Key transmission method and device
The method securely transmits initial keys to vehicle components using asymmetric encryption and wired connections, addressing insecure key transmission issues and enhancing communication security by preventing unauthorized access and reducing costs.
Patent Information
- Application Number
- JP2024516796
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-09-18
- Publication Date
- 2025-08-22
- Estimated Expiration
- 2041-09-18
AI Technical Summary
Existing key transmission processes in intelligent vehicles lack security, jeopardizing the integrity of service data due to insecure initial key generation and distribution.
A method and apparatus for securely transmitting an initial key to vehicle components using asymmetric encryption and wired connections, ensuring that only authorized components can generate shared keys for data encryption, particularly for geographic location information, without involving OEMs without navigation map production qualifications.
Enhances the security of key transmission and communication between vehicle components by preventing unauthorized access to initial and shared keys, simplifying operations, and reducing implementation complexity and costs.
Smart Images

Figure 0007728444000001 
Figure 0007728444000002 
Figure 0007728444000003
Abstract
Description
[Technical Field]
[0001] FIELD OF THE INVENTION
[0001] Embodiments of the present application relate to the field of communication technology, and in particular to a key transmission method and apparatus. [Background technology]
[0002]
[0002] With the development of intelligent vehicles, various components in the intelligent vehicle (e.g., domain controllers, electronic control units, and sensors) can communicate with each other to cooperatively complete services for the intelligent vehicle. For example, when an intelligent vehicle performs an intelligent driving service, geographical location information may be transmitted between the sensors and the intelligent driving controller.
[0003]
[0003] To ensure secure communication between various components, a shared key between different components needs to be used to encrypt related service data for transmission. The shared key is generated based on an initial key of a vehicle. The existing filling process of the initial key cannot guarantee the security of the initial key, thus jeopardizing the service data security of the vehicle. Therefore, how to securely transmit the key to improve the security performance of communication between different components is a technical problem that needs to be urgently solved. Summary of the Invention
[0004]
[0001] Embodiments of the present application disclose a key transmission method and apparatus for improving key transmission security, improving security performance of communication between components within a vehicle, and protecting service data related to the vehicle.
[0005]
[0005] According to a first aspect, an embodiment of the present application provides a key transmission method. The method may be executed by a first component of a vehicle or a chip built in the first component. The method includes: receiving a first instruction from a first key tool, the first instruction including first information associated with an initial key; and obtaining the initial key according to the first instruction. The initial key is at least used to generate a shared key, and the shared key is at least used to encrypt data including geographic location information. The first component may be a controller, an electronic control unit, a sensor, or the like in the vehicle. This is not particularly limited in the embodiment of the present application. The first instruction may be used to redeem the initial key of the first component.
[0006]
[0006] In this solution, a first key tool is used to transmit first information associated with an initial key to a first component in a vehicle, so that the first component can obtain the initial key based on the first information. This can effectively improve key transmission security, so that a shared key generated based on the initial key cannot be obtained by other devices, and can effectively improve the security performance of communication between vehicle components.
[0007]
[0007] The geographic location information data may include data related to one or more of the following: longitude and latitude, altitude, and geographic track. For example, the geolocation information data may include data where the longitude and latitude data range and / or the altitude data range are within a preset threshold range. Alternatively, the geolocation information data may be data related to a geographic location. This is not particularly limited in the embodiments of the present application. Altitude is the height of a point relative to a reference surface, for example, the height of the top of a vehicle relative to the ground. Correspondingly, altitude data includes data reflecting the height of a point relative to a reference surface, for example, the height of the top of a vehicle relative to the ground.
[0008]
[0008] The shared key may be a shared key of all components in the vehicle, or may be a shared key of components associated with a functional domain (e.g., an intelligent driving domain) in the vehicle, which is not limited in the embodiments of the present application.
[0009]
[0009] In a possible design, the initial key is unrelated to the original equipment manufacturer (OEM) or unrelated to an OEM that does not have a navigation electronic map production qualification. The OEM in this case is the OEM associated with the vehicle. In this design, the entire initial key transmission process does not require the participation of the OEM associated with the vehicle, so the initial key is invisible to the OEM, or does not require the participation of an OEM that does not have a navigation electronic map production qualification, so the initial key is invisible to OEMs that do not have a navigation electronic map production qualification. This can further improve key transmission security.
[0010]
[0010] In a possible design, the initial key is associated with an organization that has a navigation electronic map creation qualification, which can ensure the security of the initial key, and thereby ensure the transmission security of the geographical location information.
[0011]
[0011] In a possible design, the initial key is different from an authentication key, and the authentication key is from an OEM associated with the vehicle. The first component is capable of determining at least one function key based on the authentication key. The at least one function key corresponds to at least one service function of the first component. In an embodiment of the present application, a service related to geographic location information can be implemented based on the initial key from the first key tool and a shared key generated using the initial key. A service not associated with geographic location information can be implemented based on the authentication key from the OEM and a function key generated using the authentication key. In this way, different keys can be used for services related to geographic location information and services not associated with geographic location information, thereby further ensuring the transmission security of data related to geographic location information.
[0012]
[0012] The first information can be implemented in a number of ways, including but not limited to the following ways.
[0013]
[0013] Method 1: The first information includes a first ciphertext, and the first ciphertext includes information obtained by encrypting an initial key with a first public key of the first component. Correspondingly, the process of the first component obtaining the initial key according to the first instruction may be: decrypting the first ciphertext based on the first private key of the first component to obtain the initial key. The first private key corresponds to the first public key.
[0014]
[0014] In Method 1, the initial key is encrypted for transmission using the first public key of the first component, so that the first component can obtain the initial key by decrypting the ciphertext of the initial key using the first private key corresponding to the first public key. In an optional design, the first component may generate a first public key and a first private key corresponding to the first public key and send the first public key to the first key tool. The first key tool encrypts the initial key using the first public key to obtain the first ciphertext and sends the first ciphertext to the first component. Since the first component has the first private key corresponding to the first public key, the first component can decrypt the first ciphertext based on the first private key to obtain the initial key. Since the transmission of the initial key is performed according to an asymmetric encryption algorithm, the transmission security of the initial key can be effectively improved.
[0015] Method 2: The first information includes an initial key. Correspondingly, the process in which the first component obtains the initial key according to the first instruction may be: obtain the initial key according to the first instruction in a wired connection manner.
[0016]
[0016] In Method 2, in a wired connection mode, the first component can directly receive the initial key, and the first component does not need to perform encryption / decryption processing. Therefore, even a first component without encryption / decryption capabilities can obtain the initial key, ensuring the security of communications between various components. In addition, obtaining the initial key in this manner simplifies the operation of the first component and reduces the implementation complexity and cost of the component.
[0017] In a possible design, the first component may further send first response information to the first key tool. The first response information includes a filling result of the initial key. In this design, the first response information sent by the first component includes the filling result of the initial key, so that the first key tool can better monitor the key filling result of the first component.
[0018]
[0018] The initial key fillability result may indicate whether the initial key was successfully filled or whether the initial key failed to fill.
[0019] In a possible design, the initial key redemption result includes: a first identifier, the first identifier indicating that the initial key was successfully redeemed; and / or a third ciphertext, the third ciphertext including information obtained by encrypting the first random number included in the first instruction with the initial key or a derivative of the initial key. In this design, the initial key redemption result includes the first identifier and / or the third ciphertext, such that the first key tool can determine whether the initial key was successfully redeemed based on the first identifier and / or the third ciphertext.
[0020] In a possible design, the initial key validity result may include a second identifier. The second identifier may indicate that the initial key failed to be valid. In this design, the initial key validity result includes the second identifier, such that the first key tool can determine that the initial key failed to be valid based on the second identifier.
[0021] In one possible design, the initial key redemption result may further include an identifier of the vehicle and / or an identifier of the first component. In this way, the first key tool can monitor the redemption status of the initial key of the first component and / or the vehicle.
[0022]
[0022] In a possible design, the first component further receives a second instruction from the first key tool or the second key tool, where the second instruction includes second information associated with the shared key; and can obtain the shared key based on the initial key and the second information. The second instruction may be used to allocate a shared key for the first component. In this design, the first component can receive the shared key allocation instruction from the first key tool, i.e., can use the first key tool to allocate the initial key and the shared key. The key allocation task of the first component can be simplified, and the design of the key tool used for key allocation can also be simplified. Alternatively, according to the above design, the first component can allocate the shared key using a second key tool different from the first key tool, thereby achieving flexibility in allocating the initial key and the shared key. It will be understood that in the latter design, the first key tool can be used only to allocate the initial key.
[0023]
[0023] In a possible design, the first key tool and the second key tool may correspond to different key allocation environments. For example, the first key tool corresponds to a component supplier (or supplier) / component production line. That is, the first key tool may be used to allocate an initial key for the first component at the component supplier and / or within the component production line, or may be used to allocate an initial key and a shared key for the first component. The second key tool corresponds to an OEM production line. That is, the second key tool may be used to allocate a shared key for the first component at the OEM production line. In this design, different key tools are used to allocate a shared key and an initial key for the first component in different key allocation environments. In this way, not only can key allocation flexibility be achieved, but also key tools suitable for different key allocation environments can be designed. This further ensures the security of key allocation in different key allocation environments, thereby improving the security performance of communication between different components within a vehicle.
[0024] In another possible design, the first key tool and the second key tool may alternatively correspond to different components in the vehicle. For example, the first key tool corresponds to any component in the vehicle or a component in the vehicle that participates in geographic information exchange. In this case, the first key tool may be used to allocate an initial key or an initial key and a shared key to any component in the vehicle or a component in the vehicle that participates in geographic information exchange. The second key tool corresponds only to a main control component in the vehicle (e.g., a software and hardware integrated platform, i.e., a vehicle computing platform or gateway used to support intelligent driving) or components associated with a specific functional domain (e.g., an intelligent driving domain or a human machine interface (HMI)). In this case, the second key tool may be used to allocate a shared key for the main control component in the vehicle or a component associated with a specific functional domain. In this design, different key tools are used to allocate the initial key and / or the shared key to different components in the vehicle. In this way, not only can the flexibility of key allocation be realized, but also the key tool can be designed to fit various components in the vehicle, which further ensures the security of key allocation of different components in the vehicle, thereby improving the security performance of communication between different components in the vehicle.
[0025] In another possible design, the first key tool and the second key tool may alternatively correspond to different component suppliers. For example, the first key tool corresponds to component supplier 1. In this case, the first key tool may be used to allocate an initial key or an initial key and a shared key for any component in the vehicle associated with component supplier 1. For example, the second key tool corresponds to component supplier 2. In this case, the second key tool may be used to allocate a shared key for any component in the vehicle associated with component supplier 2. In this design, different key tools are used to allocate the shared key and / or the initial key for the first component for different component suppliers. In this way, not only can flexibility in key allocation be achieved, but key tools compatible with different component suppliers can also be designed. This further ensures the security of key allocation for different component suppliers, thereby improving the security performance of communication between different components in the vehicle.
[0026]
[0026] It should be noted that there are multiple implementations when the first component obtains the shared key based on the initial key and the second information, including but not limited to the following methods.
[0027]
[0027] Method 1: The second information may be used as keying material, and the first component obtains a shared key based on the initial key and the second information according to a symmetric encryption algorithm or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0028]
[0028] In Method 1, the second information can be used as keying material. The first component generates a shared key based on the initial key and the second information according to a specific key algorithm, eliminating the need to transmit the shared key using a key tool. In this way, other devices cannot obtain the shared key of the first component, effectively improving the security of the shared key of the first component. Furthermore, Method 1 has low requirements for the algorithm of the first component. For example, the shared key can be obtained as long as the first component supports a symmetric encryption algorithm, a message authentication code that follows a symmetric encryption algorithm, or a key derivation algorithm. This reduces the implementation complexity and cost of the first component.
[0029] Method 2: The second information includes information obtained by encrypting the shared key with the initial key, so that the first component can obtain the shared key based on the initial key and the second information. For example, to obtain the shared key, the second information is decrypted with the initial key.
[0030]
[0029] In Method 2, the second information includes a ciphertext of the shared key, and the ciphertext is information obtained by encrypting the shared key with an initial key. The first component can obtain the shared key based on the initial key and the ciphertext. However, other devices that do not have the initial key cannot restore the shared key even if they receive the ciphertext. This effectively improves the security of the shared key of the first component. Furthermore, Method 2 has low requirements for the algorithm of the first component. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the implementation complexity and the cost of the first component.
[0031] It should be noted that the first component may alternatively appropriate the shared key through an information exchange with the second component, including but not limited to the following implementations.
[0032]
[0031] Method 1: The second component is configured to distribute key information (e.g., second instructions) from at least the first key tool or the second key tool. Correspondingly, the first component can further receive the second instructions forwarded by the second component and use the second instructions to redeem the shared key. The second component is another component in the vehicle and different from the first component.
[0033]
[0032] In Method 1, the second component directly transfers the second command from the first key tool or the second key tool to the first component to allocate the shared key of the first component. In this way, the first key tool and the second key tool only need to communicate with the second component and can allocate the shared key for other components in the vehicle without needing to perform communication interactions with other components in the vehicle. This effectively improves the efficiency of allocating the shared key of all components in the vehicle.
[0034]
[0033] Method 2: Alternatively, the first component may receive a third instruction from the second component, where the third instruction includes third information associated with the shared key; and the shared key may be derived based on the initial key and the third information. The third instruction may be used to allocate the shared key for the first component. The third instruction may be obtained by the second component by processing the second instruction. As another example, the second component may obtain the third instruction by converting the communication protocol format of the second instruction. Alternatively, the third information may be generated by the second component. For example, the third information may include keying material generated by the second component. As another example, the second component may generate the shared key and determine the third information based on the shared key and the initial key.
[0035]
[0034] It should be understood that the implementation of the case where "the first component obtains a shared key based on the initial key and the third information" is the same as the implementation of the case where "the first component obtains a shared key based on the initial key and the second information". See the above description. It is only necessary that "the second information" be replaced with "the third information". The details will not be described again in this case.
[0036]
[0035] In Method 2, the second component can perform communication protocol format conversion on the second instruction or the second information from the first key tool or the second key tool, and correspondingly obtain the third instruction or the third information. In this way, the third instruction or the third information can be better adapted to the communication protocol between the first component and the second component, and the first component can allocate the shared key according to the instruction (i.e., the third instruction). In addition, the first component does not need to obtain a shared key allocation instruction from the first key tool or the second key tool, which can effectively improve the efficiency of allocating the shared key. Alternatively, the second component can generate a shared key allocation instruction (e.g., the third instruction or the third information) for allocating the shared key for another component (i.e., the first component) in the vehicle. In this way, the allocation of the shared key no longer depends on the first key tool or the second key tool. This simplifies the shared key allocation procedure.
[0037]
[0036] In a possible design, the first component can further send second response information in response to the second command. The second response information includes a validity result of the shared key. The first component can send the second response information to the first key tool or the second key tool. This is not particularly limited in the embodiment of the present application.
[0038] In one possible design, the first component may further send third response information in response to the third command. The third response information may include a validity result of the shared key. The first component may send the third response information to the second component.
[0039] In a possible design, the redemption result of the shared key may include: a third identifier, the third identifier indicating that the shared key has been successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting the second random number included in the second instruction or the second random number included in the third instruction with the shared key or a derivative of the shared key. In this design, the redemption result of the shared key includes the first identifier and / or the third ciphertext, such that the first key tool can determine whether the shared key has been successfully redeemed based on the first identifier and / or the third ciphertext.
[0040] In a possible design, the shared key validity result includes a fourth identifier. The fourth identifier may indicate that the shared key failed to be redeemed. In this design, the shared key validity result includes the fourth identifier, such that the first key tool can determine that the shared key failed to be redeemed based on the fourth identifier.
[0041] In one possible design, the shared key redemption result may further include an identifier of the vehicle and / or an identifier of the first component. In this design, the first key tool or the second key tool may monitor the redemption status of the shared key of the vehicle and / or the first component.
[0042] In one possible design, the first component may further receive a fourth instruction from the first key tool or key detection tool, where the fourth instruction includes a third random number; determines a first check value based on the third random number and the shared key; and transmits fourth response information including the first check value. The fourth instruction may be used to detect whether the shared key of the first component is abnormal. In this design, the first component receives the fourth instruction from the first key tool or key detection tool, generates the first check value based on the random number included in the fourth instruction and the shared key of the first component, and returns the first check value to the first key tool or key detection tool. In this manner, the first key tool or key detection tool may determine whether the shared key of the first component matches its local shared key based on the first check value, and determine whether the shared key of the first component is abnormal. This helps the first key tool or key detection tool monitor the first component's shared key for abnormalities, and if abnormalities exist, it helps ensure that the first component's shared key matches the first key tool's or key detection tool's local shared key through subsequent operations, thereby ensuring the security of communications between vehicle components.
[0043]
[0042] In a possible design, the first component is further configured to receive a fifth instruction from the first key tool or the key detection tool. The fifth instruction may include a fifth random number, and the fifth instruction may be used to detect whether the initial key of the first component is abnormal. The first component is further configured to determine a third check value based on the fifth random number and the initial key. The first component is further configured to send fifth response information. The fifth response information includes the third check value. If the initial key is abnormal, this helps to ensure that the initial key of the first component matches the local initial key of the first key tool through subsequent operations, thereby ensuring the security of a shared key subsequently determined based on the initial key.
[0044] According to a second aspect, an embodiment of the present application further provides a key transmission method. The method may be performed by a second component in a vehicle or a chip built in the second component. The method includes: obtaining a shared key fill command. The second component sends the shared key fill command to the first component. The shared key fill command is used to fill a shared key for the first component. The shared key is used at least to encrypt data including geographic location information.
[0045]
[0044] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0046]
[0045] Obtaining the shared key filling instruction by the second component may be generating or receiving the shared key filling instruction by the second component.
[0047] In a possible design, the shared key filling instruction may be a second instruction. The second instruction includes second information associated with the shared key. In this design, the second component obtaining the shared key filling instruction includes: the second component receiving a second instruction from the first key tool or the second key tool. The shared key filling instruction includes the second instruction. For example, the shared key filling instruction is the second instruction. In this design, the second component may directly use the second instruction from the first key tool or the second key tool as the shared key filling instruction and forward the shared key filling instruction to the first component to fill the shared key of the first component. This design simplifies the operation procedure of the second component, resulting in a simple implementation. Furthermore, the first component does not need to obtain the shared key filling instruction from the first key tool or the second key tool, which effectively improves the efficiency of filling the shared key.
[0048]
[0047] The second information may be implemented in multiple ways. For example, the first key tool or the second key tool may generate keying material (e.g., the keying material may be generated randomly or according to a specific rule) and use the keying material as the second information in the second instruction. As another example, the first key tool or the second key tool may generate a shared key (e.g., the shared key may be generated randomly or according to a specific rule), obtain a ciphertext of the shared key based on the initial key and the shared key, and use the ciphertext as the second information. As yet another example, the first key tool or the second key tool may encrypt the shared key using the initial key to obtain a ciphertext of the shared key, and use the ciphertext as the second information.
[0049] In another possible design, the shared key allocation instruction may include a third instruction. For example, the shared key allocation instruction is a third instruction. The third instruction includes third information associated with the shared key. In this design, the third instruction may be implemented in multiple ways, including but not limited to the following implementation.
[0050] Method 1: The third instruction is obtained by the second component by processing the second instruction.
[0051]
[0050] For example, the second component may convert the communication protocol format of the second instruction to obtain the third instruction, or may convert the communication protocol format of the second information included in the second instruction to obtain the third information included in the third instruction.
