Anti-replacement production method and system for automobile controller chip, and Anti-replacement detection method and system for automobile controller chip
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing anti-replacement methods for automotive controller chips are inadequate as they require CPU security cores, cannot detect CPU replacement, and lack real-time detection capabilities after BIOS boot.
Innovation Solution
A method involving obtaining chip identity feature information, calculating a hash value, and signing it with a private key, followed by real-time signature verification to ensure authenticity, using secure hash algorithms like SHA-1, SHA-224, SHA-256, SHA-384, or SHA-512, and reporting risks to a vehicle infotainment system and cloud.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing hardware anti-replacement methods based on processor security cores are used, then anti-replacement verification can be performed on peripherals connected to the CPU, but they cannot detect whether the CPU itself has been replaced and require utilizing security core functionality that not all CPUs possess
Solution Approach 1:
The patent extracts the anti-replacement verification function from the CPU security core and implements it independently in the BIOS/UEFI firmware. This allows the verification to work on any CPU without requiring specific hardware security features, as the verification logic resides in the firmware layer rather than depending on CPU-specific security cores.
Solution Approach 2:
The patent introduces the BIOS/UEFI firmware as an intermediary layer between the hardware and the anti-replacement verification process. This intermediary provides a universal platform that can implement verification logic independent of the underlying CPU architecture, enabling broad compatibility while maintaining verification capability.
2Reliability
If anti-replacement detection is performed during the BIOS boot phase, then verification can be conducted, but it cannot continue to perform real-time detection of whether peripheral replacement has occurred after the BIOS boot is completed
Solution Approach 1:
The patent implements continuous anti-replacement detection by integrating verification logic that operates not only during the BIOS boot phase but also continues throughout the system's operational lifetime. The firmware maintains verification capabilities that can detect replacements at any time, ensuring uninterrupted monitoring of hardware integrity.
Solution Approach 2:
The patent performs preliminary anti-replacement verification during the BIOS boot phase to establish a baseline state, then continues with ongoing detection mechanisms that monitor for changes after boot. This two-stage approach ensures both initial verification and continuous real-time detection coverage.
3Reliability
If a customer-customized signature for a Security Processor is used to prevent firmware tampering, then anti-tampering protection is achieved, but it is unable to detect whether the CPU has been replaced
Solution Approach 1:
The patent segments the verification process into two independent components: firmware integrity verification (using digital signatures) and CPU identity verification (using hardware identifiers). By separating these functions, the system can simultaneously provide firmware protection while also detecting CPU replacements, as each verification targets a different aspect of system integrity.
Solution Approach 2:
The patent creates a universal verification framework in the BIOS/UEFI that handles both firmware authentication and CPU identity verification through a single integrated process. This multi-functional approach allows the same verification mechanism to detect both firmware tampering and CPU replacement, eliminating the limitation of single-purpose verification systems.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention relates to the field of embedded technology. Disclosed are an anti-replacement production method and system for an automobile controller chip, and an anti-replacement detection method and system for an automobile controller chip. The anti-replacement production method comprises: acquiring chip identity feature information; calculating a first hash value, and storing the first hash value; uploading the first hash value; signing the uploaded first hash value, and generating signature information; and storing the signature information. The anti-replacement detection method comprises: creating a detection task; acquiring signature information written during the anti-replacement production method, and performing signature verification to obtain a second hash value; calculating a third hash value and using same as a metric value; and making a comparison. The present invention only requires the consumption of a small amount of FLASH space and a small number of chip computing resources in an automobile controller to achieve real-time detection of anti-replacement of an automobile controller chip without the need for relying on other external devices. By means of the signature and signature verification of a hash value for chip identity feature information, false detection of the replacement of a chip caused by the replacement of an external FLASH of the chip can be prevented, thereby guaranteeing the safety and reliability of a vehicle.