Software upgrade method and related apparatus
By encrypting the software upgrade package and using OTA servers and CDN accelerators to transmit the encryption token and upgrade package, the security issues in the SOTA upgrade process are resolved, enabling safe and reliable online software upgrades.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- BEIJING SINGAUTO TECH CO LTD
- Filing Date
- 2025-11-10
- Publication Date
- 2026-05-15
AI Technical Summary
How to ensure the security of software upgrades when using SOTA (State Over-The-Air) for online upgrades and prevent data interception and cracking?
The software upgrade package is encrypted to generate an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token and the encrypted upgrade package are transmitted to the vehicle to be upgraded using the OTA server and CDN accelerator, respectively, for decryption and verification.
This improves the security of online software upgrades, reduces the possibility of data interception and cracking, and ensures the security and reliability of the upgrade process.
Smart Images

Figure CN2025133926_15052026_PF_FP_ABST
Abstract
Description
Software upgrading method and related device
[0001] Cross-reference to related applications
[0002] The present disclosure is based on and claims priority to Chinese Patent Publication No. 202411603648.8, published on February 11, 2025, the entire contents of which are hereby incorporated by reference into the present disclosure. TECHNICAL FIELD
[0003] The present disclosure relates to the field of software updates, and more particularly, to a software upgrading method and related device. BACKGROUND
[0004] OTA (Over-the-Air Technology) is a technology that connects through a server mobile communication network and a terminal network, ultimately realizing the update of mobile terminal memory data and improving the function and service of the terminal.
[0005] Automotive OTA is mainly divided into SOTA (Software Over-The-Air) and FOTA (Firmware Over-The-Air) according to the upgrade type, that is, using OTA to upgrade software and firmware. Among them, SOTA is the update and experience optimization of car machine functions such as car navigation, infotainment application, and human-computer interaction.
[0006] When using SOTA for upgrading in particular, how to ensure the security of software online upgrading is a technical problem that needs to be solved by those skilled in the art. SUMMARY
[0007] Therefore, the present disclosure provides a software upgrading method and related device to solve the problem of the need to ensure the security of software online upgrading when using SOTA for upgrading in particular.
[0008] To solve the above technical problems, the present disclosure adopts the following technical solutions:
[0009] A software upgrading method applied to a control end, the software upgrading method comprising:
[0010] After determining that the identity verification of the vehicle to be upgraded is passed, obtaining software parameter information of a device to be upgraded in the vehicle to be upgraded;
[0011] Based on the software parameter information, determining a software upgrading package of the device to be upgraded;
[0012] Encrypting the software upgrading package to obtain an encrypted upgrading package;
[0013] Generate an encryption token corresponding to the digest of the encryption upgrade package;
[0014] The encryption token is transmitted to the vehicle to be upgraded via an Over-the-Air (OTA) server, enabling the vehicle to decrypt the encryption upgrade package to obtain the software upgrade package. The encryption upgrade package is then transmitted to the vehicle to be upgraded via a Content Delivery Network (CDN) accelerator, allowing the vehicle to determine the digest of the encryption upgrade package corresponding to the encryption token. The software upgrade package and the digest of the encryption upgrade package are used by the vehicle to perform a software upgrade operation on the device to be upgraded.
[0015] Optionally, determine if the vehicle to be upgraded has passed authentication, including:
[0016] Obtain the actual verification information of the devices to be upgraded in the vehicle to be upgraded;
[0017] If the actual verification information is the same as the reference verification information of the device to be upgraded stored in the control terminal, the identity verification of the vehicle to be upgraded is determined to be successful.
[0018] Optionally, based on the software parameter information, determining the software upgrade package for the device to be upgraded includes:
[0019] Obtain the latest software version of the device to be upgraded;
[0020] Extract the current software version of the device to be upgraded from the software parameter information;
[0021] Based on the differences between the latest software version and the current software version, the software upgrade package for the device to be upgraded is determined.
[0022] Optionally, generating an encryption token corresponding to the digest of the encryption upgrade package includes:
[0023] Extract the digest of the encrypted upgrade package from the encrypted upgrade package;
[0024] A token is generated using the digest of the encryption upgrade package, the random password, and the symmetric encryption algorithm.
[0025] The token is encrypted to obtain an encrypted token.
[0026] A software upgrade method, applied to a vehicle to be upgraded, the software upgrade method comprising:
[0027] The control terminal obtains the encryption token transmitted by the server and the encryption upgrade package transmitted by the CDN accelerator. The encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal obtains the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package.
[0028] The encrypted upgrade package is decrypted to obtain the software upgrade package;
[0029] Determine the digest of the encryption upgrade package corresponding to the encryption token;
[0030] Based on the software upgrade package and the digest of the encrypted upgrade package, a software upgrade operation is performed on the device to be upgraded.
