Vehicle-mounted developer mode security protection method and device, equipment and medium

By generating and encrypting dynamic passwords and performing dual verification, the problem of easily cracked passwords and single verification in traditional in-vehicle developer modes is solved, realizing security protection for in-vehicle developer modes and improving the security and legitimacy verification of passwords.

CN122221241APending Publication Date: 2026-06-16DONGFENG MOTOR GRP

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
DONGFENG MOTOR GRP
Filing Date
2026-03-20
Publication Date
2026-06-16

AI Technical Summary

Technical Problem

Traditional in-vehicle developer mode security methods suffer from easily cracked passwords, lack of device and vehicle identity verification, and a simplistic verification process, allowing unauthorized personnel to unlock developer mode at will, thus failing to meet security control requirements.

Method used

It employs a dynamic password generated based on vehicle identification number, global harmonic time stamp, and random number, and performs dual verification (numerical and time-based verification). At the same time, it encrypts and stores vehicle identification number and diagnostic tool identifier, and securely stores and verifies them through a collaborative mechanism between the cloud and the vehicle terminal.

Benefits of technology

It enhances the security of the in-vehicle developer mode, implements dual password authentication and secure storage, effectively prevents unauthorized unlocking, ensures the legitimacy of operating the device, and prevents unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122221241A_ABST
    Figure CN122221241A_ABST
Patent Text Reader

Abstract

The application discloses a vehicle-mounted developer mode security protection method and device, equipment and medium, and belongs to the technical field of vehicle-mounted intelligent diagnosis and safety management and control. The method comprises the following steps: receiving device authentication information uploaded by a diagnostic instrument and a vehicle identification code of a vehicle terminal; generating a dynamic password based on the vehicle identification code, a world coordinated timestamp and a random number, synchronizing the dynamic password to a secure storage area of the vehicle terminal, and simultaneously encrypting and storing the vehicle identification code, a diagnostic instrument identifier and the world coordinated timestamp as verification associated data of the dynamic password; performing double verification on an input password to be verified based on the verification associated data and the dynamic password in the secure storage area, and unlocking a developer mode of the vehicle terminal in the case that the verification result is passed; wherein the double verification comprises numerical value verification and time limit verification. The technical effect of improving the security of unlocking the vehicle-mounted developer mode is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of vehicle-mounted intelligent diagnostics and safety management technology, and in particular to a vehicle-mounted developer mode security protection method, device, equipment and medium. Background Technology

[0002] In the field of vehicle intelligent diagnostics, the in-vehicle terminal developer mode serves as an important access point for vehicle maintenance and debugging. Traditional protection methods often use local fixed passwords or passwords generated by the in-vehicle terminal to unlock permissions. This approach relies solely on a single password verification to control access to the developer mode and does not encrypt and store associated information such as vehicle identification numbers and operating device identifiers.

[0003] These traditional methods have significant technical flaws: First, fixed or locally generated passwords are easily cracked by reverse engineering, making it easy for unauthorized personnel to illegally unlock developer mode; second, the password generation and unlocking verification process lacks binding with the device and vehicle identity, making it impossible to accurately verify the operating entity; third, unlocking permissions are only verified by a single numerical value without a time-limited verification mechanism, making it easy for leaked passwords to be used illegally for a long time, resulting in insufficient overall security protection for developer mode and failing to meet the security control requirements of in-vehicle systems. Summary of the Invention

[0004] This invention provides a method, device, equipment, and medium for security protection of in-vehicle developer mode, so as to achieve security protection of in-vehicle developer mode.

[0005] According to one aspect of the present invention, a method for protecting the security of an in-vehicle developer mode is provided, the method comprising:

[0006] A dynamic password is generated based on the vehicle identification number, the Coordinated Universal Timestamp, and a random number. The dynamic password is synchronized to the secure storage area of ​​the vehicle's infotainment system. At the same time, the vehicle identification number, the diagnostic tool identifier, and the Coordinated Universal Timestamp are encrypted and stored as verification data associated with the dynamic password.

[0007] The input password to be verified is double-verified based on the verification association data and the dynamic password in the secure storage area. If the verification result is successful, the developer mode of the vehicle terminal is unlocked. The double verification includes numerical verification and time-sensitive verification.

