Vehicle-mounted equipment data security upgrading method and device and electronic equipment

By deploying a secure management backup area in the vehicle-mounted equipment and using backup tags to confirm data status, the network security upgrade problem of the equipment already off the production line was solved, ensuring the stability and security of parameter configuration during the upgrade process.

CN121979541APending Publication Date: 2026-05-05CONTINENTAL ZHIXING TECH (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CONTINENTAL ZHIXING TECH (SHANGHAI) CO LTD
Filing Date
2024-10-23
Publication Date
2026-05-05

AI Technical Summary

Technical Problem

How to upgrade the cybersecurity of in-vehicle equipment that has already left the production line to comply with the latest standards without affecting existing parameter configurations.

Method used

Deploy a security management backup area in the vehicle-mounted equipment, and confirm whether the data has been backed up by using the security management backup mark. After the upgrade, copy the preset data to the backup area and encrypt it, then switch to the backup data for use to ensure data security.

Benefits of technology

This technology enables the adjustment of network security configurations during vehicle-mounted equipment upgrades without affecting existing parameter configurations, thereby improving the network security of the equipment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121979541A_ABST
    Figure CN121979541A_ABST
Patent Text Reader

Abstract

The invention provides a vehicle-mounted equipment data security upgrading method and device, electronic equipment, a computer storage medium and a program product, and the method comprises the following steps: in an upgrading process, deploying a security management backup area in vehicle-mounted equipment, and setting a security management backup mark, the safety management backup mark is used for identifying whether preset data is backed up to a safety management backup area or not; after upgrading is completed, when the vehicle-mounted equipment is started, whether the safety management backup mark is an initial value or not is confirmed; under the condition that the safety management backup mark is confirmed to be the initial value, copying preset data to the safety management backup area to serve as backup data, performing data encryption on the backup data, and updating the safety management backup mark to be a preset value; and when the vehicle-mounted equipment needs to use the preset data, switching to use the backup data of the safety management backup area. According to the invention, the network security configuration of partial data in the on-board equipment of the production line can be adjusted without influencing the existing parameter configuration.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security for in-vehicle equipment, and particularly to methods, apparatuses, electronic devices, computer storage media, and program products for upgrading the data security of in-vehicle equipment. Background Technology

[0002] With the rapid development of automotive technology, cybersecurity issues related to in-vehicle devices have become increasingly prominent. Modern cars not only possess highly intelligent functions but also achieve extensive connectivity with the internet and other devices, making them vulnerable to serious cyberattacks. Hackers may exploit vulnerabilities, malware, or other means to gain unauthorized access to vehicle control systems, leading to security risks. Therefore, in recent years, relevant departments in various countries have successively introduced a series of regulations and standards to strengthen the cybersecurity of in-vehicle devices and ensure the effective protection of vehicle communication systems, user data, and driving safety.

[0003] For newly developed and manufactured vehicle-mounted equipment, companies can formulate and improve security strategies during the R&D and production phases to ensure their ability to resist potential cyberattacks. However, for vehicle-mounted equipment already off the production line, how to effectively update it to comply with the latest cybersecurity standards without affecting existing parameter configurations remains a pressing problem to be solved. Summary of the Invention

[0004] The present invention was made to solve the above-mentioned problems. Its purpose is to provide a method, device, electronic device, computer storage medium and computer program product for upgrading the data security of vehicle-mounted equipment, which can adjust the network security configuration of some data in the vehicle-mounted equipment that has been put into production line without affecting the existing parameter configuration.

[0005] According to one aspect of the present invention, a method for upgrading data security of an in-vehicle device is provided. The method includes the following steps: during the upgrade process, a security management backup area is deployed in the in-vehicle device, and a security management backup marker is set, the security management backup marker being used to identify whether preset data has been backed up to the security management backup area; after the upgrade is completed, when the in-vehicle device is started, it is confirmed whether the security management backup marker is an initial value; if it is confirmed that the security management backup marker is an initial value, the preset data is copied to the security management backup area as backup data, and the backup data is encrypted, and the security management backup marker is updated to the preset value; and when the in-vehicle device needs to use the preset data, it switches to using the backup data in the security management backup area.

[0006] Preferably, the method for upgrading the data security of in-vehicle equipment further includes the following steps: if it is confirmed that the security management backup flag is not the initial value, confirm whether the preset data is consistent with the backup data; and if the preset data is inconsistent with the backup data, update the preset data to the backup data.

[0007] Preferably, the preset data is stored in the non-volatile memory of the vehicle-mounted device, and the security management backup area is also deployed in the non-volatile memory of the vehicle-mounted device.

[0008] According to another aspect of the present invention, a data security upgrade device for an in-vehicle device is provided, comprising: a setting module, which, during the upgrade process, deploys a security management backup area in the in-vehicle device and sets a security management backup marker, the security management backup marker being used to identify whether preset data has been backed up to the security management backup area; a confirmation module, which, after the upgrade is completed, confirms whether the security management backup marker is an initial value when the in-vehicle device is started; a backup module, which, if it is confirmed that the security management backup marker is an initial value, copies the preset data to the security management backup area as backup data, encrypts the backup data, and updates the security management backup marker to the preset value; and a switching module, which, when the in-vehicle device needs to use the preset data, switches to using the backup data in the security management backup area.