[0052]
[0051] In method 1, the second component can receive a second instruction sent by the first key tool or the second key tool, and then obtain a third instruction by processing the second instruction. The second instruction includes second information associated with the shared key. The second information may be implemented in multiple ways. For details, please refer to the implementation of the second information in the corresponding possible design above when the shared key allocation instruction is the second instruction.
[0053]
[0052] In method 1, the third instruction or the third information included in the third instruction may be better adapted to the communication protocol between the first component and the second component. The first component can allocate the shared key according to the instruction (i.e., the third instruction). The first component does not need to obtain the shared key allocation instruction from the first key tool or the second key tool, which effectively improves the efficiency of allocating the shared key.
[0054] Method 2: The third instruction is generated by the second component.
[0055] For example, the second component may generate the third instruction when a predetermined condition is met or when a specific instruction is received. The shared key allocation instruction includes the third instruction. For example, the shared key allocation instruction is the third instruction.
[0056]
[0055] The "specific command" can be any command, and the second component can use the command as a trigger signal. For example, the specific command can be a diagnostic command specifically used to generate a shared key redemption command, or a diagnostic command for other functions, such as a component flash or component reset command. In an optional design, the specific command can come from a diagnostic device, a whole-vehicle electrical inspection test device, the cloud, or another component in the vehicle (e.g., a telematics box (TBO) or a gateway (GW)).
[0057]
[0056] The pre-set condition includes, but is not limited to, a device associated with the second component being started and reaching a specific point in time.
[0058]
[0057] It can be understood that "a device associated with the second component is started" may mean that the second component is started, or that the device on which the second component is located is started. For example, the second component is A. In this case, when A is started or the device on which A is located is started, A can generate the third instruction. As another example, the second component is B. In this case, when B is started or the device on which B is located is started, B can generate the third instruction.
[0059]
[0058] It can be understood that "reaching a specific point in time" may mean reaching a specific key recharge point (e.g., 00:00 on the first day of each month) or reaching a predetermined day before the key expiration date (e.g., the day before the key expiration date).
[0060]
[0059] In Method 2, the third information may be implemented in multiple ways. For example, the second component may generate keying material (e.g., the keying material may be generated randomly or according to a specific rule) and use the keying material as the third information in the third instruction. As another example, the second component may generate a shared key (e.g., the shared key may be generated randomly or according to a specific rule), obtain a ciphertext of the shared key based on the initial key and the shared key, and use the ciphertext as the third information.
[0061] In Method 2, the second component can generate a shared key allocation command to allocate a shared key for another component (i.e., the first component) in the vehicle. In this way, allocation of the shared key no longer depends on the first key tool or the second key tool. This simplifies the shared key allocation procedure.
[0062]
[0061] In a possible design, the second component receives a second instruction from the first key tool or the second key tool, where the second instruction includes second information associated with the shared key; and the shared key can be obtained based on the initial key and the second information. The second instruction can be used to allocate the shared key for the second component. In this design, the second component can receive the shared key allocation instruction from the first key tool, i.e., can use the first key tool to allocate the initial key and the shared key. This can simplify the key allocation process of the second component, and can also simplify the design of the key tool used for key allocation. Alternatively, according to the above design, the second component can allocate the shared key using a second key tool different from the first key tool, thereby achieving flexibility in allocating the initial key and the shared key.
[0063]
[0062] It should be noted that there are multiple implementations in which the second component derives the shared key based on the initial key and the second information, including but not limited to the following methods.
[0064] Method 1: The second component obtains a shared key based on the initial key and the second information according to a symmetric encryption algorithm or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0065]
[0064] In Method 1, the second information can be used as keying material. The second component generates a shared key based on the initial key and the second information according to a specific key algorithm, eliminating the need to transmit the shared key using a key tool. In this way, other devices cannot obtain the shared key of the second component, effectively improving the security of the shared key of the second component. Furthermore, Method 1 has low requirements for the algorithm of the second component. For example, the shared key can be obtained as long as the second component supports a symmetric encryption algorithm, a message authentication code following a symmetric encryption algorithm, or a key derivation algorithm. This reduces the implementation complexity and cost of the second component.
[0066]
[0065] Method 2: The second information includes information obtained by encrypting the shared key with the initial key, so that the second component can obtain the shared key based on the initial key and the second information. For example, to obtain the shared key, the second information is decrypted with the initial key.
[0067]
[0066] In Method 2, the second information includes a ciphertext of the shared key, and the ciphertext is information obtained by encrypting the shared key with an initial key. The second component can obtain the shared key based on the initial key and the ciphertext. However, other devices that do not have the initial key cannot restore the shared key even if they receive the ciphertext. This effectively improves the security of the shared key of the second component. Furthermore, Method 2 has low requirements for the algorithm of the second component. For example, as long as the second component supports some decryption algorithm, the shared key can be obtained. This reduces the implementation complexity and the cost of the second component. In another possible design, the second component can directly generate the shared key.
[0068] In one possible design, the second component may receive a first instruction from the first key tool. The first instruction includes first information associated with an initial key. The second component may obtain the initial key according to the first instruction. The initial key is used to generate at least a shared key, and the shared key is used to encrypt data including at least geographic location information.
[0069]
[0068] For a description of the geographic location information data, please refer to the related description in the first aspect.
[0070]
[0069] The first information may be implemented in multiple ways. Correspondingly, there are multiple implementations in which the second component obtains the initial key according to the first instruction, including but not limited to the following methods:
[0071]
[0070] Method 1: The first information includes a first ciphertext, and the first ciphertext includes information obtained by encrypting an initial key with a first public key of the first component. Correspondingly, the process of the second component obtaining the initial key according to the first instruction may be: decrypting the first ciphertext based on the first private key of the second component to obtain the initial key. The first private key corresponds to the first public key.
[0072]
[0071] In Method 1, the initial key is encrypted for transmission using the first public key of the second component, so that the second component can decrypt the ciphertext of the initial key using the first private key corresponding to the first public key to obtain the initial key. In an optional design, the second component may generate a first public key and a first private key corresponding to the first public key and send the first public key to the first key tool. The first key tool encrypts the initial key using the first public key to obtain the first ciphertext and sends the first ciphertext to the first component. Since the second component has the first private key corresponding to the first public key, the second component can decrypt the first ciphertext based on the first private key to obtain the initial key. Since the transmission of the initial key is performed according to an asymmetric encryption algorithm, the transmission security of the initial key can be effectively improved.
[0073] Method 2: The first information includes an initial key. Correspondingly, the process of the second component obtaining the initial key according to the first instruction may be: obtaining the initial key according to the first instruction in a wired connection manner.
[0074]
[0073] In Method 2, in a wired connection mode, the second component can directly receive the initial key, and the second component does not need to perform encryption / decryption processing. Therefore, even a second component without encryption / decryption capabilities can obtain the initial key, ensuring the security of communications between various components. In addition, obtaining the initial key in this manner simplifies the operation of the second component and reduces the implementation complexity and cost of the component.
[0075] In a possible design, the second component may further send first response information to the first key tool. The first response information includes the initial key validity result. In this design, the first response information sent by the second component includes the initial key validity result, so that the first key tool can better monitor the key validity result of the second component.
[0076]
[0075] The initial key fillability result may indicate whether the initial key was successfully filled or whether the initial key failed to fill.
[0077] In a possible design, the initial key redemption result includes: a first identifier, the first identifier indicating that the initial key was successfully redeemed; and / or a third ciphertext, the third ciphertext including information obtained by encrypting the first random number included in the first instruction with the initial key or a derivative of the initial key. In this design, the initial key redemption result includes the first identifier and / or the third ciphertext, such that the first key tool can determine whether the initial key was successfully redeemed based on the first identifier and / or the third ciphertext.
[0078] In a possible design, the initial key validity result may include a second identifier. The second identifier may indicate that the initial key failed to be valid. In this design, the initial key validity result includes the second identifier, such that the first key tool can determine that the initial key failed to be valid based on the second identifier.
[0079] In a possible design, the initial key redemption result may further include an identifier of the vehicle and / or an identifier of the second component. In this way, the first key tool can monitor the redemption status of the initial key of the second component and / or the vehicle.
[0080]
[0079] In a possible design, the second component may further send second response information in response to the second command, the second response information including a validity result of the shared key.
[0081]
[0080] The shared key redemption result may indicate whether the shared key was successfully redeemed or whether the shared key failed to redeem.
[0082] In a possible design, the redemption result of the shared key may include: a third identifier, the third identifier indicating that the shared key has been successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting the second random number included in the second instructions or the second random number included in the third instructions with the shared key or a derivative of the shared key. In this design, the redemption result of the shared key includes the first identifier and / or the third ciphertext, such that the first key tool can determine whether the shared key has been successfully redeemed based on the first identifier and / or the third ciphertext.
[0083] In a possible design, the shared key validity result includes a fourth identifier. The fourth identifier may indicate that the shared key failed to be redeemed. In this design, the shared key validity result includes the fourth identifier, such that the first key tool can determine that the shared key failed to be redeemed based on the fourth identifier.
[0084] In one possible design, the shared key redemption result may further include an identifier of the vehicle and / or an identifier of the second component. In this design, the first key tool or the second key tool may monitor the redemption status of the shared key of the vehicle and / or the second component.
[0085] In one possible design, the second component may further receive a fourth instruction from the first key tool or key detection tool, where the fourth instruction includes a third random number, the fourth instruction being used to detect whether the shared key of the first component is abnormal; determine a first check value based on the third random number and the shared key; and send fourth response information including the first check value. In this design, the second component may receive the fourth instruction from the first key tool or key detection tool, generate the first check value based on the random number included in the fourth instruction and the shared key of the second component, and return the first check value to the first key tool or key detection tool. In this manner, the first key tool or key detection tool may determine whether the shared key of the second component matches its local shared key based on the first check value, and then determine whether the shared key of the second component is abnormal. This helps the first key tool or key detection tool monitor the shared key of the second component for abnormalities, and if abnormalities exist, it helps ensure through subsequent operations that the shared key of the second component matches the local shared key of the first key tool or key detection tool, thereby ensuring the security of communications between the components of the vehicle.
[0086] In a possible design, the second component is further configured to receive a fifth instruction from the first key tool or key detection tool. The fifth instruction may include a fifth random number, and the fifth instruction may be used to detect whether the initial key of the second component is abnormal. The second component is further configured to determine a third check value based on the fifth random number and the initial key. The second component is further configured to send fifth response information. The fifth response information includes the third check value. If the initial key is abnormal, this helps to ensure that the initial key of the second component matches the local initial key of the first key tool or key detection tool through subsequent operations, thereby ensuring the security of a shared key subsequently determined based on the initial key.
[0087] According to a third aspect, an embodiment of the present application further provides a key transmission method, which may be performed by a first key tool, including: determining an initial key for a vehicle, the initial key being used to generate at least a shared key, the shared key being used to encrypt data including at least geographic location information; and transmitting a first instruction to a first component of the vehicle, the first instruction including first information associated with the initial key.
[0088]
[0087] In this solution, the first key tool transmits first information associated with the initial key to the first component in the vehicle, so that the first component can obtain the initial key based on the first information. This can effectively improve the key transmission security, so that the shared key generated based on the initial key cannot be obtained by other devices, and can effectively improve the security performance of communication between the components in the vehicle.
[0089]
[0088] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0090]
[0089] In a possible design, the initial key is unrelated to the OEM or unrelated to an OEM that does not have a navigation electronic mapping license. The OEM in this case is an OEM associated with the vehicle. In this design, the entire initial key transmission process does not require the participation of the OEM associated with the vehicle, so the initial key is invisible to the OEM, or does not require the participation of an OEM that does not have a navigation electronic mapping license, so the initial key is invisible to OEMs that do not have a navigation electronic mapping license. This can further improve the key transmission security.
[0091]
[0090] In a possible design, the initial key is associated with an organization that has a navigation electronic map creation qualification, which can ensure the security of the initial key, thereby ensuring the transmission security of the geographical location information.
[0092]
[0091] In a possible design, the initial key is different from the authentication key, which is from an original equipment manufacturer (OEM) associated with the vehicle. The authentication key is at least used to generate at least one function key, where the at least one function key corresponds to at least one service function of the first component. In this design, services related to geographic location information can be implemented based on the initial key from the first key tool and a shared key generated using the initial key. Services not associated with geographic location information can be implemented based on the authentication key from the OEM and a function key generated using the authentication key. In this way, different keys can be used for services related to geographic location information and services not related to geographic location information, further ensuring transmission security of data related to geographic location information.
[0093]
[0092] The authentication key is used to authenticate at least the function keys of the vehicle. For example, the authentication key may be one of a master ECU key (MEK), a pre-master ECU key (PMEK), and a root key. This is not particularly limited in the embodiments of the present application.
[0094] In one possible design, the first information includes a first ciphertext, the first ciphertext including information obtained by encrypting an initial key with a first public key, the first public key being from the first component.
[0095]
[0094] In one possible design, the first information includes an initial key, and sending the first instruction to the first component of the vehicle includes sending the initial key to the first component in a wired manner.
[0096]
[0095] In one possible design, the process by which the first key tool determines the initial key for the vehicle may include: generating a second public key and a second private key; sending request information to the key management system, where the request information requests the initial key and includes the second public key; and receiving a second ciphertext from the key management system and determining the initial key based on the second ciphertext and the second private key. In this design, the first key tool may request the initial key from the key management system and receive the ciphertext of the initial key. This may ensure the security of obtaining the initial key by the first key tool.
[0097]
[0096] In a possible design, the first key tool may further receive first response information from the first component, the first response information including a validity result of the initial key.
[0098]
[0097] In a possible design, if the initial key validity result indicates that the initial key failed to be valid, the first key tool may further resend the first command.
[0099]
[0098] In a possible design, the initial key redemption result includes a second identifier, which indicates that the initial key failed to redeem.
[0100]
[0099] In a possible design, the initial key redemption result may include: a first identifier indicating that the initial key has been successfully redeemed; and / or a third ciphertext including information obtained by encrypting a first random number included in the first instruction using the initial key or a derived key of the initial key.
[0101]
[0100] In a possible design, if the initial key redemption result includes a third ciphertext, the first key tool can further determine whether the initial key was successfully redeemed based on the third ciphertext.
[0102]
[0101] In a possible design, the initial key validity result may further include an identifier of the vehicle and / or an identifier of the first component.
[0103] In a possible design, if the initial key validity result indicates that the initial key is successfully filled, the first key tool may further send a second instruction to the first component, the second instruction including second information associated with the shared key.
[0104]
[0103] It should be noted that the second information may be implemented in multiple ways, including but not limited to the following implementations.
[0105]
[0104] Method 1: The first key tool generates a shared key (e.g., the shared key is generated randomly or according to a specific rule), and obtains the second information based on the initial key and the shared key. For example, the first key tool may encrypt the shared key based on the initial key to obtain the second information.
[0106]
[0105] In Method 1, the first key tool can generate a shared key and obtain second information based on the initial key and the shared key. The first component can obtain the shared key based on the ciphertext of the shared key and the initial key. However, for other devices that do not have the initial key, even if they receive the ciphertext, they cannot restore the shared key. This effectively improves the security of the shared key of the first component. Furthermore, Method 1 has low requirements for the algorithm of the first component. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the implementation complexity and the cost of the first component.
[0107]
[0106] Method 2: The first key tool may generate keying material (e.g., the keying material may be generated randomly or according to specific rules) and use the keying material as the second information.
[0108]
[0107] In Method 2, the second information can be used as keying material. In this way, the first component generates a shared key based on the initial key and the second information according to a specific key algorithm, and there is no need to transmit the shared key using the first key tool. Other devices cannot obtain the shared key of the first component, which effectively improves the security of the shared key of the first component. Furthermore, Method 2 has low requirements for the algorithm of the first component. For example, as long as the first component supports a symmetric encryption algorithm, a message authentication code following a symmetric encryption algorithm, or a key derivation algorithm, the shared key can be obtained. This reduces the implementation complexity and cost of the first component.
[0109]
[0108] In a possible design, the first key tool may further receive second response information from the first component, the second response information including a validity result of the shared key.
[0110]
[0109] In a possible design, the redemption result of the shared key may include: a third identifier indicating that the shared key has been successfully redeemed; and / or a fourth ciphertext including information obtained by encrypting a second random number included in the second instruction using the shared key or a derivative key of the shared key.
[0111]
[0110] In a possible design, if the shared key redemption result includes the fourth ciphertext, the method further includes: the first key tool further determining whether the shared key has been successfully redeemed based on the second information and the fourth ciphertext. In this design, whether the shared key has been successfully redeemed is verified using the fourth ciphertext. This helps the first key tool accurately monitor the redemption status of the shared key.
[0112]
[0111] In a possible design, the shared key redemption result may further include a fourth identifier, which indicates that the shared key failed to redeem.
[0113] In a possible design, if the validity result of the shared key indicates that the shared key has failed to be redeemed, the first key tool may further resend the second command, which can effectively improve the probability of successfully redeeming the shared key.
[0114]
[0113] In a possible design, the validity result of the shared key may further include an identifier of the vehicle and / or an identifier of the first component.
[0115]
[0114] In one possible design, the first key tool sends a fourth command to a first component of the vehicle, where the fourth command includes a third random number; receives fourth response information including a first check value, where the fourth response information includes the first check value, the first check value being associated with the third random number and a vehicle shared key, the shared key being used to encrypt data including at least geographic location information; determines, based on the first check value, whether the vehicle shared key matches a local shared key corresponding to the vehicle; and reports abnormality information if the vehicle shared key does not match the local shared key. In this method, the first key tool communicates with the first component in the vehicle and performs abnormality detection of the vehicle shared key. If an abnormality exists, this helps ensure, through subsequent operations, that the first component's shared key matches the first key tool's local shared key, thereby ensuring the security of communications between the vehicle components.
[0116] In one possible design, the first key tool may further: send a fifth command to the first component of the vehicle, where the fifth command includes a fifth random number; receive fifth response information from the first component, where the fifth response information includes a third check value, where the third check value is associated with the fifth random number and an initial key for the vehicle, the initial key being used to generate at least the shared key; determine whether the initial key for the vehicle matches a local initial key corresponding to the vehicle based on the third check value; and report abnormality information if the initial key for the vehicle does not match the local initial key. In this design, the first key tool may communicate with the first component in the vehicle and perform abnormality detection for the vehicle's initial key. If an abnormality exists, it may ensure through subsequent operations that the initial key of the first component matches the local initial key of the first key tool, thereby ensuring the security of a shared key subsequently determined based on the initial key.
[0117] According to a fourth aspect, an embodiment of the present application further provides a key transmission method. The method may be performed by a second key tool. The method includes determining second instructions and transmitting the second instructions to a first component in a vehicle. The second instructions include second information associated with a shared key. The shared key is used to encrypt data including at least geographic location information. The second instructions are used to redeem the shared key for the first component.
[0118]
[0117] In this solution, the second key tool can transmit second information associated with the shared key to the first component in the vehicle, so that the first component can obtain the shared key based on the second information and the initial key. This can effectively improve the transmission security of the shared key, so that the shared key of the first component cannot be obtained by other devices, and effectively improve the security performance of communication between the components in the vehicle.
[0119]
[0118] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0120]
[0119] It should be noted that the second information may be implemented in multiple ways, including but not limited to the following implementations.
[0121]
[0120] Method 1: The second key tool generates a shared key (e.g., the shared key is generated randomly or according to a specific rule), and obtains the second information based on the initial key and the shared key. For example, the second key tool may encrypt the shared key based on the initial key to obtain the second information.
[0122]
[0121] In Method 1, the second key tool can generate a shared key and obtain second information based on the initial key and the shared key. In this way, the first component can obtain the shared key based on the initial key and the ciphertext of the shared key. However, other devices that do not have the initial key cannot restore the shared key even if they receive the ciphertext. This effectively improves the security of the shared key of the first component. Furthermore, Method 1 has low requirements for the algorithm of the first component. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the implementation complexity and the cost of the first component.
