Remote upgrade method and system, computer device, and vehicle

By generating and encrypting upgrade information over the network, and then decrypting and verifying its legitimacy on the vehicle side, the security vulnerability of remotely upgrading low-version software is resolved, thus ensuring the security of users' legitimate upgrades.

WO2025246009A1PCT designated stage Publication Date: 2025-12-04CHONGQING CHANGAN AUTOMOBILE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/108711
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-05-30
Filing Date
2024-07-31
Publication Date
2025-12-04

AI Technical Summary

Technical Problem

During remote upgrades, security vulnerabilities exist when users upgrade to older software versions. Traditional methods cannot simultaneously meet user needs and ensure system security.

Method used

The software upgrade key is generated via the network, the number of upgrades is recorded, and the upgrade information is encrypted. The vehicle receives the encrypted information, decrypts it, and verifies the legality of the upgrade, ensuring the security and legality of the upgrade process.

Benefits of technology

When users upgrade to older software versions, the security and legality of the upgrade are ensured, avoiding security risks associated with older software versions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024108711_04122025_PF_FP_ABST
    Figure CN2024108711_04122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of remote upgrade, and discloses a remote upgrade method and system, a computer device, and a vehicle. In the present application, a network side is used to generate a first software upgrade count that records the number of times of software upgrade, a software upgrade rollback flag that indicates whether a software upgrade task is a low-version software upgrade task, and upgrade information, encrypted upgrade information and a software upgrade package which are required for a vehicle side, so that when determining, on the basis of the software upgrade rollback flag, to roll back to low-version software, the vehicle side decrypts the encrypted upgrade information sent by the network side, so as to obtain new upgrade information, and by comparing the first software upgrade count and a second software upgrade count which is stored in the vehicle side, and on the basis of the correspondence between the new upgrade information and the upgrade information, the vehicle side performs authentication for the upgrade, and when it is determined that remote upgrade is legitimate, the vehicle side rolls back to the low-version software by means of the software upgrade package, so that when a user rolls back to low-version software, the security and legitimacy of the upgrade are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Remote upgrading method, system, computer device and vehicle

[0001] The present application claims priority to the Chinese patent application No. 202410688373.6, filed on May 30, 2024, and entitled "Remote upgrading method, system, computer device and vehicle", the whole content of which is incorporated herein by reference. TECHNICAL FIELD

[0002] The present application relates to the technical field of remote upgrading, in particular to a remote upgrading method, system, computer device and vehicle. BACKGROUND

[0003] With the rapid development of intelligent and networked vehicles, in order to quickly seize the market and realize the rapid iteration of functions, the common practice in the industry is to realize the iterative upgrade of intelligent functions and the timely repair of vulnerabilities through rapid Over-The-Air (OTA) upgrade based on hardware reserved resources. However, during the OTA upgrade process, there are problems such as insufficient software quality, insufficient testing, instability of new versions, and incompatibility between the upgraded version and other vehicle parts, so there is a business demand to roll back to a lower version in the OTA upgrade business. However, according to information security risk analysis, hackers can illegally use the function of allowing upgrading to a lower version, maliciously upgrade the official version with vulnerabilities, and then attack the vehicle using this vulnerability.

[0004] Currently, encryption is often used during the OTA upgrade process to solve the problem of protecting the legality, integrity and confidentiality of the upgrade package. However, for the security vulnerabilities that may be caused by users upgrading to a lower version of software, it is often difficult to meet the user's demand to upgrade to a lower version of software while avoiding the security vulnerabilities that may be caused by upgrading to a lower version of software.

[0005] SUMMARY

[0006] Therefore, the present application provides a remote upgrading method, system, computer device and vehicle to solve the problem that the conventional method cannot guarantee system security when users upgrade to a lower version of software.

[0007] In a first aspect, the present application provides a remote upgrading method applied to a network end, which comprises:

[0008] generating a software upgrade key and sending the software upgrade key to a vehicle end;

[0009] after receiving the software upgrade task sent by the vehicle end, updating the first software upgrade times and detecting whether the software upgrade task is a low version software upgrade task to obtain a software upgrade rollback flag;

[0010] The upgrade information including the first software upgrade number is encrypted by the software upgrade key to generate encrypted upgrade information;

[0011] The upgrade information, the encrypted upgrade information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end, so that the vehicle end, after determining to upgrade to the low-version software according to the software upgrade rollback flag, decrypts the encrypted upgrade information according to the software upgrade key to obtain new upgrade information and the first software upgrade number, and after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new upgrade information and the upgrade information, upgrades to the low-version software through the software upgrade package.

[0012] The first software upgrade number recording the software upgrade number, the software upgrade rollback flag representing whether it is a low-version software upgrade task, and the upgrade information, the encrypted upgrade information, and the software upgrade package required by the vehicle end are generated by the network end, so that the vehicle end, after determining to upgrade to the low-version software according to the software upgrade rollback flag, decrypts and authenticates the encrypted upgrade information sent by the network end, and after determining that the remote upgrade is legal, upgrades to the low-version software through the software upgrade package, thereby ensuring the security and legality of the upgrade when the user upgrades the low-version software.

[0013] In an optional implementation, the software upgrade key includes a software upgrade master key; the upgrade information further includes software information and authentication information for upgrade authentication, and the encrypted upgrade information includes encrypted authentication information; the upgrade information including the first software upgrade number is encrypted by the software upgrade key to generate the encrypted upgrade information, including:

[0014] The authentication information is generated based on the first software upgrade number;

[0015] The software information is symmetrically encrypted by the software upgrade master key to obtain a rollback service key; wherein the software information is generated according to a software upgrade version corresponding to the software upgrade task, a current software version, and the software upgrade rollback flag;

[0016] The authentication information is symmetrically encrypted by the rollback service key to obtain the encrypted authentication information.

[0017] Thus, by encrypting the authentication information when generating and sending the authentication information for upgrade authentication to the vehicle end, the security of transmission is improved.

[0018] In an optional implementation, the upgrade information, the encrypted upgrade information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end, including:

[0019] The software information, the authentication information, the encrypted authentication information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end, so that the vehicle end, after determining to upgrade to the low-version software according to the software upgrade rollback flag, decrypts the encrypted authentication information according to the software upgrade master key and the software information, extracts the first software upgrade times based on the new authentication information obtained after decryption, and upgrades to the low-version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade times and the second software upgrade times stored by the vehicle end and the corresponding relationship between the new authentication information and the authentication information.

[0020] In an optional embodiment, the software upgrade key is generated and sent to the vehicle end, comprising:

[0021] After receiving the public key sent by the vehicle end, the software upgrade master key and the transmission protection key are generated;

[0022] The transmission protection key is asymmetrically encrypted by the public key to obtain the ciphertext transmission protection key, and the software upgrade master key is symmetrically encrypted according to the ciphertext transmission protection key to obtain the ciphertext software upgrade master key;

[0023] The ciphertext software upgrade master key and the ciphertext transmission protection key are sent to the vehicle end, so that the vehicle end decrypts the ciphertext transmission protection key to obtain the transmission protection key by using the private key corresponding to the public key, and decrypts the ciphertext software upgrade master key based on the transmission protection key to obtain the software upgrade master key.

[0024] Thus, the software upgrade master key is generated by the network end, and then the software upgrade master key is encrypted and sent to the vehicle end, so that the vehicle end obtains the software upgrade master key of the network end after decryption, thereby improving the security.

[0025] In an optional embodiment, the software upgrade key comprises an asymmetric key pair composed of a software upgrade public key and a software upgrade private key; the upgrade information further comprises authentication information and digest authentication information for upgrade authentication, and the encrypted upgrade information comprises signature authentication information; the upgrade information comprising the first software upgrade times is encrypted by the software upgrade key to generate the encrypted upgrade information, comprising:

[0026] The authentication information is generated based on the first software upgrade times;

[0027] The authentication information is subjected to a digest operation to obtain the digest authentication information, and the digest authentication information is asymmetrically encrypted by the software upgrade private key to obtain the signature authentication information.

[0028] Thus, when the signature authentication information for upgrade authentication is generated and sent to the vehicle end, the authentication information is encrypted and subjected to a digest operation to improve the security of transmission.

[0029] In an optional embodiment, the upgrade information, the encrypted upgrade information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end, comprising:

[0030] The authentication information, the signature authentication information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end, so that the vehicle end, after determining to upgrade to the low version software according to the software upgrade rollback flag, decrypts the signature authentication information according to the software upgrade public key to obtain the digest authentication information, performs digest operation on the authentication information to obtain new digest authentication information, and extracts the first software upgrade times from the authentication information, and after determining that the remote upgrade is legal according to the size relationship between the first software upgrade times and the second software upgrade times stored by itself and the corresponding relationship between the new digest authentication information and the digest authentication information, upgrades to the low version software through the software upgrade package.

[0031] In an optional embodiment, after receiving the software upgrade task sent by the vehicle end, the first software upgrade times are updated, and it is detected whether the software upgrade task is a low version software upgrade task, and the software upgrade rollback flag is obtained, comprising:

[0032] After receiving the software upgrade task, the first software upgrade times are increased by one, and the software upgrade version and the current software version are obtained based on the software upgrade task;

[0033] If it is detected that the software upgrade version is not higher than the current software version, it is determined that the software upgrade task is a low version software upgrade task, and the software upgrade rollback flag is set to one;

[0034] If it is detected that the software upgrade version is not higher than the current software version, it is determined that the software upgrade task is not a low version software upgrade task, and the software upgrade rollback flag is set to zero.

[0035] Therefore, by comparing the software upgrade version and the current software version, it is judged whether the vehicle end wants to upgrade to the low version software, and the software upgrade rollback flag is generated, so that the vehicle end determines whether to perform authentication through the software upgrade rollback flag.

[0036] In a second aspect, the application provides a remote upgrade method applied to a vehicle end, comprising:

[0037] Receiving the software upgrade key sent by the network end;

[0038] sending the software upgrade task to the network end, receiving the upgrade information, the encrypted upgrade information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task returned by the network end; the encrypted upgrade information is obtained by encrypting the upgrade information including the first software upgrade number by the network end through the software upgrade key, the first software upgrade number is obtained by the network end by updating the current software upgrade number after receiving the software upgrade task, and the software upgrade rollback flag is obtained by the network end by detecting whether the software upgrade task is a low version software upgrade task;

[0039] decrypting the encrypted upgrade information according to the software upgrade key to obtain the new upgrade information and the first software upgrade number stored by the network end after determining to upgrade to the low version software according to the software upgrade rollback flag;

[0040] upgrading to the low version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new upgrade information and the upgrade information.