[0031] Optionally, determining the digest of the encryption upgrade package corresponding to the encryption token includes:
[0032] The encrypted token is decrypted to obtain the token;
[0033] The token is decomposed to obtain the digest of the encrypted upgrade package.
[0034] Optionally, based on the software upgrade package and the digest of the encrypted upgrade package, a software upgrade operation is performed on the device to be upgraded, including:
[0035] Extract the digest to be verified from the encrypted upgrade package;
[0036] The digest to be verified is compared with the digest of the encrypted upgrade package;
[0037] If the comparison results are consistent, the software upgrade package is sent to the device to be upgraded so that the device to be upgraded can perform the upgrade operation according to the software upgrade package.
[0038] A software upgrade device, applied to a control terminal, the software upgrade device comprising:
[0039] The information acquisition module is used to acquire the software parameter information of the device to be upgraded in the vehicle after confirming that the vehicle to be upgraded has passed the identity verification.
[0040] The upgrade package determination module is used to determine the software upgrade package for the device to be upgraded based on the software parameter information.
[0041] An encryption module is used to encrypt the software upgrade package to obtain an encrypted upgrade package;
[0042] The token generation module is used to generate an encrypted token corresponding to the digest of the encrypted upgrade package;
[0043] An upgrade control module is used to transmit the encryption token to the vehicle to be upgraded via an Over-the-Air (OTA) server, so that the vehicle to be upgraded can decrypt the encryption upgrade package to obtain the software upgrade package. The encryption upgrade package is then transmitted to the vehicle to be upgraded via a Content Delivery Network (CDN) accelerator, so that the vehicle to be upgraded can determine the digest of the encryption upgrade package corresponding to the encryption token. The software upgrade package and the digest of the encryption upgrade package are used by the vehicle to perform a software upgrade operation on the device to be upgraded.
[0044] A software upgrade device is applied to a vehicle to be upgraded, the software upgrade device comprising:
[0045] The data acquisition module is used to acquire the encryption token transmitted by the control terminal through the server and the encryption upgrade package transmitted through the CDN accelerator; wherein, the encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal acquires the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package; the decryption module is used to decrypt the encryption upgrade package to obtain the software upgrade package;
[0046] The digest determination module is used to determine the digest of the encryption upgrade package corresponding to the encryption token;
[0047] The upgrade processing module is used to perform a software upgrade operation on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package.
[0048] A software upgrade system includes a control terminal for performing the software upgrade method described above, and a vehicle to be upgraded for performing the software upgrade method described above.
[0049] This disclosure provides a software upgrade method and related apparatus. First, the identity of the vehicle to be upgraded is verified. Only if the verification is successful does the subsequent software upgrade operation proceed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package. An encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via an OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. In other words, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades. Attached Figure Description
[0050] To more clearly illustrate the technical solutions in the embodiments or related technologies of this disclosure, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0051] Figure 1 is a flowchart of a software upgrade method provided in an embodiment of this disclosure;
[0052] Figure 2 is a flowchart of a method for determining a software upgrade package provided in an embodiment of this disclosure;
[0053] Figure 3 is a schematic diagram of a cloud encryption scenario provided by an embodiment of this disclosure;
[0054] Figure 4 is a schematic diagram of a vehicle-side decryption scenario provided by an embodiment of this disclosure;
[0055] Figure 5 is a schematic diagram of a software upgrade method provided in an embodiment of this disclosure;
[0056] Figure 6 is a flowchart of another software upgrade method provided in an embodiment of this disclosure;
[0057] Figure 7 is a flowchart of another software upgrade method provided in an embodiment of this disclosure;
[0058] Figure 8 is a schematic diagram of a software upgrade device provided in an embodiment of this disclosure;
[0059] Figure 9 is a schematic diagram of another software upgrade device provided in an embodiment of this disclosure;
[0060] Figure 10 is a schematic diagram of the structure of a software upgrade system provided in an embodiment of this disclosure. Detailed Implementation
[0061] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.
[0062] OTA (Over-the-Air Technology) is a technology that uses network connections such as server mobile communication networks and terminals to update the memory data of mobile terminals, thereby improving the functions and services of the terminals.
[0063] Automotive OTA (Over-The-Air) updates are mainly divided into SOTA (Software Over-The-Air) and FOTA (Firmware Over-The-Air), which upgrade both software and firmware. SOTA updates and optimizes in-vehicle navigation, infotainment applications, and human-machine interaction functions. FOTA updates the vehicle's firmware system via the network, upgrading firmware systems including but not limited to those controlling the engine, electric motor, transmission, and chassis suspension.