[0123]
[0122] Method 2: The second key tool may generate keying material (e.g., the keying material may be generated randomly or according to specific rules) and use the keying material as the second information.
[0124]
[0123] In Method 2, the second information can be used as keying material. Thus, the first component generates a shared key based on the initial key and the second information according to a specific key algorithm, and does not need to transmit the shared key using the second key tool. Other devices cannot obtain the shared key of the first component, which effectively improves the security of the shared key of the first component. Furthermore, Method 2 has low requirements for the algorithm of the first component. For example, the shared key can be obtained as long as the first component supports a symmetric encryption algorithm, a message authentication code that follows a symmetric encryption algorithm, or a key derivation algorithm. This reduces the implementation complexity and cost of the second component.
[0125]
[0124] Method 3: The second key tool may request a shared key from the first key tool and obtain the second information based on the initial key and the shared key. For example, the second key tool may encrypt the shared key based on the initial key to obtain the second information.
[0126]
[0125] In Method 3, the shared key is managed by the first key tool, and the second key tool requests the shared key from the first key tool. In this way, the shared key is allocated to the first component using multiple key tools, so that the shared key is not easily obtained by other devices. This can effectively improve the security of the shared key of the first component. Furthermore, Method 3 has low requirements for the algorithm of the first component. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the implementation complexity and the cost of the first component.
[0127]
[0126] In a possible design, the second key tool may further receive second response information from the first component, the second response information including a validity result of the shared key.
[0128]
[0127] In a possible design, the redemption result of the shared key includes: a third identifier indicating that the shared key has been successfully redeemed; and / or a fourth ciphertext including information obtained by encrypting a second random number included in the second instruction using the shared key or a derivative key of the shared key.
[0129]
[0128] In a possible design, if the shared key redemption result includes the fourth ciphertext, the second key tool can further determine whether the shared key has been redeemed successfully based on the second information and the fourth ciphertext. In this design, whether the shared key has been redeemed successfully is verified using the fourth ciphertext. This helps the second key tool accurately monitor the redemption status of the shared key.
[0130]
[0129] In a possible design, if the validity result of the shared key indicates that the shared key has failed to be redeemed, the second key tool may further resend the second command, which can effectively improve the probability of successfully redeeming the shared key.
[0131]
[0130] In a possible design, the validity result of the shared key includes a fourth identifier, which indicates that the shared key failed to be valid.
[0132] In a possible design, the shared key redemption result may further include an identifier of the vehicle and / or an identifier of the first component. In this way, the second key tool can monitor the redemption status of the shared key of the vehicle and / or the first component.
[0133] According to a fifth aspect, an embodiment of the present application further provides a key detection method. The method may be performed by a key detection tool. The method includes the steps of: sending a fourth instruction to a first component of the vehicle, the fourth instruction including a third random number; receiving fourth response information from the first component, the fourth response information including a first check value, the first check value being associated with the third random number and a vehicle shared key, the shared key being used at least to encrypt data including geographic location information; determining, based on the first check value, whether the vehicle shared key matches a local shared key corresponding to the vehicle; and reporting abnormality information if the vehicle shared key does not match the local shared key.
[0134] In this method, the key detection tool communicates with a first component in the vehicle and performs abnormality detection of the vehicle's shared key, which, if abnormality exists, helps to ensure that the shared key of the first component matches the local shared key of the key detection tool through subsequent operations, thereby ensuring the security of communications between the vehicle's components.
[0135]
[0134] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0136]
[0135] It should be noted that there are multiple implementations of the key detection tool that can determine whether the vehicle's shared key matches the local shared key corresponding to the vehicle based on the first check value, including but not limited to the following implementations:
[0137]
[0136] Implementation 1: A second check value is calculated based on the local shared key and a third random number, and the first check value is compared with the second check value. If the first check value matches the second check value, it is determined that the local shared key of the vehicle matches the current shared key of the vehicle. If the first check value does not match the second check value, it is determined that the local shared key of the vehicle does not match the current shared key of the vehicle. In Implementation 1, the key detection tool performs shared key abnormality detection by comparing the consistency between the second check value determined by the key detection tool and the first check value determined by the first component. This can improve the accuracy of key abnormality detection.
[0138]
[0137] Implementation 2: Based on the received first check value and the local shared key, a fourth random number is determined, and then the fourth random number is compared to whether it matches the third random number. If the third random number matches the fourth random number, it is determined that the local shared key of the vehicle stored in the key detection tool matches the current shared key of the vehicle. If the third random number does not match the fourth random number, it is determined that the local shared key of the vehicle does not match the current shared key of the vehicle. In Implementation 2, the key detection tool performs shared key abnormality detection by comparing the consistency between the fourth random number determined by the key detection tool based on the first check value and the third random number. This can improve the accuracy of key abnormality detection.
[0139] In one possible design, the key detection tool may further: send a fifth command to the first component of the vehicle, where the fifth command includes a fifth random number; receive fifth response information from the first component, where the fifth response information includes a third check value, where the third check value is associated with the fifth random number and the vehicle's initial key, the initial key being used to generate at least the shared key; determine, based on the third check value, whether the vehicle's initial key matches a local initial key corresponding to the vehicle; and report abnormality information if the vehicle's initial key does not match the local initial key. In this design, the key detection tool may perform a communication interaction with the first component in the vehicle and perform abnormality detection of the vehicle's initial key. If an abnormality exists, this helps ensure, through subsequent operations, that the first component's initial key matches the key detection tool's local initial key, thereby ensuring the security of a shared key subsequently determined based on the initial key.
[0140]
[0139] According to a sixth aspect, an embodiment of the present application further provides another key detection method. The method may be executed by a key detection tool. The method includes: acquiring a communication information ciphertext of a first component of a vehicle, where the communication information ciphertext includes information obtained by encrypting the first information with a vehicle shared key, and the first information includes geographical location information; determining, based on a local shared key corresponding to the vehicle and the communication information ciphertext, whether the vehicle shared key matches the local shared key; and reporting abnormality information if the vehicle shared key does not match the local shared key.
[0141]
[0140] In this method, the key detection tool in this method can obtain the communication information ciphertext of the first component and perform abnormality detection of the vehicle's shared key based on the communication information ciphertext. This helps to timely discover abnormalities in the vehicle's key. The key detection tool performs communication interaction with the first component in the vehicle and performs abnormality detection of the vehicle's shared key. If abnormalities exist, this helps to ensure that the shared key of the first component matches the local shared key of the key detection tool through subsequent operations, thereby ensuring the security of communications between the vehicle's components.
[0142]
[0141] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0143]
[0142] In a possible design, the process by which the key detection tool determines whether the shared key used by the vehicle matches the local shared key based on the local shared key of the vehicle and the communication information ciphertext stored in the key detection tool may include: acquiring the communication information based on the local shared key and the communication information ciphertext; and determining whether the communication information is abnormal, and if the communication information is abnormal, determining that the shared key used by the vehicle does not match the local shared key, or if the communication information is normal, determining that the shared key used by the vehicle matches the local shared key. For example, the process by the key detection tool to acquire the communication information based on the local shared key and the communication information ciphertext may include: decrypting the communication information ciphertext using the local shared key to acquire the communication information.
[0144]
[0143] In possible designs, there are multiple implementations in which the key detection tools in the fifth and sixth aspects obtain the local shared key corresponding to the vehicle, including but not limited to the following methods:
[0145]
[0144] Method 1: Obtain a vehicle identifier or a first component identifier. Based on the vehicle identifier or the first component identifier, query an initial key corresponding to the vehicle and keying material used to generate a local shared key. Generate a local shared key based on the initial key and keying material. In this way, the local shared key of the key discovery tool has high real-time performance.
[0146]
[0145] Method 2: Obtain a vehicle identifier or a first component identifier. Query the local shared key based on the vehicle identifier or the first component identifier. In this way, the key discovery tool can quickly obtain the local shared key and improve the key discovery efficiency.
[0147] In possible designs, the key detection tools of the fifth and sixth aspects may further report the abnormality information to a qualification management organization, or may report the abnormality information to a key management system. In some possible embodiments, the qualification management organization is an organization that holds a surveying and mapping license and / or an organization that engages in surveying and mapping activities pursuant to law.
[0148]
[0147] According to a seventh aspect, an embodiment of the present application provides a control device configured to implement the method performed by the first component in the first aspect.
[0149] For example, the device: a transceiver module configured to receive a first instruction from a first key tool, the first instruction including first information associated with an initial key; and a processing module configured to obtain an initial key according to a first instruction, the initial key being used to generate at least a shared key, the shared key being used to encrypt data including at least geographic location information; may contain.
[0150]
[0149] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0151]
[0150] For a description of other possible designs and related beneficial effects in the seventh aspect, please refer to the first aspect and the corresponding possible designs in the first aspect, and the details will not be described again here.
[0152]
[0151] According to an eighth aspect, an embodiment of the present application provides another control device configured to implement the method performed by the second component in the second aspect.
[0153]
[0152] For example, the device: a processing module configured to obtain a shared key redemption instruction, the shared key redemption instruction being used to redeem a shared key of a first component, the shared key being used to encrypt data including at least geographic location information; and a transceiver module configured to transmit a shared key redemption command to the first component; may contain.
[0154]
[0153] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0155]
[0154] For a description of other possible designs and related beneficial effects in the eighth aspect, please refer to the second aspect and the corresponding possible designs in the second aspect, and the details will not be described again here.
[0156]
[0155] According to a ninth aspect, an embodiment of the present application provides a key transmission device, which may be the first key tool in the third aspect.
[0157]
[0156] For example, the device: a processing module configured to determine an initial key for the vehicle, the initial key being used to generate at least a shared key, the shared key being used to encrypt data including at least geographic location information; and a transceiver module configured to transmit a first instruction to a first component of the vehicle, the first instruction including first information associated with an initial key; may contain.
[0158]
[0157] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0159]
[0158] For a description of other possible designs and related beneficial effects in the ninth aspect, please refer to the third aspect and the corresponding possible designs in the third aspect, and the details will not be described again here.
[0160]
[0159] According to a tenth aspect, an embodiment of the present application provides another key transmission device, which may be the second key tool in the fourth aspect.
[0161]
[0160] For example, the device: a processing module configured to determine second instructions; and a transceiver module configured to transmit second instructions to a first component within the vehicle, the second instructions including second information associated with a shared key, the second instructions being used to redeem the shared key for the first component, the shared key being used to encrypt data including at least geographic location information; may contain.
[0162]
[0161] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0163]
[0162] For a description of other possible designs and related beneficial effects in the tenth aspect, please refer to the fourth aspect and the corresponding possible designs in the fourth aspect, and the details will not be described again here.
[0164]
[0163] According to an eleventh aspect, an embodiment of the present application provides a key detection device for implementing the method performed by the key detection tool in the fifth aspect.
[0165]
[0164] For example, the device: a transceiver module configured to transmit fourth instructions to a first component of the vehicle, the fourth instructions including a third random number, the transceiver module further configured to receive fourth response information from the first component, the fourth response information including a first check value, the first check value being associated with the third random number and a shared key of the vehicle, the shared key being used to encrypt data including at least geographic location information; and The system includes a processing module configured to determine whether the vehicle's shared key matches a local shared key corresponding to the vehicle based on the first check value, and to report abnormality information if the vehicle's shared key does not match the local shared key.
[0166]
[0165] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0167]
[0166] For other possible designs in the eleventh aspect, please refer to the corresponding possible designs in the fifth aspect, and the details will not be described again here.
[0168]
[0167] According to a twelfth aspect, an embodiment of the present application further provides another key detection device for implementing the method performed by the key detection tool in the sixth aspect.
[0169]
[0168] For example, the device: a processing module configured to obtain a communication information ciphertext of a first component of the vehicle, the communication information ciphertext including information obtained by encrypting first information with a shared key of the vehicle, the first information including geographic location information, the processing module further configured to determine, based on a local shared key corresponding to the vehicle and the communication information ciphertext, whether the shared key of the vehicle matches the local shared key; and a transceiver module configured to report abnormality information when the vehicle's shared key does not match the local shared key;
[0170]
[0169] For a specific description of the shared key and geographic location information data, please refer to the relevant description in the first aspect or any one of the possible designs of the first aspect.
[0171]
[0170] For other possible designs in the twelfth aspect, please refer to the corresponding possible designs in the sixth aspect, and the details will not be described again here.
[0172] According to a thirteenth aspect, an embodiment of the present application further provides an on-board component. The on-board component includes a processor and a storage medium. The storage medium stores instructions. When the instructions are executed by the processor, the on-board component is capable of performing a method according to the first aspect or any one of possible designs of the first aspect, or alternatively, the on-board component is capable of performing a method according to the second aspect or any one of possible designs of the second aspect.
[0173] According to a fourteenth aspect, an embodiment of the present application further provides an electronic device. The electronic device includes a processor and a storage medium. The storage medium stores instructions. When the instructions are executed by the processor, the electronic device is enabled to perform a method according to the sixth aspect or any one of possible designs of the sixth aspect.
[0174] According to a fifteenth aspect, an embodiment of the present application provides a chip system, the chip system including a processor configured to invoke a computer program or computer instructions stored in a memory to cause the processor to perform a method according to the first aspect or any one of the possible designs of the first aspect, or to cause the processor to perform a method according to the second aspect or any one of the possible designs of the second aspect, or to cause the processor to perform a method according to the third aspect or any one of the possible designs of the third aspect, or to cause the processor to perform a method according to the fourth aspect or any one of the possible designs of the fourth aspect, or to cause the processor to perform a method according to the fifth aspect or any one of the possible designs of the fifth aspect, or to cause the processor to perform a method according to the sixth aspect or any one of the possible designs of the sixth aspect.
[0175]
[0174] In a possible design, the processor is coupled to the memory via an interface.
[0176]
[0175] In a possible design, the chip system further comprises a memory for storing computer programs or computer instructions.
[0177] According to a sixteenth aspect, an embodiment of the present application provides a computer-readable storage medium having stored thereon a computer program or instructions that, when executed, causes a method according to the first aspect or any one of the possible designs of the first aspect to be performed, or a method according to the second aspect or any one of the possible designs of the second aspect to be performed, or a method according to the third aspect or any one of the possible designs of the third aspect to be performed, or a method according to the fourth aspect or any one of the possible designs of the fourth aspect to be performed, or a method according to the fifth aspect or any one of the possible designs of the fifth aspect to be performed, or a method according to the sixth aspect or any one of the possible designs of the sixth aspect to be performed, or a method according to the first aspect or any one of the possible designs of the first aspect.
[0178] According to a seventeenth aspect, an embodiment of the present application provides a computer program product, which when run on one or more processors, performs a method according to the first aspect or any one of the possible designs of the first aspect, or performs a method according to the second aspect or any one of the possible designs of the second aspect, or performs a method according to the third aspect or any one of the possible designs of the third aspect, or performs a method according to the fourth aspect or any one of the possible designs of the fourth aspect, or performs a method according to the fifth aspect or any one of the possible designs of the fifth aspect, or performs a method according to the sixth aspect or any one of the possible designs of the sixth aspect.
[0179] According to an eighteenth aspect, an embodiment of the present application provides a vehicle, the vehicle comprising a first component of the first aspect or any one of the possible designs of the first aspect, and / or a second component of the second aspect or any one of the possible designs of the second aspect.
[0180]
[0179] For the effects of the seventh to eighteenth aspects, please refer to the explanation of the effects of the first to sixth aspects, and the details will not be described again here. [Brief explanation of the drawings]
[0181] [Figure 1]
[0180] Figure 1 is a schematic diagram of the architecture of a system to which embodiments of the present application may be applicable. [Figure 2]
[0181] Figure 2 is a schematic flow chart of generating a key tool according to an embodiment of the present application. [Figure 3]
[0182] FIG. 3 is a schematic flowchart of a key transmission method according to an embodiment of the present application. [Figure 4]
[0183] FIG. 4 is a schematic flow chart of a key tool 200 requesting an initial key from a key management system according to an embodiment of the present application. [Figure 5]
[0184] FIG. 5 is a schematic flowchart of transmitting the ciphertext of the initial key according to an embodiment of the present application. [Figure 6]
[0185] FIG. 6 is a schematic flowchart of another key transmission method according to an embodiment of the present application. [Figure 7]
[0186] FIG. 7 is a schematic flowchart of another key transmission method according to an embodiment of the present application. [Figure 8]
[0187] FIG. 8 is a schematic flowchart of a key detection method according to an embodiment of the present application. [Figure 9]
[0188] FIG. 9 is a schematic diagram of the configuration of a control device according to an embodiment of the present application. [Figure 10]
[0189] FIG. 10 is a schematic diagram of another control device configuration according to an embodiment of the present application. [Figure 11]
[0190] FIG. 11 is a schematic diagram of the configuration of a key transmission device according to an embodiment of the present application. [Figure 12]
[0191] FIG. 12 is a schematic diagram of the configuration of another key transmission device according to an embodiment of the present application. [Figure 13]
[0192] FIG. 13 is a schematic diagram of the configuration of a key detection device according to an embodiment of the present application. [Figure 14]
[0193] FIG. 14 is a schematic diagram of the configuration of another key detection device according to an embodiment of the present application. [Figure 15]
[0194] FIG. 15 is a schematic diagram of a chip system configuration according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION
[0182]
[0195] Hereinafter, embodiments of the present application will be described with reference to the accompanying drawings in the embodiments of the present application. In this application, terms such as "example," "for example," and the like are used to indicate providing an example, illustration, or explanation. Any embodiment or design manner described in this application as an "example" or "for example" should not be described as being preferred or having more advantages than another embodiment or design manner. Rather, the use of terms such as "example," "for example," and the like is intended to present related concepts in a concrete manner.
[0183]
[0196] In the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of a single item or multiple items. For example, at least one of a, b, and c may represent a, b, c, (a and b), (a and c), (b and c), or (a, b, and c), where a, b, and c may be singular or plural. The term "and / or" describes an association relationship between associated objects and indicates that three relationships may exist. For example, A and / or B may indicate three cases: only A is present, both A and B are present, and only B is present, where A and B may be singular or plural. The character " / " generally indicates an "or" relationship between related objects.
[0184]
[0197] Furthermore, unless otherwise specified, ordinal numbers such as "first" and "second" in the embodiments of the present application are used to distinguish between multiple objects, but are not intended to limit the order, chronology, priority, or importance of the multiple objects. For example, first information and second information are merely intended to distinguish between different information, and do not indicate that the two types of information differ in content, priority, transmission order, importance, etc.
[0185]
[0198] Hereinafter, technical terms used in the embodiments of the present application will be explained first.
[0186]
[0199] 1 component
[0200] The component is an electronic device or a portion of an electronic device (e.g., a chip, an integrated circuit) that has key transmission functionality within a vehicle. The electronic device may include a terminal device. For example, the component may be a vehicle cockpit (cockpit domain) device or a module within the vehicle cockpit device (e.g., a cockpit domain controller (CDC)). As another example, the component may be an electronic control unit (ECU). As yet another example, the component may be a sensor. In embodiments of the present application, the key transmission functionality includes receiving and / or transmitting data associated with the key. The data associated with the key may include, but is not limited to, the key, a ciphertext generated based on the key, information used to flash the key, information used to verify the integrity of the key, information used to detect whether the key is abnormal, information used to provide feedback on the key status, etc.
[0187]
[0201] In some technical scenarios, the names of devices with similar key transmission functions in a vehicle may not be called components, however, for ease of explanation, in the embodiments of the present application, electronic devices with key transmission functions in a vehicle are collectively called components.
