Platform tamper-proof circuit based on engine controller
By designing a platform anti-tampering circuit based on the engine controller and combining software and hardware, the circuit board version can be quickly determined, solving the problems of engine controller data tampering and cumbersome CVN verification, and improving data security and the engine controller's anti-tampering capabilities.
Patent Information
- Application Number
- CN202422939297.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Utility models(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2034-11-29
AI Technical Summary
In the existing technology, engine controller data tampering is frequent, resulting in changes in engine performance and unqualified emissions. In addition, the existing CVN verification process is cumbersome, affecting vehicle safety.
A platform anti-tampering circuit based on the engine controller is designed. The circuit board version can be quickly determined by reading the GPIO status. The anti-tampering methods of software and hardware are combined, including resistors, capacitors and identification modules. The GPIO status is used to determine the mass production or sample version. An independent verification code calculation tool and a web remote call tool are used to verify the data file.
It enables quick determination of circuit board versions, avoids tedious CVN verification, enhances data security, prevents incompletely developed ECUs from being tampered with, and improves the security and data integrity of engine controllers.
Smart Images

Figure CN223450412U_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The utility model relates to the field of automobile electronic safety technology, specifically relates to a platform tamper -resistant circuit based on engine controller. BACKGROUND
[0002] Engine control unit (ECU) as one of the key components of engine, directly influences engine performance and emission performance. At present, the situation of tampering with engine controller data by illegal means appears on the market, for example, the engine power output is improved by modifying ECU data, some vehicle functions are turned on or off, and the emission is modified, etc. This illegal behavior not only causes the change of engine performance and the failure to meet the emission standard, but also has adverse effects on vehicle safety.
[0003] The Chinese patent with publication number CN118708392A discloses an ECU abnormal writing identification method and device based on CVN value and a vehicle. In the implementation process, CVN verification needs to be repeated every time the writing is performed, and the writing is relatively cumbersome every time. UTILITY MODEL CONTENT
[0004] The utility model provides a platform tamper -resistant circuit based on engine controller to solve the above problems.
[0005] The technical scheme adopted is a platform tamper -resistant circuit based on engine controller, which is used for reading GPIO state.
[0006] The tamper -resistant circuit includes resistance R1010, resistance R1005, capacitor C1011 and identification module I_A_VCC / M.
[0007] One end of the resistance R1010 is connected with the target circuit board, and the other end of the resistance R1010 is grounded.
[0008] The resistance R1005 is connected with the resistance R1010 in parallel, one end of the resistance R1005 is connected with the target circuit board, the other end of the resistance R1005 is grounded through the capacitor C1011, and the two ends of the resistance R1005 are both provided with test points.
[0009] The identification module I_A_VCC / M is used for identifying high and low levels.
[0010] Further, when the target circuit board is a sample version, the resistance R1001 is pasted on the target circuit board, and the resistance R1001 is connected with the resistance R1010 and the resistance R1005 respectively, and the identification module I_A_VCC / M identifies as high level.
[0011] Further, when the target circuit board is a mass production version, the VCC end on the target circuit board is connected with the resistor R1010 and the resistor R1005 respectively, and the identification module I_A_VCC / M is identified as a low level.
[0012] The utility model discloses the beneficial effects are:
[0013] 1. The circuit provided by the application can read the GPIO state of the circuit board, thereby quickly judging whether the circuit board is a mass production version or a sample version, and the sample version does not need CVN verification when developing, thereby improving the judgment speed.
[0014] 2. The problem that the existing scheme needs to repeatedly perform CVN verification every time during the implementation process and every time the writing is relatively cumbersome is solved to a great extent. BRIEF DESCRIPTION OF DRAWINGS
[0015] Figure 1 It is a kind of platform tamper-proofing circuit diagram based on engine controller;
[0016] Figure 2 It is another kind of platform tamper-proofing circuit diagram based on engine controller;
[0017] Figure 3 It is a kind of platform tamper-proofing method flow chart based on engine controller. DETAILED DESCRIPTION
[0018] The embodiments of the present application will be described in detail below with specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the content disclosed in the specification. The present application can also be implemented or applied in different specific embodiments, and various modifications or changes can be made to the details in the specification without departing from the spirit of the present application. It should be noted that the following examples and features in the examples can be combined with each other without conflict.