[0064] When using SOTA for upgrades, ensuring the security of online software upgrades is a technical problem that urgently needs to be solved by those skilled in the art.
[0065] This disclosure provides a software upgrade method and related apparatus. First, the identity of the vehicle to be upgraded is verified. Only if the verification is successful does the subsequent software upgrade operation proceed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package. An encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via an OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0066] Based on the above, this disclosure provides a software upgrade method in one embodiment, primarily using State Over-The-Air (SOTA) online software upgrades. SOTA helps users remotely fix bugs, unlock new features, unlock configurations, and perform remote checks, improving vehicle efficiency and saving users significant time spent traveling to and from dealerships. The software upgrade method mainly involves two components: a control terminal and the vehicle to be upgraded. The control terminal, which can be cloud-based, is primarily used for software upgrade control operations, such as determining and distributing the software upgrade package. The vehicle to be upgraded refers to the entity requiring software upgrades; its type, model, and manufacturer are not limited. The vehicle contains devices to be upgraded, such as battery controllers, in-vehicle navigation software, infotainment applications, and human-machine interface software—any software that meets the requirements for SOTA upgrades is acceptable.
[0067] Referring to Figure 1, a software upgrade method may include:
[0068] S11. After confirming that the identity verification of the vehicle to be upgraded has passed, the control terminal obtains the software parameter information of the device to be upgraded in the vehicle.
[0069] In practical applications, before upgrading vehicles, upgrade strategies can be created for different controllers of different vehicle models. For example, this upgrade could involve upgrading the infotainment applications of 1000 B-model vehicles in Zone A, or upgrading the battery controllers of all vehicles in Zone A. The specific upgrade strategy would be set by the upgrade personnel.
[0070] After identifying the vehicles to be upgraded, i.e., the scope of the upgrade, an upgrade strategy is developed. To ensure that no problems occur during the upgrade process, the upgrade strategy needs to be tested. Only after the test is passed can the upgrade operation be allowed. In addition, a necessary internal review mechanism is required before the upgrade task is released.
[0071] After the upgrade strategy and internal review are approved, the upgrade can begin. During the upgrade, the identity of the vehicle to be upgraded needs to be verified in advance to ensure that the vehicle's current communication is normal and its identity is legitimate.
[0072] During identity verification, in this embodiment, communication can be established between the cloud and the vehicle to be upgraded to obtain the actual verification information of the device to be upgraded within the vehicle. This actual verification information may include seed information. Specifically, the cloud sends a seed request to the vehicle to be upgraded, the vehicle to be upgraded sends the seed request to the device to be upgraded within the vehicle, and the device to be upgraded sends its own seed to the cloud via the vehicle to be upgraded.
[0073] The vehicle to be upgraded is equipped with a main controller (TU), which can be a T-BOX (Telematics BOX). The main controller TU acts as a communication device between the cloud and the device to be upgraded. The cloud sends a seed request to the main controller TU, which then forwards the seed request to the device to be upgraded. The device to be upgraded then sends its own seed to the cloud through the main controller TU.
[0074] The reference verification information of the device to be upgraded, stored internally in the cloud, specifically refers to the legitimate seed of the device to be upgraded. If the actual verification information is the same as the reference verification information of the device to be upgraded stored on the control terminal, the control terminal determines that the identity verification of the vehicle to be upgraded has passed. That is, if the seed transmitted by the device to be upgraded is the same as the legitimate seed of the device to be upgraded stored in the cloud, it means that the identity verification of the device to be upgraded and the vehicle to be upgraded has passed, and the upgrade operation can be performed.
[0075] When performing the upgrade operation, it is necessary to determine the upgrade package for this upgrade. At this time, it is necessary to obtain the software parameter information of the device to be upgraded in the vehicle to be upgraded. The software parameter information can be such as the software version number. At this time, the cloud still sends the request to the device to be upgraded through the main controller TU, and the device to be upgraded responds with the software version number.
[0076] It should be noted that the software version number and seed can be obtained together to reduce the number of communications.
[0077] S12. The control terminal determines the software upgrade package for the device to be upgraded based on the software parameter information.
[0078] Specifically, taking an ECU (Electronic Control Unit) as an example, the software package for the new version of the ECU's software is tested and uploaded to the OTA cloud system. Then, the OTA cloud system will automatically or manually generate a software upgrade package based on the current software package uploaded by the ECU and the latest software version.
[0079] Specifically, referring to Figure 2, step S12 may include:
[0080] S21. Obtain the latest software version of the device to be upgraded.
[0081] Specifically, the latest software version is the new software version of the aforementioned ECU, which can be uploaded by technicians, such as V3.0.
[0082] S22. Extract the current software version of the device to be upgraded from the software parameter information.
[0083] Specifically, the device to be upgraded is extracted directly from the software parameter information, such as the current software version number of the ECU, which is V1.0.