[0188]
[0202] 2. Key Tool
[0203] The key tool is a software system or electronic device having key transmission and / or key detection functions. The electronic device may be a terminal device, such as various user equipment (UE). In an optional design, the key tool may be an OEM diagnostic tool, OEM diagnostic equipment, dealer diagnostic equipment, dealer diagnostic tool (tester tool), or on-board diagnostics (OBD) system. In some embodiments, the key tool may be used to implement one or more of the following functions: allocating an initial key for a component within a vehicle; allocating a shared key for a component within a vehicle; or detecting whether the shared key and initial key for a component within a vehicle are abnormal. The key tool may be one or more key tools. This is not particularly limited in the embodiments of the present application.
[0189]
[0204] 3. Qualification Management System
[0205] The qualification management organization may be used to implement one or more of the following functions: assigning key tools, evaluating software security mechanisms of component suppliers and / or vehicle OEMs, evaluating hardware security mechanisms of component suppliers and / or vehicle OEMs, evaluating the production environment of component suppliers and / or vehicle OEMs, and detecting or monitoring key usage while the vehicle is in operation. In some possible embodiments, the qualification management organization is an organization that holds a surveying and mapping qualification and / or an organization that engages in surveying and mapping activities pursuant to law.
[0190]
[0206] 4. Key Management System
[0207] The key management system may be used to perform one or more of the following functions: managing the generation of initial keys for the vehicle, managing the distribution of initial keys, and managing the storage of initial keys. In some possible embodiments, the key management system may be deployed at a Certification Management Organization or may be deployed at an OEM's management system.
[0191]
[0208] 5.Shared key
[0209] In an embodiment of the present application, the shared key may be used to encrypt communication information between different components in a vehicle, for example, to encrypt geographic location information transmitted between different components. In an embodiment of the present application, the shared key may be a key shared by all components in the vehicle, or may be a key shared by components associated with a functional domain (e.g., an intelligent driving domain) in the vehicle, or may be a key shared by components associated with a service in the vehicle. This is not particularly limited in the embodiment of the present application.
[0192]
[0210] 6. Initial key (seed)
[0211] In some embodiments, the initial key may be used as keying material and is used to generate the shared key, while in some other embodiments, the initial key may be used to encrypt the shared key to effect encrypted transmission of the shared key.
[0193]
[0212] In some embodiments, the initial key for a vehicle is uniformly assigned by the OEM associated with the vehicle to the component supplier of each component in the vehicle, and then transferred by the component supplier to an employee of the component supplier in an offline manner (e.g., via encrypted email or an encrypted password file). Finally, the employee of the component supplier imports the initial key into the component production line system and allocates the initial key to the corresponding component. Therefore, the initial key may be disclosed to a person in the process of allocating the initial key. A shared key is generated based on the initial key for the vehicle. Once the initial key is obtained by another device, the security of the shared key cannot be guaranteed. In some cases, the OEM assigns the same initial key to all vehicles of the same vehicle type. Once the initial key is obtained by another device, the security of the shared keys for all vehicles of the same vehicle type is compromised. As a result, the security of communications between different components in a vehicle is compromised. Therefore, how to securely transmit the initial key to improve the security of communications between different components is a technical problem that urgently needs to be solved.
[0194]
[0213] In consideration of this, an embodiment of the present application provides a key transmission method. This method may be performed by a first component and a first key tool in a vehicle. In this method, the first component may receive a first instruction from the first key tool. The first instruction includes first information associated with an initial key. The first component may then obtain the initial key according to the first instruction. The initial key may be used to generate at least a shared key, and the shared key may be used to encrypt data including at least geographic location information. This effectively improves the security of key transmission so that the shared key generated based on the initial key cannot be obtained by other devices, effectively improving the safety performance of communication between vehicle components, and protecting the geographic location information associated with the components.
[0195]
[0214] The following describes the system architecture and service scenarios in the embodiments of the present application. It should be noted that the system architecture and service scenarios described in the present application are intended to more clearly explain the technical solutions in the present application, and do not constitute limitations on the technical solutions provided in the present application. Those skilled in the art will understand that with the development of system architectures and the emergence of new service scenarios, the technical solutions provided in the present application can also be applied to similar technical problems.
[0196]
[0215] 1 is a schematic diagram of a possible system architecture according to an embodiment of the present application. The system includes a key tool 200 and a vehicle 100. The vehicle 100 includes a first component 101. For example, the first component 101 may be an ECU, a domain controller, or a sensor within the vehicle 100. The key tool 200 has one or more functions of Function 1, Function 2, Function 3, and Function 4.
[0197]
[0216] Function 1 is the initial key allocation function.
[0198]
[0217] In a possible implementation, the key tool 200 can be used to determine an initial key for the vehicle 100 and send a first command to the first component 101. The first command includes first information associated with the initial key. The first component 101 can then receive the first command and obtain the initial key based on the first information. The initial key can be used to generate a shared key, which is invisible to the OEM associated with the vehicle 100. The shared key may be used to encrypt communication information (e.g., geographic location information) of the vehicle 100. In this way, the vehicle 100 effectively improves the transmission security of the initial key, thereby preventing other devices from obtaining the initial key and the shared key generated based on the initial key, effectively improving the security of communications between the components of the vehicle 100.
[0199]
[0218] Function 2 is a shared key allocation function.
[0200]
[0219] In a possible implementation, the key tool 200 may send a second instruction to the first component 101 when the initial key is successfully allocated to the first component 101. The second instruction includes second information associated with the shared key. The first component 101 may then receive the second instruction and obtain the shared key based on the second information and the initial key. In this way, the efficiency of obtaining the shared key by the first component 101 is effectively improved.
[0201]
[0220] In an optional implementation, the vehicle 100 may further include a second component 102. The first component 101 and the second component 102 may communicate with each other, and the second component 102 and the key tool 200 may communicate with each other. In a possible implementation, the key tool 200 may alternatively send a second instruction to the second component 102 to redeem a shared key for the second component 102. The second component 102 may convert the second instruction to obtain a third instruction, send the third instruction to the first component 101, and redeem the shared key for the first component 101 using the third instruction. In another possible implementation, after the key tool 200 sends the second instruction to the second component 102, the second component 102 can forward the second instruction to the first component 101 and allocate the shared key for the first component 101 by using the second instruction. In this way, the key tool 200 can allocate the shared key for the first component 101 without needing to perform a communication interaction with the first component 101. This effectively improves the efficiency of allocating the shared key to multiple components in the vehicle 100.
[0202]
[0221] It should be noted that the second component 102 may be a component integrated into the entire vehicle, such as an intelligent driving domain controller or a central gateway, and the first component 101 may be a single component in a component production line or any on-board component. If the shared key is a vehicle-wide shared key, the first component 101 and the second component 102 only need to belong to the vehicle 100. If the shared key is a function key for a specific service, the first component 101 and the second component 102 may be associated with the same service.
[0203]
[0222] Function 3 is a function that detects a key using a random number.
[0204]
[0223] In a possible implementation, the key tool 200 can send a fourth command to the first component 101. The fourth command includes a third random number. The first component 101 can then receive the fourth command, generate a first check value based on the shared key of the vehicle 100 and the third random number, and return fourth response information including the first check value to the key tool 200. The key tool 200 determines, based on the first check value, whether the shared key used by the vehicle 100 matches the local shared key corresponding to the vehicle 100 and determined by the key tool 200, and reports abnormality information if the shared key used by the vehicle 100 does not match the local shared key stored in the key tool 200. In this way, the key tool 200 interacts with the first component 101 to detect the shared key of the vehicle 100.
[0205]
[0224] In another possible implementation, key tool 200 may further be used to detect the vehicle's initial key. The detection process may be as follows: key tool 200 may send a fifth command to first component 101. The fifth command includes a fifth random number. Then, first component 101 may receive the fifth command, generate a third check value based on the fifth random number and the vehicle's initial key, and return fifth response information including the third check value to key tool 200. Based on the third check value, key tool 200 determines whether the initial key used by vehicle 100 matches the local initial key corresponding to vehicle 100 and determined by key tool 200, and reports abnormality information if the initial key used by vehicle 100 does not match the local initial key stored in key tool 200. In this way, key tool 200 interacts with first component 101 to detect the vehicle's initial key.
[0206]
[0225] Function 4 is a function for detecting a key using a communication information ciphertext. In a possible implementation, the key tool 200 can obtain the communication information ciphertext of the first component 101 of the vehicle 100. The communication information ciphertext includes first information encrypted using the shared key of the vehicle 100. The first information includes geographic location information. The key tool 200 determines whether the shared key of the vehicle 100 matches a local shared key corresponding to the vehicle 100 and determined by the key tool 200, and reports abnormality information if the shared key of the vehicle 100 does not match the local shared key of the vehicle 100. In this way, the key tool 200 can detect the shared key of the vehicle 100 simply by obtaining the communication information ciphertext of the first component 101 in the vehicle 100. This effectively improves detection efficiency. Furthermore, due to the randomness and / or real-time nature of the communication information ciphertext, the robustness of key detection can be further improved through key detection performed based on the communication information ciphertext, and the shared key can be prevented from being forged.
[0207]
[0227] It should be noted that the key tool 200 may be any of a first key tool, a second key tool, and a key detection tool. The first key tool may have Function 1. Alternatively, the first key tool may further have one or more of the following functions: Function 2, Function 3, and Function 4 in addition to Function 1. The second key tool may have Function 2. The key detection tool may have Function 3 and / or Function 4. Key detection may specifically include detection of an initial key and / or a shared key.
[0208]
[0228] Thus, if key tool 200 has function 1, or if key tool 200 has one or more of functions 2, 3, and 4 in addition to function 1, key tool 200 may be a first key detection tool. If key tool 200 has only a shared key filling function, key tool 200 may be a second key detection tool. If key tool 200 has only a key detection function, key tool 200 may be a key detection tool. Furthermore, key tool 200 may alternatively correspond to another key tool. The other key tool may have functions 2 and 3, or may have functions 2 and 4, or may have functions 2, 3, and 4.
[0209]
[0229] In a possible implementation, the first key tool and the second key tool may correspond to different key allocation environments. For example, the first key tool may correspond to a component supplier / component production line, i.e., the first key tool may be used to allocate an initial key for the first component at the component supplier and / or within the component production line, or may be used to allocate an initial key and a shared key for the first component. The second key tool may correspond to an OEM production line, i.e., the second key tool may be used to allocate a shared key for the first component at the OEM production line. In this implementation, different key tools are used to allocate an initial key and a shared key for the first component in different key allocation environments. In this manner, not only can key allocation flexibility be achieved, but key tools adapted to different key allocation environments can also be realized. This further ensures the security of key allocation in different key allocation environments, thereby improving the security performance of communications between different components within a vehicle.
[0210]
[0230] In another possible implementation, the first key tool and the second key tool may alternatively correspond to different components in the vehicle. For example, the first key tool may correspond to any component in the vehicle or a component in the vehicle that participates in geographic information exchange. In this case, the first key tool may be used to allocate an initial key or an initial key and a shared key for any component in the vehicle or a component in the vehicle that participates in geographic information exchange. The second key tool may correspond to a main control component in the vehicle (e.g., a software and hardware integrated platform, i.e., a vehicle computing platform or gateway used to support intelligent driving) or only components associated with a specific functional domain (e.g., an intelligent driving domain or HMI). In this case, the second key tool may be used to allocate a shared key for the main control component in the vehicle or components associated with a specific functional domain. In this implementation, different key tools are used to allocate an initial key and / or a shared key for different components in the vehicle. In this manner, not only can key allocation flexibility be achieved, but also key tools adapted to various components in the vehicle can be realized. This further ensures the security of key allocation of different components in the vehicle, thereby improving the security performance of communications between different components in the vehicle.
[0211]
[0231] In another possible implementation, the first key tool and the second key tool may alternatively correspond to different component suppliers. For example, the first key tool corresponds to component supplier 1. In this case, the first key tool may be used to allocate an initial key or an initial key and a shared key for any component in the vehicle associated with component supplier 1. For example, the second key tool corresponds to component supplier 2. In this case, the second key tool may be used to allocate a shared key for any component in the vehicle associated with component supplier 2. In this implementation, different key tools are used to allocate the initial key and / or the shared key for the first component for different component suppliers. In this way, not only can flexibility in key allocation be achieved, but key tools tailored to different component suppliers can also be achieved. This further ensures the security of key allocation for different component suppliers and improves the security performance of communication between different components in the vehicle.
[0212]
[0232] It should be noted that the key tool 200 may be assigned to an OEM by a Certification Management Authority. For example, Figure 2 shows a process by which a Certification Management Authority assigns a key tool to an OEM. The process includes the following steps:
[0213]
[0233] S201: The qualification management organization determines that the OEM qualification and environmental information of the OEM production line meets the security requirements, and generates an initial key.
[0214]
[0234] The security requirements include one or more of the following: security requirements for data protection mechanisms of components and the entire vehicle, security requirements for the network environment of the production line, and standard requirements for personnel management systems.
[0215]
[0235] S202: The Certification Management Authority assigns a key tool to the OEM and stores the initial key in the key tool.
[0216]
[0236] The key tool has an initial key filling function. In optional designs, the key tool also has keying material generation and / or keying material filling functions.
[0217]
[0237] Optionally, the above process may further include step S200, which is specifically as follows:
[0218]
[0238] S200: The OEM sends key tool request information to the qualification management authority. In response, the qualification management authority receives the key tool request information. The key tool request includes the OEM's qualification information, OEM production line environment information, and vehicle type information. Specifically, upon receiving the OEM's key tool request information, the qualification management authority verifies the OEM's relevant information. If the verification is successful, the qualification management authority can assign the key tool to the OEM. In this way, the use security of the key tool is effectively improved and the security of the key is enhanced.
[0219]
[0239] It should be understood that the key tool allocation process implemented in accordance with Figure 2 may be used by a qualification management organization to allocate key tools to vehicle component suppliers or other organizations, but this is not a limitation of the embodiments of the present application.
[0220]
[0240] It should be noted that if the key tool 200 has different functions, the corresponding key transmission method of the key tool 200 will also be different. Hereinafter, the key transmission method provided in the embodiments of the present application will be described with reference to specific embodiments.
[0221]
[0241] 3 is a schematic flowchart corresponding to a key transmission method according to an embodiment of the present application. For example, the method is performed by the key tool 200 and the first component 101 shown in FIG. 1. In FIG. 3, the key tool 200 has the above-mentioned function 1 (i.e., initial key allocation function). It should be understood that in this method, the key tool 200 may be the first key tool. The method may include the following steps:
[0222]
[0242] S301: The key tool 200 determines the initial key for the vehicle 100.
[0223]
[0243] The initial key may be used to generate a shared key, which may be used to encrypt data including geographic location information.
[0224]
[0244] The geographic location data may include data related to one or more of the following: longitude and latitude, altitude, and geographic track. For example, the geolocation data may include data whose longitude and latitude data range and / or altitude data range are within a preset threshold range. The geolocation data may also be data related to a geographic location. This is not particularly limited in the embodiments of the present application. Altitude is the height of a point relative to a reference surface, for example, the height of the top of a vehicle relative to the ground. Correspondingly, altitude data includes data reflecting the height of a point relative to a reference surface, for example, the height of the top of a vehicle relative to the ground.
[0225]
[0245] There are multiple implementations in which the key tool 200 determines the initial key for the vehicle 100, including but not limited to the following methods.
[0226]
[0246] Method 1: The key tool 200 pre-stores the initial key of the vehicle 100, and the key tool 200 can locally query and determine the initial key of the vehicle 100 based on the type information of the vehicle 100.
[0227]
[0247] For example, continue to refer to FIG. 2. When allocating key tool 200 to an OEM associated with vehicle 100, the entitlement management authority may store an initial key corresponding to vehicle 100 in an internal storage area of key tool 200. Key tool 200 may then locally query the initial key for vehicle 100 based on the type information of vehicle 100. In embodiments of the present application, an OEM associated with a vehicle may perform one or more of the following functions: developing a vehicle, integrating a vehicle, and producing a vehicle. Alternatively, an OEM associated with a vehicle may implement another function related to the vehicle. This is not particularly limited in embodiments of the present application.
[0228]
[0248] In Method 1, the key tool 200 can quickly determine the initial key for the vehicle 100. This helps improve the efficiency of initial key allocation.
[0229]
[0249] Method 2: The key tool 200 may request an initial key from the key management system.
[0230]
[0250] In an optional design of Method 2, the key tool 200 may be assigned to an OEM by a Certification Management Authority, but the Certification Management Authority does not pre-store the initial key in the key tool 200 .
[0231]
[0251] Example 1: Figure 4 is a schematic flow chart of the key tool 200 obtaining an initial key from a key management system in Method 2. The process includes the following steps:
[0232]
[0252] S3011: The key tool 200 generates a second public key and a second private key.
[0233]
[0253] In a possible implementation, the key tool 200 can generate the second public key and the second private key according to an asymmetric key algorithm. The asymmetric encryption algorithm may be an SM2 algorithm, an RSA algorithm, or the like. This is not particularly limited in the embodiments of the present application. In this way, the key tool 200 does not need to share the same key information with the key management system in advance. This simplifies the initial key allocation process.
[0234]
[0254] S3012: The key tool 200 sends the request information to the key management system. In response, the key management system receives the request information.
[0235]
[0255] The request information may request an initial key, and the request information includes the second public key. The key management system may then execute S3013 in response to the request information.
[0236]
[0256] S3013: The key management system generates a second ciphertext based on the second public key.
[0237]
[0257] In a possible implementation, the key management system may encrypt the initial key of the vehicle 100 using the second public key to obtain a second ciphertext.
[0238]
[0258] S3014: The key management system sends the second ciphertext. In response, the key tool 200 receives the second ciphertext.
[0239]
[0259] S3015: The key tool 200 determines an initial key based on the second ciphertext and the second private key.
[0240]
[0261] The second ciphertext contains information obtained by encrypting the initial key with the second public key, so that the key tool 200 can decrypt the second ciphertext with the second private key to obtain the initial key.
[0241]
[0261] Example 2: Key tool 200 sends request information to the key management system. The request information may request an initial key, and the request information includes a preset key. Then, the key management system receives the request information and, in response to the request information, encrypts the initial key of vehicle 100 based on the preset key information to obtain a second ciphertext. The key management system sends the second ciphertext to key tool 200, and key tool 200 determines the initial key based on the second ciphertext and the preset key. In this way, key tool 200 does not need to generate a temporary key. This reduces the implementation complexity of key tool 200.
[0242]
[0262] In Method 2, the key tool 200 can request the initial key from the key management system in real time, and the key management system can encrypt the initial key and send it to the key tool 200. This effectively improves real-time performance and the security of the initial key.
[0243]
[0263] It should be understood that the key management system may be deployed in a qualification management organization or in the management system of an OEM, which is not particularly limited in the embodiments of the present application.
[0244]
[0264] Method 3: The key tool 200 generates an initial key for the vehicle 100.
[0245]
[0265] For example, the key tool 200 can generate an initial key for the vehicle 100 based on information about the vehicle 100. The key tool 200 can generate the initial key for the vehicle 100 randomly or according to a specific rule, which is not particularly limited in the embodiments of the present application.
[0246]
[0266] In Method 3, the key tool 200 can generate the initial key for the vehicle 100 in real time, which can effectively guarantee the real-time performance of the initial key.
[0247]
[0267] S302: The key tool 200 transmits a first command to the first component 101 of the vehicle 100. In response, the first component 101 receives the first command.
[0248]
[0268] The first instruction may include first information related to an initial key, such that the first instruction can be used to redeem the initial key for the first component 101.
[0249]
[0269] In an optional design, before S302, the key tool 200 sends a key fill command to the first component 101. The key fill command may be used to trigger the fill of an initial key.
[0250]
[0270] S303: The first component 101 obtains the initial key according to the first command.