[0009] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded by the processor and executing the method described in one aspect above.

[0010] According to another aspect of the present invention, a computer storage medium is provided, wherein at least one instruction or at least one program is stored therein, the at least one instruction or the at least one program being loaded by a processor and executing the method as described in one aspect above.

[0011] According to another aspect of the present invention, a computer program product is provided, comprising at least one instruction or at least one program segment, wherein the at least one instruction or the at least one program segment is loaded by a processor and executes the method as described in one aspect above. Attached Figure Description

[0012] Figure 1 This is a flowchart illustrating the data security upgrade method for in-vehicle equipment provided in an embodiment of the present invention.

[0013] Figure 2This is a structural block diagram of the vehicle-mounted equipment data security upgrade device provided in an embodiment of the present invention.

[0014] Figure 3 This is a structural block diagram of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0015] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0016] Unless otherwise specified, all terms used herein (including technical and scientific terms) have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having the meaning consistent with their meaning in the context of the relevant art and the invention, and will not be interpreted as having an idealized or overly formal meaning unless expressly so defined herein.

[0017] This invention provides a method, apparatus, electronic device, computer storage medium, and computer program product for upgrading the data security of in-vehicle equipment. It can adjust the network security configuration of some data in in-vehicle equipment already on the production line without affecting existing parameter configurations. The method and apparatus are based on the same concept. Since the principles by which the method and apparatus solve problems are similar, their implementations can be mutually referenced, and repeated details will not be elaborated further.

[0018] Figure 1 This is a flowchart illustrating a method for upgrading data security of in-vehicle equipment according to an embodiment of the present invention. This method can be applied to computer equipment, which refers to electronic devices capable of data computation and processing. The method may include the following steps.

[0019] S11: During the upgrade process, a security management backup area is deployed in the vehicle-mounted equipment, and a security management backup marker is set. This security management backup marker is used to identify whether preset data has been backed up to the security management backup area.

[0020] Here, deploying a security management backup area in an in-vehicle device refers to setting up a security management backup area in the in-vehicle device's memory, specifically for storing preset data. A security management backup flag is used to identify whether preset data has been backed up to the security management backup area. When initially setting the security management backup flag, it is initialized to an initial value, which can be "0".

[0021] S12: After the upgrade is complete, when the vehicle device starts, confirm whether the security management backup flag is at its initial value.

[0022] After the vehicle-mounted equipment upgrade is completed, start the vehicle-mounted equipment and confirm whether the security management backup flag is at its initial value. If it is the first startup after the upgrade, the security management backup flag should be the initial value after initialization, and the confirmation result of whether the security management backup flag is at its initial value is "yes", proceed to step S13. If it is not the first startup after the upgrade, the preset data should have been backed up to the security management backup area during the first startup, and the security management backup flag should no longer be at its initial value, and the confirmation result of whether the security management backup flag is at its initial value is "no", proceed to step S14.

[0023] S13: Copy the preset data to the security management backup area as backup data, encrypt the backup data, and update the security management backup mark to the preset value.

[0024] If the security management backup flag is confirmed to be at its initial value in step S12, preset data is copied to the security management backup area. This preset data copied to the security management backup area is referred to as backup data. The preset data here refers to data that was not originally encrypted but will subsequently require encryption protection. Its content is not limited and can be any type of data. Furthermore, this preset data can be data stored in various storage devices of the vehicle-mounted device, such as data stored in the non-volatile memory of the vehicle-mounted device. Then, the backup data in the security management backup area is encrypted to protect it from unauthorized access or tampering, and the security management backup flag is updated to the preset value. This preset value is, for example, "1".

[0025] S16: When the vehicle-mounted equipment needs to use preset data, it will switch to using backup data in the security management backup area.

[0026] Because the backup data in the security management backup area is protected, it is used in all functional algorithms of the vehicle equipment to ensure security.

[0027] S14: Confirm whether the preset data and backup data are consistent.

[0028] If it is confirmed in step S12 that the security management backup flag is not the initial value, it is necessary to verify whether the preset data and the backup data are consistent. This is because the preset data is not encrypted and may be tampered with; therefore, it is necessary to verify whether the preset data has been tampered with. If the preset data and the backup data are consistent, it means that the preset data has not been tampered with, and proceed to step S16. If the preset data and the backup data are inconsistent, it means that the preset data has been tampered with, and proceed to step S15.

[0029] S15: Update the preset data to the backup data.

[0030] Since the preset data is inconsistent with the backup data, it means that the preset data has been tampered with. Although the various functional algorithms of the vehicle equipment use the backup data in the security management backup area, the vehicle may still have the function of using the unprotected preset data. Therefore, when the inconsistency between the preset data and the backup data is detected, the preset data is updated to the backup data to ensure that the preset data is correct.