[0041] The first software upgrade number recording the software upgrade number, the software upgrade rollback flag indicating whether it is a low version software upgrade task and the upgrade information, the encrypted upgrade information and the software upgrade package required by the vehicle end are generated by the network end, so that the vehicle end decrypts and authenticates the encrypted upgrade information sent by the network end after determining to upgrade to the low version software according to the software upgrade rollback flag, and upgrades to the low version software through the software upgrade package after determining that the remote upgrade is legal, thereby guaranteeing the safety and legality of the upgrade when the user upgrades the low version software.

[0042] In an optional embodiment, the software upgrade key includes a software upgrade master key; the upgrade information further includes software information and authentication information for upgrade authentication, and the encrypted upgrade information includes encrypted authentication information.

[0043] The upgrade information, the encrypted upgrade information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task returned by the network end are received, including:

[0044] The software information, the authentication information, the encrypted authentication information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task returned by the network end are received.

[0045] Decrypting the encrypted upgrade information according to the software upgrade key to obtain the new upgrade information and the first software upgrade number stored by the network end, including:

[0046] Symmetrically encrypting the software information according to the software upgrade master key to obtain the rollback service key.

[0047] The encrypted authentication information is decrypted by the rollback service key to obtain decrypted new authentication information, and the first software upgrade number stored at the network end is extracted from the new authentication information.

[0048] Thus, the encrypted information sent by the network end is decrypted by the software upgrade master key, so as to facilitate subsequent remote upgrade legality judgment and improve the security of information transmission.

[0049] In an optional embodiment, before upgrading to the low-version software through the software upgrade package, the method further comprises:

[0050] If it is detected that the first software upgrade number is greater than the second software upgrade number, it is judged whether the new authentication information is consistent with the authentication information;

[0051] If it is detected that the new authentication information is consistent with the authentication information, it is determined that the remote upgrade is legal, the value of the first software upgrade number is assigned to the second software upgrade number, and the step of upgrading to the low-version software through the software upgrade package is executed;

[0052] If it is detected that the new authentication information is inconsistent with the authentication information, or the first software upgrade number is not greater than the second software upgrade number, the upgrade is stopped.

[0053] Thus, by judging the size relationship between the first software upgrade number and the second software upgrade number, and judging the consistency relationship between the new authentication information and the authentication information, it is judged whether the low-version upgrade is legal, the security of remote upgrade is improved, and the security risk caused by the security vulnerability of the low-version software is avoided.

[0054] In an optional embodiment, after receiving the software upgrade key sent by the network end, the method further comprises:

[0055] The software upgrade version and the current software version are obtained, the software upgrade version and the current software version are compared, and a software upgrade rollback flag used to represent whether it is a low-version software upgrade task is obtained;

[0056] After it is determined to upgrade to the low version according to the software upgrade rollback flag, the software upgrade version, the current software version and the software upgrade rollback flag are symmetrically encrypted to obtain a rollback service key, and the authentication information, the encrypted authentication information and the software upgrade package input by the user through an offline mode are received; the authentication information, the encrypted authentication information and the software upgrade package are obtained by the user from the network end;

[0057] The step of decrypting the encrypted authentication information by the rollback service key to obtain decrypted new authentication information and subsequent steps are executed.

[0058] Thus, in the offline scenario, the low version legal upgrade is performed by receiving the user input authentication information, encrypting the authentication information and the software upgrade package.

[0059] In an alternative embodiment, the software upgrade key comprises an asymmetric key pair composed of the software upgrade public key and the software upgrade private key; the upgrade information further comprises authentication information and digest authentication information for upgrade authentication, and the encrypted upgrade information comprises signed authentication information;

[0060] The received upgrade information, encrypted upgrade information, software upgrade rollback flag and software upgrade package corresponding to the software upgrade task returned by the network end, comprises:

[0061] The received authentication information, signed authentication information, software upgrade rollback flag and software upgrade package corresponding to the software upgrade task returned by the network end;

[0062] The encrypted upgrade information is decrypted according to the software upgrade key to obtain new upgrade information and the first software upgrade number stored by the network end, comprising:

[0063] The signed authentication information is decrypted according to the software upgrade public key sent by the network end to obtain the digest authentication information, the authentication information is subjected to digest operation to obtain new digest authentication information, and the first software upgrade number is extracted from the authentication information.

[0064] Thus, the signed authentication information sent by the network end is decrypted by the software upgrade public key, so as to facilitate the subsequent remote upgrade legality judgment and improve the security of information transmission.

[0065] In an alternative embodiment, before upgrading to the low version software by the software upgrade package, the method further comprises:

[0066] If the detected new digest authentication information is consistent with the digest authentication information, it is judged whether the first software upgrade number is greater than the second software upgrade number;

[0067] If it is detected that the first software upgrade number is greater than the second software upgrade number, it is determined that the remote upgrade is legal, the value of the first software upgrade number is assigned to the second software upgrade number, and the step of upgrading to the low version software by the software upgrade package is executed;

[0068] If it is detected that the first software upgrade number is not greater than the second software upgrade number, or the new digest authentication information is not consistent with the digest authentication information, the upgrade is stopped.

[0069] Thus, by judging the size relationship between the first software upgrade number and the second software upgrade number, and judging the consistency relationship between the new digest authentication information and the digest information, it is judged whether the low version upgrade is legal, the security of remote upgrade is improved, and the security risk caused by the security vulnerability of the low version software is avoided.

[0070] In an optional embodiment, after receiving the software upgrade public key sent by the network end, the method further comprises:

[0071] obtaining the software upgrade version and the current software version, comparing the software upgrade version and the current software version to obtain a software upgrade rollback flag for indicating whether it is a low version software upgrade task;

[0072] After determining to upgrade to the low version according to the software upgrade rollback flag, receiving authentication information for upgrade authentication, signature authentication information and the software upgrade package input by the user in an offline manner, performing the step of decrypting the signature authentication information according to the software upgrade public key sent by the network end to obtain digest authentication information and subsequent steps; the authentication information, the signature authentication information and the software upgrade package are obtained by the user from the network end.

[0073] Thus, in the offline scenario, the low version legal upgrade is performed by receiving the authentication information, the signature authentication information and the software upgrade package input by the user.

[0074] In a third aspect, the application provides a remote upgrade system, which comprises a network end and a vehicle end.

[0075] The network end is configured to generate a software upgrade key and send the software upgrade key to the vehicle end; after receiving the software upgrade task sent by the vehicle end, update a first software upgrade number, and detect whether the software upgrade task is a low version software upgrade task to obtain a software upgrade rollback flag; encrypt upgrade information including the first software upgrade number by using the software upgrade key to generate encrypted upgrade information; and send the upgrade information, the encrypted upgrade information, the software upgrade rollback flag and a software upgrade package corresponding to the software upgrade task to the vehicle end.

[0076] The vehicle end is configured to, after determining to upgrade to the low version software according to the software upgrade rollback flag, decrypt the encrypted upgrade information according to the software upgrade key to obtain new upgrade information and the first software upgrade number, and after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and a second software upgrade number stored by itself and the corresponding relationship between the new upgrade information and the upgrade information, upgrade to the low version software by using the software upgrade package.

[0077] By using the network end to generate the first software upgrade times for recording software upgrade times, the software upgrade rollback flag for indicating whether it is a low version software upgrade task, and the upgrade information, the encrypted upgrade information and the software upgrade package required by the vehicle end, the vehicle end can decrypt the encrypted upgrade information to obtain new upgrade information and the first software upgrade times after determining to upgrade to the low version software according to the software upgrade rollback flag, and can upgrade to the low version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade times and the second software upgrade times stored by itself and the corresponding relationship between the new upgrade information and the upgrade information, so as to guarantee the security and legality of the upgrade when the user upgrades the low version software.

[0078] In a fourth aspect, the present application provides a computer device, comprising: a first memory and a first processor, which are communicatively connected with each other, and the first memory stores a first computer instruction; the first processor executes the first computer instruction to perform the remote upgrade method of the first aspect or any of the corresponding embodiments thereof.

[0079] In a fifth aspect, the present application provides a vehicle, comprising: a second memory and a second processor, which are communicatively connected with each other, and the second memory stores a second computer instruction; the second processor executes the second computer instruction to perform the remote upgrade method of the second aspect or any of the corresponding embodiments thereof.

[0080] The present application has the following beneficial effects:

[0081] By using the network end to generate the first software upgrade times for recording software upgrade times, the software upgrade rollback flag for indicating whether it is a low version software upgrade task, and the upgrade information, the encrypted upgrade information and the software upgrade package required by the vehicle end, the vehicle end can decrypt the encrypted upgrade information to obtain new upgrade information and the first software upgrade times after determining to upgrade to the low version software according to the software upgrade rollback flag, and can upgrade to the low version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade times and the second software upgrade times stored by itself and the corresponding relationship between the new upgrade information and the upgrade information, so as to guarantee the security and legality of the upgrade when the user upgrades the low version software. BRIEF DESCRIPTION OF DRAWINGS

[0082] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the description of the embodiments or the prior art. Obviously, the drawings described below are some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.

[0083] Fig. 1 is a structural block diagram of a remote upgrading system according to an embodiment of the present application;

[0084] Fig. 2 is a structural block diagram of another remote upgrading system according to an embodiment of the present application;

[0085] Fig. 3 is a structural block diagram of yet another remote upgrading system according to an embodiment of the present application;

[0086] Fig. 4 is a flowchart of a remote upgrading method according to an embodiment of the present application;

[0087] Fig. 5 is a flowchart of a symmetric authentication remote online upgrading method according to an embodiment of the present application;

[0088] Fig. 6 is a flowchart of a symmetric authentication remote offline upgrading method according to an embodiment of the present application;

[0089] Fig. 7 is a flowchart of an asymmetric authentication remote online upgrading method according to an embodiment of the present application;

[0090] Fig. 8 is a flowchart of an asymmetric authentication remote offline upgrading method according to an embodiment of the present application;

[0091] Fig. 9 is a hardware structure diagram of a computer device according to an embodiment of the present application;

[0092] Fig. 10 is a hardware structure diagram of a vehicle according to an embodiment of the present application. DETAILED DESCRIPTION

[0093] In order to make the purposes, technical solutions and advantages of the embodiments of the present application clearer, the following will combine the drawings in the embodiments of the present application to make a clear and complete description of the technical solutions in the embodiments of the present application. Obviously, the described embodiments are some embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.