[0008] According to another aspect of the present invention, an in-vehicle developer mode security protection device is provided, the device comprising:

[0009] The authentication information receiving module is used to receive the device authentication information uploaded by the diagnostic instrument and the vehicle identification code from the vehicle terminal.

[0010] The dynamic code generation module is used to generate a dynamic password based on the vehicle identification code, the Coordinated Universal Time Stamp and a random number, synchronize the dynamic password to the secure storage area of ​​the vehicle terminal, and encrypt and store the vehicle identification code, diagnostic tool identifier and the Coordinated Universal Time Stamp as verification association data of the dynamic password.

[0011] The verification and unlocking module is used to perform dual verification on the input password to be verified based on the verification association data and the dynamic password in the secure storage area. If the verification result is successful, the developer mode on the vehicle terminal is unlocked. The dual verification includes numerical verification and time-limited verification.

[0012] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0013] At least one processor;

[0014] and memory that is communicatively connected to at least one processor;

[0015] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor to enable at least one processor to execute the vehicle developer mode security protection method of any embodiment of the present invention.

[0016] According to another aspect of the present invention, a computer-readable storage medium is provided, which stores computer instructions for causing a processor to execute and implement the vehicle developer mode security protection method of any embodiment of the present invention.

[0017] The technical solution of this invention receives device authentication information uploaded by a diagnostic instrument and the vehicle identification number (VIN) from the vehicle's infotainment system. Based on the VIN, a Coordinated Universal Time Stamp (UTC), and a random number, a dynamic password is generated and synchronized to the secure storage area of ​​the vehicle's infotainment system. Simultaneously, the VIN, diagnostic instrument identifier, and UTC are encrypted and stored as verification data for the dynamic password. The input password is then subjected to dual verification based on the verification data and the dynamic password in the secure storage area. If the verification is successful, the developer mode on the vehicle's infotainment system is unlocked. This dual verification includes numerical verification and time-sensitive verification. This solution addresses the technical problems of traditional in-vehicle developer mode protection, such as easily cracked passwords, lack of secure password storage, single verification dimensions, and unauthorized devices being able to arbitrarily initiate unlocking requests. It achieves the technical effects of improving the security of in-vehicle developer mode passwords, realizing dual verification and secure password storage, verifying the authorization of operating devices, and effectively preventing unauthorized personnel from illegally unlocking the developer mode.

[0018] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0020] Figure 1 A flowchart illustrating a vehicle-mounted developer mode security protection method provided in an embodiment of the present invention;

[0021] Figure 2a A flowchart illustrating another vehicle-mounted developer mode security protection method provided in this embodiment of the invention;

[0022] Figure 2b A flowchart illustrating an alternative example of an in-vehicle developer mode security protection method provided in an embodiment of the present invention;

[0023] Figure 3 This is a schematic diagram of the structure of an in-vehicle developer mode security protection device provided in an embodiment of the present invention;

[0024] Figure 4 A schematic diagram of the structure of an electronic device for implementing a vehicle-mounted developer mode security protection method according to an embodiment of the present invention. Detailed Implementation

[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0027] Figure 1 This is a flowchart illustrating a method for protecting in-vehicle developer mode security, provided by an embodiment of the present invention. This embodiment is applicable to in-vehicle developer mode security protection situations. The method can be executed by an in-vehicle developer mode security protection device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, the method specifically includes the following steps:

[0028] S110: Receives the device authentication information uploaded by the diagnostic tool and the vehicle identification number from the vehicle terminal.

[0029] Among them, the diagnostic tool can be understood as an in-vehicle interactive device used for vehicle fault diagnosis; the device authentication information can be understood as the identity information to verify whether the diagnostic tool is an authorized device; the vehicle terminal can be understood as the intelligent control terminal of the vehicle; and the vehicle identification code can be understood as the unique identification code of the vehicle, used to distinguish different vehicles.

[0030] Specifically, the cloud-based backend receives the device authentication information uploaded by the diagnostic tool, as well as the vehicle identification number corresponding to the vehicle's infotainment system to be operated by the diagnostic tool. It then performs basic identity verification on both the diagnostic tool and the vehicle, and receives relevant information from the authorized diagnostic tool.