[0251]
[0271] It should be understood that the process in which the first component 101 obtains the initial key according to the first instruction is a process in which the first component 101 obtains the initial key based on the first information. The process in which the first component 101 determines the initial key based on the first information may be used as part or all of the initial key allocation process. In an optional implementation, the first component 101 obtains the initial key based on the first information, and the initial key allocation is completed. In another optional implementation, after obtaining the initial key, the first component 101 further activates a hardware security module (HSM) to locally store the initial key, and the initial key allocation is completed.
[0252]
[0272] The first information may be implemented in multiple ways. Accordingly, multiple implementations in which the first component 101 obtains the initial key based on the first information include, but are not limited to, the following methods:
[0253]
[0273] Method 1: The first information includes a first ciphertext. The first ciphertext includes information obtained by encrypting an initial key with a first public key. The first component 101 can obtain the initial key based on the first ciphertext. In other words, the key tool 200 can transmit the ciphertext of the initial key (i.e., the first ciphertext) to the first component 101. The key tool 200 can request the initial key from the key management system (see FIG. 2 for a description of the specific process).
[0254]
[0274] For example, Figure 5 is a schematic flowchart of the encryption and transmission of the initial key in Method 1. The process includes the following steps:
[0255]
[0275] S3021: The first component 101 generates a first public key and a first private key.
[0256]
[0276] In a possible implementation, the first component 101 can call the HSM to generate a first public key and a first private key. The algorithm used to generate the first public key and the first private key is not particularly limited in the embodiments of the present application. For example, the algorithm may be an asymmetric encryption algorithm (e.g., SM2 algorithm, RSA algorithm) or other algorithms.
[0257]
[0277] S3022: The first component 101 sends the first public key to the key tool 200. In response, the key tool 200 receives the first public key.
[0258]
[0278] Alternatively, the first component 101 may send the first public key encrypted by using a preset key to the key tool 200. For example, the preset key may be an authentication key or another key shared between the first component and the key tool 200. This effectively improves the transmission security of the first public key. Furthermore, the transmission security of the first ciphertext that is subsequently obtained by using the first public key is effectively improved.
[0259]
[0279] S3023: The key tool 200 obtains a first ciphertext based on the first public key and the initial key.
[0260]
[0280] In a possible implementation, the key tool 200 may encrypt an initial key based on a first public key to generate a first ciphertext.
[0261]
[0281] S3024: The key tool 200 transmits the first ciphertext. In response, the first component 101 receives the first ciphertext.
[0262]
[0282] S3025: The first component 101 obtains an initial key based on the first ciphertext and the first private key.
[0263]
[0283] In a possible implementation, the first component 101 may decrypt the first ciphertext by using the first private key to obtain the initial key.
[0264]
[0284] Furthermore, after obtaining the initial key, the first component 101 may further invoke the HSM, so that the HSM encrypts the initial key based on the local authentication key of the first component 101 and stores the encrypted initial key in the internal storage space of the first component 101, or may directly store the initial key in the internal storage space of the first component 101 to redeem the initial key.
[0265]
[0285] It should be understood that in embodiments of the present application, the authentication key may be managed and maintained by the OEM and used to authenticate functional keys developed by the OEM or component suppliers. The authentication key may correspond to all vehicles within a vehicle type, or to an entire vehicle, or to functional components within an entire vehicle, or to an ECU within an entire vehicle.
[0266]
[0286] For example, the authentication key may be a master ECU key (MEK), a pre-master ECU key (PMEK) (also called an ECU initial hardware authorization key), or a root key. This is not particularly limited in the embodiments of the present application. The root key is a pre-configured key transferred by the OEM to a component supplier. The component supplier assigns the preset key to components in a vehicle. The entire vehicle production line can assign functional keys to components in the vehicle according to the authentication and authorization of the preset key.
[0267]
[0287] Functional keys, also known as service keys, may be used to encrypt ECU keys for various functions throughout the vehicle. For example, functional keys may include, but are not limited to, pre-shared keys (PSKs), master keys (MKs) used for service applications, and session keys (SKs). PSKs may include security onboard communication (SecOC) keys used to secure onboard network communications and device keys used for device authentication.
[0268]
[0288] In Method 1, the key tool 200 transmits the ciphertext of the initial key to the first component 101. This can ensure the security of the transmission of the initial key.
[0269]
[0289] Optionally, the first component 101 may further directly store the first ciphertext in its internal storage space and decrypt the first ciphertext to obtain the initial key when the initial key needs to be used.
[0270]
[0290] Method 2: The first information includes an initial key. In other words, the key tool 200 may transmit the initial key to the first component 101.
[0271]
[0291] Correspondingly, the process by which the key tool 200 sends the first command to the first component 101 of the vehicle 100 may be as follows: the key tool 200 sends the initial key to the first component 101 in a wired manner. The key tool 200 and the first component 101 may be connected in a wired manner via a network cable, a data cable, etc. This is not particularly limited in the embodiments of the present application.
[0272]
[0292] In Method 2, the key tool 200 can directly transmit the initial key to the first component 101 in the vehicle 100, so that the first component 101 can quickly obtain the initial key. In addition, in the wired connection method, the first component 101 can directly receive the initial key, and the first component 101 does not need to perform encryption / decryption processing. Therefore, even a first component 101 that does not have encryption / decryption capabilities can obtain the initial key, ensuring the security of communications between different components. Furthermore, obtaining the initial key in this manner simplifies the operation of the first component 101 and reduces the implementation complexity and cost of the first component 101.
[0273]
[0293] 3 , the initial key is independent of the OEM associated with the vehicle 100, the component supplier, the OEM associated with the vehicle 100, or the OEM without a navigation electronic map creation qualification (the OEM in this case may be associated with the vehicle 100). In other words, the entire initial key transmission process does not require the participation of the OEM associated with the vehicle 100 or the OEM without a navigation electronic map creation qualification. As a result, the initial key is invisible to the OEM or the OEM without a navigation electronic map creation qualification. This can effectively improve the key transmission security, thereby preventing other devices from obtaining the shared key generated based on the initial key, effectively improving the security performance of communication between components of the vehicle 100 and protecting data associated with the components.
[0274]
[0294] Optionally, please further refer to Fig. 3. The key transmission method provided in the embodiment of the present application may further include step S304. Step S304 is specifically as follows:
[0275]
[0295] S304: The first component 101 sends the first response information. In response, the key tool 200 receives the first response information.
[0276]
[0296] It should be understood that the first response information is response information sent by the first component 101 in response to the first command received from the key tool 200. The first response information may include an initial key fill result. The initial key fill result may indicate that the initial key was successfully filled or that the initial key failed to be filled.
[0277]
[0297] In a possible implementation, the first instruction may include a first random number. Thus, after receiving the first instruction, the first component 101 may obtain a third ciphertext based on the initial key and the first random number. For example, to obtain the third ciphertext, the first random number may be encrypted using the initial key or a derived key of the initial key.
[0278]
[0298] Correspondingly, for example, the initial key validity result may include a first identifier, the first identifier indicating that the initial key has been successfully valid, and / or a third cryptogram. It will be appreciated that different information included in the initial key validity result indicates different scenarios in which key tool 200 determines that the initial key has been successfully valid.
[0279]
[0299] Scenario 1
[0300] If the initial key validity result received by key tool 200 includes the first identifier, key tool 200 considers the initial key to be successfully valid.
[0280]
[0301] Scenario 2
[0302] If the initial key redemption result received by key tool 200 includes a third ciphertext, key tool 200 can determine whether the initial key was successfully redeemed based on the third ciphertext.
[0281]
[0303] There are multiple implementations in which the key tool 200 determines whether the initial key has been successfully redeemed based on the third ciphertext, including but not limited to the following methods.
[0282]
[0304] Method 1: After receiving the third ciphertext, key tool 200 may obtain a second random number based on the initial key and the third ciphertext. For example, key tool 200 may use the initial key to decrypt the third ciphertext to obtain a second random number and compare the second random number with the first random number included in the first instruction. If the value of the first random number is the same as the value of the second random number, key tool 200 determines that the initial key has been successfully redeemed. If the value of the first random number is different from the value of the second random number, key tool 200 determines that the initial key has not been redeemed.
[0283]
[0305] Method 2: The key tool 200 may obtain local verification information based on the local initial key and the first random number. For example, the key tool 200 may use the local initial key to encrypt the first random number included in the first instruction to obtain ciphertext 1 (i.e., local verification information) and compare the third ciphertext with ciphertext 1. If the value of the third ciphertext is the same as the value of ciphertext 1, the key tool 200 determines that the initial key has been successfully redeemed. If the value of the third ciphertext is different from the value of ciphertext 1, the key tool 200 determines that the initial key has not been successfully redeemed. Optionally, after receiving the third ciphertext, the key tool 200 may determine the local verification information based on the local initial key and the first random number.
[0284]
[0306] Scenario 3
[0307] If the initial key redemption result received by key tool 200 includes the first identifier and the third ciphertext, key tool 200 needs to again determine whether the initial key was successfully redeemed based on the third ciphertext.
[0285]
[0308] It should be understood that in some embodiments, after the first component 101 receives the first instruction, the initial key seed 2 obtained and stored based on the first information in the first instruction may not be stored completely. As a result, the initial key seed 2 stored in the first component 101 differs from the seed 1 to be redeemed by the key tool 200. Therefore, even if the initial key redemption result received by the key tool 200 includes the first identifier, the key tool 200 still needs to re-determine whether the initial key has been successfully redeemed based on the third ciphertext.
[0286]
[0309] A specific implementation in which the key tool 200 again determines whether the initial key has been successfully allocated based on the third ciphertext is similar to the specific implementation in which the key tool 200 determines whether the initial key has been successfully allocated based on the third ciphertext in Scenario 2, so please refer to the above description and will not be described in detail again here.
[0287]
[0310] As another example, the initial key redemption result may include a second identifier. The second identifier may indicate that the initial key failed to redeem. Optionally, the second identifier may further indicate the reason why the initial key failed to redeem, for example, that an HSM in the first component 101 failed to decrypt the first ciphertext or that the first component 101 has insufficient storage space.
[0288]
[0311] Optionally, the initial key redemption result may further include an identifier of the vehicle 100 and / or an identifier of the first component 101. Correspondingly, the key tool 200 may count and store the redemption status of the initial key based on the identifier of the vehicle 100 and / or the identifier of the first component 101.
[0289]
[0312] To ensure that the initial key is successfully allocated, if the initial key validity result indicates that the initial key failed to be allocated, the key tool 200 may resend the first command to the first component 101. Optionally, if the number of times the first command is sent exceeds a preset threshold, the key tool 200 stops sending the first command to the first component 101. In this implementation, the validity of the initial key allocation can be guaranteed.
[0290]
[0313] In a possible implementation, if the initial key validity result indicates that the initial key was successfully filled, the key tool 200 can send a second instruction to the first component 101. The second instruction is used to fill a shared key for the first component 101.
[0291]
[0314] The process by which the keytool 200 appropriates the shared key of the first component 101 will now be described with reference to a specific example.
[0292]
[0315] For example, see Figure 6. In Figure 6, key tool 200 has function 2 described above, i.e., key tool 200 has function 2 (i.e., shared key allocation function) described above. It should be understood that in this scheme, key tool 200 can be a first key tool or a second key tool.
[0293]
[0316] The process by which the key tool 200 allocates a shared key for the first component 101 includes the following steps.
[0294]
[0317] S601: The key tool 200 sends a second instruction, and in response, the first component 101 receives the second instruction.
[0295]
[0318] The second instructions include second information associated with the shared key.
[0296]
[0319] S602: The first component 101 determines a shared key based on the second information and the initial key.
[0297]
[0320] It should be understood that the process by which the first component 101 determines the shared key based on the second information and the initial key may be part or all of the shared key allocation process. In an optional embodiment, the first component 101 determines the shared key based on the second information and the initial key, and allocation of the shared key is complete. In an optional implementation, after determining the shared key, the first component 101 activates the HSM to store the shared key locally, and allocation of the shared key is complete.
[0298]
[0321] The second information may be implemented in multiple ways. Correspondingly, there are multiple implementations in which the first component 101 determines the shared key based on the second information and the initial key, including but not limited to the following:
[0299]
[0322] Method 1: The second information is keying material (e.g., salt), and the first component 101 can generate a shared key based on the second information and the initial key after receiving the second command.
[0300]
[0323] In a possible implementation, the process by which the first component 101 obtains a shared key based on an initial key and the second information may be: obtaining a shared key based on the initial key and the second information according to a symmetric encryption algorithm, or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0301]
[0324] For example, the first component 101 can obtain the shared key according to the following formula:
[0302] KEK=ENC(salt,seed)
[0325] Here, KEK is a shared key, salt is an example of keying material, seed is an initial key, and ENC is any symmetric encryption algorithm, key derivation function, or message authentication code based on a symmetric encryption algorithm. A symmetric encryption algorithm uses a single key, and both the sender and receiver use that key to encrypt and decrypt data. Symmetric encryption algorithms may include, but are not limited to, the DES algorithm, the 3DES algorithm, the SM1 algorithm, and the SM4 algorithm. A message authentication code (MAC) is a technique used to verify integrity and perform authentication. A key derivation function is a function used to derive key data from a shared key bit string. Key derivation functions include, but are not limited to, a password-based key derivation function (PBKDF) and the scrypt algorithm. In the embodiments of the present application, the symmetric encryption algorithm and key derivation function are not particularly limited.
[0303]
[0326] In Method 1, the first component 101 can generate the shared key, which effectively improves the security of the shared key redemption.
[0304]
[0327] Method 2: The second information is a ciphertext of the shared key.
[0305]
[0328] In a possible implementation, the shared key is generated by the key tool 200, and the key tool 200 can obtain the second information based on the initial key and the shared key. For example, the key tool 200 may encrypt the shared key using the initial key to obtain the second information. Correspondingly, the first component 101 may obtain the shared key based on the initial key and the second information after receiving the second instruction. For example, to obtain the shared key, the first component 101 may decrypt the second information using the initial key.
[0306]
[0329] The algorithm used by the key tool 200 in the process of encrypting the shared key based on the initial key may be a symmetric encryption algorithm or a key derivation function, which is not particularly limited in the embodiments of the present application. For the symmetric encryption algorithm and the key derivation function, please refer to the above description of the symmetric encryption algorithm and the key derivation function. The details will not be described again here.
[0307]
[0330] In Method 2, the second information includes a ciphertext of the shared key, and the ciphertext is information obtained by encrypting the shared key with an initial key. The first component 101 can obtain the shared key by decrypting the ciphertext with the initial key. However, other devices that do not have the initial key cannot restore the shared key even if they receive the ciphertext. This effectively improves the security of the shared key of the first component. Furthermore, Method 2 has low requirements on the algorithm of the first component 101. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the complexity and cost of implementing the first component.
[0308]
[0331] S603: The first component 101 sends the second response information. In response, the key tool 200 receives the second response information.
[0309]
[0332] It should be understood that the second response information is response information sent by the first component 101 in response to the second command received from the key tool 200. The second response information includes a shared key validity result. The shared key validity result may indicate that the initial key was successfully valid or that the initial key failed to be valid.
[0310]
[0333] In a possible implementation, the second instruction may include a third random number. Thus, after receiving the second instruction, the first component 101 may obtain a fourth ciphertext by using the third random number and the shared key or a derivative of the shared key. For example, to obtain the fourth ciphertext, the third random number is encrypted by using the shared key or a derivative of the shared key.
[0311]
[0334] Correspondingly, in a possible implementation, the shared key redemption result may include a third identifier, indicating that the shared key has been successfully redeemed; and / or a fourth cryptogram. It will be appreciated that different information included in the shared key redemption result indicates different scenarios in which the key discovery tool 200 determines that the shared key has been successfully redeemed.
[0312]
[0335] Scenario 1
[0336] If the shared key redemption result received by key tool 200 includes the third identifier, key tool 200 considers the shared key to be successfully redeemed.
[0313]
[0337] Scenario 2
[0338] If the shared key redemption result received by key tool 200 includes a fourth ciphertext, key tool 200 can determine whether the shared key was successfully redeemed based on the fourth ciphertext.
[0314]
[0339] There are multiple implementations in which the key tool 200 determines whether the shared key has been successfully redeemed based on the fourth ciphertext, including but not limited to the following methods.
[0315]
[0340] Method 1: After receiving the fourth ciphertext, key tool 200 may obtain a fourth random number based on the shared key and the fourth ciphertext. For example, to obtain the fourth random number, the fourth ciphertext is decrypted using the shared key. Key tool 200 compares the fourth random number with the third random number included in the second instruction. If the value of the third random number is the same as the value of the fourth random number, key tool 200 determines that the shared key was successfully loaded. If the value of the third random number is different from the value of the fourth random number, key tool 200 determines that the shared key was not successfully loaded.
[0316]
[0341] Method 2: After receiving the fourth ciphertext, key tool 200 may obtain a local verification message based on the local shared key and the third random number. For example, key tool 200 encrypts the third random number using the local shared key to obtain ciphertext 2 (i.e., local verification information), and compares the fourth ciphertext with ciphertext 2. If the value of the fourth ciphertext is the same as the value of ciphertext 2, key tool 200 determines that the shared key has been successfully redeemed. If the value of the fourth ciphertext is different from the value of ciphertext 2, key tool 200 determines that the shared key has not been redeemed.
[0317]
[0342] Scenario 3
[0343] If the shared key redemption result received by key tool 200 includes the third identifier and the fourth ciphertext, key tool 200 needs to re-determine whether the shared key has been successfully redeemed based on the fourth ciphertext. It should be understood that in some embodiments, after first component 101 receives the second instruction, the shared key KEY2 obtained and stored based on the first information in the second instruction may not be stored completely. As a result, the shared key KEY2 stored in first component 101 differs from KEY1 to be redeemed by key tool 200. Therefore, even if the shared key redemption result received by key tool 200 includes the first identifier, key tool 200 still needs to re-determine whether the shared key has been successfully redeemed based on the fourth ciphertext.
[0318]
[0344] A specific implementation in which the key tool 200 again determines whether the shared key has been successfully allocated based on the fourth ciphertext is similar to the specific implementation in which the key tool 200 determines whether the shared key has been successfully allocated based on the fourth ciphertext in scenario 2, so please refer to the above description and will not be described in detail again here.
[0319]
[0345] In another possible implementation, the shared key redemption result may include a fourth identifier. The fourth identifier may indicate that the shared key failed to redeem. Optionally, the second identifier may further indicate the reason why the shared key failed to redeem, for example, that the HSM in the first component 101 failed the first decryption or that the first component 101 has insufficient storage space.
[0320]
[0346] Optionally, the shared key redemption result may further include the vehicle identifier and / or the identifier of the first component 101. Correspondingly, the key tool 200 may count and store the redemption status of the shared key based on the vehicle 100 identifier and / or the first component 101 identifier.
[0321]
[0347] In a possible implementation, if the shared key validity result indicates that the shared key failed to be redeemed, the key tool 200 may resend the second command. Optionally, if the number of times the key tool 200 sends the second command exceeds a preset threshold, the key tool 200 stops sending the second command to the first component 101. In this implementation, the validity of the shared key redemption can be guaranteed.
[0322]
[0348] 6, the key tool 200 can appropriate the shared key for the first component 101. This effectively increases the security of the shared key for the first component 101.
[0323]
[0349] It should be noted that in some embodiments, the second component 102 in the vehicle 100 may alternatively appropriate the shared key for the first component 101 .
[0324]
[0350] For example, Figure 7 is a schematic flow chart of a second component 102 redeeming a shared key for a first component 101. The process includes the following steps:
[0325]
[0351] S701: The second component 102 obtains a shared key filling instruction. Obtaining may be understood as receiving or generating.