[0084] S23. Based on the difference information between the latest software version and the current software version, determine the software upgrade package for the device to be upgraded.
[0085] Specifically, if the device to be upgraded needs to be upgraded from V1.0 to V3.0, then the different content from V1.0 needs to be obtained from the V3.0 software package to obtain the software upgrade package for the device to be upgraded.
[0086] S13. The control terminal encrypts the software upgrade package to obtain an encrypted upgrade package.
[0087] In this embodiment, as shown in Figure 3, for the software upgrade package Up, the cloud generates an encrypted upgrade package Up′ using a symmetric encryption algorithm. Symmetric encryption algorithms can include DES (Data Encryption Standard), 3DES (Triple DES), AES (Advanced Encryption Standard), XOR (exclusive OR), etc. Alternatively, asymmetric encryption algorithms can be selected for encryption operations as needed.
[0088] S14. The control terminal generates an encryption token corresponding to the digest of the encryption upgrade package.
[0089] Specifically, the cloud extracts the digest of the encrypted upgrade package from Up′, and then uses the digest, a random password, and a symmetric encryption algorithm to generate a token using the formula T = Base64(D, Cm, Rp). This token is then uploaded to the cloud's PKI (Public Key Infrastructure) server. The PKI server encrypts the token to obtain an encrypted token, which is obtained using the following formula: T' = Encrypt(T).
[0090] This formula represents the use of an encryption algorithm (usually based on a public key in a Public Key Infrastructure, PKI) to encrypt the original token T, generating an encrypted token T', where T = original token, T' = encrypted token, and Encrypt = encryption operation.
[0091] S15. The control terminal transmits the encryption token to the vehicle to be upgraded via the OTA server.
[0092] Specifically, in this embodiment of the disclosure, in order to improve the reliability of data transmission, the encryption token and the encryption upgrade package are transmitted separately.
[0093] The encrypted token is transmitted to the main controller (TU) in the vehicle to be upgraded via the OTA server shown in Figure 3.
[0094] S16. The control terminal transmits the encrypted upgrade package to the vehicle to be upgraded via a CDN accelerator.
[0095] Specifically, referring to Figure 3, for the encrypted upgrade package Up′, it is sent to the main controller TU in the vehicle to be upgraded via a CDN (Content Delivery Network) accelerator.
[0096] In this embodiment, a CDN accelerator is used to improve transmission efficiency.
[0097] It should be noted that the encrypted upgrade package can be transmitted to the vehicle to be upgraded via CDN accelerator after it is generated, or it can be transmitted sequentially with the encryption token. When transmitting sequentially, the transmission order is not required; the encrypted upgrade package can be transmitted first, followed by the encryption token.
[0098] S17. The vehicle to be upgraded decrypts the encrypted upgrade package to obtain the software upgrade package.
[0099] Specifically, as shown in Figure 4, the decryption process of the vehicle to be upgraded is the reverse operation of the cloud encryption process.
[0100] After receiving the encrypted upgrade package Up′, the main controller TU in the vehicle to be upgraded decrypts it using a symmetric decryption algorithm to obtain the software upgrade package.
[0101] S18. The vehicle to be upgraded determines the digest of the encrypted upgrade package corresponding to the encrypted token.
[0102] Specifically, the main controller TU decrypts the encrypted token to obtain a token, and then decomposes the token to obtain the digest of the encrypted upgrade package, a random password, and a symmetric encryption algorithm. Alternatively, after receiving the encrypted token, the main controller TU performs asymmetric decryption through secure key storage to generate a token, which is then further decomposed into the encrypted upgrade package digest, a random password, and a symmetric encryption algorithm.
[0103] S19. The vehicle to be upgraded performs a software upgrade operation on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package.
[0104] In practical applications, encrypted upgrade packages or encryption tokens may be illegally tampered with, causing the encrypted upgrade packages or encryption tokens received by the vehicle to be illegitimate data. Therefore, it is necessary to perform verification operations on encrypted upgrade packages and encryption tokens. Only after the verification is successful can the upgrade operation be performed to ensure the security of the upgrade.
[0105] During verification, since the token contains a digest of the encrypted upgrade package, and the digest can also be extracted from the encrypted upgrade package, tamper verification can be performed by comparing whether the two digests are the same.
[0106] In practice, a digest, called the verification digest, is extracted from the encrypted upgrade package. This verification digest is compared with the digest of the encrypted upgrade package extracted from the token, or a signature verification operation is performed. If the comparison results are consistent, it indicates that the encrypted upgrade package and encrypted token received by the vehicle are correct and have not been tampered with. At this point, the upgrade operation can proceed, and the software upgrade package is sent to the device to be upgraded, enabling the device to perform the upgrade operation based on the software upgrade package. During the upgrade process, the device to be upgraded can report the upgrade status in real time or periodically, allowing the cloud to monitor the upgrade progress. Additionally, the cloud can set an upgrade timeout. If the device to be upgraded fails to complete the upgrade within the timeout period, an upgrade exception message is output to the cloud, prompting the cloud to re-perform the upgrade operation.