[0031] In some embodiments, the device authentication information is the device digital certificate of the diagnostic instrument, which is a unique identity authentication file configured when the diagnostic instrument leaves the factory.

[0032] Among them, the device digital certificate can be understood as the electronic identity credential configured when the diagnostic instrument leaves the factory; the exclusive identity authentication file can be understood as an identity verification file that corresponds only to a single diagnostic instrument and cannot be shared.

[0033] Specifically, the device authentication information uploaded by the diagnostic instrument is its exclusive digital certificate configured at the factory. The cloud uses this unique digital certificate to accurately verify the authorization of the diagnostic instrument and exclude operation requests from unauthorized diagnostic instruments.

[0034] S120. Generate a dynamic password based on the vehicle identification code, the Coordinated Universal Time Stamp, and a random number. Synchronize the dynamic password to the secure storage area on the vehicle's terminal. Simultaneously, encrypt and store the vehicle identification code, the diagnostic tool identifier, and the Coordinated Universal Time Stamp as verification data associated with the dynamic password.

[0035] Among them, the Coordinated Universal Time stamp can be understood as a time identifier generated based on Coordinated Universal Time, used to mark the specific time when the data was generated; the random number can be understood as a value randomly generated in the cloud, used to improve the uniqueness and security of the dynamic password; the dynamic password can be understood as a non-fixed temporary password; the secure storage area can be understood as an independently divided encrypted storage area on the vehicle's terminal; the diagnostic tool identifier can be understood as the unique identity identifier of the diagnostic tool; and the verification associated data can be understood as a set of encrypted stored data bound to the dynamic password and used for password verification.

[0036] Specifically, the cloud uses the vehicle identification number as the core, combines the Coordinated Universal Time Stamp and random number to generate a dynamic password through a specific algorithm. This dynamic password is then synchronized to the secure storage area on the vehicle's device for local encrypted storage. At the same time, the vehicle identification number, diagnostic tool identifier, and the Coordinated Universal Time Stamp used to generate the password are encrypted and stored as verification data for subsequent verification of the dynamic password.

[0037] In some embodiments, the step of generating a dynamic password based on the vehicle identification number, the Coordinated Universal Time Stamp, and a random number, and synchronizing the dynamic password to the secure storage area of ​​the vehicle's infotainment system, includes:

[0038] The vehicle identification number, the Coordinated Universal Time Stamp, and a 128-bit random number are concatenated to obtain the original data. The original data is then subjected to hash and modulo operations to generate a dynamic password in a six-digit format.

[0039] The original data can be understood as the basic data obtained by directly concatenating the vehicle identification number, the Coordinated Universal Time Stamp, and a 128-bit random number; the hash operation can be understood as an irreversible operation that converts original data of arbitrary length into a hash value of fixed length; the modulo operation can be understood as the operation of finding the remainder after dividing two numbers, which is used to convert the result into a number of a specified number of digits.

[0040] Specifically, the vehicle identification number, the Coordinated Universal Time Stamp, and a 128-bit random number are concatenated to form the original data. The original data is then subjected to hash and modulo operations to generate a dynamic password in a six-digit format. This dynamic password is then synchronized to the secure storage area of ​​the vehicle's infotainment system for local encrypted storage.

[0041] In some embodiments, simultaneously encrypting and storing the vehicle identification code, diagnostic tool identifier, and Coordinated Universal Timestamp includes: encrypting the dynamic password along with the associated vehicle identification code, diagnostic tool identifier, and Coordinated Universal Timestamp, storing it in a cloud password repository, and configuring a preset validity period for the dynamic password.

[0042] The cloud-based password repository can be understood as a cloud-based database specifically used for encrypted storage of dynamic passwords and related information; the preset validity period can be understood as a pre-set usable time range for dynamic passwords, which will become invalid if the password is not used within this range. The preset validity period can be pre-set based on experience, and this embodiment does not impose specific restrictions on it.

[0043] Specifically, the dynamic password, along with the associated vehicle identification number, diagnostic tool identifier, and Coordinated Universal Timestamp, is encrypted and stored in a unified cloud password repository. At the same time, a preset validity period is configured for the dynamic password to achieve secure cloud management of the dynamic password and associated data.