[0326]
[0352] The shared key allocation command includes information related to the shared key. Therefore, the shared key allocation command can be used to allocate a shared key for the first component 101. The shared key is used to encrypt data including at least geographic location information. For a specific description of the shared key and geographic location information data, please refer to the related description above.
[0327]
[0353] S702: The second component 102 transmits a shared key allocation command, and in response, the first component 101 receives the shared key allocation command.
[0328]
[0354] The shared key allocation instruction may be implemented in multiple ways, including but not limited to the following implementations:
[0329]
[0355] Implementation 1: The shared key fill instruction may include a second instruction. For example, the shared key fill instruction is the second instruction. In another example, the shared key fill instruction includes other information in addition to the second instruction. The second instruction includes second information associated with the shared key.
[0330]
[0356] For example, the second component 102 determining the shared key filling instruction may be as follows: the second component 102 receives the second instruction from the key tool 200 and uses the second instruction as the shared key filling instruction. Correspondingly, the second component 102 may directly forward the first instruction from the key tool 200 to the first component 101.
[0331]
[0357] In Implementation 1, the second component directly transfers the second command from the key tool 200 to the first component to allocate the shared key of the first component. In this way, the operation procedure of the second component 102 can be simplified, and the implementation is simple. In addition, the first component 101 does not need to obtain the shared key allocation command from the key tool 200, which effectively improves the efficiency of allocating the shared key.
[0332]
[0358] The second information may be implemented in multiple ways. For example, key tool 200 may generate keying material (e.g., the keying material may be generated randomly or according to a specific rule) and use the keying material as the second information in the second instruction. As another example, key tool 200 may generate a shared key (e.g., the shared key may be generated randomly or according to a specific rule), obtain a ciphertext of the shared key based on the initial key and the shared key, and use the ciphertext as the second information. As yet another example, key tool 200 may encrypt the shared key using the initial key, obtain a ciphertext of the shared key, and use the ciphertext as the second information.
[0333]
[0359] Implementation 2: The shared key fill instruction may include a third instruction. For example, the shared key fill instruction is the third instruction. As another example, the shared key fill instruction includes other information in addition to the third instruction. The third instruction includes third information associated with the shared key.
[0334]
[0360] The third instruction may be implemented in multiple ways, including but not limited to the following implementations.
[0335]
[0361] Method 1: The second component 102 receives a second instruction from the key tool 200 and processes the second instruction to obtain a third instruction.
[0336]
[0362] For example, the second component 102 may convert the communication protocol format of the second instructions to obtain the third instructions, or the second component 102 may convert the communication protocol format of the second information included in the second instructions to obtain the third information included in the third instructions.
[0337]
[0363] Correspondingly, the second component 102 can receive the second instruction sent by the key tool 200 and then obtain the third instruction by processing the second instruction. The second instruction includes second information associated with the shared key. The second information may be implemented in multiple ways. For details, please refer to the implementation of the second information in Implementation 1. The details will not be described again here.
[0338]
[0364] In Method 1, the third instruction or the third information included in the third instruction can better fit the communication protocol between the first component and the second component 102. The first component 101 can allocate the shared key according to the instruction (i.e., the third instruction). The first component does not need to obtain the shared key allocation instruction from the key tool 200, which effectively improves the efficiency of allocating the shared key.
[0339]
[0365] Method 2: The second component 102 generates a third instruction.
[0340]
[0366] For example, if a preset condition is met or if a specific command is received, the second component 102 may generate a third command and use the third command as a shared key redemption command.
[0341]
[0367] The "specific command" can be any command that the second component can use as a trigger signal. For example, the specific command can be a diagnostic command specifically used to generate a shared key redemption command, or it can be a diagnostic command for other functions, such as a component flash or component reset command. In an optional design, the specific command can come from a diagnostic device, a whole-vehicle electrical inspection test device, the cloud, or another component in the vehicle (e.g., a TBOX or GW).
[0342]
[0368] The pre-set condition may include, but is not limited to, a device associated with the second component being started and reaching a particular point in time.
[0343]
[0369] It can be understood that "a device associated with the second component is started" may mean that the second component is started, or that the device on which the second component is located is started. For example, the second component is A. In this case, when A is started or the device on which A is located is started, A can generate the third instruction. As another example, the second component is B. In this case, when B is started or the device on which B is located is started, B can generate the third instruction.
[0344]
[0370] It can be understood that "reaching a specific point in time" may mean reaching a specific key expiration point (e.g., 00:00 on the first day of each month) or reaching a predetermined day before key expiration (e.g., the day before key expiration).
[0345]
[0371] Correspondingly, in Method 2, the third information may be implemented in multiple ways. For example, the second component may generate keying material (e.g., the keying material is generated randomly or according to a specific rule) and use the keying material as the third information in the third instruction. As another example, the second component may generate a shared key (e.g., the shared key is generated randomly or according to a specific rule), obtain a ciphertext of the shared key based on the initial key and the shared key, and use the ciphertext as the third information.
[0346]
[0372] In Method 2, the second component can generate a shared key allocation command to allocate a shared key for another component (i.e., the first component) in the vehicle. In this way, allocation of the shared key no longer depends on the first key tool or the second key tool. This simplifies the shared key allocation procedure.
[0347]
[0373] S703: The first component 101 determines a shared key according to the shared key allocation command and the initial key.
[0348]
[0374] In a possible implementation, the shared key allocation instruction may be a second instruction. The second instruction includes second information associated with the shared key. Therefore, the first component 101 may determine the shared key based on the second information and the initial key. For an implementation in which the first component 101 determines the shared key based on the second information and the initial key, please refer to the related description above. Details will not be described again here.
[0349]
[0375] In another possible implementation, the shared key allocation instruction may be a third instruction. The third instruction includes third information associated with the shared key. Thus, the first component 101 may determine the shared key based on the third information and the initial key. There are multiple implementations in which the first component 101 determines the shared key based on the third information and the initial key, including, but not limited to, the following methods:
[0350]
[0376] Method 1: The third information is keying material (e.g., salt), and the first component 101 can generate a shared key based on the third information and the initial key after receiving the third command.
[0351]
[0377] In a possible implementation, the process by which the first component 101 obtains a shared key based on the initial key and the third information may be: obtaining a shared key based on the initial key and the third information according to a symmetric encryption algorithm, or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0352]
[0378] For example, the first component 101 can obtain the shared key according to the following formula:
[0353] KEK=ENC(salt,seed)
[0379] Here, KEK is a shared key, salt is an example of keying material, seed is an initial key, and ENC is any symmetric encryption algorithm, key derivation function, or message authentication code based on a symmetric encryption algorithm. For details of symmetric encryption algorithms, message authentication codes based on symmetric encryption algorithms, and key derivation functions, please refer to the above descriptions of symmetric encryption algorithms and key derivation functions. The details will not be described again here.
[0354]
[0380] In Method 1, the first component 101 can generate the shared key, which effectively improves the security of the shared key redemption.
[0355]
[0381] Method 2: The third information is the ciphertext of the shared key.
[0356]
[0382] In a possible implementation, the shared key is generated by the key tool 200, and the key tool 200 can obtain the third information based on the initial key and the shared key. For example, the key tool 200 may encrypt the shared key using the initial key to obtain the third information. Correspondingly, the first component 101 may obtain the shared key based on the initial key and the third information after receiving the third command. For example, to obtain the shared key, the key tool 200 may decrypt the third information using the initial key. The algorithm used by the key tool 200 in the process of encrypting the shared key based on the initial key may be a symmetric encryption algorithm or a key derivation function. This is not particularly limited in the embodiments of the present application. For the symmetric encryption algorithm and the key derivation function, please refer to the above description of the symmetric encryption algorithm and the key derivation function. The details will not be described again here.
[0357]
[0383] In Method 2, the third information includes a ciphertext of the shared key, and the ciphertext is information obtained by encrypting the shared key with an initial key. The first component 101 can obtain the shared key by decrypting the ciphertext with the initial key. However, other devices that do not have the initial key cannot restore the shared key even if they receive the ciphertext. This effectively improves the security of the shared key of the first component. Furthermore, Method 2 has low requirements on the algorithm of the first component 101. For example, as long as the first component supports some decryption algorithm, the shared key can be obtained. This reduces the complexity and cost of implementing the first component.
[0358]
[0384] S704: The first component 101 transmits response information in response to the shared key allocation command.
[0359]
[0385] In a possible implementation, the shared key allocation command is a second command, and the response information responsive to the shared key allocation command includes second response information responsive to the second command. For a description of the second response information, please refer to the related description above. The details will not be described again here.
[0360]
[0386] In another possible implementation, the shared key allocation command may be the third command, and the response information responsive to the shared key allocation command includes third response information responsive to the third command. The specific implementation of the third response information is similar to the implementation of the second response information, and refer to the above description of the second response information. Details that only require the second response information to be replaced with the third response information will not be described again here.
[0361]
[0387] There are multiple implementations in which the first component 101 sends the third response information, including but not limited to the following implementations.
[0362]
[0388] Implementation 1: The first component 101 sends the third response information to the second component 102, and the second component 102 receives the third response information and forwards the third response information to the key tool 200. In this implementation, the first component 101 does not need to interact with the key tool, and can use the second component 102 to feed back the validity result of the shared key to the key tool 200.
[0363]
[0389] Implementation 2: The first component 101 can send third response information to the second component 102, and the second component 102 can receive the third response information and perform corresponding processing on the third response information.
[0364]
[0390] Case 1: The process by which the second component 102 processes the third response information may be as follows: convert the protocol format of the third response information, so that the processed protocol format of the third response information is adapted to the communication protocol between the second component 102 and the key tool 200.
[0365]
[0391] Case 2: The process of the second component 102 processing the third response information may be as follows: determine the key allocation status of the first component 101 based on the third response information. For example, verify whether the shared key of the first component 101 has been successfully allocated based on the identification information included in the third response information. Then, the second component 102 can send the allocation results of the shared keys of all components in the vehicle 100 to the key tool 200. In this way, the amount of calculation of the key tool 200 can be reduced, and as a result, the key tool 200 can quickly grasp the allocation status of the shared key.
[0366]
[0392] Implementation 3: The first component 101 may send the third response information directly to the key tool 200. In this implementation, the first component 101 interacts with the key tool 200, and the key tool 200 can quickly determine the redemption status of the shared key of the first component 101.
[0367]
[0393] 7, the second component 102 redeems the shared key of the first component 101, so that the first component 101 does not need to obtain a shared key redemption command from the key tool 200. This effectively improves the efficiency of redeeming the shared key of the components in the vehicle.
[0368]
[0394] It will be understood that in a possible embodiment, after receiving the second instruction from the key tool 200, the second component 102 may alternatively obtain a shared key based on the initial key and the second information, and redeem the shared key of the second component 102. The implementation of "the second component 102 obtains a shared key based on the initial key and the second information" is similar to the implementation of "the first component 101 obtains a shared key based on the initial key and the second information." For the implementation of "the first component 101 obtains a shared key based on the initial key and the second information," please refer to the related description above.
[0369]
[0395] It will be understood that in a possible embodiment, the second component 102 can receive a first instruction from the key tool 200, in which the first instruction includes first information associated with the initial key; and the second component can obtain the initial key according to the first instruction. The implementation of "the second component 102 obtains the initial key according to the first instruction" is similar to the implementation of "the first component 101 and the second component 102 obtain the initial key according to the first instruction," and see the related description above. It just requires that "the first component 101" be replaced with "the second component 102."
[0370]
[0396] In an optional design, before sending the first instruction to the second component 102, the key tool 200 can also send a key fill instruction to the second component 102. The key fill instruction may be used to trigger the fill of an initial key.
[0397] In order to ensure the correct use of the shared key or initial key of the components in the vehicle, the embodiment of the present application further provides a key detection method, which will be described in detail below with reference to specific examples.
[0398] Embodiment 1 8 is a schematic flowchart corresponding to a key detection method according to an embodiment of the present application. For example, the method is performed by the key tool 200 and the first component 101 shown in FIG. 1. In FIG. 8, the key tool 200 has the above-mentioned function 3 (i.e., the function of detecting a key using a random number). It should be understood that in this method, the key tool 200 may be a key detection tool. The key detection method includes the following steps:
[0371]
[0399] S801: The key tool 200 sends a fourth command. In response, the first component 101 receives the fourth command.
[0372]
[0400] The fourth instruction is used to detect whether the shared key of the vehicle 100 is abnormal. The shared key is used to encrypt data including at least geographic location information. For the geographic location information data, please refer to the description of the geographic location information data above. Details will not be described again here.
[0373]
[0401] In a possible implementation, the fourth instruction includes a third random number.
[0374]
[0402] Optionally, before sending the fourth instruction, the key tool 200 may further execute S800, i.e., verify the identity of the first component 101 based on an identifier of the first component 101 or an identifier of the vehicle associated with the first component 101.
[0375]
[0403] For example, the key tool 200 may verify the identity of the first component 101 by using a security protocol with identity authentication capabilities, such as the transport layer security (TLS) protocol.
[0376]
[0404] S802: The first component 101 determines a first check value based on the third random number and the shared key.
[0377]
[0405] For example, the first component 101 may determine the first check value C according to the following formula:
[0378] C=ENC(Rand3,KEK)
[0406] Here, ENC is any symmetric encryption algorithm (e.g., SM4) or a message authentication code based on a symmetric encryption algorithm (e.g., a cipher-based message authentication code (CMAC)), Rand3 is a third random number, and KEK is a shared key for the vehicle. For the symmetric encryption algorithm, the message authentication code based on a symmetric encryption algorithm, and the key derivation function, please refer to the above description of the symmetric encryption algorithm, the message authentication code based on a symmetric encryption algorithm, and the key derivation function. The details will not be described again here.
[0379]
[0407] S803: The first component 101 sends the fourth response information. In response to this, the key tool 200 receives the fourth response information.
[0380]
[0408] The fourth response information includes a first check value that can be used to determine whether the shared key matches the local shared key of the key tool 200.
[0381]
[0409] S804: The key tool 200 determines whether the vehicle's shared key matches the local shared key corresponding to the vehicle based on the first check value.
[0382]
[0410] In one possible implementation, the process by which key tool 200 determines whether the vehicle's shared key matches the local shared key corresponding to the vehicle based on the first check value may be as follows: key tool 200 calculates a second check value based on the local shared key and a third random number and compares the first check value with the second check value. If the first check value matches the second check value, it is determined that the vehicle's local shared key stored in key tool 200 matches the vehicle's current shared key. If the first check value does not match the second check value, it is determined that the vehicle's local shared key stored in key tool 200 does not match the vehicle's current shared key. In this implementation, key tool 200 performs shared key abnormality detection by comparing the consistency between the second check value determined by key tool 200 and the first check value determined by the first component. This can improve the accuracy of key abnormality detection.
[0383]
[0411] For example, the key tool 200 may obtain the second check value according to the following formula: C'=ENC(Rand3,KEK1)
[0412] where C' is the second check value, ENC is any symmetric encryption algorithm (e.g., SM4) or a message authentication code based on a symmetric encryption algorithm (e.g., CMAC), Rand3 is a third random number, and KEK1 is a local shared key. For the symmetric encryption algorithm, the message authentication code based on a symmetric encryption algorithm, and the key derivation function, please refer to the above description of the symmetric encryption algorithm, the message authentication code based on a symmetric encryption algorithm, and the key derivation function. The details will not be described again here.
[0384]
[0413] In another possible implementation, the process by which key tool 200 determines whether the vehicle's shared key matches the local shared key corresponding to the vehicle based on the first check value may be as follows: key tool 200 may determine a fourth random number based on the received first check value and the local shared key, and then compare the fourth random number to determine whether it matches the third random number. If the third random number matches the fourth random number, the vehicle's local shared key stored in key tool 200 matches the vehicle's current shared key. If the third random number does not match the fourth random number, the vehicle's local shared key stored in key tool 200 does not match the vehicle's current shared key. In this implementation 2, key tool 200 performs shared key abnormality detection by comparing the consistency between the fourth random number determined by key tool 200 based on the first check value and the third random number. This can improve the accuracy of key abnormality detection.
[0385]
[0414] There are several implementations in which the key tool 200 obtains the local shared key, including but not limited to the following methods.
[0386]
[0415] Method 1: Obtain a vehicle identifier or an identifier of the first component 101. Based on the vehicle identifier or the identifier of the first component 101, query an initial key corresponding to the vehicle and keying material used to generate a local shared key. Generate a local shared key based on the initial key and keying material. In this way, the local shared key of the key discovery tool has high real-time performance.
[0387]
[0416] Method 2: Obtain the vehicle identifier or the identifier of the first component 101. Query the local shared key based on the vehicle identifier or the identifier of the first component 101. In this way, the key discovery tool can quickly obtain the local shared key, improving the efficiency of key discovery.
[0388]
[0417] S805: The key tool 200 reports abnormality information if the vehicle shared key does not match the local shared key.
[0389]
[0418] In a possible implementation, the key tool 200 may report the abnormality information to a certification authority, which is an organization that holds a surveying and mapping license and / or engages in surveying and mapping activities pursuant to law, or may report the abnormality information to a key management system.
[0390]
[0419] In the embodiment shown in FIG. 8, the key tool 200 performs communication interaction with the first component 101 in the vehicle to realize abnormality detection of the vehicle's shared key, resulting in more accurate abnormality detection of the vehicle's shared key.
[0391]
[0420] In a possible embodiment, if the shared key is applied to the first component 102 by using the second component 102, the key tool 200 may detect the initial key of the first component 101 or the initial key of the second component 102 when detecting the vehicle key.
[0421] Embodiment 2 The key tool 200 has the above-mentioned function 4 (i.e., the function of detecting a key using a communication information ciphertext). It should be understood that in this method, the key tool 200 may also be a key detection tool. In this method, the embodiment of the present application provides another key detection method. The method includes the following steps:
[0392]
[0422] A: The key tool 200 obtains the communication information ciphertext of the first component 101 of the vehicle.
[0393]
[0423] The communication information ciphertext includes information obtained by encrypting first information using the shared key of the vehicle 100. The first information includes geographical location information. For the data of the geographical location information, please refer to the description of the data of the geographical location information data. Details will not be described again here.
[0394]
[0424] B: Based on the local shared key of vehicle 100 stored in key tool 200 and the communication information ciphertext, key tool 200 determines whether the shared key currently being used by vehicle 100 matches the local shared key.
[0395]
[0425] The shared key of the vehicle 100 may be a shared key of all components in the vehicle 100, or may be a shared key of components associated with a functional domain in the vehicle 100. This is not limited to the embodiment of the present application.
[0396]
[0426] In a possible implementation, key tool 200 can obtain the vehicle's local shared key, decrypt the communication information ciphertext using the vehicle's local shared key, obtain the decrypted communication information, and determine whether the communication information is abnormal. If the communication information is abnormal, key tool 200 determines that the vehicle's shared key does not match the vehicle's local shared key. If the communication information is normal, key tool 200 determines that the vehicle's shared key matches the vehicle's local shared key.
[0397]
[0427] For example, the communication information is geographical location information. The current location of the vehicle to be detected is geographical location 1, and the geographical location information obtained by the key tool 200 by decrypting the obtained communication information ciphertext is geographical location 2. If geographical location 1 does not match geographical location 2, the shared key of the vehicle to be detected is determined to be inconsistent with the local shared key of the key tool 200, and abnormality information is reported. There are multiple cases in which geographical location 1 does not match geographical location 2. For example, there may be cases in which the longitude and latitude data of geographical location 1 do not match those of geographical location 2. Or, there may be cases in which the altitude data of geographical location 1 does not match those of geographical location 2.