[0094] In an automobile software upgrading process, a user has a demand for upgrading a lower version than a current software version. When upgrading a lower version than the current software version, a traditional method can bring a security risk due to a security vulnerability existing in the lower version software. Therefore, it is necessary to control the permission of upgrading a lower version of legal software, to meet the demand of the user for independently and legally upgrading a lower version of software, and to avoid other users from illegally upgrading a lower version of software.

[0095] Therefore, the embodiment of the present application provides a remote upgrading scheme. Whether remote upgrading is legal is determined through interactive information between a network end and a vehicle end. The vehicle end upgrades to a lower version of software after determining that the remote upgrading is legal. The demand of the user for upgrading a lower version of software can be met, and security and legality are guaranteed.

[0096] According to the embodiment of the present application, a remote upgrading system is provided, as shown in FIG. 1. The remote upgrading system includes a network end 101 and a vehicle end 102. The network end 101 is a port receiving a vehicle upgrading request, such as a cloud server, an edge server, and the like. The vehicle end 102 can be a vehicle, a vehicle machine, a controller, or a client software installed on the vehicle, and the like. The embodiment of the present application is not limited thereto.

[0097] The network end 101 is configured to generate a software upgrading key and send the software upgrading key to the vehicle end 102. After receiving a software upgrading task sent by the vehicle end 102, the network end 101 updates a first software upgrading frequency, detects whether the software upgrading task is a lower version software upgrading task, and obtains a software upgrading rollback flag. The network end 101 encrypts upgrading information including the first software upgrading frequency by using the software upgrading key, generates encrypted upgrading information, and sends the upgrading information, the encrypted upgrading information, the software upgrading rollback flag, and a software upgrading package corresponding to the software upgrading task to the vehicle end 102.

[0098] The vehicle end 102 is configured to decrypt the encrypted upgrading information by using the software upgrading key after determining to upgrade to a lower version of software according to the software upgrading rollback flag, obtain new upgrading information and the first software upgrading frequency, and determine that the remote upgrading is legal according to a size relationship between the first software upgrading frequency and a second software upgrading frequency stored by the vehicle end 102 and a corresponding relationship between the new upgrading information and the upgrading information. The vehicle end 102 upgrades to the lower version of software by using the software upgrading package.

[0099] The remote upgrading system provided by the embodiments of the present application uses the network end to generate the first software upgrading frequency for recording the software upgrading frequency, the software upgrading rollback flag for indicating whether it is a low version software upgrading task, and the upgrading information, the encrypted upgrading information and the software upgrading package required by the vehicle end, so that the vehicle end decrypts the encrypted upgrading information to obtain the new upgrading information and the first software upgrading frequency after determining to upgrade to the low version software according to the software upgrading rollback flag, and upgrades to the low version software through the software upgrading package after determining that the remote upgrading is legal according to the size relationship between the first software upgrading frequency and the second software upgrading frequency stored by itself and the corresponding relationship between the new upgrading information and the upgrading information, so as to guarantee the safety and legality of the upgrading when the user upgrades the low version software.

[0100] In some optional embodiments, as shown in FIG. 2, the network end 101 includes an authentication unit 201 and an upgrading unit 202, and the vehicle end 102 includes a vehicle authentication unit 203 and a display and input unit 204.

[0101] It should be noted that the upgrading unit 202 needs to perform a series of security operations such as encryption and signature on the software package when receiving the software upgrading task, and the vehicle authentication unit needs to perform decryption and signature verification on the upgrading package to protect the confidentiality and legality of the upgrading package. The above process is a necessary process of the secure upgrading process, and details can be referred to the description of the related technology, which will not be described here. The implementation steps of the embodiments of the present application are performed on the basis of the above process.

[0102] Optionally, as shown in FIG. 3, the authentication unit 201 mainly includes a key generation module 2011, a key storage module 2012 and an authentication module 2013, wherein the key generation module 2011 is used to generate a software upgrading key, for example, a software upgrading master key, an asymmetric key pair composed of a software upgrading public key and a software upgrading private key; the key storage module 2012 is used to store the software upgrading key generated by the key generation module 2011; and the authentication module 2013 is mainly used to encrypt the upgrading information to obtain the encrypted upgrading information.

[0103] Optionally, referring to FIG. 3 again, the vehicle authentication unit 203 mainly includes a vehicle key management module 2031, a vehicle key storage module 2032 and an authentication module 2033, and the vehicle authentication unit 203 is used to determine the legal operation of the low version software in the software upgrading process. Among them, the vehicle key management module 2031 is used to receive the information sent by the network end, the vehicle key storage module 2032 is used to store the information sent by the network end, and the authentication module 2033 is used to decrypt the information sent by the network end and determine whether the remote upgrading is legal based on the decrypted information.

[0104] Referring to FIG. 3 again, the display unit 204 mainly comprises a display module 2041 and a vehicle-end authentication input module 2042, the vehicle-end authentication input module 2042 is used for receiving information input by a user, and the display module 2041 is used for displaying information.

[0105] In addition, the upgrade unit 202 manages the first software upgrade times stored in the network end through OTA_COUNT, and the initial value of OTA_COUNT is 0; the authentication module 2033 of the vehicle end manages the second software upgrade times stored in the vehicle end through V_OTA_COUNT, and the initial value of V_OTA_COUNT is 0.

[0106] According to the embodiment of the present application, a remote upgrade method is provided. It should be noted that the steps shown in the flowchart can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0107] In the embodiment, a remote upgrade method is provided, which can be used in the network end 101 and the vehicle end 102 as shown in FIG. 1. FIG. 4 is a schematic diagram of an interaction process of a remote upgrade system according to the embodiment of the present application, wherein the network end 101 is used to execute steps S101 to S104, the vehicle end 102 is used to execute steps S201 to S205, and the specific interaction process of the network end 101 and the vehicle end 102 is as follows.

[0108] In step S101, a software upgrade key is generated, and the software upgrade key is sent to the vehicle end.

[0109] Specifically, the embodiment of the present application mainly includes symmetric authentication and asymmetric authentication. In the symmetric authentication scheme, the network end generates a software upgrade master key, and sends the software upgrade master key to the vehicle end after encryption; in the asymmetric authentication scheme, the network end generates an asymmetric key pair composed of a software upgrade public key and a software upgrade private key, and sends the software upgrade public key to the vehicle end.

[0110] In step S201, the software upgrade key sent by the network end is received.

[0111] Specifically, in the symmetric authentication scheme, the vehicle end receives the ciphertext of the software upgrade master key encrypted by the network end, and obtains the software upgrade master key by decrypting the ciphertext; in the asymmetric authentication scheme, the vehicle end receives the software upgrade public key sent by the network end, and the software upgrade public key corresponds to the software upgrade private key of the network end.

[0112] It should be noted that steps S101 and S201 are essentially processes of initializing the network side and the vehicle side, and the network side and the vehicle side maintain communication connection during the initialization process. After the initialization is completed, the vehicle can be upgraded through an online mode, and can also be offline to obtain data required for upgrading to upgrade. During the offline upgrading process, the vehicle side can disconnect the communication connection with the network side.

[0113] In addition, the network side manages the first software upgrade times through OTA_COUNT during initialization, and the initial value is 0. The vehicle side manages the second software upgrade times through V_OTA_COUNT, and the initial value is 0.

[0114] Step S202, sending a software upgrade task to the network side.

[0115] Specifically, the vehicle side generates a software upgrade task according to the current software version installed by the controller, the required software upgrade version and other information, and sends an upgrade request to the network side.

[0116] Step S102, after receiving the software upgrade task sent by the vehicle side, updating the first software upgrade times, and detecting whether the software upgrade task is a low version software upgrade task, obtaining a software upgrade rollback flag.

[0117] Specifically, the network side records the first software upgrade times after receiving a software upgrade task each time, and judges whether the vehicle side wants to upgrade to a low version software, generates a software upgrade rollback flag, so that the vehicle side determines whether to perform authentication through the software upgrade rollback flag.

[0118] In some optional embodiments, the above step S102 comprises:

[0119] Step a1, after receiving the software upgrade task, adding one to the first software upgrade times, and obtaining the software upgrade version and the current software version based on the software upgrade task.

[0120] Step a2, if it is detected that the software upgrade version is not higher than the current software version, it is determined that the software upgrade task is a low version software upgrade task, and the software upgrade rollback flag is set to one.

[0121] Step a3, if it is detected that the software upgrade version is not higher than the current software version, it is determined that the software upgrade task is not a low version software upgrade task, and the software upgrade rollback flag is set to zero.

[0122] Exemplarily, referring to Fig. 2 again, when receiving the software upgrade task, the upgrade unit increments the counter OTA_COUNT representing the first software upgrade times by 1, judges the software upgrade version number, sets the software upgrade rollback flag RE_OTA_FLAG to 0 when the software upgrade version is higher than the current software version of the vehicle-side controller, and sets the RE_OTA_FLAG to 1 when the software upgrade version is lower than or equal to the current software version of the vehicle-side controller.

[0123] In step S103, the upgrade information including the first software upgrade times is encrypted by the software upgrade key to generate encrypted upgrade information.

[0124] Specifically, under the symmetric authentication scheme, the upgrade information mainly includes the first software upgrade times, software information and authentication information for upgrade authentication, and the encrypted upgrade information mainly includes encrypted authentication information obtained by encrypting the authentication information; under the asymmetric authentication scheme, the upgrade information mainly includes the first software upgrade times, authentication information for upgrade authentication and digest authentication information obtained by encrypting the authentication information, and the encrypted upgrade information mainly includes signature authentication information obtained by encrypting the digest authentication information.

[0125] In step S104, the upgrade information, the encrypted upgrade information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task are sent to the vehicle side.

