental information collected by vehicle sensors, including but not limited to road conditions, traffic conditions, weather conditions, and the distance and speed of surrounding objects. Environmental perception data provides the vehicle with a comprehensive understanding of the external environment and is a key source of information for determining the vehicle's operating scenario.

[0060] The aforementioned vehicle status data covers the operational status of various systems and components within the vehicle, such as engine speed, battery voltage, vehicle speed, steering wheel angle, and brake pressure. This vehicle status data accurately depicts the vehicle's operating conditions and is crucial for monitoring the health of the in-vehicle network. For example, when a vehicle is traveling at high speed, the engine and tires experience greater stress, and the vehicle status data will display higher operating parameters, indicating that the system needs to remain highly vigilant.

[0061] In the process of acquiring environmental perception data and vehicle status data, a sensor network distributed throughout the vehicle body can continuously collect detailed information about the surrounding environment and its own status, including but not limited to visual data captured by cameras, distance information measured by radar, vehicle speed readings provided by vehicle speed sensors, and communication traffic recorded by network monitoring modules.

[0062] Furthermore, risk assessment processing is performed on environmental perception data and vehicle status data. This can be achieved based on a pre-set risk assessment model, which, after training, can identify key patterns and abnormal behaviors related to vehicle safety. When processing environmental perception data and vehicle status data, time series analysis, anomaly detection algorithms, and risk weights for specific scenarios can be employed to ultimately output a real-time risk index reflecting the overall safety risk of the vehicle. A higher real-time risk index indicates a greater potential safety threat to the vehicle, requiring more stringent communication security measures.

[0063] Based on the above optional embodiments, by acquiring the vehicle's environmental perception data and vehicle status data, and then performing risk assessment processing on the environmental perception data and vehicle status data, a real-time risk index reflecting the current risk status is generated. Thus, through the dynamic generation of the real-time risk index, the relationship between vehicle communication security and system performance can be effectively balanced, adaptive key management under different operating conditions can be realized, and the self-protection capability of the vehicle in the face of a changing security environment can be significantly improved.

[0064] In one optional embodiment, the rotation event data includes: random seed data, preceding communication key, control unit identification data, and rotation counter data, wherein the random seed data is used to randomly derive key update data, the preceding communication key is used to represent the communication key currently used by the vehicle electronic control unit, the control unit identification data is used to construct the association between the key update data and the vehicle electronic control unit, and the rotation counter data is used to represent the number of key rotation events.

[0065] The aforementioned random seed data can be a non-repeating sequence of numbers generated by a quantum random number generator (QRNG), which can serve as the starting value for subsequent key derivation. The unpredictability of the random seed data ensures that each derived key update is completely independent of the preceding communication key, thereby improving key security. The preceding communication key refers to the communication key currently in use by the vehicle's electronic control unit before the key rotation event occurs.

[0066] The aforementioned control unit identification data is a unique code used to clearly identify the vehicle's electronic control unit (ECU). In the in-vehicle network, each ECU has its unique identifier, enabling key update data to accurately locate the specific ECU requiring a key update. Establishing a direct link between key update data and the ECU ensures the targeted and efficient nature of the key update process. The aforementioned rotation counter data represents the number of key rotation events that occur, helping to track the key's lifecycle.

[0067] Based on the above optional embodiments, by integrating rotation event data including random seed data, preceding communication keys, control unit identification data, and rotation counter data, highly secure, accurately located, and orderly updated vehicle key management is achieved. This not only enhances the key's resistance to attacks but also ensures that each key update targets the correct vehicle electronic control unit. Furthermore, the effective use of rotation counter data further strengthens key security. Therefore, this embodiment significantly improves the security and protection level of vehicle communication without compromising vehicle network performance, providing robust information security for vehicles operating in complex and ever-changing environments.