[0044] S130. Based on the verification association data and the dynamic password in the secure storage area, perform dual verification on the input password to be verified. If the verification result is successful, unlock the developer mode on the vehicle terminal.

[0045] The dual verification includes numerical verification and time-limited verification. The password to be verified can be understood as the password entered by the user on the vehicle's infotainment system that needs to be validated; dual verification can be understood as validating the password from two different dimensions; numerical verification can be understood as verifying the consistency of the numerical content of the password; and time-limited verification can be understood as verifying whether the password is within a valid time frame.

[0046] Specifically, based on the encrypted verification data and the dynamic password stored in the vehicle's secure storage area, the system performs dual verification on the user-entered password, checking both its value and validity period. Only when both verifications pass will the vehicle's system remove the developer mode access restriction, thus unlocking the developer mode. Failure to pass either verification step will result in immediate rejection of the unlock.

[0047] In some embodiments, the dual verification of the input password to be verified based on the verification association data and the dynamic password in the secure storage area includes: performing a consistency comparison between the password to be verified and the dynamic password;

[0048] If the comparison results are consistent, the numerical verification result is determined to be passed.

[0049] Among them, consistency comparison can be understood as comparing the password to be verified with the dynamic password in the secure storage area bit by bit to determine whether the two digital contents are completely the same; the numerical verification result can be understood as the conclusion of passing or failing after the consistency comparison of the password digital contents.

[0050] Specifically, the system compares the password entered by the user with the dynamic password stored in the vehicle's secure storage area. If the numerical content of the two matches perfectly, the numerical verification result is considered successful, and the developer mode of the vehicle's system is unlocked. If the match is inconsistent, the numerical verification result is considered unsuccessful.

[0051] In some embodiments, the dual verification of the input password to be verified based on the verification association data and the dynamic password in the secure storage area includes: obtaining the current Coordinated Universal Timestamp (UTC), calculating the time difference between the current UTC and the UTC when the dynamic password was generated; and determining the timeliness verification result as passed if the time difference does not exceed a preset time difference threshold.

[0052] Among them, the current Coordinated Universal Time stamp can be understood as the time identifier generated by the Coordinated Universal Time obtained in real time when performing time verification; the time difference can be understood as the time difference between the current Coordinated Universal Time stamp and the Coordinated Universal Time stamp when the dynamic password was generated; the preset time difference threshold can be understood as the maximum time difference allowed by the preset dynamic password, which is the standard for judging whether the password is within the validity period.

[0053] Specifically, the system obtains the current Coordinated Universal Timestamp (UTC), calculates the time difference between the current UTC and the UTC when the dynamic password was generated, and confirms that the dynamic password is still within its valid validity period when the time difference does not exceed a preset threshold. The validity verification passes, and the vehicle-mounted system removes the developer mode access restriction, completing the unlocking of developer mode. If the time difference exceeds the threshold, the validity verification result is considered a failure.

[0054] The technical solution of this invention receives device authentication information uploaded by a diagnostic instrument and the vehicle identification number (VIN) from the vehicle's infotainment system. Based on the VIN, a Coordinated Universal Time Stamp (UTC), and a random number, a dynamic password is generated and synchronized to the secure storage area of ​​the vehicle's infotainment system. Simultaneously, the VIN, diagnostic instrument identifier, and UTC are encrypted and stored as verification data for the dynamic password. The input password is then subjected to dual verification based on the verification data and the dynamic password in the secure storage area. If the verification is successful, the developer mode on the vehicle's infotainment system is unlocked. This dual verification includes numerical verification and time-sensitive verification. This solution addresses the technical problems of traditional in-vehicle developer mode protection, such as easily cracked passwords, lack of secure password storage, single verification dimensions, and unauthorized devices being able to arbitrarily initiate unlocking requests. It achieves the technical effects of improving the security of in-vehicle developer mode passwords, realizing dual verification and secure password storage, verifying the authorization of operating devices, and effectively preventing unauthorized personnel from illegally unlocking the developer mode.