[0398]
[0428] As another example, the communication information is geographical location information. The geographical location information acquired by the key tool 200 by decrypting the acquired communication information ciphertext is geographical location 2, and the longitude and latitude data range of geographical location 2 exceeds the preset threshold range. In this case, the shared key of the vehicle to be detected is determined to be inconsistent with the local shared key of the key tool 200, and abnormality information is reported.
[0399]
[0429] As another example, the communication information is geographical location information. The geographical location information acquired by the key tool 200 by decrypting the acquired communication information ciphertext is geographical location 2, and the altitude data range of geographical location 2 exceeds a preset threshold range. In this case, the shared key of the vehicle to be detected is determined to be inconsistent with the local shared key of the key tool 200, and abnormality information is reported. When the shared key of the vehicle is inconsistent with the local shared key, abnormality information is reported.
[0400]
[0430] The key tool 200 may report the abnormality information to the certificate management authority or may report it to the key management system, which is not particularly limited in the embodiment of the present application.
[0401]
[0431] In this embodiment, the key detection tool can automatically obtain the communication information ciphertext of the first component and perform anomaly detection of the vehicle shared key based on the communication information ciphertext, which is helpful to timely discover the anomaly of the vehicle key.
[0402]
[0432] In a possible embodiment, if the shared key is applied to the first component 102 by using the second component 101, the key tool 200 may detect the initial key of the first component 101 or may detect the initial key of the second component 102 when detecting the vehicle key.
[0403]
[0433] It should be noted that the initial key in the above embodiment is different from the authentication key, which is from the OEM associated with the vehicle. In some possible embodiments, the first component 101 can further determine at least one function key based on the authentication key. The at least one function key corresponds to at least one service function.
[0404]
[0434] In this manner, the first component may further determine a function key used to implement the service function of the first component based on the authentication key from the OEM. As a result, the service function of the first component is securely executed, effectively improving vehicle data security. According to this design, a service related to geographic location information can be implemented based on an initial key from the first key tool and a shared key generated using the initial key. A service unrelated to geographic location information can be implemented based on an authentication key from the OEM and a function key generated using the authentication key. In this manner, different keys can be used for services related to geographic location information and services unrelated to geographic location information, thereby further ensuring the transmission security of data related to geographic location information.
[0405]
[0435] The above describes the key transmission method and key detection method provided in the embodiment of the present application. The following describes the device in the embodiment of the present application.
[0406]
[0436] 9 is a schematic diagram of a possible configuration of a control device according to an embodiment of the present application. The device 900 can be configured to perform the functions of the first component 91.
[0407]
[0437] For example, device 900: a transceiver module 900 configured to receive a first instruction from a first key tool, the first instruction including first information associated with an initial key; and a processing module 902 configured to obtain an initial key according to a first instruction; wherein the initial key is used at least to generate a shared key, and the shared key is used at least to encrypt data including the geographic location information.
[0408]
[0438] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0409]
[0439] The shared key may be a shared key for all components in the vehicle, or may be a shared key for components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0410]
[0440] The initial key is not associated with the original equipment manufacturer (OEM) associated with the vehicle, or is not associated with the OEM or component supplier associated with the vehicle 100, or is not associated with an OEM that does not have a navigation electronic mapping qualification (the OEM in this case may be associated with the vehicle). In other words, the entire initial key transmission process does not require the participation of the OEM associated with the vehicle or an OEM that does not have a navigation electronic mapping qualification, so the initial key is invisible to the OEM or an OEM that does not have a navigation electronic mapping qualification. This can further improve key transmission security.
[0411] In this manner, services related to geographic location information can be implemented based on the initial key from the first key tool and the shared key generated using the initial key. Services not associated with geographic location information can be implemented based on the authentication key from the OEM and the functional key generated using the authentication key. Therefore, different keys can be used for services related to geographic location information and services not related to geographic location information, thereby further ensuring the transmission security of data related to geographic location information.
[0412]
[0441] In a possible implementation, the initial key is different from the authentication key, which is from an OEM associated with the vehicle. The processing module 902 may be further configured to determine at least one function key based on the authentication key. The at least one function key corresponds to at least one service function of the first component.
[0413]
[0442] The first information can be implemented in a number of ways, including but not limited to the following ways.
[0414]
[0443] Method 1: The first information includes a first ciphertext, and the first ciphertext includes information obtained by encrypting an initial key with a first public key of the first component. Correspondingly, the processing module 902 is further configured to decrypt the first ciphertext based on a first private key of the first component to obtain the initial key. The first private key corresponds to the first public key.
[0415]
[0444] Method 2: The first information includes an initial key. Correspondingly, the processing module 902 is further configured to obtain the initial key according to the first instruction in a wired connection manner.
[0416]
[0445] In one possible implementation, the transceiver module 901 is further configured to send first response information to the first key tool. The first response information includes an initial key validity result. The initial key validity result can indicate that the initial key was successfully valid or that the initial key failed to be valid.
[0417]
[0446] In a possible implementation, the initial key redemption result may include: a first identifier, the first identifier indicating that the initial key has been successfully redeemed; and / or a third ciphertext, the third ciphertext including information obtained by encrypting the first random number included in the first instruction with the initial key or a derivative key of the initial key. In this implementation, the initial key redemption result includes the first identifier and / or the third ciphertext, such that the first key tool can determine whether the initial key has been successfully redeemed based on the first identifier and / or the third ciphertext.
[0418]
[0447] In a possible implementation, the initial key redemption result may include a second identifier, which may indicate that the initial key failed to redeem.
[0419]
[0448] In a possible implementation, the initial key validity result may further include an identifier of the vehicle and / or an identifier of the first component.
[0420]
[0449] In one possible implementation, the transceiver module 901 is further configured to receive a second instruction from the first key tool or the second key tool. The second instruction includes second information associated with the shared key. The processing module 902 is further configured to obtain the shared key based on the initial key and the second information. The second instruction may be used to redeem the shared key for the first component.
[0421]
[0450] In a possible implementation, the first key tool and the second key tool may correspond to different key allocation environments. For specific examples and advantageous effects, please refer to the above description of the first key tool and the second key tool.
[0422]
[0451] In another possible implementation, the first key tool and the second key tool may alternatively correspond to different components within the vehicle. See the above description of the first key tool and the second key tool for specific examples and advantages.
[0423]
[0452] In another possible implementation, the first key tool and the second key tool may alternatively correspond to different component suppliers. See the above description of the first key tool and the second key tool for specific examples and beneficial effects.
[0424]
[0453] It should be noted that there are multiple implementations when the processing module 902 obtains the shared key based on the initial key and the second information, including but not limited to the following methods.
[0425]
[0454] Method 1: The processing module 902 obtains a shared key based on the initial key and the second information according to a symmetric encryption algorithm, or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0426]
[0455] For specific descriptions of the symmetric encryption algorithm, the message authentication code based on the symmetric encryption algorithm, and the key derivation function, please refer to the above descriptions of the symmetric encryption algorithm, the message authentication code based on the symmetric encryption algorithm, and the key derivation function, and the details will not be described again here.
[0427]
[0456] Method 2: The second information includes information obtained by encrypting the shared key with the initial key, so that the first component can obtain the shared key based on the initial key and the second information. For example, to obtain the shared key, the second information is decrypted with the initial key.
[0428]
[0457] In a possible implementation, the second component is configured to distribute at least key information from the first key tool. In this way, the first key tool only needs to communicate with the second component and does not need to perform communication interactions with other components in the vehicle. This effectively improves the efficiency of allocating the shared key to all components in the vehicle.
[0429]
[0458] Correspondingly, in a possible implementation, the processing module 902 is further configured to derive a shared key based on the initial key and the third information according to a symmetric encryption algorithm or based on a message authentication code or a key derivation function of the symmetric encryption algorithm. In this implementation, the shared key of the first component is not easily obtained by other devices, so that the security of the shared key is high.
[0430]
[0459] In another possible implementation, the third information includes information obtained by encrypting the shared key with the initial key. The processing module 902 is further configured to decrypt the third information with the initial key to obtain the shared key. In this implementation, the efficiency of obtaining the shared key by the first component is high.
[0431]
[0460] In a possible implementation, the transceiver module 901 may further transmit second response information in response to the second command. The second response information may include a validity result of the shared key. The first component may transmit the second response information to the first key tool or the second key tool. This is not particularly limited in the embodiment of the present application.
[0432]
[0461] In a possible implementation, the transceiver module 901 may further transmit third response information in response to the third command. The third response information may include a validity result of the shared key. The first component may transmit the third response information to the first key tool or the second component. This is not particularly limited in the embodiment of the present application.
[0433]
[0462] In a possible implementation, the shared key redemption result may include: a third identifier, the third identifier indicating that the shared key was successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting the second random number included in the second instruction or the second random number included in the third instruction using the shared key or a derivative of the shared key.
[0434]
[0463] In a possible implementation, the shared key validity result includes a fourth identifier. The fourth identifier can indicate that the shared key failed to be redeemed. In this implementation, the shared key validity result includes a second identifier, such that the first key tool can determine that the shared key failed to be redeemed based on the second identifier.
[0435]
[0464] In a possible implementation, the shared key redemption result may further include an identifier of the vehicle and / or an identifier of the first component. In this way, the first key tool or the second key tool can monitor the redemption status of the shared key of the vehicle and / or the first component.
[0436]
[0465] In one possible implementation, the transceiver module 901 is further configured to receive a fourth instruction from the first key tool or key detection tool. The fourth instruction includes a third random number, and the fourth instruction is used to determine whether the shared key matches a local shared key of the first key tool or key detection tool. The processing module 902 is further configured to determine a first check value based on the third random number and the shared key. The transceiver module 901 is further configured to transmit fourth response information. The fourth response information includes the first check value.
[0437]
[0466] In a possible implementation, the transceiver module 901 is further configured to receive a fifth instruction from the first key tool or key detection tool. The fifth instruction may include a fifth random number, and the fifth instruction may be used to detect whether the initial key of the first component is abnormal. The processing module 902 is further configured to determine a third check value based on the fifth random number and the initial key. The transceiver module 901 is further configured to transmit fifth response information. The fifth response information includes the third check value.
[0438]
[0467] It should be understood that reference should be made to the above description for beneficial effects corresponding to possible implementations of the control device 900 shown in Figure 9. The details will not be described again here.
[0439]
[0468] 10 is a schematic diagram of another possible configuration of a control device according to an embodiment of the present application. The device 1000 can be configured to perform the functions of the second component 102.
[0440]
[0469] The device 1000: a processing module 1001 configured to obtain a shared key fill instruction, the shared key fill instruction including information related to a shared key, the shared key being used to encrypt data including at least geographic location information; and a transceiver module 1002 configured to transmit a shared key redemption command;
[0441]
[0470] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0442]
[0471] The shared key may be a shared key for all components in the vehicle, or may be a shared key for components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0443]
[0472] There are multiple implementations for obtaining a shared key fulfillment command, including but not limited to the following implementations:
[0444]
[0473] Implementation 1: The shared key fill instruction may include a second instruction. For example, the shared key fill instruction is the second instruction. In another example, the shared key fill instruction includes other information in addition to the second instruction. The second instruction includes second information associated with the shared key. For a related description of the second information, please refer to the above description. The details will not be described again here.
[0445]
[0474] For example, the processing module 1001 may obtain the shared key allocation command as follows: the transceiver module 1002 may receive a second command from the key tool 200 and use the second command as the shared key allocation command.
[0446]
[0475] Implementation 2: The shared key fill instruction includes a third instruction. For example, the shared key fill instruction is a third instruction. As another example, the shared key fill instruction includes other information in addition to the third instruction. The third instruction includes third information associated with the shared key. The third instruction may be implemented in multiple ways, including but not limited to the following implementations.
[0447]
[0476] Method 1: The transceiver module 1002 can receive a second instruction from the key tool 200, and the processing module 1001 obtains a third instruction after processing the second instruction.
[0477] For example, the processing module 1002 may convert the communication protocol format of the second instruction to obtain the third instruction, or the processing module 1001 may convert the communication protocol format of the second information included in the second instruction to obtain the third information included in the third instruction.
[0448]
[0478] Correspondingly, the second component can receive the second instruction sent by the first key tool or the second key tool, and then obtain the third instruction by processing the second instruction. The second instruction includes second information associated with the shared key. The second information may be implemented in multiple ways. For details, please refer to the implementation of the second information in Implementation 1. The details will not be described again here.
[0449]
[0479] Method 2: The processing module 1001 generates a third instruction.
[0450]
[0480] For example, the processing module 1001 may generate a third command when a preset condition is met or when a specific command is received.
[0451]
[0481] The "specific command" can be any command that the second component can use as a trigger signal. For example, the specific command can be a diagnostic command specifically used to generate a shared key redemption command, or it can be a diagnostic command for other functions, such as a component flash or component reset command. In optional designs, the specific command can come from diagnostic equipment, a whole-vehicle electrical inspection test device, the cloud, or another component in the vehicle.
[0452]
[0482] The pre-set condition may include, but is not limited to, a device associated with the second component being started and reaching a particular point in time.
[0453]
[0483] It can be understood that "a device associated with the second component is started" may mean that the second component is started, or that the device on which the second component is located is started. For example, the second component is A. In this case, when A is started or the device on which A is located is started, A can generate the third instruction. As another example, the second component is B. In this case, when B is started or the device on which B is located is started, B can generate the third instruction.
[0454]
[0484] It can be understood that "reaching a specific point in time" may refer to reaching a specific key recharge point (e.g., 00:00 on the first day of each month) or to reaching a preset day before the key expiration date (e.g., the day before the key expiration date).
[0455]
[0485] Correspondingly, in Method 2, the third information may be implemented in multiple ways. For example, the processing module 1001 may generate keying material (e.g., the keying material may be generated randomly or according to a specific rule) and use the keying material as the third information in the third instruction. As another example, the processing module 1002 may generate a shared key (e.g., the shared key may be generated randomly or according to a specific rule), obtain a ciphertext of the shared key based on the initial key and the shared key, and use the ciphertext as the third information.
[0456]
[0486] In one possible design, the transceiver module 1002 may receive a second instruction from the first key tool or the second key tool. The second instruction includes second information associated with the shared key. The processing module 1001 may derive the shared key based on the initial key and the second information. The second instruction may be used to allocate the shared key for the second component.
[0457]
[0487] It should be noted that there are multiple implementations in which the processing module 1001 obtains the shared key based on the initial key and the second information, including but not limited to the following methods.
[0458]
[0488] Method 1: The processing module 1001 obtains a shared key based on the initial key and the second information according to a symmetric encryption algorithm, or based on a key derivation function of the symmetric encryption algorithm or a message authentication code.
[0459]
[0489] Method 2: The second information includes information obtained by encrypting the shared key with the initial key, so that the processing module 1001 can obtain the shared key based on the initial key and the second information. For example, to obtain the shared key, the second information is decrypted with the initial key.
[0460]
[0490] In another possible design, processing module 1001 may generate the shared key directly.
[0461]
[0491] In one possible design, the processing module 1001 may further send second response information in response to the second command. The second response information may include a shared key validity result. The shared key validity result may indicate that the shared key was successfully valid or that the shared key failed to be valid.
[0462]
[0492] Case 1: The shared key redemption result may include: a third identifier, the third identifier indicating that the shared key was successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting the second random number included in the second instruction or the second random number included in the third instruction using the shared key or a derivative of the shared key.
[0463]
[0493] Case 2: The shared key validity result includes a fourth identifier. The fourth identifier may indicate that the shared key failed to be redeemed. In this design, the shared key validity result includes a fourth identifier, such that the first key tool can determine that the shared key failed to be redeemed based on the fourth identifier.
[0464]
[0494] Optionally, the shared key validity result may further include an identifier of the vehicle and / or an identifier of the second component.
[0465]
[0495] In one possible design, the processing module 1001 may receive a first instruction from a first key tool. The first instruction includes first information associated with an initial key. The processing module 1001 may obtain the initial key according to the first instruction. The initial key is used to generate at least a shared key, and the shared key is used to encrypt data including at least geographic location information. For implementation of the first information, see the related description above.
[0466]
[0496] In one possible design, the processing module 1001 may further send first response information to the first key tool. The first response information may include an initial key validity result. The initial key validity result may indicate that the initial key of the second component has been successfully valid or that the initial key has failed to be valid.
[0467]
[0497] Case 1: The initial key redemption result includes: a first identifier, the first identifier indicating that the initial key was successfully redeemed; and / or a third ciphertext, the third ciphertext including information obtained by encrypting the first random number included in the first instruction with the initial key or a derived key of the initial key.
[0468]
[0498] Case 2: The initial key validity result may include a second identifier, which may indicate that the initial key failed to be valid.
[0469]
[0499] Optionally, the initial key validity result may further include an identifier of the vehicle and / or an identifier of the second component.
[0470]
[0500] In one possible design, the transceiver module 1002 may further receive a fourth command from the first key tool or key detection tool. The fourth command includes a third random number. The processing module 1001 determines a first check value based on the third random number and the shared key. The first check value is used to determine whether the shared key is consistent with a local shared key of the first key tool or key detection tool. The transceiver module 1002 transmits fourth response information. The fourth response information includes the first check value. The fourth command may be used to detect whether the shared key of the second component is abnormal.
[0471]
[0501] In one possible design, the transceiver module 1002 is further configured to receive a fifth command from the first key tool or the key detection tool. The fifth command may include a fifth random number, and the fifth command may be used to detect whether the initial key of the second component is abnormal. The processing module 1001 is further configured to determine a third check value based on the fifth random number and the initial key. The transceiver module 1002 is further configured to transmit fifth response information. The fifth response information includes the third check value.
[0472]
[0502] It should be understood that reference should be made to the previous description for beneficial effects corresponding to possible implementations of the control device 1000 shown in Fig. 10. The details will not be described again here.
[0473]
[0503] 11 is a schematic diagram of a possible configuration of a key distribution device according to the aforementioned embodiment of the present application. The key distribution device 1100 may be a first key tool.
[0474]
[0504] For example, device 1100: a processing module 1001 configured to determine an initial key for the vehicle, the initial key being used to generate at least a shared key, the shared key being used to encrypt data including at least geographic location information; and The present invention includes a transceiver module 1102 configured to transmit a first instruction to a first component of the vehicle, the first instruction including first information associated with an initial key.
[0475]
[0505] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0476]
[0506] The shared key may be a shared key for all components in the vehicle, or may be a shared key for components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0477]
[0507] In a possible implementation, the initial key is unassociated with the original equipment manufacturer OEM or with an OEM that does not have navigation electronic mapping capabilities, in which case the OEM is the OEM associated with the vehicle.
[0478]
[0508] In a possible design, the initial key is associated with an organization that has a navigation electronic map creation qualification, which can ensure the security of the initial key, and thus the security of the transmission of the geographical location information.
[0479]
[0509] In a possible implementation, the initial key is different from the authentication key, which is from the original equipment manufacturer (OEM) associated with the vehicle. The authentication key is used to authenticate at least the vehicle's functional keys. For example, the authentication key may be a MEK, a PMEK, or a root key. This is not particularly limited in the embodiments of the present application.
[0480]
[0510] In a possible implementation, the first information includes a first ciphertext, the first ciphertext including information obtained by encrypting an initial key with a first public key, the first public key being from the first component.
[0481]
[0511] In one possible implementation, the first information includes an initial key. The transceiver module 1102 is further configured to transmit the initial key to the first component via a wired connection.
[0482]
[0512] In one possible implementation, the transceiver module 1102 is further configured to: generate a second public key and a second private key; send request information to the key management system, the request information requesting an initial key, the request information including the second public key; and receive a second ciphertext from the key management system. The processing module 1001 is further configured to determine the initial key based on the second ciphertext and the second private key.