[0068] In an optional embodiment, the vehicle key rotation method in this application further includes:

[0069] A wake-up request instruction is generated based on the key rotation event. The wake-up request instruction is used to request the quantum random number generator to generate random seed data with a preset bit length within a preset time.

[0070] The serial peripheral interface is used to send a wake-up request command to the quantum random number generator.

[0071] Receive random seed data returned by the quantum random number generator based on the wake-up request command.

[0072] The aforementioned wake-up request instruction is used to instruct the quantum random number generator to activate from a low-power or sleep state and generate random seed data of a specified length within a specified time range. For example, the QRNG outputs 256-bit random seed data and passes a self-test within 20µs. The wake-up request instruction ensures that the QRNG can respond quickly when needed and provide high-quality random numbers on demand, without having to remain in an active state and consume resources.

[0073] After generating the wake-up request command, the Serial Peripheral Interface (SPI) is used to send the wake-up request command to the quantum random number generator. The SPI is used for data transmission between the gateway electronic control unit and the quantum random number generator, ensuring accurate delivery of the wake-up request command and efficient reception of random seed data.

[0074] Upon detecting a key rotation event, the gateway electronic control unit generates and sends a wake-up request command to activate the quantum random number generator (QRNG). The wake-up request command is transmitted via a serial peripheral interface, requesting the QRNG to generate random seed data of a preset length within a preset time. Subsequently, the quantum random number generator responds to the wake-up request command, generating and returning the random seed data. The gateway electronic control unit receives the random seed data and uses it for the next stage of the key derivation process.

[0075] Based on the above optional embodiments, a wake-up request instruction is generated based on the key rotation event, and then the wake-up request instruction is sent to the quantum random number generator via the serial peripheral interface. Finally, the random seed data returned by the quantum random number generator based on the wake-up request instruction is received. This ensures that the quantum random number generator is called only when necessary in the vehicle system, which saves valuable resources in the vehicle environment and maintains the randomness and security required for key updates, thereby significantly enhancing the security of vehicle network communication.

[0076] In an optional embodiment, step S13, generating key update data based on rotation event data, includes:

[0077] Step S131: Generate an updated communication key based on the rotation event data, wherein the updated communication key and the previous communication key are uncorrelated.

[0078] Step S132: Perform a hash operation on the update communication key to obtain the update key digest, wherein the update key digest is used to verify the update communication key in the vehicle electronic control unit.

[0079] Step S133: Determine key update data based on the updated communication key and the updated key digest.

[0080] The updated communication key described above can be a new key derived from random seed data, the previous communication key, control unit identification data, and rotation counter data after a key rotation event occurs. There is no mathematical or logical connection between the updated communication key and the previous communication key, ensuring that the new key remains secure even if the previous key is compromised.

[0081] Furthermore, a hash operation is performed on the updated communication key to obtain an updated key digest. The updated key digest is a fixed-length output generated after the updated communication key is hashed. In the key update process of this application embodiment, the updated key digest can be used to verify the validity of the updated communication key. Differences in the updated key digest can indicate that the updated communication key may have been damaged or forged during transmission, thereby enabling the vehicle electronic control unit to promptly identify and refuse to update insecure communication keys.

[0082] In an optional embodiment, in step S14, sending key update data to the vehicle electronic control unit includes:

[0083] Step S141: Encrypt the updated communication key to obtain the key encryption result.

[0084] Step S142: Broadcast the key encryption result to the vehicle electronic control unit using the first communication channel, and broadcast the updated key digest to the vehicle electronic control unit using the second communication channel.

[0085] Specifically, encrypting the update communication key using an encryption algorithm ensures that the update communication key is protected from tampering during transmission. The encrypted result is the output of the updated communication key, which can be broadcast to the vehicle's electronic control unit in the first communication channel for decryption and use.

[0086] The first communication channel mentioned above can be a Controller Area Network Flexible Data Rate (CAN FD) channel. The second communication channel mentioned above can be an Ethernet channel, which provides higher bandwidth communication capabilities in an in-vehicle environment for broadcasting updated key digests.