[0055] Figure 2a This is a flowchart illustrating another vehicle-mounted developer mode security protection method provided by an embodiment of the present invention. Based on the above embodiments, this embodiment is a further refinement of the above embodiments, and its specific implementation can be found in the technical solution of this embodiment. Technical terms that are the same as or corresponding to those in the above embodiments will not be repeated here. Figure 2a As shown, the method specifically includes the following steps:

[0056] S210 receives the device authentication information uploaded by the diagnostic tool and the vehicle identification number from the vehicle terminal.

[0057] S220. Generate a dynamic password based on the vehicle identification code, the Coordinated Universal Time Stamp, and a random number. Synchronize the dynamic password to the secure storage area on the vehicle's infotainment system. Simultaneously, encrypt and store the vehicle identification code, diagnostic tool identifier, and the Coordinated Universal Time Stamp as verification data associated with the dynamic password.

[0058] S230. Based on the verification association data and the dynamic password in the secure storage area, perform dual verification on the input password to be verified. If the verification result is successful, unlock the developer mode on the vehicle terminal. The dual verification includes numerical verification and time-sensitive verification.

[0059] S240. Generate an operation audit log and upload the operation audit log to the cloud-based backend management system; wherein, the operation audit log includes the vehicle identification code, the diagnostic tool identifier, the usage time of the dynamic password, and operation instructions in developer mode.

[0060] The operation audit log can be understood as a log file that records relevant operation information after the in-vehicle developer mode is unlocked; the cloud-based backend management system can be understood as a system deployed in the cloud for unified management of in-vehicle developer mode related data, operation processes and logs.

[0061] Specifically, after the vehicle's infotainment system unlocks developer mode, it automatically generates an operation audit log containing the vehicle identification number, diagnostic tool identifier, dynamic password usage time, and operation commands in developer mode. This log is then encrypted and uploaded to the cloud-based backend management system, achieving full recording and cloud storage of developer mode operations.

[0062] The technical solution of this invention solves the technical problems of untraceable operation behavior and difficulty in locating the cause of security problems after the in-vehicle developer mode is unlocked by generating and uploading operation audit logs. It achieves the technical effect of leaving a full trace of the use of developer mode, facilitating subsequent auditing and tracing, and improving the security and manageability of the in-vehicle system.

[0063] Figure 2b A flowchart illustrating an optional example of another in-vehicle developer mode security protection method provided by an embodiment of the present invention, such as... Figure 2b As shown, the method specifically includes the following steps:

[0064] S310 diagnostic instrument identity authentication and information upload, with legality verification completed in the cloud.

[0065] Specifically, the diagnostic tool retrieves its own dedicated device digital certificate through a security chip, combines it with the vehicle identification number (VIN) of the vehicle to be operated, and completes a TLS 1.3 handshake with the cloud through a two-way authentication module. Then, it encrypts and uploads the device authentication information and the VIN to the cloud-based backend management system. The cloud-based backend management system retrieves the cloud authentication database to verify the legality of the diagnostic tool's device digital certificate and VIN registration, and only accepts information uploaded by authorized diagnostic tools.

[0066] S320: Dynamic passwords are dynamically generated in the cloud, enabling dual-end encrypted storage and password synchronization.

[0067] Specifically, after cloud verification is successful, the password generation engine generates a dynamic password based on the vehicle identification number (VIN), the Coordinated Universal Timestamp (UTC timestamp, with a precision of 1 second), and a 128-bit random number (Nonce). Specifically, the VIN, UTC timestamp, and 128-bit random number are concatenated into raw data, hashed using SHA-256, and then modulo-operated to generate a 6-digit dynamic password. The dynamic password is then synchronized to the vehicle's secure storage area via an SM4 encrypted channel. Simultaneously, the dynamic password, along with the associated VIN, diagnostic tool identifier, and UTC timestamp, are encrypted using AWSKMS and stored in the cloud password repository. A preset validity period of 5 minutes is configured for the dynamic password, forming the verification data associated with it.

[0068] For example, a 6-digit numeric password can be generated using a password generation engine based on the VIN code, timestamp, and random number entropy source, as shown in the following formula:

[0069] P=(SHA-256(VIN∥Timestamp∥Nonce))mod106;

[0070] Nonce is a 128-bit random number generated in the cloud, and Timestamp is a Coordinated Universal Timestamp (with a precision of 1 second).