[0019] It should be noted that the diagrams provided in the following examples only illustrate the basic concept of the present application in a schematic manner, and the diagrams only show the components related to the present application, not the number, shape and size of the components during actual implementation. The actual implementation of each component may be randomly changed in shape, number and proportion, and the component layout pattern may also be more complex.
[0020] In this embodiment, a platform tamper-proofing circuit based on an engine controller is used to read the GPIO state.
[0021] The tamper-proofing circuit includes a resistor R1010, a resistor R1005, a capacitor C1011 and an identification module I_A_VCC / M.
[0022] One end of the resistor R1010 is connected to the target circuit board, and the other end of the resistor R1010 is grounded.
[0023] The resistor R1005 is connected in parallel with the resistor R1010, one end of the resistor R1005 is connected to the target circuit board, and the other end of the resistor R1005 is grounded through the capacitor C1011, and both ends of the resistor R1005 are provided with test points.
[0024] The identification module I_A_VCC / M is used to identify high and low levels.
[0025] The purpose of such design is that the circuit provided by the present application can read the GPIO state of the circuit board, so as to quickly judge whether the circuit board is a mass production version or a sample version, and the sample version does not need CVN verification when developing, thereby improving the judgment speed; to a great extent, the problem of repeated CVN verification and cumbersome each time of writing in the implementation process of the prior art is solved.
[0026] Meanwhile, in the specific implementation, as shown in Figure 1 When the target circuit board is a sample version, the resistor R1001 is attached to the target circuit board, and the resistor R1001 is connected with the resistor R1010 and the resistor R1005 respectively, and the identification module I_A_VCC / M identifies as high level.
[0027] As shown in Figure 2 When the target circuit board is a mass production version, the VCC end of the target circuit board is connected with the resistor R1010 and the resistor R1005 respectively, and the identification module I_A_VCC / M identifies as low level.
[0028] The purpose of such design is to judge whether a circuit board is a mass production version or a sample (Prototype) by reading external IO (input / output port), and whether to enable CVN verification (sample closes CVN verification function):
[0029] Using the GPIO state
[0030] GPIO configuration:
[0031] The designer may reserve one or more GPIOs (general input / output ports) on the circuit board for identifying the state of the circuit board.
[0032] For example, one GPIO can be used as a state indication, which indicates a sample when it is at a high level, and indicates mass production when it is at a low level.
[0033] Read GPIO:
[0034] Write a program to read the state of the specified GPIO.
[0035] Use the microcontroller's GPIO read function, or read the state of the GPIO through an external device (such as Arduino or Raspberry Pi).
[0036] Interpret the state:
[0037] According to the read GPIO state, determine whether the circuit board is a mass production version.
[0038] At the same time, in order to prevent tampering, the embodiment also provides an engine controller-based platform tamper-proofing method based on the CVN judgment, including the following steps:
[0039] S1. Calibrate the data;
[0040] S2. Upload the calibrated data file and A2L file;
[0041] S3. Generate a data file with a check code;
[0042] S4. Upgrade the ECU software;
[0043] S5. Verify through the data file with the check code;
[0044] S6. Process based on the verification result.
[0045] At the same time, in specific implementation, in S1, the calibration data interval writes the check code of all data in the interval to a position outside the calibration data interval.
[0046] In addition, in S2, the check code calculation tool developed based on c# language reads the address and data information in the data hex file, and calculates the check code of the specified address interval data.
[0047] At the same time, in S2, the check code calculation tool developed based on c# language parses the variable attributes in the A2L file and calculates the check code.
[0048] Moreover, in S3, the check code is written to the specified address position in the data file, and a new data file with the check code is generated.
[0049] At the same time, in S5, it includes Bootloader software upgrade check code verification and APP check code verification.
[0050] The purpose of the design is that, on the one hand, the small amount of ECU with incomplete anti-tamper function that has been developed at the initial stage of the project development is limited from being used for data tampering by the method, greatly enhancing the data security after batch, and on the other hand, the independent check code calculation tool is adopted to facilitate the customized check code generation mode, and will not affect the existing software integration, data calibration, production line generation, etc.