[0087] The use of the first and second communication channels significantly improves the efficiency and reliability of data transmission. Each vehicle electronic control unit can independently verify the validity of the update communication key by receiving information from the two channels. That is, by comparing whether the received update key illumination and the digest data recalculated based on the decryption result are consistent, it can be determined whether the update communication key has been tampered with or transmitted incorrectly.

[0088] Based on the above optional embodiments, by encrypting the updated communication key to obtain the key encryption result, the encrypted key result is broadcast to the vehicle electronic control unit via the first communication channel, and the updated key digest is broadcast to the vehicle electronic control unit via the second communication channel. This greatly improves the security and efficiency of the vehicle network communication key update process. Encryption ensures the security and privacy of the updated communication key during transmission, preventing potential eavesdropping and tampering risks. Simultaneously, the parallel broadcast mechanism of the dual channels ensures that even if one channel encounters a problem, the other channel can still successfully complete the verification, avoiding the impact of a single communication failure on the entire key rotation process.

[0089] Figure 2 This is a flowchart of another vehicle key rotation method according to an embodiment of this application, such as... Figure 2 As shown, the process includes the following steps:

[0090] Step S21: Receive key update data sent by the vehicle's gateway electronic control unit. The key update data is generated based on rotation event data. The rotation event data is used to represent the event metadata corresponding to the key rotation event. The rotation event data is acquired when the vehicle's operating parameters meet the key rotation conditions. The vehicle operating parameters include the vehicle's mileage or operating time. The key rotation conditions are determined based on the vehicle's real-time risk index.

[0091] Step S22: Verify the key update data to obtain the key verification result, wherein the key verification result is used to determine whether there is a transmission anomaly in the key update data.

[0092] Step S23: In response to the key verification result being successful, use the key update data to perform communication verification on the vehicle's in-vehicle network data.

[0093] Specifically, the vehicle's electronic control unit that receives the data can perform a series of verification operations, such as comparing the received update key digest with the digest it calculates based on the received update communication key, and checking whether the timestamp meets expectations, in order to determine whether there are any abnormalities or tampering in the key update data during transmission, and finally obtain the key verification result.

[0094] If the key verification result indicates that the data transmission is correct, i.e., the verification is successful, the vehicle's electronic control unit can use the updated key to perform a new round of encryption and decryption verification on the in-vehicle network data, ensuring the security and integrity of the vehicle's internal communication.

[0095] After receiving and verifying the key update data, the vehicle's electronic control unit can write the verified new key into the designated key slot of its hardware security module and immediately activate it. The key slot is a hardware area specifically designed for storing and processing keys. By directly writing and activating the new key, communication security can be upgraded quickly. Simultaneously, the original key is marked as invalid, ensuring that the old key is no longer used for any encryption or decryption operations after the new key takes effect, thus avoiding the security risks of key reuse. In the hardware security module, key status management can be achieved by setting specific key attributes, thereby enabling rapid switching of key usage status and ensuring the continuity of communication security.

[0096] Based on steps S21 to S23 above, by receiving key update data sent by the vehicle's gateway electronic control unit, verifying the key update data, obtaining a key verification result, and finally responding to the key verification result as successful, the key update data is used to perform communication verification on the vehicle's in-vehicle network data, thereby ensuring the integrity and reliability of the key update process. This embodiment of the application achieves intelligent and efficient rotation of the in-vehicle network key through dynamically adjusted key rotation conditions and timely generated key update data. This ensures that the in-vehicle key is updated in real time according to changes in the vehicle's risk status, effectively resisting potential network attacks, further improving the security and reliability of in-vehicle network communication, and thus solving the technical problem of poor communication security and reliability caused by the fixed-period rotation of in-vehicle keys in related technologies.

[0097] The vehicle key rotation method in the embodiments of this application will be further described below.