[0126] Specifically, under the symmetric authentication scheme, the network side sends the software information, the authentication information, the encrypted authentication information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task to the vehicle side; under the asymmetric authentication scheme, the network side sends the authentication information, the signature authentication information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task to the vehicle side.

[0127] In step S203, the upgrade information, the encrypted upgrade information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task returned by the network side are received.

[0128] In step S204, after determining to upgrade to the low-version software according to the software upgrade rollback flag, the encrypted upgrade information is decrypted according to the software upgrade key to obtain new upgrade information and the first software upgrade times stored by the network side.

[0129] Specifically, the vehicle side decrypts the encrypted upgrade information according to the software upgrade master key or the software upgrade public key to obtain new upgrade information and the first software upgrade times OTA_COUNT of the network side.

[0130] Step S205, after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the correspondence relationship between the new upgrade information and the upgrade information, the vehicle is upgraded to the low version software through the software upgrade package.

[0131] Specifically, the vehicle determines whether the remote upgrade is legal according to the size relationship between the first software upgrade number OTA_COUNT and the second software upgrade number V_OTA_COUNT and the correspondence relationship between the new upgrade information and the upgrade information, and only when the remote upgrade is legal, the vehicle is allowed to be upgraded to the low version software through the software upgrade package.

[0132] The remote upgrade method provided by the embodiment of the present application uses the network end to generate the first software upgrade number recording the software upgrade number, the software upgrade rollback flag representing whether it is a low version software upgrade task, and the upgrade information, the encrypted upgrade information and the software upgrade package required by the vehicle end, so as to facilitate the vehicle end to decrypt the encrypted upgrade information to obtain the new upgrade information and the first software upgrade number after determining to upgrade to the low version software according to the software upgrade rollback flag, and to upgrade to the low version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the correspondence relationship between the new upgrade information and the upgrade information, thereby guaranteeing the safety and legality of the upgrade when the user upgrades the low version software.

[0133] The embodiment of the present application can control the permission of upgrading the low version legal software when the user upgrades the software lower than the current software version, meet the user's independent and legal upgrade of the low version software, avoid the illegal upgrade of the legal low version software by other illegal users, and avoid the security risks caused by the security vulnerabilities of the low version software.

[0134] In the embodiment, a remote upgrade method is provided, which can be used in a network end 101 and a vehicle end 102 as shown in FIG. 1, and FIG. 5 is a schematic diagram of an interaction process of a remote upgrade system according to the embodiment of the present application, wherein the network end 101 is used to perform steps S301 to S306, the vehicle end 102 is used to perform steps S401 to S406, and the specific interaction process of the network end 101 and the vehicle end 102 is as follows.

[0135] Step S301, generating a software upgrade master key and sending the software upgrade master key to the vehicle end.

[0136] In some optional embodiments, the above step S301 includes:

[0137] Step b1, after receiving the public key sent by the vehicle end, generating a software upgrade master key and a transmission protection key.

[0138] Step b2, asymmetrically encrypt the transmission protection key by the public key to obtain the ciphertext transmission protection key, and symmetrically encrypt the software upgrade master key according to the ciphertext transmission protection key to obtain the ciphertext software upgrade master key.

[0139] Step b3, send the ciphertext software upgrade master key and the ciphertext transmission protection key to the vehicle end.

[0140] Exemplarily, referring to Fig. 3 again, the vehicle-end-key management module generates an asymmetric key, the private key SK is securely stored in the vehicle-end-key management module, and the public key PK is sent to the authentication unit through an offline or online manner to request the authentication unit to provide the OTA_MASTER_KEY.

[0141] Referring to Fig. 3 again, the authentication unit calls the key generation module to randomly generate a 128-bit or 256-bit random number as the software upgrade master key OTA_MASTER_KEY, the OTA_MASTER_KEY is securely stored in the key storage module and cannot be exported in plaintext, and generally the key generation module can be implemented by using a cryptographic machine (Hardware Security Module, HSM) device. Then, the authentication unit calls the key generation module to randomly generate a 128-bit or 256-bit random number as the transmission protection key TRANS_KEY, and the TRANS_KEY is used to encrypt and protect the OTA_MASTER_KEY.

[0142] Optionally, after receiving the public key PK, the authentication unit asymmetrically encrypts the transmission protection key TRANS_KEY by the PK to obtain the ciphertext transmission protection key ENC_TRANS_KEY. The asymmetric encryption algorithm can be a general and secure algorithm such as RSA (Rivest-Shamir-Adleman Algorithm) or ECC (Elliptic Curve Cryptography), and the embodiments of the present application are not limited thereto.

[0143] Next, the software upgrade master key OTA_MASTER_KEY is symmetrically encrypted by the ciphertext transmission protection key ENC_TRANS_KEY to obtain a ciphertext software upgrade master key ENC_OTA_MASTER_KEY. Exemplarily, the symmetric encryption algorithm can be a general and secure algorithm such as an Advanced Encryption Standard (AES) or an SM4 Block Cipher Algorithm (SM4), and the embodiments of the present application are not limited thereto. Finally, the ENC_TRANS_KEY and the ENC_OTA_MASTER_KEY are sent to the vehicle-side key management module.

[0144] In step S401, the software upgrade master key sent by the network side is received.

[0145] In some optional embodiments, the vehicle side decrypts the ciphertext transmission protection key by using a private key corresponding to the public key to obtain the transmission protection key, and decrypts the ciphertext software upgrade master key based on the transmission protection key to obtain the software upgrade master key.

[0146] Exemplarily, the vehicle-side key management module decrypts the ciphertext transmission protection key ENC_TRANS_KEY by using the private key SK to obtain the transmission protection key TRANS_KEY, and then decrypts the ciphertext software upgrade master key ENC_OTA_MASTER_KEY by using the obtained transmission protection key TRANS_KEY to obtain the software upgrade master key OTA_MASTER_KEY, and stores the obtained software upgrade master key OTA_MASTER_KEY in the vehicle-side key storage module in a secure manner.

[0147] Thus, the software upgrade master key is generated by the network side, and then the software upgrade master key is encrypted and sent to the vehicle side, so that the vehicle side obtains the software upgrade master key of the network side after decryption, and the security is improved.

[0148] In step S402, the software upgrade task is sent to the network side. For details, please refer to step S202 of the embodiment shown in FIG. 4, which will not be described here.

[0149] In step S302, after receiving the software upgrade task sent by the vehicle side, the first software upgrade number is updated, and it is detected whether the software upgrade task is a low-version software upgrade task to obtain a software upgrade rollback flag. For details, please refer to step S102 of the embodiment shown in FIG. 4, which will not be described here.

[0150] In step S303, the authentication information is generated based on the first software upgrade number.

[0151] Specifically, the authentication information CERT_INFO is information used by the vehicle-side authentication module to determine whether the remote upgrade process is a legal action, and the content thereof mainly consists of a random number RNG and a first software upgrade number OTA_COUNT.

[0152] In step S304, the software information is symmetrically encrypted by the software upgrade master key to obtain a rollback service key.

[0153] In some optional embodiments, referring again to FIG. 3, the upgrade unit generates the software information SOFT_INFO and the authentication information CERT_INFO, and then sends the software information SOFT_INFO and the authentication information CERT_INFO used for authentication to the authentication module in the authentication unit. The authentication module calls the OTA_MASTER_KEY to perform a secure operation on the SOFT_INFO based on a symmetric encryption algorithm to obtain a rollback service key OTA_RE_KEY of the current software version.

[0154] The software information SOFT_INFO is a derivation factor used to generate the OTA_RE_KEY of the one-time pad related to the upgrade service, and is composed of the software version number SOFT_VN (including the current software version and the software upgrade version), the software upgrade rollback flag RE_OTA_FLAG, and the like.

[0155] In step S305, the authentication information is symmetrically encrypted by the rollback service key to obtain encrypted authentication information.

[0156] In some optional embodiments, referring again to FIG. 3, the authentication unit calls the rollback service key OTA_RE_KEY to perform a secure operation on the authentication information CERT_INFO based on a symmetric encryption algorithm to obtain the encrypted authentication information ENC_CERT_INFO, and then returns the ENC_CERT_INFO to the upgrade unit.

[0157] Thus, by encrypting the authentication information when generating and sending the authentication information used for upgrade authentication to the vehicle side, the security of transmission is improved.

[0158] In step S306, the software information, the authentication information, the encrypted authentication information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle side.

[0159] Exemplarily, referring again to FIG. 3, after receiving the encrypted authentication information ENC_CERT_INFO, the upgrade unit sends the encrypted authentication information ENC_CERT_INFO, the authentication information CERT_INFO, the software information SOFT_INFO, the software upgrade package, and the software upgrade rollback flag RE_OTA_FLAG to the vehicle-side authentication unit through the OTA channel.

[0160] Step S403, receiving the software information, the authentication information, the encrypted authentication information, the software upgrade rollback flag and the software upgrade package corresponding to the software upgrade task returned by the network side.

[0161] Step S404, after determining to upgrade to the low version software according to the software upgrade rollback flag, performing symmetric encryption on the software information according to the software upgrade master key to obtain the rollback service key.

[0162] Specifically, the software upgrade rollback flag is used to indicate the software upgrade state, when its value is 0, it indicates that the upgrade version is higher than the current software version of the vehicle side, which is the normal software upgrade process; when the value is 1, it indicates that the upgrade version is lower than the current software version of the vehicle side, which is a special upgrade process, and the vehicle side needs to authenticate the upgrade process to determine whether the low version remote upgrade is legal.

[0163] Exemplarily, referring to Fig. 3 again, when the vehicle side authentication unit determines that RE_OTA_FLAG=0, it indicates that it is a normal upgrade process, and then passes; when RE_OTA_FLAG=1, it indicates that it is a special upgrade process, and needs to be authenticated. When the vehicle side authentication unit determines that authentication is needed, the authentication module first calls the software upgrade master key OTA_MASTER_KEY to perform a secure operation based on a symmetric encryption algorithm on the software information SOFT_INFO, and the operation mode is the same as that of the authentication module calculating OTA_RE_KEY, to obtain the rollback service key OTA_RE_KEY.

[0164] Step S405, decrypting the encrypted authentication information by the rollback service key to obtain the decrypted new authentication information, and extracting the first software upgrade count stored in the network side from the new authentication information.

