Vehicle-Mounted Device Upgrades Using Distributed Sub-Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for upgrading vehicle-mounted device firmware and software are inefficient due to long upgrade periods and the need to ensure correct upgrade sequences among dependent devices, which are not adequately addressed in existing technologies.
Innovation Solution
A method and apparatus that ensures a vehicle-mounted device is upgraded only after all dependent devices are upgraded by using sub-keys to construct decryption keys, ensuring a correct upgrade sequence and normal operation, while improving security and reducing power consumption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If conventional recall method is used for upgrading vehicle-mounted devices, then upgrade sequence control is simple, but upgrade efficiency is low due to long upgrade period
Solution Approach 1:
The patent segments the encryption key into multiple sub-keys, where each sub-key is held by a different vehicle-mounted device. This allows parallel distribution of upgrade files to multiple devices simultaneously, eliminating the sequential recall process and significantly reducing upgrade time while maintaining secure access control.
Solution Approach 2:
The patent performs preliminary distribution of encrypted upgrade files and sub-keys to all dependent vehicle-mounted devices before the actual upgrade execution. This preliminary action enables devices to be ready for upgrade simultaneously, allowing parallel execution and improving overall upgrade efficiency without compromising security.
2Productivity
If OTA method is used for upgrading vehicle-mounted devices, then upgrade efficiency is improved, but it is difficult to ensure correct upgrade sequence among dependent devices
Solution Approach 1:
The encryption key is segmented into multiple sub-keys distributed to different devices. A dependent device can only decrypt and execute its upgrade file after collecting all required sub-keys from devices that have successfully completed their upgrades. This mechanism inherently enforces the correct upgrade sequence while allowing parallel file distribution, thus maintaining both efficiency and reliability.
Solution Approach 2:
The patent introduces an intermediary mechanism where sub-keys act as mediators between devices. A dependent device uses collected sub-keys to decrypt its upgrade file, and this decryption process itself serves as verification that all depended devices have been upgraded. This intermediary mechanism ensures sequence control without requiring complex centralized coordination.
3Reliability
If sub-keys are transmitted for constructing decryption keys, then security is enhanced, but transmission security of sub-keys must be ensured
Solution Approach 1:
The encryption key is segmented into multiple sub-keys, each of which is individually encrypted and distributed to different devices. No single sub-key alone can decrypt the upgrade file; all sub-keys are required. This segmentation inherently reduces transmission security risks because even if one sub-key is intercepted, the upgrade file remains protected. The system achieves enhanced security through distributed key management rather than transmitting a single sensitive key.
Data Source
Figure 1
Figure 2A
Figure 2B~4
AI summary
Embodiments of this application provide a vehicle-mounted device upgrade method and apparatus, which may be applied to upgrade of a vehicle-mounted device in an intelligent vehicle field. The method includes: A second vehicle-mounted device determines that upgrade of the second vehicle-mounted device succeeds; and the second vehicle-mounted device sends a first sub-key to a first vehicle-mounted device, where the first sub-key is used to construct a first key for decrypting a first ciphertext, and the first ciphertext is obtained by encrypting a first upgrade file of the first vehicle-mounted device; and the first vehicle-mounted device receives the first sub-key and a second sub-key, where the second sub-key is used to construct the first key, and restores the first key based on the first sub-key and the second sub-key, to implement upgrade of the first vehicle-mounted device. In the embodiments of this application, it is ensured that a vehicle-mounted device is upgraded only after vehicle-mounted devices on which the vehicle-mounted device depend are upgraded. This ensures a correct upgrade sequence and ensures normal running of each vehicle-mounted device.