[0071] Password repository: Passwords are stored using AWSKMS encryption and are associated with the diagnostic instrument ID, vehicle VIN, and expiration date (default 5 minutes).

[0072] Audit Log Blockchain: Built on Hyperledger Fabric, it stores password issuance records and operation logs, ensuring immutability.

[0073] The S330, diagnostic tool, and vehicle infotainment system interact with each other via password to complete the encryption request and password distribution.

[0074] Specifically, the diagnostic tool sends encrypted password request data to the vehicle's infotainment system via the password reading interface using the UDS protocol (0x27 service). The request data consists of a vehicle identification number (VIN) encrypted with SM2 and a Coordinated Universal Time Stamp (UTC). Upon receiving the request data, the vehicle's infotainment system decrypts it, verifies the VIN's compatibility with its own, and, if successful, encrypts the dynamic password using the SM4 algorithm with the pre-shared key (K_Vehicle-Diagnostic Tool), generates password response data, and sends it to the diagnostic tool.

[0075] Specifically, the diagnostic tool sends encryption requests via the CAN bus at a rate of 10Mbps; the vehicle's infotainment system has a built-in password verification module with basic functions for password request parsing and encrypted transmission.

[0076] The S340 and the vehicle's infotainment system complete dual verification. Once the verification is successful, the developer mode is unlocked.

[0077] Specifically, the user enters the password to be verified on the vehicle's infotainment system. The password verification module on the system performs numerical and time-based verification on the entered password based on the verification association data and the dynamic password in the secure storage area. First, the password to be verified is compared with the dynamic password in the secure storage area. If they match, the numerical verification passes. Then, the system obtains the current Coordinated Universal Timestamp and calculates the time difference between it and the Coordinated Universal Timestamp when the dynamic password was generated. If the difference does not exceed 300 seconds (a preset time difference threshold), the time-based verification passes. After both verifications pass, the vehicle's infotainment system automatically removes the developer mode permission restrictions and unlocks the device.

[0078] The S350 and vehicle-mounted system generate operation audit logs, which are then uploaded to the cloud and stored on the blockchain in an immutable manner.

[0079] Specifically, after the vehicle's infotainment system unlocks developer mode, the operation log generator automatically generates operation audit logs. The logs include the vehicle identification number, diagnostic tool identifier, the usage time of the dynamic password, and the operation instructions in developer mode. The vehicle's infotainment system encrypts and packages the operation audit logs and uploads them to the cloud-based backend management system. The cloud then associates the audit logs with the dynamic password generation, synchronization, and distribution records and uploads them to the audit log blockchain built on Hyperledger Fabric for storage.

[0080] Specifically, the on-device secure storage area can temporarily cache audit logs to ensure data security before uploading.

[0081] The audit log contains a full lifecycle record of passwords, meeting the requirements of traceability and solving the problems of lack of traceability and inability to attribute malicious operations in traditional technology audits.

[0082] Optionally, the entire process can be managed in the cloud, enabling dynamic password rotation and real-time revocation.

[0083] Specifically, the cloud-based backend management system monitors the validity period of dynamic passwords in real time. Passwords automatically expire after the preset validity period. It also supports manual real-time revocation of issued dynamic passwords according to actual needs. For the multiple operation requirements of developer mode, the cloud can re-execute the S320-S350 process based on the diagnostic instrument's subsequent legitimate request, realizing on-demand rotation of dynamic passwords.

[0084] The technical solution of this invention constructs a collaborative password generation and verification mechanism involving the cloud, the vehicle's infotainment system, and a diagnostic tool. The cloud generates a 6-digit password and performs dual-end encrypted storage. The vehicle's infotainment system performs dual verification of the input password's value and timeliness. After unlocking, it generates an audit log containing full lifecycle information and uploads it to the blockchain for storage. This achieves encryption and anti-cracking protection for the in-vehicle developer mode and full traceability of the operation process. It solves the technical problems of traditional in-vehicle developer modes, such as the susceptibility to cracking using fixed / local passwords, the lack of unified cloud management, and the absence of operation audit traceability. It achieves the technical effects of increasing the cost of password cracking, enabling dynamic password rotation and real-time revocation, meeting traceability requirements, and reducing unauthorized access attempts in the developer mode.