[0107] If the comparison results are inconsistent, it means that at least one of the encrypted upgrade package and the encrypted token received by the vehicle has been tampered with. In this case, the signature verification fails and the upgrade task ends.
[0108] To enable those skilled in the art to better understand this disclosure, an upgrade scenario will now be described in conjunction with Figure 5.
[0109] Specifically, the TSP Cloud (TSP: telematics service provider) is the OTA cloud in this embodiment. When performing an upgrade, the cloud establishes an upgrade task and wakes up the main controller TU. After the main controller TU is woken up, it wakes up the in-vehicle network and sends a version number acquisition request and a seed request to the device to be upgraded in the vehicle through remote diagnostics. The device to be upgraded sends its own seed, version number, and status to the cloud through the main controller TU.
[0110] The cloud can also request a key from Server PLM (Product Lifecycle Management). Server PLM returns the key to the cloud, which uses it for symmetric encryption and token encryption. Different encryption operations may use different keys, depending on the configuration. Furthermore, the key can be set to expire at regular intervals, allowing for timely adjustments even if the key is leaked.
[0111] The cloud sends the key to the main controller TU, which then uses the key to perform the corresponding decryption operation.
[0112] In addition, after obtaining the version number of the component, i.e. the device to be upgraded, the main controller TU can check the version to ensure the accuracy of the upgrade.
[0113] In addition, the main controller TU receives and downloads the upgrade file package sent from the cloud, decrypts and verifies it using a key, and controls the device to be upgraded to perform the upgrade operation after successful verification.
[0114] In this embodiment of the disclosure, the upgrade process meets the security requirements of SOTA (State Over-The-Air), specifically in terms of security, performance, reliability, availability, and robustness. Security aspects mainly include server-side security, communication security, and the security of the upgrade strategy. This embodiment of the disclosure mainly involves the following aspects:
[0115] 1. Application security (cloud, mobile): When making software modifications to a vehicle, user authorization is required. Users can authorize the software via their mobile devices before downloading and updating the software package.
[0116] 2. Data Security (Server): Encryption operations are performed through the server;
[0117] 3. Communication security: Achieved through the development of a vehicle-to-cloud communication protocol;
[0118] 4. Two-way authentication: The cloud system and the vehicle-side customer can perform two-way identity authentication to verify each other's identity information; identity verification can be implemented through Seed.
[0119] 5. Encrypted transmission: The cloud platform and vehicle client need to be developed for compatibility based on the standard API (Application Programming Interface). Signature verification, session symmetric encryption and decryption, and other methods are used to ensure the secure transmission of OTA data, avoid man-in-the-middle attacks, prevent tampering, and prevent replay.
[0120] 6. Signature Verification and Vehicle-Side Security: Safe storage of OTA upgrade packages on the vehicle side, secure storage conditions on vehicle-side devices such as T-BOX and gateways, assisting in ensuring secure storage of upgrade packages on the vehicle side, secure signature verification algorithms and keys, and providing data and logic security protection solutions for vehicle-side OTA upgrade logic.
[0121] As can be seen from the above, the embodiments of this disclosure upgrade security from multiple angles and in all aspects, including application security, data security, communication security, two-way authentication, encrypted transmission, signature verification, and vehicle-side security, thereby improving the security of software upgrades.
[0122] In real-world scenarios, after an upgrade task is published, vehicles receive a corresponding upgrade notification. Once the upgrade task is published in the cloud, vehicles within the upgrade scope will receive the notification, which includes information such as the upgrade scope and timeframe. Making software modifications to a vehicle requires user authorization. Only after user authorization can the software package be downloaded and the corresponding upgrade operation executed. The vehicle retrieves the necessary software package and corresponding upgrade execution script from the cloud, performs security and integrity checks on the vehicle, and executes the upgrade only after ensuring security. The installation of the upgrade package is the specific process of upgrading automotive software. After the upgrade process is completed, regardless of success or failure, the vehicle must report the relevant status to the cloud. The feedback of vehicle data is fundamental to effective management.
[0123] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package. An encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via an OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0124] Furthermore, this disclosure utilizes remote upgrades via the network to update the vehicle's software system, upgrading and optimizing in-vehicle navigation, infotainment applications, human-machine interaction, and other in-vehicle functions, thereby achieving software upgrades and repairs. This accelerates automotive product iteration, reduces costs (due to factory repairs), improves user experience, strengthens new touchpoints for user communication, and continuously improves current product development cycle methods. Simultaneously, it needs to meet the target market's requirements for vehicle information security and increase revenue.