[0098] In an optional embodiment, in step S22, the key update data is verified to obtain the key verification result, including:

[0099] In response to the key update data meeting the preset verification conditions, the key verification result is determined to be successful. The preset verification conditions are used to compare the consistency between the key update data and the preset cache data, which represents the key cache data in the gateway electronic control unit.

[0100] Based on the updated communication key and the updated key digest, the gateway electronic control unit determines the key update data. It can create a preset block to store the key cache data corresponding to the key update data. The key cache data can include: the updated key digest corresponding to the key update data, a timestamp, and mileage data closely related to the vehicle's driving conditions. The updated key digest can be used to verify the integrity of the updated communication key, and the timestamp records the precise time of the key update, helping to prevent single points of failure and replay attacks. The timestamp and mileage data together constitute a dynamic, risk-driven key lifecycle record, ensuring that each round of key updates has a clear temporal and spatial context.

[0101] After the preset block is constructed, the gateway electronic control unit can broadcast the block information to all participating nodes in the vehicle network, i.e., the vehicle electronic control units, through a distributed consensus algorithm. The distributed consensus algorithm can quickly and efficiently reach agreement among all vehicle electronic control units within a 100ms time window, confirming the correctness and validity of the preset block. The selection of the time window needs to fully consider the real-time and response speed requirements of the vehicle environment, ensuring that the key update process does not cause delays or affect the normal driving and functional execution of the vehicle.

[0102] Once a pre-defined block is confirmed through a distributed consensus algorithm, it is appended to the circular cache of each vehicle's electronic control unit. The circular cache is a lightweight storage mechanism that allows for the cyclic overwriting of older data within limited storage space to maintain the latest key update records. This effectively reduces the demand for onboard hardware storage resources while ensuring the availability of the lightchain and the up-to-dateness of on-chain data. Even with limited storage space, it can maintain a sufficient number of block records, supporting real-time verification and historical backtracking of key update events.

[0103] By constructing pre-defined blocks in the vehicular network to store key update data, not only are key information for each key update recorded, but a distributed consensus algorithm also ensures consistent confirmation of key rotation events across all nodes, thereby improving the security and reliability of vehicular network communication. Simultaneously, the application of circular caching keeps storage requirements and resource consumption within a reasonable range, enabling effective operation even in resource-constrained vehicular environments. This lightweight chain evidence storage mechanism provides a dynamic, reliable, and low-overhead update and verification solution for vehicular key management, significantly enhancing the vehicle's security capabilities in complex security environments.

[0104] In this embodiment, after receiving the key update data, the vehicle electronic control unit further executes a verification process to ensure that the received key update data is complete, intact, and untampered with. Specifically, the vehicle electronic control unit can check whether a preset block exists in the lightweight blockchain, whose preset cached data is directly related to the key rotation event. This ensures that the key rotation event has been confirmed and recorded by the vehicle network, thereby verifying the legality and validity of the key update. By querying the lightweight blockchain, the vehicle electronic control unit can confirm that various details in the key update process, such as timestamps, mileage, and event metadata, are correctly stored in the vehicle system.

[0105] Upon receiving the key update data, the vehicle's electronic control unit can also accurately compare the received update key digest with the digest record in the preset block. If the two match perfectly, it means that the update key digest has maintained its integrity during transmission and has not been subjected to man-in-the-middle attacks or data tampering.

[0106] The vehicle's electronic control unit (ECU) can also use its internal decryption capabilities to process the key encryption result. After successful decryption, the ECU can recalculate the hash digest of the decrypted key and match it with the previously received updated key digest. If the two digests match, it proves the accuracy of the decryption process and further verifies the security of the key during transmission.

[0107] If the vehicle's electronic control unit detects an inconsistent result during any of the above checks, it can be determined that the key update data fails to meet the preset verification conditions. In this case, the received key update data must be discarded immediately, and the anomaly must be recorded in the local log. By immediately discarding abnormal data and recording the anomaly, the security and stability of in-vehicle network communication are further ensured.