[0165] Exemplarily, referring to Fig. 3 again, the authentication module decrypts the encrypted authentication information ENC_CERT_INFO by the rollback service key OTA_RE_KEY to obtain new CERT_INFO', and extracts the first software upgrade count OTA_COUNT in the new CERT_INFO'.

[0166] Thus, the encrypted information sent by the network side is decrypted by the software upgrade master key, so as to facilitate the subsequent remote upgrade legality judgment and improve the security of information transmission.

[0167] Step S406, after determining the remote upgrade to be legal according to the size relationship between the first software upgrade count and the second software upgrade count stored by itself and the corresponding relationship between the new authentication information and the authentication information, upgrading to the low version software by the software upgrade package.

[0168] In some optional embodiments, the step S406 comprises:

[0169] Step c1, if the first software upgrade number is detected to be greater than the second software upgrade number, it is determined whether the new authentication information is consistent with the authentication information.

[0170] Step c2, if the new authentication information is detected to be consistent with the authentication information, it is determined that the remote upgrade is legal, the value of the first software upgrade number is assigned to the second software upgrade number, and the step of upgrading to the low-version software through the software upgrade package is performed.

[0171] Step c3, if the new authentication information is detected to be inconsistent with the authentication information, or the first software upgrade number is not greater than the second software upgrade number, the upgrade is stopped.

[0172] Exemplarily, referring to Fig. 3 again, after the first software upgrade number OTA_COUNT in the new CERT_INFO' is extracted, it is compared with the second software upgrade number V_OTA_COUNT stored in the authentication module. If OTA_COUNT>V_OTA_COUNT, the CERT_INFO' is compared with the issued CERT_INFO. If they are the same, it is determined that the upgrade of the low-version software is a legal behavior, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If the CERT_INFO' is not the same as the issued CERT_INFO, it is determined to be abnormal, and the upgrade is interrupted. If OTA_COUNT≤V_OTA_COUNT, it is determined to be illegal upgrade, and the upgrade is terminated.

[0173] Therefore, by judging the size relationship between the first software upgrade number and the second software upgrade number, and judging the consistency relationship between the new authentication information and the authentication information, it is determined whether the upgrade of the low-version software is legal, the security of the remote upgrade is improved, and the security risk caused by the security vulnerability of the low-version software is avoided.

[0174] The remote upgrade method provided by the embodiment of the application uses the network end to generate the first software upgrade number recording the software upgrade number, the software upgrade rollback flag representing whether it is a low-version software upgrade task, and the software information, the authentication information, the encrypted authentication information and the software upgrade package required by the vehicle end, so that the vehicle end decrypts the encrypted authentication information to obtain the new authentication information and the first software upgrade number after determining to upgrade to the low-version software according to the software upgrade rollback flag, and upgrades to the low-version software through the software upgrade package after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new authentication information and the authentication information, so that the security and legality of the upgrade are ensured when the user upgrades the low-version software.

[0175] In the embodiment, a remote upgrading method is provided, which can be used in the network end 101 and the vehicle end 102 as shown in FIG. 1. FIG. 6 is a schematic diagram of an interaction process of a remote upgrading system according to the embodiment of the application, wherein the network end 101 is configured to perform step S501, and the vehicle end 102 is configured to perform steps S601 to S605. The specific interaction process of the network end 101 and the vehicle end 102 is as follows.

[0176] In step S501, a software upgrading master key is generated and sent to the vehicle end. For details, refer to step S301 of the embodiment shown in FIG. 5, which is not described here again.

[0177] In step S601, the software upgrading master key sent by the network end is received. For details, refer to step S401 of the embodiment shown in FIG. 5, which is not described here again.

[0178] In step S602, the software upgrading version and the current software version are obtained, and the software upgrading version and the current software version are compared to obtain a software upgrading rollback flag for indicating whether it is a low-version software upgrading task.

[0179] Specifically, when the software upgrading process is performed, the vehicle-end authentication unit judges the software version number. When the software upgrading version is higher than the current software version of the vehicle end, it is indicated that it is a normal upgrading process, and then the process is passed. When the software upgrading version is lower than or equal to the current software version of the vehicle end, it is indicated that it is a special upgrading process, and authentication is needed to determine whether the low-version remote upgrading is legal, thereby obtaining the software upgrading rollback flag RE_OTA_FLAG for indicating whether it is a low-version software upgrading task.

[0180] In step S603, after it is determined to upgrade to a low version according to the software upgrading rollback flag, the software upgrading version, the current software version and the software upgrading rollback flag are symmetrically encrypted to obtain a rollback service key, and the authentication information for upgrading authentication input by the user in an offline manner, the encrypted authentication information and the software upgrading package are received.

[0181] Exemplarily, referring again to FIG. 3, when the vehicle-end authentication unit determines that authentication is needed, the authentication module performs a secure operation on the software version number SOFT_VN including the software upgrading version and the current software version and the software upgrading rollback flag RE_OTA_FLAG based on a symmetric encryption algorithm by using the OTA_MASTER_KEY to obtain a rollback service key OTA_RE_KEY, and then prompts the user to input the authentication information CERT_INFO, the encrypted authentication information ENC_CERT_INFO and the software upgrading package through a display interface. The symmetric encryption operation is performed in the same way as the authentication module OTA_RE_KEY.

[0182] It should be noted that the authentication information, the encrypted authentication information and the software upgrade package are obtained by the user from the network side. The user can input the software upgrade task of the vehicle side to the network side. After obtaining the encrypted authentication information ENC_CERT_INFO and other data, the network side upgrade unit will offline the encrypted authentication information ENC_CERT_INFO, the authentication information CERT_INFO and the software upgrade package to the user.

[0183] Thus, in the offline scenario, the legal upgrade of the low version is performed by receiving the authentication information, the encrypted authentication information and the software upgrade package input by the user.

[0184] In step S604, the encrypted authentication information is decrypted by using the rollback service key to obtain the decrypted new authentication information, and the first software upgrade number stored in the network side is extracted from the new authentication information. For details, please refer to step S405 of the embodiment shown in FIG. 5, which will not be repeated here.

[0185] In step S605, after determining the remote upgrade to be legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new authentication information and the authentication information, the software is upgraded to the low version by using the software upgrade package. For details, please refer to step S406 of the embodiment shown in FIG. 5, which will not be repeated here.

[0186] The remote upgrade method provided in the embodiment of the present application generates a software upgrade master key by using the network side, and the vehicle side receives the software information, the authentication information, the encrypted authentication information and the software upgrade package input by the user in an offline manner, so that after the vehicle side determines to upgrade to the low version software according to the software upgrade rollback flag, the encrypted authentication information is decrypted by using the software upgrade master key to obtain the new authentication information and the first software upgrade number, and after determining the remote upgrade to be legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new authentication information and the authentication information, the software is upgraded to the low version by using the software upgrade package, thereby ensuring the security and legality of the upgrade when the user upgrades the low version software.

[0187] In the embodiment, a remote upgrade method is provided, which can be used in the network side 101 and the vehicle side 102 as shown in FIG. 1. FIG. 7 is a schematic diagram of the interaction process of the remote upgrade system according to the embodiment of the present application, wherein the network side 101 is used to perform steps S701 to S705, and the vehicle side 102 is used to perform steps S801 to S805. The specific interaction process of the network side 101 and the vehicle side 102 is as follows:

[0188] In step S701, an asymmetric key pair composed of a software upgrade public key and a software upgrade private key is generated, and the software upgrade public key is sent to the vehicle side.

[0189] In some optional embodiments, referring to Fig. 3 again, the authentication unit calls the key generation module to randomly generate an asymmetric key pair composed of the software upgrade public key OTA_MASTER_KEY_P and the software upgrade private key OTA_MASTER_KEY_S. The OTA_MASTER_KEY_S is securely stored in the key storage module and cannot be derived in plaintext, while the OTA_MASTER_KEY_P is sent to the vehicle end. Exemplarily, the key generation module is implemented by using a cryptographic machine (HSM) device.

[0190] Step S801, receiving the software upgrade public key sent by the network end.

[0191] Specifically, the authentication unit of the network end sends the public key OTA_MASTER_KEY_P to the vehicle authentication unit offline, and the vehicle authentication unit securely stores the OTA_MASTER_KEY_P in the vehicle-end key management module.

[0192] Step S802, sending the software upgrade task to the network end. For details, please refer to step S402 of the embodiment shown in Fig. 5, which will not be repeated here.

[0193] Step S702, after receiving the software upgrade task sent by the vehicle end, updating the first software upgrade times, and detecting whether the software upgrade task is a low-version software upgrade task, obtaining the software upgrade rollback flag. For details, please refer to step S302 of the embodiment shown in Fig. 5, which will not be repeated here.

[0194] Step S703, generating the authentication information based on the first software upgrade times. For details, please refer to step S303 of the embodiment shown in Fig. 5, which will not be repeated here.

[0195] Step S704, performing a digest operation on the authentication information to obtain the digest authentication information, and performing asymmetric encryption on the digest authentication information by using the software upgrade private key to obtain the signature authentication information.

[0196] In some optional embodiments, referring to Fig. 3 again, the upgrade unit sends the authentication information CERT_INFO used for authentication to the authentication module in the authentication unit. The authentication module performs a digest operation on the CERT_INFO to obtain the digest authentication information DIG_CERT_INFO. The digest operation algorithm can be any general and secure digest algorithm, such as SHA256, SM3, etc., which is not limited in the embodiments of the present application. Then, the software upgrade private key OTA_MASTER_KEY_S is called to perform a secure operation based on an asymmetric encryption algorithm on the digest authentication information DIG_CERT_INFO to obtain the signature authentication information SIG_CERT_INFO, and then returns the SIG_CERT_INFO to the upgrade unit.

[0197] Thus, by encrypting and digesting the authentication information when generating and sending the signed authentication information for upgrading authentication to the vehicle end, the security of transmission is improved.

[0198] In step S705, the authentication information, the signed authentication information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle end.

[0199] Exemplarily, referring to FIG. 3 again, after the upgrade unit receives the signed authentication information SIG_CERT_INFO, the signed authentication information SIG_CERT_INFO, the authentication information CERT_INFO, the software upgrade rollback flag, and the software upgrade package are sent to the vehicle authentication unit through the OTA channel.