[0483]
[0513] In another possible implementation, the transceiver module 1102 is further configured to: send request information to the key management system, the request information requesting an initial key, the request information including a preset key; receive a second ciphertext, the second ciphertext including information regarding encrypting the initial key using the preset key; and determine the initial key based on the second ciphertext and the preset key.
[0484]
[0514] In one possible implementation, the transceiver module 1102 is further configured to receive first response information from the first component, the first response information including an initial key validity result.
[0485]
[0515] If the initial key allocation result indicates that the initial key has failed to be allocated, the transceiver module 1102 is further configured to resend the first command, which can effectively improve the probability of successfully allocating the initial key.
[0486]
[0516] In a possible implementation, the initial key validity result includes a second identifier, which indicates that the initial key failed to be valid.
[0487]
[0517] In a possible design, the initial key redemption result may include: a first identifier, the first identifier indicating that the initial key was successfully redeemed; and / or a third ciphertext, the third ciphertext including information obtained by encrypting the first random number included in the first instruction with the initial key or a derivative key of the initial key.
[0488]
[0518] Correspondingly, when the initial key allocation result includes the third ciphertext, the processing module 1101 is further configured to determine whether the initial key has been successfully allocated based on the third ciphertext. In this implementation, whether the initial key has been successfully allocated is verified by using the third ciphertext. This helps the first key tool to accurately monitor the allocation status of the initial key.
[0489]
[0519] In a possible implementation, the initial key validity result may further include an identifier of the vehicle and / or an identifier of the first component.
[0490]
[0520] In one possible implementation, if the initial key validity result indicates that the initial key has been successfully allocated, the transceiver module 1102 is further configured to send a second instruction to the first component, the second instruction including second information associated with the shared key.
[0491]
[0521] In a possible implementation, the processing module 1001 is further configured to generate a shared key and encrypt the shared key based on the initial key to obtain the second information.
[0492]
[0522] In one possible implementation, the transceiver module 1102 is further configured to receive second response information from the first component, the second response information including a validity result of the shared key.
[0493]
[0523] In a possible design, the shared key redemption result may include: a third identifier, the third identifier indicating that the shared key was successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting a second random number included in the second instruction with the shared key or a derivative of the shared key.
[0494]
[0524] Correspondingly, if the shared key redemption result includes the fourth ciphertext, the processing module 1001 is further configured to determine whether the shared key has been successfully redeemed based on the second information and the fourth ciphertext.
[0495]
[0525] In a possible implementation, the shared key validity result may further include a fourth identifier, which indicates that the shared key failed to be valid.
[0496]
[0526] In a possible implementation, if the shared key validity result indicates that the shared key failed to be valid, the transceiver module 1102 is further configured to resend the second command.
[0497]
[0527] In a possible implementation, the validity result of the shared key may further include an identifier of the vehicle and / or an identifier of the first component.
[0498]
[0528] In a possible design, the transceiver module 1102 is further configured to: send a fourth command to a first component of the vehicle, the fourth command including a third random number; receive fourth response information, the fourth response information including a first check value, the first check value being associated with the third random number and a vehicle shared key, the shared key being used at least to encrypt data including geographic location information; determine, based on the first check value, whether the vehicle shared key matches a local shared key corresponding to the vehicle; and report abnormality information if the vehicle shared key does not match the local shared key.
[0499]
[0529] In a possible design, the transceiver module 1102 is further configured to: send a fifth command to a first component of the vehicle, the fifth command including a fifth random number; receive fifth response information from the first component, the fifth response information including a third check value, the third check value being associated with the fifth random number and an initial key for the vehicle, the initial key being used to generate at least a shared key; determine, based on the third check value, whether the initial key for the vehicle matches a local initial key corresponding to the vehicle; and report abnormality information if the initial key for the vehicle does not match the local initial key.
[0500]
[0530] It should be understood that for the beneficial effects corresponding to the possible implementation of the key transmission device 1100 shown in Fig. 11, please refer to the above description, and the details will not be described again here.
[0501]
[0531] 12 is a schematic diagram of another possible configuration of a key distribution device according to the above embodiment of the present application. The key distribution device 1200 may be a second key tool.
[0502]
[0532] For example, device 1200: a processing module 1201 configured to determine a second instruction; a transceiver module 1202 configured to transmit a second instruction to a first component within the vehicle; wherein the second instructions include second information associated with the shared key, the shared key being used to encrypt data including at least the geographic location information, and the second instructions being used to redeem the shared key for the first component.
[0503]
[0533] The shared key may be a shared key for all components in the vehicle, or may be a shared key for components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0504]
[0534] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0505]
[0535] It should be noted that the second information may be implemented in multiple ways, including but not limited to the following implementations.
[0506]
[0536] Method 1: The processing module 1201 generates a shared key and obtains the second information based on the initial key and the shared key. For example, the second key tool may encrypt the shared key based on the initial key to obtain the second information.
[0507]
[0537] Method 2: The processing module 1201 may generate keying material and use the keying material as the second information.
[0508]
[0538] For example, the processing module 1201 may generate keying material randomly or according to certain rules.
[0509]
[0539] The transceiver module 1202 requests the shared key from the first key source, and the transceiver module 1201 obtains the second information based on the initial key and the shared key. For example, the processing module 1201 encrypts the shared key based on the initial key to obtain the second information.
[0510]
[0540] In one possible implementation, the transceiver module 1202 can further receive second response information from the first component, the second response information including a validity result of the shared key.
[0511]
[0541] In a possible design, the redemption result of the shared key includes: a third identifier, the third identifier indicating that the shared key was successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting a second random number included in the second instruction with the shared key or a derivative of the shared key.
[0512]
[0542] In a possible implementation, if the shared key redemption result includes the fourth ciphertext, the processing module 1201 may further determine whether the shared key has been successfully redeemed based on the second information and the fourth ciphertext.
[0513]
[0543] In a possible implementation, if the shared key validity result indicates that the shared key failed to be valid, the second key tool may further resend the second command.
[0514]
[0544] In a possible implementation, the shared key validity result includes a fourth identifier, which indicates that the shared key failed to be valid.
[0515]
[0545] In a possible implementation, the validity result of the shared key may further include an identifier of the vehicle and / or an identifier of the first component.
[0516]
[0546] It should be understood that for the beneficial effects corresponding to the possible implementation of the key transmission device 1200 shown in Fig. 12, please refer to the above description, and the details will not be described again here.
[0517]
[0547] FIG. 13 is a schematic diagram of a possible configuration of a key detection device according to the aforementioned embodiment of the present application.
[0518]
[0548] For example, device 1300: a transceiver module 1301 configured to transmit fourth instructions to a first component of the vehicle, the fourth instructions including a third random number, the transceiver module further configured to receive fourth response information from the first component, the fourth response information including a first check value, the first check value being associated with the third random number and a shared key of the vehicle, the shared key being used at least to encrypt data including geographic location information; and a processing module 1302 configured to determine, based on the first check value, whether the shared key of the vehicle matches a local shared key corresponding to the vehicle; the transceiver module 1301 is further configured to report abnormality information if the vehicle shared key does not match the local shared key.
[0519]
[0549] The shared key of the vehicle may be a shared key of all components in the vehicle, or may be a shared key of components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0520]
[0550] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0521]
[0551] In a possible design, the processing module 1302 may be configured to: calculate a second check value based on the local shared key and the third random number; compare the first check value with the second check value; and determine that the vehicle's local shared key matches the vehicle's current shared key if the first check value matches the second check value; or determine that the vehicle's local shared key does not match the vehicle's current shared key if the first check value does not match the second check value.
[0522]
[0552] There are multiple implementations in which the processing module 1302 obtains the local shared key, including but not limited to the following methods.
[0523]
[0553] Method 1: Obtain a vehicle identifier or a first component identifier. Based on the vehicle identifier or the first component identifier, query an initial key corresponding to the vehicle and keying material used to generate a local shared key. Generate a local shared key based on the initial key and keying material. In this way, the local shared key of the key discovery tool has high real-time performance.
[0524]
[0554] Method 2: Obtain a vehicle identifier or a first component identifier. Query the local shared key based on the vehicle identifier or the first component identifier. In this way, the key discovery tool can quickly obtain the local shared key and improve key discovery efficiency.
[0525]
[0555] In a possible design, the transceiver module 1301 can report the abnormality information to a credential management authority or can report the abnormality information to a key management system.
[0526]
[0556] In a possible implementation, the key detection device 1300 is a key detection tool.
[0527]
[0557] It should be understood that the reader is referred to the above description for the beneficial effects corresponding to the possible implementation of the key detection device 1300 shown in Fig. 13. The details will not be described again here.
[0528]
[0558] FIG. 14 is a schematic diagram of another possible configuration of a key detection device according to an embodiment of the present application.
[0529]
[0559] For example, device 1400: a processing module 401 configured to obtain a communication information ciphertext of a first component of the vehicle, the communication information ciphertext including information obtained by encrypting first information using a shared key of the vehicle, the first information including geographic location information, the processing module 1401 further configured to determine whether the shared key of the vehicle matches the local shared key based on the communication information ciphertext and a local shared key corresponding to the vehicle; and a transceiver module 1402 configured to report abnormality information if the vehicle's shared key does not match the local shared key;
[0560] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0530]
[0561] In a possible design, the processing module 1401 can decrypt the communication information ciphertext using the local shared key to obtain the communication information, determine whether the communication information is abnormal, and if the communication information is abnormal, determine that the shared key used by the vehicle does not match the local shared key; or, if the communication information is normal, determine that the shared key used by the vehicle matches the local shared key.
[0531]
[0562] In possible designs, there are multiple implementations for the processing module 1401 to obtain the local shared key, including but not limited to the following methods.
[0532]
[0563] Method 1: Obtain a vehicle identifier or a first component identifier. Based on the vehicle identifier or the first component identifier, query an initial key corresponding to the vehicle and keying material used to generate a local shared key. Generate a local shared key based on the initial key and keying material. In this way, the local shared key of the key discovery tool has high real-time performance.
[0533]
[0564] Method 2: Obtain a vehicle identifier or a first component identifier. Query the local shared key based on the vehicle identifier or the first component identifier. In this way, the key discovery tool can quickly obtain the local shared key, improving key discovery efficiency.
[0534]
[0565] In possible designs, the transceiver module 1402 may further report the abnormality information to a credential management authority, or may report the abnormality information to a key management system.
[0535]
[0566] The shared key may be a shared key for all components in the vehicle, or may be a shared key for components associated with a functional domain in the vehicle, which is not limited in the embodiment of the present application.
[0536]
[0567] For the geographic location information data, please refer to the above description of the geographic location information data, and the details will not be described again here.
[0537]
[0568] In a possible implementation, the key detection device 1400 is a key detection tool.
[0538]
[0569] It should be understood that the reader is referred to the above description for the beneficial effects corresponding to the possible implementation of the key detection device 1400 shown in Fig. 14. The details will not be described again here.
[0539]
[0570]
[0013] An embodiment of the present application further provides a chip system. See Figure 15. The chip system 1500 includes at least one processor. When program instructions are executed in the at least one processor 1501, the method embodiments shown in Figures 2 to 8 are implemented.
[0540]
[0571] Furthermore, the chip system may further include a communication interface 1503, which is configured to input or output information. Furthermore, the chip system may further include a memory 1502. The memory 1502 is coupled to the processor via the communication interface 1503 and configured to store the aforementioned instructions, such that the processor reads the instructions stored in the memory via the communication interface 1503.
[0541]
[0572] It should be understood that the connection medium between the processor 1501, the memory 1502, and the communication interface 1503 is not limited to the embodiment of the present application. In the embodiment of the present application, the memory 1502, the processor 1501, and the communication interface 1503 are connected via the communication bus 1504 in FIG. 15. In FIG. 15, the bus is represented by a thick line. The connection topology between other components is merely an example for explanation and does not constitute a limitation. The bus may include an address bus, a data bus, a control bus, etc. In FIG. 15, only one thick line is used for simplicity of illustration, but this does not mean that there is only one bus or only one type of bus, etc.
[0542]
[0573] An embodiment of the present application further provides a vehicle, the vehicle including a first component in a first aspect or in any one of the possible designs of the first aspect, and / or a second component in a second aspect or in any one of the possible designs of the second aspect.
[0543]
[0574] An embodiment of the present application further provides a computer program product including instructions, which, when run on the aforementioned device, may perform the key transmission method in the aforementioned embodiment or the key detection method in the aforementioned embodiment.
[0544]
[0575] An embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed, the key transmission method in the above-mentioned embodiment may be implemented, or the key detection method in the above-mentioned embodiment may be implemented. The above-mentioned embodiments may be combined with each other to achieve various technical effects.
[0545]
[0576] Based on the above description of the implementation, those skilled in the art will clearly understand that for ease of explanation and simplicity, the above division into functional modules is only used as an example for explanation. In actual applications, the above functions may be allocated to different functional modules for implementation based on requirements, that is, the internal structure of the device can be divided into different functional modules to realize all or part of the above functions.
[0546]
[0577] Those skilled in the art will appreciate that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a hardware-only embodiment, a software-only embodiment, or an embodiment that combines software and hardware. Furthermore, the present application may take the form of a computer program product embodied in one or more computer-usable storage media (including, but not limited to, disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0547]
[0578] The present application has been described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the present application. It should be understood that computer program instructions may be used to implement each step and / or each block in the flowcharts and / or block diagrams, and combinations of steps and / or blocks in the flowcharts and / or block diagrams. These computer program instructions are provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or another programmable data processing device to cause a machine, such that the instructions, executed by the processor of the computer or another programmable data processing device, cause an apparatus configured to perform the function specified in one or more steps in the flowcharts and / or one or more blocks in the block diagrams.
[0548]
[0579] These computer program instructions may alternatively direct a computer or another programmable data processing device to operate in a particular manner and may be stored in a computer-readable memory, such that the instructions stored in the computer-readable memory generate an artifact that includes an instruction apparatus that implements the function specified in one or more steps in the flowcharts and / or one or more blocks in the block diagrams.
[0549]
[0580] These computer program instructions may alternatively be loaded into a computer or other programmable data processing apparatus such that a sequence of operations and steps are performed on the computer or other programmable apparatus, resulting in a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing a particular function of one or more procedures in the flowcharts and / or one or more blocks in the block diagrams.
[0550]
[0581] It is obvious that those skilled in the art can make various modifications and variations to the present application without departing from the scope of protection of the present application, and the present application is intended to cover these modifications and variations, provided that they fall within the scope of protection defined by the following claims of the present application and their equivalent technologies.
Claims
1. 1. A key transmission method applied to a first component of a plurality of components in a vehicle, the method comprising: receiving a first instruction from a first key tool, the first instruction including first information associated with an initial key; obtaining the initial key according to the first instruction; wherein the initial key is used at least to generate a shared key, and the shared key is used at least to encrypt data, including geographic location information, in communications between a plurality of components within the vehicle.
2. 10. The method of claim 1, wherein the initial key is unassociated with an OEM (original equipment manufacturer) or an OEM (original equipment manufacturer) that does not have navigation electronic mapping capabilities, and the OEM is associated with a vehicle.
3. 3. The method of claim 1 or 2, wherein the initial key is different from an authentication key, the authentication key being from an OEM (original equipment manufacturer) associated with the vehicle; the method further comprising:
11. The method of claim 10, further comprising: determining at least one function key based on the authentication key, the at least one function key corresponding to at least one service function of the first component.
4. 4. The method according to claim 1, wherein the first information is a first ciphertext, the first ciphertext being obtained by encrypting the initial key with a first public key of the first component; obtaining the initial key in accordance with the first instructions includes decrypting the first ciphertext based on a first private key of the first component to obtain the initial key; The method, wherein the first private key corresponds to the first public key.
5. 4. The method according to claim 1, wherein the first information includes the initial key; The method, wherein the step of obtaining the initial key in accordance with the first instruction includes the step of obtaining the initial key in accordance with the first instruction in a wired connection manner.
6. 6. The method of claim 1, further comprising the step of sending first response information to the first key tool, the first response information including a validity result of the initial key.
7. 7. The method of claim 6, wherein the initial key validity result is: a first identifier indicating that the initial key was successfully redeemed; and / or a third ciphertext including information obtained by encrypting a first random number included in the first instruction using the initial key or a derivative of the initial key; A method comprising:
8. 7. The method of claim 6, wherein the validity result includes a second identifier, the second identifier indicating that the initial key failed to be valid.
9. 9. The method of any one of claims 1 to 8, further comprising: receiving second instructions from the first key tool or a second key tool, the second instructions including second information associated with the shared key; and obtaining a shared key associated with the second information based on the initial key and the second information; wherein the first key tool and the second key tool correspond to different key allocation environments.
10. 10. The method according to claim 9, wherein the step of obtaining the shared key based on the initial key and the second information comprises: deriving the shared key based on the initial key and the second information in accordance with a symmetric encryption algorithm or based on a message authentication code or key derivation function of a symmetric encryption algorithm.
11. 10. The method according to claim 9, wherein the second information includes information obtained by encrypting the shared key using the initial key, and the step of obtaining the shared key based on the initial key and the second information includes: decrypting the second information with the initial key to obtain the shared key.
12. 9. The method of any one of claims 1 to 8, further comprising: receiving third instructions from a second component, the third instructions including third information associated with the shared key; and obtaining the shared key based on the initial key and the third information; wherein the second component is configured at least to distribute key information from a key tool.
13. 13. The method of claim 12, wherein the step of deriving the shared key based on the initial key and the third information comprises: deriving the shared key based on the initial key and the third information in accordance with a symmetric encryption algorithm or based on a message authentication code or key derivation function of a symmetric encryption algorithm.
14. 13. The method of claim 12, wherein the third information includes information obtained by encrypting the shared key using the initial key, and the step of obtaining the shared key based on the initial key and the third information comprises: decrypting the third information with the initial key to obtain the shared key.
15. 12. The method of claim 9, further comprising the step of transmitting second response information in response to the second command, the second response information including a validity result of the shared key.
16. 15. The method of claim 12, further comprising the step of transmitting third response information in response to the third command, the third response information including a validity result of the shared key.
17. 16. The method of claim 15, wherein the shared key validity result is: a third identifier indicating that the shared key has been successfully redeemed; and / or a fourth ciphertext, the fourth ciphertext including information obtained by encrypting a second random number included in the second instruction or a second random number included in a third instruction using the shared key or a derivative of the shared key; A method comprising:
18. 17. The method of claim 15 or 16, wherein the shared key redemption result includes a fourth identifier, the fourth identifier indicating that the shared key failed to redeem.
19. 19. The method of any one of claims 1 to 18, further comprising: receiving a fourth instruction from the first key tool or a key detection tool, the fourth instruction including a third random number, the fourth instruction capable of being used to detect whether the shared key is abnormal; determining a first check value based on the third random number and the shared key; transmitting fourth response information including the first test value; A method comprising:
20. 20. An on-board device including a processor and a storage medium, the storage medium storing instructions that, when executed by the processor, enable the on-board device to perform the method of any one of claims 1 to 19.
21. 20. A vehicle including a first component configured to perform a method according to any one of claims 1 to 19.
22. 20. A chip comprising one or more processors and interface circuitry, the interface circuitry configured to provide information input and / or output for the one or more processors, the chip being configured to perform a method according to any one of claims 1 to 19.
23. 20. A computer storage medium storing instructions that, when executed, perform the method of any one of claims 1 to 19.
24. A computer program product causing one or more processors to carry out a method according to any one of claims 1 to 19.
Citation Information
Patent Citations
Rail transit tool moving track positioning and monitoring method and system
CN113104065A
User mutual authentication system, method therefor and recording medium
JP2000339270A
Key generation method, key generation system, and computer program
JP2017108212A
Portable device registration system and portable device registration method
WO2013114973A1
System, certification authority, vehicle-mounted computer, vehicle, public key certificate issuance method, and program
WO2017217070A1