[0051] In the embodiment, the Bootloader software upgrade check and APP check mode are provided, in which, in the Bootloader software upgrade check code verification, after the data transmission is completed, the Bootloader calculates the check code of the calibration area data and compares it with the check value saved in the APP to determine whether they match, and after the Bootloader software upgrade check code verification is passed, in the APP check code verification, after the controller is powered on, the APP calculates the check code of the calibration area data and compares it with the check code saved in the APP to determine whether they match.
[0052] Based on the above verification results, when the Bootloader software upgrade check code verification fails, the flashing fails, and when the APP check code verification fails, the engine start is limited.
[0053] In this way, on the one hand, if the APP software with incomplete anti-tamper function is flashed, the Bootloader will prompt that the verification fails, thereby prohibiting the flashing, and on the other hand, if the APP software is flashed using the Bootloader with incomplete anti-tamper function, the APP internal check value will limit the engine start when it fails, and a check code calculation tool is developed to directly read the data file and write the check code into the data file, which is convenient for writing the check code into the data file after data solidification, and the tool is independent of the software integration, data calibration, and production line production processes, and the existing processes do not need to be adjusted.
[0054] It should be noted that the technical solution provided in the embodiment adopts a combination of software and hardware to prevent tampering of the engine controller, in which the APP internal check needs to compare the check code when powered on, and the check code in the software part needs to be placed in two areas and algorithms to increase the difficulty of cracking, and the comparison of the check code is added in the Bootloader flashing stream to prevent the flashed software from being cracked.
[0055] Meanwhile, in S2 in the embodiment, a webpage remote call check code calculation tool is further included, which can upload data files and A2L files through a webpage interface, remotely call the tool to generate a data file with a check code, and download the generated data file through the webpage.
[0056] The purpose of the design is to develop a platform software to realize a tool for remotely calling a calculation check code of a webpage.
[0057] And the user permission management is added, which is convenient for setting up a special data management personnel to use the tool, and through the webpage, the check code calculation tool is called, which is convenient for low-cost management of the tool version and use permission.
[0058] It should be pointed out that the embodiment adopts a development of an independent check code calculation tool, and a remote calling tool based on jenkins.
[0059] Finally, it should be pointed out that: the above is only a preferred embodiment of the utility model, and is not used for limiting the utility model, although the utility model has been described in detail with reference to the foregoing embodiments, for those skilled in the art, the technical scheme recorded in the foregoing embodiments can still be modified, or some technical features can be replaced, and any modification, equivalent replacement, improvement, etc. within the spirit and principle of the utility model should be included in the protection scope of the utility model.
Claims
1. A platform anti-tampering circuit based on an engine controller, characterized in that: The anti-tamper circuit is used to read the GPIO status; The anti-tamper circuit includes a resistor R1010, a resistor R1005, a capacitor C1011 and an identification module I_A_VCC / M; One end of the resistor R1010 is connected to the target circuit board, and the other end of the resistor R1010 is grounded; The resistor R1005 is connected in parallel with the resistor R1010. One end of the resistor R1005 is connected to the target circuit board, and the other end of the resistor R1005 is grounded via the capacitor C1011. Test points are set at both ends of the resistor R1005. The identification module I_A_VCC / M is used to identify high and low levels.
2. The platform anti-tampering circuit based on the engine controller according to claim 1, characterized in that: When the target circuit board is a sample version, a resistor R1001 is attached to the target circuit board, and the resistor R1001 is connected to the resistor R1010 and the resistor R1005 respectively, and the identification module I_A_VCC / M identifies it as a high level.
3. The platform anti-tampering circuit based on the engine controller according to claim 1, characterized in that: When the target circuit board is a mass-produced version, the VCC terminal on the target circuit board is connected to the resistor R1010 and the resistor R1005 respectively, and the identification module I_A_VCC / M identifies it as a low level.
Citation Information
Patent Citations
ECU abnormal flash identification method and device based on CVN value and vehicle
CN118708392A