[0200] In step S803, the authentication information, the signed authentication information, the software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task returned by the network end are received.

[0201] In step S804, after determining to upgrade to the low-version software according to the software upgrade rollback flag, the signed authentication information is decrypted to obtain the digest authentication information according to the software upgrade public key, the authentication information is digested to obtain new digest authentication information, and the first software upgrade number is extracted from the authentication information.

[0202] Specifically, the software upgrade rollback flag is used to indicate the software upgrade state. When the value is 0, it indicates that the upgrade version is higher than the current software version of the vehicle end, which is a normal software upgrade process. When the value is 1, it indicates that the upgrade version is lower than the current software version of the vehicle end, which is a special upgrade process, and the vehicle end needs to authenticate the upgrade process to determine whether the low-version remote upgrade is legal.

[0203] Exemplarily, referring to FIG. 3 again, when the vehicle authentication unit determines that RE_OTA_FLAG=0, it indicates a normal upgrade process, and then passes. When RE_OTA_FLAG=1, it indicates a special upgrade process, which needs to be authenticated. When the vehicle authentication unit determines that authentication is needed, the authentication module calls the software upgrade public key OTA_MASTER_KEY_P to decrypt the signed authentication information SIG_CERT_INFO to obtain the digest authentication information DIG_CERT_INFO, and then digests the received authentication information CERT_INFO to obtain new digest authentication information DIG_CERT_INFO'. The digesting method is the same as the algorithm used by the authentication module. In addition, the first software upgrade number in the authentication information CERT_INFO is extracted.

[0204] Thus, the signature authentication information sent by the network end is decrypted by the software upgrade public key, so as to facilitate subsequent remote upgrade legality judgment and improve the security of information transmission.

[0205] In step S805, after judging the remote upgrade legality according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new digest authentication information and the digest authentication information, the software is upgraded to the low version software through the software upgrade package.

[0206] In some optional embodiments, the step S805 includes:

[0207] In step d1, if it is detected that the new digest authentication information is consistent with the digest authentication information, it is judged whether the first software upgrade number is greater than the second software upgrade number.

[0208] In step d2, if it is detected that the first software upgrade number is greater than the second software upgrade number, it is judged that the remote upgrade is legal, the value of the first software upgrade number is assigned to the second software upgrade number, and the step of upgrading the software to the low version software through the software upgrade package is executed.

[0209] In step d3, if it is detected that the first software upgrade number is not greater than the second software upgrade number, or the new digest authentication information is not consistent with the digest authentication information, the upgrade is stopped.

[0210] For example, the authentication module compares whether the new digest authentication information DIG_CERT_INFO' is the same as the digest authentication information DIG_CERT_INFO. If they are different, the upgrade is terminated. If they are the same, the first software upgrade number OTA_COUNT is compared with the second software upgrade number V_OTA_COUNT stored in the authentication module. If OTA_COUNT>V_OTA_COUNT, it is judged that the upgrade of the low version software is a legal behavior, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If OTA_COUNT≤V_OTA_COUNT, it is judged that the upgrade is illegal, and the upgrade is terminated.

[0211] Thus, by judging the size relationship between the first software upgrade number and the second software upgrade number and judging the consistency relationship between the new digest authentication information and the digest information, it is judged whether the low version upgrade is legal, the security of the remote upgrade is improved, and the security risk caused by the security vulnerability of the low version software is avoided.

[0212] In this embodiment, a remote upgrading method is provided, which can be used in the network end 101 and the vehicle end 102 as shown in FIG. 1. FIG. 8 is a schematic diagram of an interaction process of a remote upgrading system according to an embodiment of the present application, wherein the network end 101 is configured to perform step S901, and the vehicle end 102 is configured to perform steps S1001 to S1005. The specific interaction process of the network end 101 and the vehicle end 102 is as follows.

[0213] In step S901, an asymmetric key pair composed of a software upgrading public key and a software upgrading private key is generated, and the software upgrading public key is sent to the vehicle end. For details, refer to step S701 of the embodiment shown in FIG. 7, which will not be repeated here.

[0214] In step S1001, the software upgrading public key sent by the network end is received. For details, refer to step S801 of the embodiment shown in FIG. 7, which will not be repeated here.

[0215] In step S1002, the software upgrading version and the current software version are obtained, and the software upgrading version and the current software version are compared to obtain a software upgrading rollback flag for indicating whether it is a low-version software upgrading task. For details, refer to step S602 of the embodiment shown in FIG. 6, which will not be repeated here.

[0216] In step S1003, after it is determined to upgrade to a low-version software according to the software upgrading rollback flag, the authentication information for upgrading authentication, the signature authentication information, and the software upgrading package input by the user in an offline manner are received.

[0217] Exemplarily, referring again to FIG. 3, when the vehicle end authentication unit determines that authentication is needed, the authentication unit prompts the user to input the authentication information CERT INFO, the signature authentication information SIG CERT INFO, and the software upgrading package through the display module.

[0218] It should be noted that the authentication information CERT INFO, the signature authentication information SIG CERT INFO, and the software upgrading package are obtained by the user from the network end. The user can input the software upgrading task of the vehicle end to the network end. After the upgrading unit of the network end obtains the signature authentication information SIG CERT INFO and other data, the encrypted authentication information ENC CERT INFO, the authentication information CERT INFO, and the software upgrading package are offline to the user.

[0219] Thus, in an offline scenario, the low-version legal upgrading is performed by receiving the authentication information, the signature authentication information, and the software upgrading package input by the user.

[0220] Step S1004, the signature authentication information is decrypted according to the software upgrade public key to obtain digest authentication information, the authentication information is subjected to digest operation to obtain new digest authentication information, and the first software upgrade number is extracted from the authentication information. For details, please refer to step S804 of the embodiment shown in FIG. 7, which will not be repeated here.

[0221] Step S1005, after determining that the remote upgrade is legal according to the size relationship between the first software upgrade number and the second software upgrade number stored by itself and the corresponding relationship between the new digest authentication information and the digest authentication information, the software is upgraded to the low version software through the software upgrade package. For details, please refer to step S805 of the embodiment shown in FIG. 7, which will not be repeated here.

[0222] The remote upgrade method of the embodiment of the present application will be further described in detail in combination with multiple application scenarios. The remote upgrade method can be applied to the remote upgrade system shown in FIG. 3.

[0223] 1) When the symmetric cryptographic algorithm is used:

[0224] The authentication unit generates a software upgrade master key, which is used for secure operation based on an encryption algorithm on the software information SOFT_INFO input by the upgrade unit to obtain the rollback service key OTA_RE_KEY of the current software version. The rollback service key OTA_RE_KEY is used for legality and upgrade permission protection of the upgrade version.

[0225] The upgrade unit is used for managing and issuing the upgrade software version. When it is determined that the software upgrade version is lower than the current vehicle software version, the software upgrade rollback flag RE_OTA_FLAG is generated.

[0226] Optionally, the upgrade unit generates authentication information CERT_INFO, encrypts the CERT_INFO through the OTA_RE_KEY to obtain encrypted authentication information ENC_CERT_INFO, and then issues the software upgrade package, the encrypted authentication information ENC_CERT_INFO, the authentication information CERT_INFO and the software upgrade rollback flag RE_OTA_FLAG to the vehicle-side authentication unit.

[0227] Scenario 1: When the online software upgrade process is performed, this scenario is generally used after the vehicle is put on the market, and the new version of software is unstable during the upgrade of the new version of software, and a large-scale upgrade to the low version of the mass-produced vehicle is needed. The vehicle-side authentication unit judges the software upgrade version. When the software upgrade version to be upgraded is higher than the current software version, it is passed. When it is lower than the current software version, the software information SOFT_INFO is extracted, and the software information SOFT_INFO is subjected to a secure operation based on a symmetric encryption algorithm through the preset software upgrade master key OTA_MASTER_KEY. The operation mode is the same as that of the authentication unit to generate the rollback service key OTA_RE_KEY. The rollback service key OTA_RE_KEY is obtained, the encrypted authentication information ENC_CERT_INFO is decrypted through the OTA_RE_KEY, the CERT_INFO' is obtained, and the CERT_INFO' is compared with the issued CERT_INFO. If they are the same, it is judged that the upgrade to the low version is a legal behavior. If they are not the same, it is judged as an exception, and the upgrade is interrupted.

[0228] Scenario 2: When the offline software upgrade process is performed, this scenario is mainly used in the test phase or the single vehicle type is upgraded to the low version through the offline mode such as the USB interface in the mass production stage. The vehicle-side authentication unit judges the software upgrade version. When the software upgrade version is lower than or equal to the vehicle-side software version number, it is explained that the special upgrade process needs to be authenticated. The authentication module calls the OTA_MASTER_KEY to perform a secure operation based on a symmetric encryption algorithm on SOFT_VN and RE_OTA_FLAG. The operation mode is the same as that of the authentication module OTA_RE_KEY. The OTA_RE_KEY is obtained, and then the display interface prompts the user to input the CERT_INFO and the ENC_CERT_INFO and other information.

[0229] The authentication module calls the OTA_RE_KEY to decrypt the encrypted authentication information ENC_CERT_INFO to obtain the CERT_INFO'. The first software upgrade count OTA_COUNT in the CERT_INFO' is extracted and compared with the second software upgrade count V_OTA_COUNT securely stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, the CERT_INFO' is compared with the issued CERT_INFO. If they are the same, it is judged that the upgrade to the low version is a legal behavior, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If they are not the same, it is judged as an exception, and the upgrade is interrupted. If OTA_COUNT≤V_OTA_COUNT, it is judged as illegal upgrade, and the upgrade is terminated.

[0230] 2) When the asymmetric cryptographic algorithm is used:

[0231] The upgrading unit, upon receiving the software upgrading task, increments a counter OTA_COUNT representing the number of software upgrades by 1, and then judges the software upgrade version number. When the software upgrade version number is higher than the current software version, the software upgrade rollback flag RE_OTA_FLAG is set to 0. When the software upgrade version number is lower than or equal to the current software version, the RE_OTA_FLAG is set to 1. Then, the authentication information CERT_INFO used for authentication is sent to the authentication module in the authentication unit.