[0085] Figure 3 This is a schematic diagram of a vehicle-mounted developer mode security protection device provided in an embodiment of the present invention. Figure 3 As shown, the device includes: an authentication information receiving module 410, a dynamic code generation module 420, and a verification and unlocking module 430.

[0086] The system includes: an authentication information receiving module 410 for receiving device authentication information uploaded by the diagnostic tool and the vehicle identification code from the vehicle terminal; a dynamic code generation module 420 for generating a dynamic password based on the vehicle identification code, a Coordinated Universal Time Stamp (UTC), and a random number, synchronizing the dynamic password to the secure storage area of ​​the vehicle terminal, and encrypting and storing the vehicle identification code, the diagnostic tool identifier, and the UTC as verification data for the dynamic password; and a verification unlocking module 430 for performing dual verification on the input password based on the verification data and the dynamic password in the secure storage area, unlocking the developer mode of the vehicle terminal if the verification result is successful; wherein the dual verification includes numerical verification and timeliness verification.

[0087] The technical solution of this invention receives device authentication information uploaded by a diagnostic instrument and the vehicle identification number (VIN) from the vehicle's infotainment system. Based on the VIN, a Coordinated Universal Time Stamp (UTC), and a random number, a dynamic password is generated and synchronized to the secure storage area of ​​the vehicle's infotainment system. Simultaneously, the VIN, diagnostic instrument identifier, and UTC are encrypted and stored as verification data for the dynamic password. The input password is then subjected to dual verification based on the verification data and the dynamic password in the secure storage area. If the verification is successful, the developer mode on the vehicle's infotainment system is unlocked. This dual verification includes numerical verification and time-sensitive verification. This solution addresses the technical problems of traditional in-vehicle developer mode protection, such as easily cracked passwords, lack of secure password storage, single verification dimensions, and unauthorized devices being able to arbitrarily initiate unlocking requests. It achieves the technical effects of improving the security of in-vehicle developer mode passwords, realizing dual verification and secure password storage, verifying the authorization of operating devices, and effectively preventing unauthorized personnel from illegally unlocking the developer mode.

[0088] In some embodiments, the device authentication information is the device digital certificate of the diagnostic instrument, which is a unique identity authentication file configured when the diagnostic instrument leaves the factory.

[0089] In some embodiments, the dynamic code generation module is specifically used for:

[0090] The vehicle identification number, the Coordinated Universal Time Stamp, and a 128-bit random number are concatenated to obtain the original data. The original data is then subjected to hash and modulo operations to generate a dynamic password in a six-digit format.

[0091] In some embodiments, the dynamic code generation module is specifically used for:

[0092] The dynamic password, along with the associated vehicle identification number, diagnostic tool identifier, and Coordinated Universal Timestamp, is encrypted, stored in a cloud-based password repository, and a preset validity period is configured for the dynamic password.

[0093] In some embodiments, the verification and unlocking module includes:

[0094] A consistency comparison unit is used to perform a consistency comparison between the password to be verified and the dynamic password.

[0095] The numerical verification unit is used to determine that the numerical verification result is passed if the comparison results are consistent.

[0096] In some embodiments, the verification and unlocking module includes:

[0097] The time difference determination unit is used to obtain the current Coordinated Universal Timestamp and calculate the time difference between the current Coordinated Universal Timestamp and the Coordinated Universal Timestamp when the dynamic password was generated.

[0098] The timeliness verification unit is used to determine that the timeliness verification result is passed if the time difference does not exceed a preset time difference threshold.

[0099] In some embodiments, the apparatus further includes:

[0100] The log generation module is used to generate an operation audit log after unlocking the developer mode on the vehicle terminal, and upload the operation audit log to the cloud backend management system; wherein, the operation audit log includes the vehicle identification code, the diagnostic tool identifier, the usage time of the dynamic password, and the operation instructions in the developer mode.

[0101] The vehicle developer mode security protection device provided in the embodiments of the present invention can execute the vehicle developer mode security protection method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.