[0125] In addition, during the upgrade process, the security mechanisms of the whole vehicle security algorithm, such as cloud-based signature encryption of the upgrade package and vehicle-side signature verification and decryption, ensure the safe implementation of the upgrade process and take into account the security of vehicle-side software version and data writing.
[0126] In addition, the SOTA system can identify the current software version of the vehicle and develop an upgrade strategy suitable for the vehicle.
[0127] Based on the above, one embodiment of this disclosure provides a software upgrade method applied to a control terminal. Referring to FIG6, the software upgrade method includes:
[0128] S31. After confirming that the vehicle to be upgraded has passed identity verification, obtain the software parameter information of the device to be upgraded in the vehicle.
[0129] S32. Based on the software parameter information, determine the software upgrade package for the device to be upgraded.
[0130] S33. Encrypt the software upgrade package to obtain an encrypted upgrade package.
[0131] S34. Generate an encryption token corresponding to the digest of the encryption upgrade package.
[0132] S35. The encryption token is transmitted to the vehicle to be upgraded via an Over-the-Air (OTA) server, so that the vehicle to be upgraded can decrypt the encryption upgrade package to obtain the software upgrade package. The encryption upgrade package is then transmitted to the vehicle to be upgraded via a Content Delivery Network (CDN) accelerator, so that the vehicle to be upgraded can determine the digest of the encryption upgrade package corresponding to the encryption token. The software upgrade package and the digest of the encryption upgrade package are used by the vehicle to upgrade the software to perform a software upgrade operation on the device to be upgraded.
[0133] Among them, confirming that the identity verification of the vehicle to be upgraded has passed includes:
[0134] Obtain the actual verification information of the device to be upgraded in the vehicle to be upgraded. If the actual verification information is the same as the reference verification information of the device to be upgraded stored in the control terminal, it is determined that the identity verification of the vehicle to be upgraded has passed.
[0135] The process of determining the software upgrade package for the device to be upgraded based on the software parameter information includes:
[0136] Obtain the latest software version of the device to be upgraded, extract the current software version of the device to be upgraded from the software parameter information, and determine the software upgrade package of the device to be upgraded based on the difference information between the latest software version and the current software version.
[0137] The encryption token used to generate the digest of the encryption upgrade package includes:
[0138] Extract the digest of the encrypted upgrade package from the encrypted upgrade package, and generate a token using the digest of the encrypted upgrade package, a random password, and a symmetric encryption algorithm. Then, encrypt the token to obtain an encrypted token.
[0139] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via the OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0140] Based on the above, one embodiment of this disclosure provides a software upgrade method applied to a vehicle to be upgraded. Referring to FIG7, the software upgrade method includes:
[0141] S41. Obtain the encryption token transmitted by the control terminal through the server and the encryption upgrade package transmitted through the CDN accelerator; wherein, the encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal obtains the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package; the encryption token corresponds to the digest of the encryption upgrade package;
[0142] S42. Decrypt the encrypted upgrade package to obtain the software upgrade package;
[0143] S43. Determine the digest of the encryption upgrade package corresponding to the encryption token;
[0144] S44. Based on the software upgrade package and the digest of the encrypted upgrade package, perform a software upgrade operation on the device to be upgraded.
[0145] The process of determining the digest of the encryption upgrade package corresponding to the encryption token includes:
[0146] The encrypted token is decrypted to obtain the token;
[0147] The token is decomposed to obtain the digest of the encrypted upgrade package.
[0148] The software upgrade operation on the device to be upgraded, based on the software upgrade package and the digest of the encrypted upgrade package, includes:
[0149] Extract the digest to be verified from the encrypted upgrade package;
[0150] The digest to be verified is compared with the digest of the encrypted upgrade package;
[0151] If the comparison results are consistent, the software upgrade package is sent to the device to be upgraded so that the device to be upgraded can perform the upgrade operation according to the software upgrade package.
[0152] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via the OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0153] Based on the above embodiments of the software upgrade method applied to the control terminal, another embodiment of this disclosure provides a software upgrade apparatus applied to the control terminal. Referring to FIG8, the software upgrade apparatus includes:
[0154] The information acquisition module 11 is used to acquire the software parameter information of the device to be upgraded in the vehicle after determining that the vehicle to be upgraded has passed the identity verification.
[0155] The upgrade package determination module 12 is used to determine the software upgrade package of the device to be upgraded based on the software parameter information.