[0232] The authentication module performs a digest operation on the authentication information CERT_INFO to obtain digest authentication information DIG_CERT_INFO. The digest operation algorithm can be any general and secure digest algorithm, such as SHA256, SM3, etc. Then, the authentication module calls the software upgrade private key OTA_MASTER_KEY_S to perform a secure operation based on an asymmetric encryption algorithm on the digest authentication information DIG_CERT_INFO to obtain signature authentication information SIG_CERT_INFO. Then, the SIG_CERT_INFO is returned to the upgrading unit.

[0233] Scenario 3: When online software upgrading is performed, this scenario generally occurs after the vehicle is put on the market. During the process of upgrading the new version software, the new version software is unstable, and it is necessary to upgrade the mass-produced vehicle to a low version. After the upgrading unit receives the SIG_CERT_INFO, the SIG_CERT_INFO, the CERT_INFO, the software upgrade package, the software upgrade rollback flag RE_OTA_FLAG, etc. are sent to the vehicle-side authentication unit through the OTA channel.

[0234] When the vehicle-end authentication unit judges that RE_OTA_FLAG = 0, it means that it is a normal upgrade process, and then it is passed. When RE_OTA_FLAG = 1, it means that it is a special upgrade process, and authentication is needed. When the vehicle-end authentication unit judges that authentication is needed, the authentication module decrypts SIG_CERT_INFO by using OTA_MASTER_KEY_P to obtain DIG_CERT_INFO, and then performs a digest operation on the received CERT_INFO to obtain DIG_CERT_INFO'. The digest operation method is the same as the algorithm used by the authentication module. Then, DIG_CERT_INFO' and DIG_CERT_INFO are compared. If they are different, the upgrade is terminated. If they are the same, OTA_COUNT in CERT_INFO is extracted and compared with V_OTA_COUNT stored in the authentication module. If OTA_COUNT > V_OTA_COUNT, it is judged that the upgrade of the low version is a legal behavior, and the value of OTA_COUNT is assigned to V_OTA_COUNT. If OTA_COUNT ≤ V_OTA_COUNT, it is judged that the upgrade is illegal, and the upgrade is terminated.

[0235] Scenario 4: When performing offline software upgrade, this scenario is mainly used for testing stage or troubleshooting single vehicle type through offline upgrade, such as USB interface upgrade of low version authentication. After the upgrade unit receives SIG_CERT_INFO, it is offline to the user.

[0236] The vehicle-end authentication unit judges the software upgrade version. When the software upgrade version is higher than the current software version, it means that it is a normal upgrade process, and then it is passed. When the software upgrade version is lower than or equal to the current software version, it means that it is a special upgrade process, and authentication is needed. When the vehicle-end authentication unit judges that authentication is needed, the authentication unit prompts the user to input CERT_INFO, SIG_CERT_INFO and other information through the display module.

[0237] The authentication module calls the OTA_MASTER_KEY_P to decrypt the SIG_CERT_INFO to obtain the DIG_CERT_INFO, and then performs a digest operation on the received CERT_INFO to obtain DIG_CERT_INFO', the digest operation method being the same as the algorithm used by the authentication module, and then compares whether the DIG_CERT_INFO' and the DIG_CERT_INFO are the same, if not, the upgrade is terminated, and if the same, the OTA_COUNT in the CERT_INFO is extracted and compared with the V_OTA_COUNT stored in the authentication module in a secure manner, if the OTA_COUNT > V_OTA_COUNT, it is judged that the upgrade of the low version is a legal behavior, and the value of the OTA_COUNT is assigned to the V_OTA_COUNT, if the OTA_COUNT ≤ V_OTA_COUNT, it is judged as illegal upgrade, and the upgrade is terminated.

[0238] The embodiment of the application provides a secure remote upgrade system for upgrading low version software, which is used for solving the problem of illegal upgrade of low version software by illegal users using known vulnerabilities of the low version software when the new version software needs to be upgraded to the low version software due to quality problems, and simultaneously performs security protection on illegal low version software upgrade in online upgrade and offline upgrade two upgrade scenes.

[0239] The embodiment of the application further provides a computer device, which can be applied to a network side.

[0240] Referring to FIG. 9, FIG. 9 is a structural schematic diagram of a computer device provided by an optional embodiment of the application. As shown in FIG. 9, the computer device comprises one or more first processors 10, a first memory 20, and an interface for connecting various components, including a high-speed interface and a low-speed interface. Various components are communicatively connected with each other by different buses, and can be installed on a common mainboard or in other manners as needed. The processor can process instructions executed in the computer device, including instructions stored in the memory or on the memory to display a GUI on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple storages. Similarly, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). In FIG. 9, one first processor 10 is taken as an example.

[0241] The first processor 10 can be a central processor, a network processor, or a combination thereof. The first processor 10 can further include a hardware chip. The hardware chip can be an application specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device can be a complex programmable logic device, a field programmable logic device, a general array logic, or any combination thereof.

[0242] The first memory 20 stores instructions executable by the at least one first processor 10 to cause the at least one first processor 10 to perform the methods illustrated in the above embodiments.

[0243] The first memory 20 can include a program storage area and a data storage area. The program storage area can store an operating system and application programs required by at least one function. The data storage area can store data created according to the use of the computer device, and the like. In addition, the first memory 20 can include a high-speed random access memory, and can further include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some alternative embodiments, the first memory 20 can optionally include a memory disposed remotely with respect to the first processor 10, and these remote memories can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0244] The first memory 20 can include a volatile memory, such as a random access memory, and can also include a non-volatile memory, such as a flash memory, a hard disk, or a solid state disk. The first memory 20 can further include a combination of the above-mentioned types of memories.

[0245] The computer device further includes an input device 30 and an output device 40. The first processor 10, the first memory 20, the input device 30, and the output device 40 can be connected through a bus or other means, and in FIG. 9, an example of connection through a bus is shown.

[0246] The input device 30 can receive inputted digital or character information, and generate key signal inputs related to the user settings and function controls of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touchpad, a pointing stick, one or more mouse buttons, a trackball, a joystick, and the like. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), a tactile feedback device (e.g., a vibration motor), and the like. The display device includes, but is not limited to, a liquid crystal display, a light emitting diode, a display, and a plasma display. In some alternative embodiments, the display device can be a touch screen.

[0247] The embodiments of the present application also provide a vehicle. Please refer to FIG. 10, which is a structural schematic diagram of a vehicle according to an optional embodiment of the present application. As shown in FIG. 10, the vehicle comprises one or more second processors 50, a second memory 60, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The vehicle also comprises a second input device 70 and a second output device 80. The second processor 50, the second memory 60, the second input device 70 and the second output device 80 can be connected through a bus or other means, and in FIG. 10, the connection through a bus is taken as an example. The communication process of the second processor 50, the second memory 60, the second input device 70 and the second output device 80 in the vehicle can refer to the description of the computer device above, and will not be repeated here.

[0248] The embodiments of the present application also provide a computer readable storage medium. The method according to the embodiments of the present application can be implemented in hardware, firmware, or recorded in a storage medium, or stored in a remote storage medium or a non-transitory machine readable storage medium and stored in a local storage medium by downloading computer code through a network, so that the method described herein can be processed by such software on a storage medium using a general purpose computer, a special purpose processor or programmable or special purpose hardware. The storage medium can be a magnetic disk, an optical disk, a read-only memory, a random access memory, a flash memory, a hard disk or a solid state disk, etc. Alternatively, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that the computer, processor, microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code, which is accessed and executed by the computer, processor or hardware when the software or computer code is accessed and executed by the computer, processor or hardware, to implement the method shown in the above embodiments.

[0249] Part of the present application can be applied as a computer program product, for example, computer program instructions, when executed by a computer, through the operation of the computer, the method and / or technical solutions according to the present application can be called or provided. Those skilled in the art should understand that the form of computer program instructions in computer readable medium includes but is not limited to source file, executable file, installation package file, etc. Correspondingly, the way of computer program instructions executed by computer includes but is not limited to: the computer directly executes the instructions, or the computer executes the corresponding compiled program after compiling the instructions, or the computer reads and executes the instructions, or the computer reads and installs the corresponding installed program after installing the instructions. Here, the computer readable medium can be any available computer readable storage medium or communication medium accessible to the computer.

[0250] While embodiments of the application have been described in connection with the preferred embodiments of the various figures, those of ordinary skill in the art will appreciate that various modifications and variations of the preferred embodiments can be employed without departing from the spirit and scope of the application.

Claims

1. A remote upgrade method, characterized in that, Applied to the network end, the method includes: Generate a software upgrade key and send the software upgrade key to the vehicle. After receiving a software upgrade task sent by the vehicle, update the first software upgrade count and check whether the software upgrade task is a low version software upgrade task to obtain a software upgrade rollback flag. The upgrade information, including the number of the first software upgrades, is encrypted using the software upgrade key to generate encrypted upgrade information. The upgrade information, encrypted upgrade information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task are sent to the vehicle terminal. After the vehicle terminal determines to upgrade to a lower version software based on the software upgrade rollback flag, it decrypts the encrypted upgrade information using the software upgrade key to obtain new upgrade information and a first software upgrade count. After determining the validity of the remote upgrade based on the relationship between the first software upgrade count and its own stored second software upgrade count, as well as the correspondence between the new upgrade information and the upgrade information, the vehicle terminal upgrades to the lower version software using the software upgrade package.

2. The method according to claim 1, characterized in that, The software upgrade key includes a software upgrade master key; the upgrade information also includes software information and authentication information used for upgrade authentication, and the encrypted upgrade information includes encrypted authentication information; The step of encrypting the upgrade information, including the number of the first software upgrades, using a software upgrade key to generate encrypted upgrade information includes: Based on the number of software upgrades mentioned above, generate authentication information; The software information is symmetrically encrypted using the software upgrade master key to obtain the rollback service key; wherein, the software information is generated based on the software upgrade version corresponding to the software upgrade task, the current software version, and the software upgrade rollback flag; The authentication information is symmetrically encrypted using the fallback service key to obtain encrypted authentication information.