[0031] According to the vehicle-mounted equipment data security upgrade method involved in this embodiment, the security configuration level of certain data can be adjusted during the vehicle-mounted equipment upgrade process, thereby facilitating the adjustment of the network security configuration of some data in the vehicle-mounted equipment already off the production line without affecting the existing parameter configuration.

[0032] Figure 2 This is a structural block diagram of the vehicle-mounted equipment data security upgrade device provided in an embodiment of the present invention. Figure 2 As shown, the vehicle-mounted equipment data security upgrade device 200 includes: a setting module 201, a confirmation module 202, a backup module 203, and a switching module 204.

[0033] The setup module 201 is used to deploy a security management backup area in the vehicle-mounted device during the upgrade process and set a security management backup marker, which is used to identify whether preset data has been backed up to the security management backup area. The confirmation module 202 is used to confirm whether the security management backup marker is at its initial value when the vehicle-mounted device starts up after the upgrade is completed. The backup module 203 is used to copy the preset data to the security management backup area as backup data if the security management backup marker is confirmed to be at its initial value, encrypt the backup data, and update the security management backup marker to the preset value. The update unit 204 is used to switch to using the backup data in the security management backup area whenever the vehicle-mounted device needs to use the preset data.

[0034] Figure 3 This is a structural block diagram of the electronic device provided in an embodiment of the present invention. Figure 3 As shown, the present invention also provides an electronic device 300, which includes a processor and a memory. The memory stores at least one instruction or at least one program, which is loaded by the processor and executes the methods described in the above embodiments.

[0035] The present invention also provides a computer storage medium storing at least one instruction or at least one program, wherein the at least one instruction or at least one program is loaded by a processor and executed by the method described in the above embodiments.

[0036] The present invention also provides a computer program product, comprising at least one instruction or at least one program segment, characterized in that the at least one instruction or the at least one program segment is loaded by a processor and executes the method described in the above embodiments.

[0037] Optionally, in this embodiment, the storage medium may be located at at least one of the multiple network servers in a computer network. Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0038] Those skilled in the art will recognize that the modules, units, and method steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of electronic hardware and software, the components and steps of the examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can implement the described functions using different methods for each specific application, but such implementations should not be considered beyond the scope of the invention.

[0039] Although the present invention has been described with reference to specific embodiments, those skilled in the art should recognize that the scope of the invention is not limited to the specific combinations of the above-described technical features, but also includes other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the present invention.

Claims

1. A method for upgrading data security of vehicle-mounted equipment, characterized in that, The method includes the following steps: During the upgrade process, a security management backup area is deployed in the vehicle-mounted device, and a security management backup marker is set. This security management backup marker is used to identify whether preset data has been backed up to the security management backup area. After the upgrade is completed, when the vehicle-mounted device is started, confirm whether the security management backup flag is at its initial value; If the security management backup flag is confirmed to be at its initial value, the preset data is copied to the security management backup area as backup data, the backup data is encrypted, and the security management backup flag is updated to the preset value. as well as When the vehicle-mounted device needs to use preset data, it switches to use the backup data in the security management backup area.

2. The method for upgrading data security of in-vehicle equipment as described in claim 1, characterized in that, Further steps include the following: If it is confirmed that the security management backup flag is not the initial value, confirm whether the preset data is consistent with the backup data; as well as If the preset data is inconsistent with the backup data, the preset data will be updated to the backup data.

3. The method for upgrading the data security of in-vehicle equipment as described in claim 1 or 2, characterized in that, The preset data is stored in the non-volatile memory of the vehicle device, and the security management backup area is also deployed in the non-volatile memory of the vehicle device.

4. A data security upgrade device for vehicle-mounted equipment, characterized in that, include: During the upgrade process, the module is configured to deploy a security management backup area in the vehicle-mounted device and set a security management backup marker, which is used to identify whether preset data has been backed up to the security management backup area. After the module upgrade is completed, when the vehicle-mounted device starts up, it confirms whether the security management backup flag is at its initial value. The backup module, upon confirming that the security management backup marker is at its initial value, copies preset data to the security management backup area as backup data, encrypts the backup data, and updates the security management backup marker to the preset value. as well as The switching module switches to use the backup data in the security management backup area whenever the vehicle-mounted device needs to use preset data.

5. An electronic device, characterized in that, The electronic device includes a processor and a memory, the memory storing at least one instruction or at least one program, the at least one instruction or the at least one program being loaded by the processor and executed as described in any one of claims 1 to 3.

6. A computer storage medium, characterized in that, The storage medium stores at least one instruction or at least one program segment, which is loaded by a processor and executed according to any one of claims 1 to 3.

7. A computer program product comprising at least one instruction or at least a program segment, characterized in that, The at least one instruction or the at least one program segment is loaded by the processor and executed as described in any one of claims 1 to 3.