[0102] Figure 4 This is a schematic diagram of the structure of an electronic device for implementing the vehicle-mounted developer mode security protection method according to embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (such as helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0103] like Figure 4 As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded into the RAM 13 from storage unit 18. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0104] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0105] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as the method of in-vehicle developer mode security protection.

[0106] In some embodiments, the method-based in-vehicle developer mode security protection can be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the method-based in-vehicle developer mode security protection described above can be performed. Alternatively, in other embodiments, processor 11 can be configured to perform the method-based in-vehicle developer mode security protection by any other suitable means (e.g., by means of firmware).

[0107] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0108] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0109] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0110] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0111] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0112] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.

[0113] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0114] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A security protection method for in-vehicle developer mode, characterized in that, include: Receive the device authentication information uploaded by the diagnostic tool and the vehicle identification number from the vehicle terminal; A dynamic password is generated based on the vehicle identification number, the Coordinated Universal Timestamp, and a random number. The dynamic password is synchronized to the secure storage area of ​​the vehicle's infotainment system. At the same time, the vehicle identification number, the diagnostic tool identifier, and the Coordinated Universal Timestamp are encrypted and stored as verification data associated with the dynamic password. The input password to be verified is double-verified based on the verification association data and the dynamic password in the secure storage area. If the verification result is successful, the developer mode of the vehicle terminal is unlocked. The double verification includes numerical verification and time-sensitive verification.

2. The method according to claim 1, characterized in that, The device authentication information is the diagnostic instrument's digital certificate, which is a unique identity authentication file configured when the diagnostic instrument leaves the factory.

3. The method according to claim 1, characterized in that, The process of generating a dynamic password based on the vehicle identification number, the Coordinated Universal Time Stamp, and a random number, and synchronizing the dynamic password to the secure storage area on the vehicle's infotainment system, includes: The vehicle identification number, the Coordinated Universal Time Stamp, and a 128-bit random number are concatenated to obtain the original data. The original data is then subjected to hash and modulo operations to generate a dynamic password in a six-digit format.

4. The method according to claim 1, characterized in that, The simultaneous encryption and storage of the vehicle identification number, diagnostic tool identifier, and Coordinated Universal Time Stamp includes: The dynamic password, along with the associated vehicle identification number, diagnostic tool identifier, and Coordinated Universal Timestamp, is encrypted, stored in a cloud-based password repository, and a preset validity period is configured for the dynamic password.

5. The method according to claim 1, characterized in that, The dual verification of the input password based on the verification association data and the dynamic password in the secure storage area includes: The password to be verified is compared with the dynamic password for consistency. If the comparison results are consistent, the numerical verification result is determined to be passed.

6. The method according to claim 1, characterized in that, The dual verification of the input password based on the verification association data and the dynamic password in the secure storage area includes: Obtain the current Coordinated Universal Timestamp and calculate the time difference between the current Coordinated Universal Timestamp and the Coordinated Universal Timestamp when the dynamic password was generated; If the time difference does not exceed the preset time difference threshold, the timeliness verification result is determined to be passed.

7. The method according to claim 1, characterized in that, After unlocking the developer mode on the vehicle-mounted system, it also includes: An operation audit log is generated and uploaded to the cloud-based backend management system; wherein, the operation audit log includes the vehicle identification code, the diagnostic tool identifier, the usage time of the dynamic password, and operation instructions in developer mode.

8. A vehicle-mounted developer mode security protection device, characterized in that, include: The authentication information receiving module is used to receive the device authentication information uploaded by the diagnostic instrument and the vehicle identification code from the vehicle terminal. The dynamic code generation module is used to generate a dynamic password based on the vehicle identification code, the Coordinated Universal Time Stamp, and a random number, synchronize the dynamic password to the secure storage area of ​​the vehicle's infotainment system, and simultaneously encrypt and store the vehicle identification code, diagnostic tool identifier, and the Coordinated Universal Time Stamp. The verification and unlocking module is used to perform dual verification on the input password to be verified based on the verification association data and the dynamic password in the secure storage area. If the verification result is successful, the developer mode on the vehicle terminal is unlocked. The dual verification includes numerical verification and time-limited verification.

9. An electronic device, characterized in that, The electronic device includes: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the vehicle developer mode security protection method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the vehicle developer mode security protection method according to any one of claims 1-7.