Security protection method in in-vehicle system and device

US2022173902A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2022173902-A1
Application numberUS-202217675966-A
CountryUS
Kind codeA1
Filing dateFeb 18, 2022
Priority dateAug 20, 2019
Publication dateJun 2, 2022
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Embodiments of this application provide a security protection method in an in-vehicle system and a device, relate to the field of internet of vehicles technologies, to deploy a first security protection module on an electronic control unit, deploy a second security protection module on a domain controller, and deploy a third security protection module on a gateway based on security level requirements of the gateway, the domain controller, and the electronic control unit, so that the gateway, the domain controller, and the electronic control unit have different security levels. A security level of the first security protection module is a first security level, a security level of the second security protection module is a second security level, and a security level of the third security protection module is a third security level.

First claim

Opening claim text (preview).

What is claimed is: 1 . An in-vehicle system, comprising: a gateway; a domain controller coupled to the gateway; and an electronic control unit (ECU) coupled to the domain controller, wherein the ECU is configured with a first security protection module, the first security protection module is configured to provide security protection for the ECU, and a security level of the first security protection module is a first security level, wherein the domain controller is configured with a second security protection module, the second security protection module is configured to provide security protection for the domain controller, and a security level of the second security protection module is a second security level, and wherein the domain controller is configured with a third security protection module, the third security protection module is configured to provide security protection for the gateway, and a security level of the third security protection module is a third security level. 2 . The in-vehicle system according to claim 1 , wherein the third security level is higher than or equal to the second security level, and the second security level is higher than the first security level. 3 . The in-vehicle system according to claim 1 , wherein the first security protection module comprises a device identifier composition engine (DICE), wherein the second security protection module comprises a trusted platform module-thin, an embedded secure element (eSE), a chip comprising a physically isolated security processor SP system, or a chip comprising a physically isolated hardware security module (HSM), and wherein the third security protection module comprises a trusted platform module-rich, an (eSE), a chip comprising a physically isolated security processor (SP) system, or a chip comprising a physically isolated HSM. 4 . An in-vehicle security protection system, wherein the in-vehicle security protection system comprises an electronic control unit (ECU), a domain controller, and a gateway, wherein the ECU is configured to generate a public key of the ECU and a private key of the ECU by using a first security protection module, wherein the first security protection module is configured to provide security protection for the ECU, and a security level of the first security protection module is a first security level, wherein the ECU is further configured to sign a firmware digest of the ECU by using the private key of the ECU, to obtain first signature information, wherein the ECU is further configured to send the first signature information, the public key of the ECU, and the firmware digest of the ECU to the domain controller; wherein the domain controller is configured to receive the first signature information, the public key of the ECU, and the firmware digest of the ECU from the ECU, wherein the domain controller is further configured to send the first signature information, the public key of the ECU, and the firmware digest of the ECU to the gateway, wherein the gateway is configured to receive the first signature information, the public key of the ECU, and the firmware digest of the ECU from the domain controller, and wherein the gateway is further configured to send the first signature information, the public key of the ECU, and the firmware digest of the ECU to a server. 5 . The in-vehicle security protection system according to claim 4 , wherein the first security protection module comprises a device identifier composition engine (DICE). 6 . The in-vehicle security protection system according to claim 4 , wherein the domain controller stores an ECU list, and the ECU is in the ECU list. 7 . The in-vehicle security protection system according to claim 4 , wherein the firmware digest of the ECU is obtained by calculating firmware of the ECU according to a first digest function. 8 . The in-vehicle security protection system according to claim 4 , wherein the in-vehicle security protection system further comprises the server, wherein the server is configured to receive the first signature information, the public key of the ECU, and the firmware digest of the ECU from the gateway, wherein the server is further configured to perform verification on the first signature information by using the public key of the ECU, wherein the server is further configured to, when the first signature information has been verified, send first response information to the gateway, wherein the first response information is used to indicate to start the ECU, wherein the gateway is further configured to receive the first response information from the server, wherein the gateway is further configured to send the first response information to the domain controller, wherein the domain controller is further configured to receive the first response information from the gateway, wherein the domain controller is further configured to send the first response information to the ECU, and wherein the ECU is further configured to receive the first response information from the domain controller. 9 . An in-vehicle security protection system, comprising: an electronic control unit (ECU); a domain controller coupled to the ECU; and a gateway coupled to the domain controller, wherein the ECU is configured to generate a public key of the ECU and a private key of the ECU by using a first security protection module, wherein the first security protection module is configured to provide security protection for the ECU, and a security level of the first security protection module is a first security level, wherein the ECU is further configured to sign a firmware digest of the ECU by using the private key of the ECU to obtain first signature information, wherein the ECU is further configured to send the first signature information, the public key of the ECU, and the firmware digest of the ECU to the domain controller, wherein the domain controller is configured to receive the first signature information, the public key of the ECU, and the firmware digest of the ECU from the ECU, wherein the domain controller is further configured to generate a public key of the domain controller and a private key of the domain controller by using a second security protection module, wherein the second security protection module is configured to provide security protection for the domain controller, and a security level of the second security protection module is a second security level, wherein the domain controller is further configured to perform verification on the first signature information by using the public key of the ECU, wherein the domain controller is further configured to, when the first signature information has been verified, sign the firmware digest of the ECU by using the private key of the domain controller, to obtain second signature information, wherein the domain controller is further configured to send the second signature information, the public key of the domain controller, and the firmware digest of the ECU to the gateway, wherein the gateway is configured to receive the second signature information, the public key of the domain controller, and the firmware digest of the ECU from the domain controller, wherein the gateway is further configured to generate a public key of the gateway and a private key of the gateway by using a third security protection module, wherein the third security protection module is configured to provide security protection for the gateway, and a security level of the third security protection module is a third security level, wherein the gateway is further configured to perform verification on the second signature information by using the public key of the domain controller, wherein the

Assignees

Inventors

Classifications

  • Vehicles · CPC title

  • for authentication of entities (cryptographic mechanisms or cryptographic arrangements for entity authentication H04L9/32) · CPC title

  • for key exchange, e.g. in peer-to-peer networks (cryptographic mechanisms or cryptographic arrangements for key agreement H04L9/0838) · CPC title

  • involving digital signatures · CPC title

  • H04L67/12Primary

    specially adapted for proprietary or special-purpose networking environments, e.g. medical networks, sensor networks, networks in vehicles or remote metering networks · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2022173902A1 cover?
Embodiments of this application provide a security protection method in an in-vehicle system and a device, relate to the field of internet of vehicles technologies, to deploy a first security protection module on an electronic control unit, deploy a second security protection module on a domain controller, and deploy a third security protection module on a gateway based on security level requir…
Who is the assignee on this patent?
Huawei Tech Co Ltd
What technology area does this patent fall under?
Primary CPC classification H04L67/12. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Jun 02 2022 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 9 related publications on this page (citations in our corpus or others sharing the same primary CPC).