[0108] Figure 3 This is a schematic diagram of a vehicle key rotation method according to an embodiment of this application, as shown below. Figure 3 As shown, the method includes the following steps:

[0109] Step S301: Obtain the vehicle's real-time risk index and vehicle operating parameters. The real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time.

[0110] Step S302: In response to the vehicle operating parameters meeting the key rotation conditions, obtain rotation event data, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event;

[0111] Step S303: Generate an updated communication key based on the rotation event data, wherein the updated communication key and the previous communication key are uncorrelated;

[0112] Step S304: Perform a hash operation on the updated communication key to obtain the updated key digest, wherein the updated key digest is used to verify the updated communication key in the vehicle electronic control unit;

[0113] Step S305: Encrypt the updated communication key to obtain the key encryption result;

[0114] Step S306: Broadcast the key encryption result to the vehicle electronic control unit using the first communication channel, and broadcast the updated key digest to the vehicle electronic control unit using the second communication channel;

[0115] Step S307: Verify the key update data to obtain the key verification result, wherein the key verification result is used to determine whether there is a transmission anomaly in the key update data;

[0116] In step S308, in response to the key verification result being successful, the vehicle's in-vehicle network data is verified using the key update data.

[0117] Based on the above optional embodiments, by acquiring the vehicle's real-time risk index and vehicle operating parameters, and then responding to the vehicle operating parameters meeting the key rotation conditions, rotation event data is acquired. Subsequently, key update data is generated based on the rotation event data, and finally, the key update data is sent to the vehicle's electronic control unit (ECU) so that the ECU can perform a key rotation operation based on the key update data. This ensures the integrity and reliability of the key update process. This application embodiment achieves intelligent and efficient rotation of the vehicle network key through dynamically adjusted key rotation conditions and timely generated key update data. This ensures that the vehicle key is updated in real time according to changes in the vehicle's risk status, effectively resisting potential network attacks and further improving the security and reliability of vehicle network communication.

[0118] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0119] According to an embodiment of this application, an apparatus embodiment for a vehicle key rotation method is provided. It should be noted that the apparatus can be used to execute the above-described vehicle key rotation method.

[0120] Figure 4 This is a structural block diagram of a vehicle key rotation device according to an embodiment of this application, such as... Figure 4 As shown, the device includes:

[0121] The first acquisition module 401 is used to acquire the vehicle's real-time risk index and vehicle operating parameters, wherein the real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time; the second acquisition module 402 is used to acquire rotation event data in response to the vehicle operating parameters meeting the key rotation conditions, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event; the generation module 403 is used to generate key update data based on the rotation event data, wherein the key update data is used to perform communication verification on the vehicle's in-vehicle network data; and the sending module 404 is used to send the key update data to the vehicle's electronic control unit so that the vehicle's electronic control unit performs a key rotation operation based on the key update data.

[0122] Optionally, the first acquisition module 401 is further configured to: acquire environmental perception data and vehicle status data of the vehicle, wherein the environmental perception data is used to determine the vehicle's operating scenario and the vehicle status data is used to represent the vehicle's operating condition; and perform risk assessment processing on the environmental perception data and vehicle status data to obtain a real-time risk index.

[0123] Optionally, the rotation event data includes: random seed data, preceding communication key, control unit identification data, and rotation counter data. The random seed data is used to randomly derive key update data, the preceding communication key is used to indicate the communication key currently used by the vehicle electronic control unit, the control unit identification data is used to establish the association between the key update data and the vehicle electronic control unit, and the rotation counter data is used to indicate the number of key rotation events.