3. The method according to claim 2, characterized in that, Sending the upgrade information, encrypted upgrade information, software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task to the vehicle includes: The software information, authentication information, encrypted authentication information, software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle terminal. After the vehicle terminal determines to upgrade to a lower version software based on the software upgrade rollback flag, it decrypts the encrypted authentication information based on the software upgrade master key and the software information. Based on the new authentication information obtained after decryption, it extracts the first software upgrade count. After determining the validity of the remote upgrade based on the relationship between the first software upgrade count and the second software upgrade count stored in the vehicle terminal, as well as the correspondence between the new authentication information and the authentication information, it upgrades to the lower version software using the software upgrade package.

4. The method according to claim 2, characterized in that, The process of generating a software upgrade key and sending the software upgrade key to the vehicle includes: After receiving the public key sent by the vehicle, a software upgrade master key and a transmission protection key are generated; The transmission protection key is asymmetrically encrypted using the public key to obtain the ciphertext transmission protection key, and the software upgrade master key is symmetrically encrypted using the ciphertext transmission protection key to obtain the ciphertext software upgrade master key. The encrypted software upgrade master key and the encrypted transmission protection key are sent to the vehicle terminal, so that the vehicle terminal can use the private key corresponding to the public key to decrypt the encrypted transmission protection key to obtain the transmission protection key, and decrypt the encrypted software upgrade master key based on the transmission protection key to obtain the software upgrade master key.

5. The method according to claim 1, characterized in that, The software upgrade key includes an asymmetric key pair consisting of a software upgrade public key and a software upgrade private key; the upgrade information also includes authentication information and digest authentication information for upgrade authentication, and the encrypted upgrade information includes signature authentication information; The step of encrypting the upgrade information, including the number of the first software upgrades, using a software upgrade key to generate encrypted upgrade information includes: Based on the number of software upgrades mentioned above, generate authentication information; The authentication information is digested to obtain digest authentication information, and the digest authentication information is asymmetrically encrypted using the software upgrade private key to obtain signature authentication information.

6. The method according to claim 5, characterized in that, Sending the upgrade information, encrypted upgrade information, software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task to the vehicle includes: The authentication information, signature authentication information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task are sent to the vehicle terminal. After the vehicle terminal determines to upgrade to a lower version software based on the software upgrade rollback flag, it decrypts the signature authentication information using the software upgrade public key to obtain the digest authentication information, performs a digest operation on the authentication information to obtain a new digest authentication information, extracts the first software upgrade count from the authentication information, and determines the remote upgrade is legitimate based on the relationship between the first software upgrade count and the second software upgrade count stored in the vehicle terminal, as well as the correspondence between the new digest authentication information and the digest authentication information. Then, it upgrades to the lower version software using the software upgrade package.

7. The method according to claim 1, characterized in that, Upon receiving a software upgrade task from the vehicle, the first software upgrade count is updated, and it is checked whether the software upgrade task is a low-version software upgrade task to obtain a software upgrade rollback flag, including: Upon receiving a software upgrade task, increment the first software upgrade count by one, and obtain the software upgrade version and the current software version based on the software upgrade task; If the detected software upgrade version is not higher than the current software version, then the software upgrade task is determined to be a low-version software upgrade task, and the software upgrade rollback flag is set to one. If the detected software upgrade version is not higher than the current software version, it is determined that the software upgrade task is not a low-version software upgrade task, and the software upgrade rollback flag is set to zero.

8. A remote upgrade method, characterized in that, Applied to the vehicle end, the method includes: Receive the software upgrade key sent from the network. Send a software upgrade task to the network terminal, and receive upgrade information, encrypted upgrade information, software upgrade rollback flag, and other information returned by the network terminal. The software upgrade package corresponding to the task; wherein, the encrypted upgrade information is obtained by the network end encrypting the upgrade information including the first software upgrade number using the software upgrade key, the first software upgrade number is obtained by the network end updating the current software upgrade number after receiving the software upgrade task, and the software upgrade rollback flag is obtained by the network end by detecting whether the software upgrade task is a low version software upgrade task; After determining to upgrade to a lower version of the software based on the software upgrade rollback flag, the encrypted upgrade information is decrypted based on the software upgrade key to obtain new upgrade information and the first software upgrade count stored on the network. After determining the remote upgrade to be legitimate based on the relationship between the first number of software upgrades and the second number of software upgrades stored in the software itself, as well as the correspondence between the new upgrade information and the upgrade information, the software is upgraded to a lower version using the software upgrade package.

9. The method according to claim 8, characterized in that, The software upgrade key includes a software upgrade master key; the upgrade information also includes software information and authentication information used for upgrade authentication, and the encrypted upgrade information includes encrypted authentication information; The upgrade information, encrypted upgrade information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task returned by the receiving network end include: Receive software information, authentication information, encrypted authentication information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task returned by the network end; The step of decrypting the encrypted upgrade information according to the software upgrade key to obtain new upgrade information and the first software upgrade count stored on the network includes: The software information is symmetrically encrypted using the software upgrade master key to obtain the rollback service key. The encrypted authentication information is decrypted using the rollback service key to obtain new authentication information, and the first software upgrade count stored on the network is extracted from the new authentication information.

10. The method according to claim 9, characterized in that, Before upgrading to a lower version of the software using the software upgrade package, the method further includes: If the number of first software upgrades is greater than the number of second software upgrades, then it is determined whether the new authentication information is consistent with the authentication information. If new authentication information is detected that matches the authentication information, the remote upgrade is deemed legitimate. The value of the first software upgrade count is assigned to the second software upgrade count, and the step of upgrading to a lower version of the software via the software upgrade package is executed. If new authentication information is detected that is inconsistent with the existing authentication information, or if the number of first software upgrades is not greater than the number of second software upgrades, then the upgrade process will stop.

11. The method according to claim 10, characterized in that, After receiving the software upgrade key sent from the network end, the method further includes: Obtain the software upgrade version and the current software version, compare the software upgrade version and the current software version, and obtain a software upgrade rollback flag to indicate whether it is a low-version software upgrade task. After determining to upgrade to a lower version based on the software upgrade rollback flag, the software upgrade version, the current software version, and the software upgrade rollback flag are symmetrically encrypted to obtain a rollback service key. The system then receives authentication information, encrypted authentication information, and the software upgrade package input by the user offline for upgrade authentication. The authentication information, encrypted authentication information, and the software upgrade package are obtained by the user from the network. The steps include decrypting the encrypted authentication information using the rollback service key to obtain the decrypted new authentication information, and subsequent steps.

12. The method according to claim 8, characterized in that, The software upgrade key includes an asymmetric key pair consisting of a software upgrade public key and a software upgrade private key; the upgrade information also includes authentication information and digest authentication information for upgrade authentication, and the encrypted upgrade information includes signature authentication information; The upgrade information, encrypted upgrade information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task returned by the receiving network end include: Receive authentication information, signature authentication information, software upgrade rollback flag, and software upgrade package corresponding to the software upgrade task returned by the network end; The step of decrypting the encrypted upgrade information according to the software upgrade key to obtain new upgrade information and the first software upgrade count stored on the network includes: The signature authentication information is decrypted using the software upgrade public key sent from the network to obtain the digest authentication information. A digest operation is then performed on the authentication information to obtain a new digest authentication information, and the first software upgrade count is extracted from the authentication information.

13. The method according to claim 12, characterized in that, Before upgrading to a lower version of the software using the software upgrade package, the method further includes: If new digest authentication information is detected that matches the digest authentication information, then it is determined whether the number of first software upgrades is greater than the number of second software upgrades; If the first software upgrade count is detected to be greater than the second software upgrade count, the remote upgrade is deemed legitimate, the value of the first software upgrade count is assigned to the second software upgrade count, and the step of upgrading to a lower version of the software via the software upgrade package is executed; If the number of first software upgrades is not greater than the number of second software upgrades, or if the new digest authentication information is inconsistent with the digest authentication information, the upgrade will be stopped.

14. The method according to claim 13, characterized in that, After receiving the software upgrade public key sent from the network end, the method further includes: Obtain the software upgrade version and the current software version, compare the software upgrade version and the current software version, and obtain a software upgrade rollback flag to indicate whether it is a low-version software upgrade task. After determining to upgrade to a lower version based on the software upgrade rollback flag, the system receives authentication information, signature authentication information, and software upgrade package input by the user offline for upgrade authentication. It then executes the step of decrypting the signature authentication information to obtain digest authentication information based on the software upgrade public key sent from the network, and subsequent steps. The authentication information, signature authentication information, and software upgrade package are obtained by the user from the network.

15. A remote upgrade system, characterized in that, The system includes a network terminal and a vehicle terminal; The network terminal is used to generate a software upgrade key and send the software upgrade key to the vehicle terminal; after receiving the software upgrade task sent by the vehicle terminal, it updates the first software upgrade count and checks whether the software upgrade task is a low version software upgrade task to obtain a software upgrade rollback flag. The upgrade information, including the number of the first software upgrades, is encrypted using the software upgrade key to generate encrypted upgrade information. The upgrade information, encrypted upgrade information, software upgrade rollback flag, and the software upgrade package corresponding to the software upgrade task are sent to the vehicle. The vehicle terminal is configured to, after determining that it is upgrading to a lower version of software based on the software upgrade rollback flag, decrypt the encrypted upgrade information according to the software upgrade key to obtain new upgrade information and a first software upgrade count. After determining that the remote upgrade is legitimate based on the relationship between the first software upgrade count and the second software upgrade count stored in the vehicle and the correspondence between the new upgrade information and the upgrade information, it upgrades to a lower version of software via the software upgrade package.

16. A computer device, characterized in that, include: A first memory and a first processor are interconnected and communicate with each other. The first memory stores first computer instructions, and the first processor executes the remote upgrade method according to any one of claims 1 to 7 by executing the first computer instructions.

17. A vehicle, characterized in that, include: A second memory and a second processor are communicatively connected to each other. The second memory stores second computer instructions, and the second processor executes the remote upgrade method of any one of claims 8 to 14 by executing the second computer instructions.

Citation Information

Patent Citations

  • Remote upgrading method and system, computer equipment and vehicle

    CN118612198A

  • Vehicle software upgrading method, vehicle-mounted terminal, vehicle and server

    CN113867748A

  • Security upgrading method and system of terminal, electronic equipment and readable storage medium

    CN115967502A

  • Safety upgrading method and device for engineering machinery and engineering machinery

    CN116886282A

  • Vehicle verification method, and related apparatus and system

    WO2023232045A1