[0156] Encryption module 13 is used to encrypt the software upgrade package to obtain an encrypted upgrade package;
[0157] The token generation module 14 is used to generate an encryption token corresponding to the digest of the encryption upgrade package;
[0158] The upgrade control module 15 is used to transmit the encryption token to the vehicle to be upgraded via an over-the-air (OTA) server, and to transmit the encrypted upgrade package to the vehicle to be upgraded via a content delivery network (CDN) accelerator, so that the vehicle to be upgraded can decrypt the encrypted upgrade package to obtain the software upgrade package, determine the digest of the encrypted upgrade package corresponding to the encryption token, and perform a software upgrade operation on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package.
[0159] The information acquisition module 11 includes:
[0160] The authentication module is used to obtain the actual verification information of the device to be upgraded in the vehicle to be upgraded. If the actual verification information is the same as the reference verification information of the device to be upgraded stored in the control terminal, it is determined that the authentication of the vehicle to be upgraded has passed.
[0161] Specifically, the upgrade package determination module 12 is used for:
[0162] Obtain the latest software version of the device to be upgraded, extract the current software version of the device to be upgraded from the software parameter information, and determine the software upgrade package of the device to be upgraded based on the difference information between the latest software version and the current software version.
[0163] The token generation module 14 includes:
[0164] The first digest extraction submodule is used to extract a digest of the encrypted upgrade package from the encrypted upgrade package;
[0165] The token generation submodule is used to generate a token using the digest of the encryption upgrade package, a random password, and a symmetric encryption algorithm.
[0166] The token encryption submodule is used to encrypt the token to obtain an encrypted token.
[0167] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via the OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0168] It should be noted that the working process of each module and sub-module in this embodiment is described in the corresponding descriptions in the above embodiments, and will not be repeated here.
[0169] Based on the above embodiments of the software upgrade method applied to the vehicle to be upgraded, another embodiment of this disclosure provides a software upgrade apparatus applied to the vehicle to be upgraded. Referring to FIG9, the software upgrade apparatus includes:
[0170] The data acquisition module 21 is used to acquire the encryption token transmitted by the control terminal through the server and the encryption upgrade package transmitted through the CDN accelerator; the encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal acquires the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package; the encryption token corresponds to the digest of the encryption upgrade package;
[0171] Decryption module 22 is used to decrypt the encrypted upgrade package to obtain the software upgrade package;
[0172] The digest determination module 23 is used to determine the digest of the encryption upgrade package corresponding to the encryption token;
[0173] The upgrade processing module 24 is used to perform a software upgrade operation on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package.
[0174] Specifically, the abstract determination module 23 is used for:
[0175] The encrypted token is decrypted to obtain a token, and the token is then decomposed to obtain a digest of the encrypted upgrade package.
[0176] The upgrade processing module 24 includes:
[0177] The second digest extraction submodule is used to extract the digest to be verified from the encrypted upgrade package;
[0178] The comparison submodule is used to compare the digest to be verified with the digest of the encryption upgrade package;
[0179] The upgrade processing submodule is used to send the software upgrade package to the device to be upgraded if the comparison results are consistent, so that the device to be upgraded can perform the upgrade operation according to the software upgrade package.
[0180] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via the OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0181] It should be noted that the working process of each module and sub-module in this embodiment is described in the corresponding description in the above embodiment, and will not be repeated here.
[0182] Another embodiment of this disclosure provides a software upgrade system, referring to FIG10, including the control terminal 31 described above and the vehicle 32 to be upgraded.
[0183] In this embodiment, the identity of the vehicle to be upgraded is first verified. Only if the verification is successful will the subsequent software upgrade operation be performed, ensuring the security of online software upgrades. During the software upgrade, the software upgrade package is encrypted to obtain an encrypted upgrade package, and an encryption token corresponding to the digest of the encrypted upgrade package is generated. The encryption token is transmitted to the vehicle to be upgraded via the OTA server, and the encrypted upgrade package is transmitted to the vehicle to be upgraded via a CDN accelerator. That is, this disclosure reduces the possibility of both data being intercepted and cracked simultaneously by using encryption operations and two different transmission methods to transmit the encryption token and the encrypted upgrade package separately, further ensuring the security of online software upgrades.
[0184] The above description of the disclosed embodiments enables those skilled in the art to make or use this disclosure. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this disclosure. Therefore, this disclosure is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A software upgrade method, applied to a control terminal, the software upgrade method comprising: After confirming that the vehicle to be upgraded has passed identity verification, obtain the software parameter information of the device to be upgraded in the vehicle; Based on the software parameter information, determine the software upgrade package for the device to be upgraded; The software upgrade package is encrypted to obtain an encrypted upgrade package; Generate an encryption token corresponding to the digest of the encryption upgrade package; The encryption token is transmitted to the vehicle to be upgraded via an Over-the-Air (OTA) server, enabling the vehicle to decrypt the encryption upgrade package to obtain the software upgrade package. The encryption upgrade package is then transmitted to the vehicle to be upgraded via a Content Delivery Network (CDN) accelerator, allowing the vehicle to determine the digest of the encryption upgrade package corresponding to the encryption token. The software upgrade package and the digest of the encryption upgrade package are used by the vehicle to perform a software upgrade operation on the device to be upgraded.