[0124] Optionally, the second acquisition module 402 is further configured to: generate a wake-up request instruction based on a key rotation event, wherein the wake-up request instruction is used to request the quantum random number generator to generate random seed data according to a preset bit length within a preset time; send the wake-up request instruction to the quantum random number generator using a serial peripheral interface; and receive the random seed data returned by the quantum random number generator based on the wake-up request instruction.

[0125] Optionally, the generation module 403 is further configured to: generate an updated communication key based on the rotation event data, wherein the updated communication key and the previous communication key are uncorrelated; perform a hash operation on the updated communication key to obtain an updated key digest, wherein the updated key digest is used to verify the updated communication key in the vehicle electronic control unit; and determine key update data based on the updated communication key and the updated key digest.

[0126] Optionally, the sending module 404 is further configured to: encrypt the update communication key to obtain the key encryption result; broadcast the key encryption result to the vehicle electronic control unit using the first communication channel; and broadcast the update key digest to the vehicle electronic control unit using the second communication channel.

[0127] Figure 5 This is a structural block diagram of another vehicle key switching device according to an embodiment of this application, such as... Figure 5 As shown, the device includes:

[0128] The receiving module 501 is used to receive key update data sent by the vehicle's gateway electronic control unit. The key update data is generated based on rotation event data, which represents the event metadata corresponding to the key rotation event. The rotation event data is acquired when the vehicle's operating parameters meet the key rotation conditions. The vehicle operating parameters include the vehicle's mileage or operating time. The key rotation conditions are determined based on the vehicle's real-time risk index. The verification module 502 is used to verify the key update data to obtain a key verification result. The key verification result is used to determine if there is a transmission anomaly in the key update data. The processing module 503, in response to a successful key verification result, uses the key update data to perform communication verification on the vehicle's in-vehicle network data.

[0129] Optionally, the verification module 502 is further configured to: determine the key verification result as successful in response to the key update data meeting the preset verification conditions, wherein the preset verification conditions are used to compare the consistency between the key update data and the preset cache data, and the preset cache data is used to represent the key cache data in the gateway electronic control unit.

[0130] It should be noted that the above modules can be implemented by software or hardware. For the latter, they can be implemented in the following ways, but are not limited to: all the above modules are located in the same processor; or, the above modules are located in different processors in any combination.

[0131] Embodiments of this application also provide a vehicle, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the methods described in various embodiments of this application when it runs.

[0132] Optionally, in this embodiment, the processor can be configured to perform the following steps via a computer program:

[0133] S1, obtain the vehicle's real-time risk index and vehicle operating parameters. The real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time.

[0134] S2, in response to the vehicle operating parameters meeting the key rotation conditions, obtain rotation event data, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event;

[0135] S3, Generate key update data based on rotation event data, wherein the key update data is used to verify the communication of the vehicle's in-vehicle network data;

[0136] S4, send key update data to the vehicle electronic control unit so that the vehicle electronic control unit can perform a key rotation operation based on the key update data.

[0137] Embodiments of this application also provide a computer-readable storage medium including a stored executable program, wherein, when the executable program is running, it controls the device where the computer-readable storage medium is located to perform the methods of various embodiments of this application.

[0138] Optionally, in this embodiment, the storage medium may be configured to store a computer program for performing the following steps:

[0139] S1, obtain the vehicle's real-time risk index and vehicle operating parameters. The real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time.

[0140] S2, in response to the vehicle operating parameters meeting the key rotation conditions, obtain rotation event data, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event;

[0141] S3, Generate key update data based on rotation event data, wherein the key update data is used to verify the communication of the vehicle's in-vehicle network data;

[0142] S4, send key update data to the vehicle electronic control unit so that the vehicle electronic control unit can perform a key rotation operation based on the key update data.

[0143] Embodiments of this application also provide a computer program product, including a computer program that, when executed by a processor, implements the methods of various embodiments of this application.

[0144] Embodiments of this application also provide a computer program product, including a non-volatile computer-readable storage medium for storing a computer program that, when executed by a processor, implements the methods in various embodiments of this application.

