Electronic Controller Flash Method Using Authorization File Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Intelligent vehicle ECUs face security risks due to the lack of source verification during software package updates, as they do not authenticate the origin of software packages before programming, leading to potential malicious software installation.
Innovation Solution
An electronic controller programming method that involves sending device information to a management server, generating and verifying an authorization file using public and private keys, and comparing software package feature information to ensure the software package is authentic and meets preset conditions before programming the ECU.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the ECU accepts software packages without verification, then programming speed and ease of operation are improved, but security and reliability deteriorate due to potential malicious software installation
Solution Approach 1:
The patent applies preliminary action by performing authorization verification before the actual programming operation. The ECU receives and verifies an authorization file containing encrypted device information and software package feature information before accepting the software package. This pre-verification ensures that only authenticated software packages from authorized sources can be programmed into the ECU, thus improving reliability without significantly impacting operational efficiency.
2Reliability
If the ECU verifies the source of software packages, then security and reliability are improved, but device complexity and programming time increase
Solution Approach 1:
The patent introduces an authorization file as an intermediary element that mediates between the programming tool and the ECU. This authorization file, generated by a management server and containing encrypted verification data, serves as a credential that simplifies the verification process. The ECU uses this intermediary file to authenticate both the software package and the programming tool, reducing the complexity of direct verification mechanisms while maintaining high security standards.
3Reliability
If the ECU performs authorization verification, then security is improved, but programming time and processing duration increase
Solution Approach 1:
The authorization verification is performed as a preliminary step before the actual software programming. The ECU validates the authorization file containing device information and software package features upfront, ensuring that only authenticated packages are processed. This preliminary verification prevents time-wasting rejections later in the process and ensures efficient use of programming time while maintaining security.
Solution Approach 2:
The patent implements a conditional skipping mechanism where the authorization verification process is streamlined based on the validity of the authorization file. If the authorization file is valid and the ECU successfully decrypts and verifies the device information and software package feature information, the system rapidly proceeds to the programming phase without unnecessary delays. This allows the system to 'rush through' the verification process when conditions are favorable, minimizing time loss.
Data Source
Figure 1~2
Figure 3~4
Figure 5
AI summary
Provided are an electronic controller programming method, an electronic controller, and a management server. The electronic controller sends device information to a programming tool; the programming tool sends the device information to the management server, so that the management server can generate, according to the device information, an authorization file encrypted by a private key, and a software package and send the authorization file and the software package to the programming tool; the programming tool programs the electronic controller with the authorization file; the electronic controller uses a local public key to perform signature verification on the authorization file; after the signature verification succeeds, software packet feature information in the authorization file is further compared with the device information, and the software package is programmed to the electronic controller in a case that a comparison result satisfies a preset condition. Through the signature verification performed on the authorization file through the public key, the security of the software package is ensured, and the electronic controller is prevented from being programmed with a software package from an unknown source; and meanwhile, a content of the authorization file is verified, which further ensures that the software package satisfies the preset condition and avoids wrong programming.