2. The software upgrade method according to claim 1, wherein, The process of confirming that the vehicle to be upgraded has passed identity verification includes: Obtain the actual verification information of the devices to be upgraded in the vehicle to be upgraded; If the actual verification information is the same as the reference verification information of the device to be upgraded stored in the control terminal, the identity verification of the vehicle to be upgraded is determined to be successful.
3. The software upgrade method according to claim 1, wherein, The step of determining the software upgrade package for the device to be upgraded based on the software parameter information includes: Obtain the latest software version of the device to be upgraded; Extract the current software version of the device to be upgraded from the software parameter information; Based on the differences between the latest software version and the current software version, the software upgrade package for the device to be upgraded is determined.
4. The software upgrade method according to claim 1, wherein, The encryption token used to generate the digest of the encryption upgrade package includes: Extract the digest of the encrypted upgrade package from the encrypted upgrade package; A token is generated using the digest of the encryption upgrade package, the random password, and the symmetric encryption algorithm. The token is encrypted to obtain an encrypted token.
5. A software upgrade method, applied to a vehicle to be upgraded, the software upgrade method comprising: The control terminal obtains the encryption token transmitted by the server and the encryption upgrade package transmitted by the CDN accelerator; wherein, the encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal obtains the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package; The encrypted upgrade package is decrypted to obtain the software upgrade package; Determine the digest of the encryption upgrade package corresponding to the encryption token; Based on the software upgrade package and the digest of the encrypted upgrade package, a software upgrade operation is performed on the device to be upgraded.
6. The software upgrade method according to claim 5, wherein, The step of determining the digest of the encryption upgrade package corresponding to the encryption token includes: The encrypted token is decrypted to obtain the token; The token is decomposed to obtain the digest of the encrypted upgrade package.
7. The software upgrade method according to claim 5, wherein, The process of performing a software upgrade on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package includes: Extract the digest to be verified from the encrypted upgrade package; The digest to be verified is compared with the digest of the encrypted upgrade package; If the comparison results are consistent, the software upgrade package is sent to the device to be upgraded so that the device to be upgraded can perform the upgrade operation according to the software upgrade package.
8. A software upgrade device, applied to a control terminal, the software upgrade device comprising: The information acquisition module is used to acquire the software parameter information of the device to be upgraded in the vehicle after confirming that the vehicle to be upgraded has passed the identity verification. The upgrade package determination module is used to determine the software upgrade package for the device to be upgraded based on the software parameter information. An encryption module is used to encrypt the software upgrade package to obtain an encrypted upgrade package; The token generation module is used to generate an encrypted token corresponding to the digest of the encrypted upgrade package; The upgrade control module is used to transmit the encryption token to the vehicle to be upgraded via an over-the-air (OTA) server, so that the vehicle to be upgraded can decrypt the encryption upgrade package to obtain the software upgrade package. The encryption upgrade package is then transmitted to the vehicle to be upgraded via a content delivery network (CDN) accelerator, so that the vehicle to be upgraded can determine the digest of the encryption upgrade package corresponding to the encryption token. The software upgrade package and the digest of the encryption upgrade package are used by the vehicle to perform a software upgrade operation on the device to be upgraded.
9. A software upgrade device, applied to a vehicle to be upgraded, the software upgrade device comprising: The data acquisition module is used to acquire the encryption token transmitted by the control terminal through the server and the encryption upgrade package transmitted through the CDN accelerator; wherein, the encryption upgrade package is obtained by the control terminal through the following steps: after determining that the identity verification of the vehicle to be upgraded is successful, the control terminal acquires the software parameter information of the device to be upgraded in the vehicle to be upgraded, determines the software upgrade package of the device to be upgraded based on the software parameter information, and encrypts the software upgrade package to obtain the encryption upgrade package; The decryption module is used to decrypt the encrypted upgrade package to obtain the software upgrade package; The digest determination module is used to determine the digest of the encryption upgrade package corresponding to the encryption token; The upgrade processing module is used to perform a software upgrade operation on the device to be upgraded based on the software upgrade package and the digest of the encrypted upgrade package.
10. A software upgrade system, comprising a control terminal for performing the software upgrade method as described in any one of claims 1 to 4, and a vehicle to be upgraded for performing the software upgrade method as described in any one of claims 5 to 7.