[0145] Embodiments of this application also provide a computer program that, when executed by a processor, implements the methods described in the various embodiments of this application.

[0146] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0147] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.

[0148] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0149] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0150] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.

[0151] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

Claims

1. A vehicle key rotation method, characterized in that, include: The vehicle's real-time risk index and vehicle operating parameters are obtained, wherein the real-time risk index is used to determine the vehicle's key rotation conditions, and the vehicle operating parameters include the vehicle's mileage or operating time. In response to the vehicle operating parameters satisfying the key rotation condition, rotation event data is acquired, wherein the rotation event data is used to represent the event metadata corresponding to the key rotation event; Key update data is generated based on the rotation event data, wherein the key update data is used to perform communication verification on the vehicle's in-vehicle network data; The key update data is sent to the vehicle electronic control unit so that the vehicle electronic control unit performs a key rotation operation based on the key update data.

2. The method according to claim 1, characterized in that, Obtaining the real-time risk index of the vehicle includes: The environmental perception data and vehicle status data of the vehicle are acquired, wherein the environmental perception data is used to determine the operating scenario of the vehicle, and the vehicle status data is used to represent the operating condition of the vehicle. The environmental perception data and the vehicle status data are processed for risk assessment to obtain the real-time risk index.

3. The method according to claim 1, characterized in that, The rotation event data includes: random seed data, preceding communication key, control unit identification data, and rotation counter data. The random seed data is used to randomly derive the key update data. The preceding communication key is used to represent the communication key currently used by the vehicle electronic control unit. The control unit identification data is used to establish the association between the key update data and the vehicle electronic control unit. The rotation counter data is used to represent the number of key rotation events.

4. The method according to claim 3, characterized in that, The vehicle key rotation method also includes: A wake-up request instruction is generated based on the key rotation event, wherein the wake-up request instruction is used to request the quantum random number generator to generate the random seed data within a preset time and according to a preset bit length; The wake-up request command is sent to the quantum random number generator using the serial peripheral interface; Receive the random seed data returned by the quantum random number generator based on the wake-up request instruction.

5. The method according to claim 3, characterized in that, Generating the key update data based on the rotation event data includes: An updated communication key is generated based on rotation event data, wherein the updated communication key and the preceding communication key are uncorrelated. A hash operation is performed on the updated communication key to obtain an updated key digest, wherein the updated key digest is used to verify the updated communication key in the vehicle electronic control unit; The key update data is determined based on the updated communication key and the updated key digest.

6. The method according to claim 5, characterized in that, Sending the key update data to the vehicle electronic control unit includes: The updated communication key is encrypted to obtain the key encryption result; The key encryption result is broadcast to the vehicle electronic control unit via a first communication channel, and the updated key digest is broadcast to the vehicle electronic control unit via a second communication channel.

7. A vehicle key rotation method, characterized in that, include: The system receives key update data sent by the vehicle's gateway electronic control unit. The key update data is generated based on rotation event data, which represents the event metadata corresponding to the key rotation event. The rotation event data is acquired when the vehicle's operating parameters meet the key rotation conditions. The vehicle operating parameters include the vehicle's mileage or operating time. The key rotation conditions are determined based on the vehicle's real-time risk index. The key update data is verified to obtain a key verification result, wherein the key verification result is used to determine whether there is a transmission anomaly in the key update data; In response to the key verification result being successful, the vehicle's in-vehicle network data is verified using the key update data.

8. The method according to claim 7, characterized in that, The key update data is verified to obtain the key verification result, which includes: In response to the key update data satisfying the preset verification conditions, the key verification result is determined to be successful. The preset verification conditions are used to compare the consistency between the key update data and the preset cache data, which represents the key cache data in the gateway electronic control unit.

9. A vehicle, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, wherein, when the executable program is executed, it controls the device on which the storage medium is located to perform the method according to any one of claims 1 to 8.