{"id":62253,"date":"2026-01-19T16:34:27","date_gmt":"2026-01-19T08:34:27","guid":{"rendered":"https:\/\/www.wsisp.com\/helps\/62253.html"},"modified":"2026-01-19T16:34:27","modified_gmt":"2026-01-19T08:34:27","slug":"tls%e5%8a%a0%e5%af%86%e9%80%9a%e4%bf%a1%e5%9c%a8%e8%bd%a6%e8%bd%bd%e7%bd%91%e7%bb%9c%e4%b8%8eoem%e6%9c%8d%e5%8a%a1%e5%99%a8%e4%b8%ad%e7%9a%84%e6%b7%b1%e5%ba%a6%e8%a7%a3%e6%9e%90","status":"publish","type":"post","link":"https:\/\/www.wsisp.com\/helps\/62253.html","title":{"rendered":"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790"},"content":{"rendered":"<h3>\u5f15\u8a00&#xff1a;\u5f53\u6c7d\u8f66\u5b66\u4f1a\u4e86&#034;\u6084\u6084\u8bdd&#034;<\/h3>\n<p>\u60f3\u8c61\u4e00\u4e0b&#xff0c;\u4f60\u9a7e\u9a76\u7740\u4e00\u8f86\u667a\u80fd\u6c7d\u8f66\u884c\u9a76\u5728\u9ad8\u901f\u516c\u8def\u4e0a\u3002\u8f66\u8f86\u6b63\u6084\u6084\u5730\u4e0e\u5236\u9020\u5546\u7684\u670d\u52a1\u5668&#034;\u4ea4\u8c08&#034;&#xff1a;\u62a5\u544a\u8f66\u8f86\u72b6\u6001\u3001\u63a5\u6536\u8f6f\u4ef6\u66f4\u65b0\u3001\u83b7\u53d6\u5b9e\u65f6\u8def\u51b5\u3002\u4f46\u8fd9\u6bb5\u5bf9\u8bdd\u5982\u679c\u88ab\u6076\u610f\u7a83\u542c\u8005\u542c\u5230\u4f1a\u600e\u6837&#xff1f;\u4ed6\u4eec\u53ef\u80fd\u77e5\u9053\u4f60\u7684\u4f4d\u7f6e\u3001\u9a7e\u9a76\u4e60\u60ef&#xff0c;\u751a\u81f3\u80fd\u8fdc\u7a0b\u63a7\u5236\u4f60\u7684\u8f66\u8f86\u3002TLS&#xff08;\u4f20\u8f93\u5c42\u5b89\u5168\u534f\u8bae&#xff09;\u5c31\u662f\u4e3a\u8fd9\u79cd\u5bf9\u8bdd\u914d\u4e0a\u7684&#034;\u52a0\u5bc6\u8033\u673a&#034;&#xff0c;\u8ba9\u6c7d\u8f66\u4e0e\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u65e2\u79c1\u5bc6\u53c8\u53ef\u9760\u3002<\/p>\n<p>\u4eca\u5929&#xff0c;\u6211\u4eec\u5c06\u6df1\u5165\u63a2\u7d22\u8fd9\u4e2a&#034;\u52a0\u5bc6\u8033\u673a&#034;\u7684\u5de5\u4f5c\u539f\u7406&#xff0c;\u63ed\u5f00TLS\u5728\u8f66\u8f7d\u7f51\u7edc\u4e2d\u7684\u795e\u79d8\u9762\u7eb1\u3002\u65e0\u8bba\u4f60\u662f\u5de5\u7a0b\u5e08\u3001\u6280\u672f\u7231\u597d\u8005&#xff0c;\u8fd8\u662f\u5bf9\u672a\u6765\u4ea4\u901a\u5145\u6ee1\u597d\u5947\u7684\u666e\u901a\u4eba&#xff0c;\u6211\u90fd\u5c06\u7528\u6700\u751f\u52a8\u7684\u65b9\u5f0f&#xff0c;\u5e26\u4f60\u7406\u89e3\u8fd9\u4e2a\u4fdd\u969c\u667a\u80fd\u6c7d\u8f66\u5b89\u5168\u7684\u6838\u5fc3\u6280\u672f\u3002<\/p>\n<h3>\u7b2c\u4e00\u90e8\u5206&#xff1a;\u8f66\u8f7d\u901a\u4fe1\u7684\u5b89\u5168\u6311\u6218\u2014\u2014\u4e3a\u4ec0\u4e48\u9700\u8981TLS&#xff1f;<\/h3>\n<h4>1.1 \u667a\u80fd\u6c7d\u8f66\u7684\u901a\u4fe1\u751f\u6001<\/h4>\n<p>\u73b0\u4ee3\u6c7d\u8f66\u5df2\u4e0d\u518d\u662f\u5b64\u7acb\u7684\u673a\u68b0\u88c5\u7f6e&#xff0c;\u800c\u662f\u4e00\u4e2a\u79fb\u52a8\u7684\u6570\u636e\u4e2d\u5fc3&#xff1a;<\/p>\n<p>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u2502                   \u8f66\u8f7d\u7f51\u7edc\u901a\u4fe1\u62d3\u6251                          \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502 \u8f66\u5185\u7f51\u7edc     \u2502 \u8f66\u9645\u901a\u4fe1     \u2502 \u8f66\u4e91\u901a\u4fe1      \u2502 \u8f66\u8def\u901a\u4fe1      \u2502<br \/>\n\u2502  (CAN\u603b\u7ebf)   \u2502 (V2V)       \u2502 (V2C)        \u2502 (V2I)        \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502 ECU\u4e4b\u95f4\u901a\u4fe1  \u2502 \u8f66\u8f86\u4e4b\u95f4     \u2502 \u8f66\u8f86\u4e0eOEM     \u2502 \u8f66\u8f86\u4e0e\u57fa\u7840\u8bbe\u65bd \u2502<br \/>\n\u2502             \u2502             \u2502 \u670d\u52a1\u5668        \u2502             \u2502<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<\/p>\n<p>\u5728\u6240\u6709\u8fd9\u4e9b\u901a\u4fe1\u4e2d&#xff0c;\u8f66\u4e91\u901a\u4fe1&#xff08;Vehicle-to-Cloud&#xff09; \u7684\u5b89\u5168\u6700\u4e3a\u5173\u952e&#xff0c;\u56e0\u4e3a\u5b83\u76f4\u63a5\u5173\u7cfb\u5230\u8f66\u8f86\u63a7\u5236\u3001\u7528\u6237\u9690\u79c1\u548c\u5236\u9020\u5546\u7684\u77e5\u8bc6\u4ea7\u6743\u3002<\/p>\n<h4>1.2 \u4e09\u5927\u5b89\u5168\u5a01\u80c1<\/h4>\n<p>\u8ba9\u6211\u4eec\u901a\u8fc7\u4e09\u4e2a\u573a\u666f\u7406\u89e3TLS\u7684\u5fc5\u8981\u6027&#xff1a;<\/p>\n<h5>\u573a\u666f\u4e00&#xff1a;\u7a83\u542c\u653b\u51fb<\/h5>\n<p>\u9ed1\u5ba2\u5c0f\u5f20\u5728\u8def\u8fb9\u5496\u5561\u9986&#xff0c;\u7528\u4e00\u53f0\u666e\u901a\u7b14\u8bb0\u672c\u622a\u83b7\u4e86\u9644\u8fd1\u8f66\u8f86\u7684\u901a\u4fe1\u6570\u636e\u3002\u4ed6\u60ca\u8bb6\u5730\u53d1\u73b0&#xff0c;\u80fd\u6e05\u695a\u5730\u770b\u5230\u54ea\u4e9b\u8f66\u8f86\u5728\u62a5\u544a&#034;\u5239\u8f66\u7247\u78e8\u635f&#034;\u3001\u201c\u7535\u6c60\u7535\u91cf\u4e0d\u8db3\u201d&#xff0c;\u751a\u81f3&#034;\u5f53\u524d\u4f4d\u7f6e&#xff1a;XX\u5c0f\u533a\u5730\u4e0b\u8f66\u5e93B\u533a23\u53f7\u8f66\u4f4d&#034;\u3002<\/p>\n<p>\u6ca1\u6709TLS&#xff1a;\u6240\u6709\u901a\u4fe1\u90fd\u662f\u660e\u6587\u7684&#xff0c;\u5982\u540c\u7528\u5bf9\u8bb2\u673a\u516c\u5f00\u558a\u8bdd\u3002<\/p>\n<h5>\u573a\u666f\u4e8c&#xff1a;\u4e2d\u95f4\u4eba\u653b\u51fb<\/h5>\n<p>\u9ed1\u5ba2\u5c0f\u674e\u66f4\u806a\u660e&#xff0c;\u4ed6\u4f2a\u9020\u4e86\u4e00\u4e2a&#034;\u7279\u65af\u62c9\u5347\u7ea7\u670d\u52a1\u5668&#034;&#xff0c;\u544a\u8bc9\u8f66\u8f86&#xff1a;\u201c\u6211\u662f\u5b98\u65b9\u670d\u52a1\u5668&#xff0c;\u8bf7\u4e0b\u8f7d\u6700\u65b0\u7cfb\u7edf\u66f4\u65b0\u201d\u3002\u8f66\u8f86\u4fe1\u4ee5\u4e3a\u771f&#xff0c;\u4e0b\u8f7d\u4e86\u5305\u542b\u6076\u610f\u8f6f\u4ef6\u7684&#034;\u66f4\u65b0\u5305&#034;\u3002<\/p>\n<p>\u6ca1\u6709TLS&#xff1a;\u65e0\u6cd5\u9a8c\u8bc1\u5bf9\u65b9\u8eab\u4efd&#xff0c;\u5982\u540c\u63a5\u7535\u8bdd\u65f6\u4e0d\u77e5\u9053\u5bf9\u65b9\u662f\u8c01\u3002<\/p>\n<h5>\u573a\u666f\u4e09&#xff1a;\u6570\u636e\u7be1\u6539<\/h5>\n<p>\u9ed1\u5ba2\u5c0f\u738b\u622a\u83b7\u4e86\u8f66\u8f86\u53d1\u9001\u7684&#034;\u4e00\u5207\u6b63\u5e38&#034;\u72b6\u6001\u62a5\u544a&#xff0c;\u4fee\u6539\u4e3a&#034;\u53d1\u52a8\u673a\u4e25\u91cd\u6545\u969c&#xff0c;\u8bf7\u7acb\u5373\u505c\u8f66&#034;&#xff0c;\u7136\u540e\u8f6c\u53d1\u7ed9OEM\u670d\u52a1\u5668\u3002\u670d\u52a1\u5668\u4fe1\u4ee5\u4e3a\u771f&#xff0c;\u8fdc\u7a0b\u9501\u6b7b\u4e86\u8f66\u8f86\u3002<\/p>\n<p>\u6ca1\u6709TLS&#xff1a;\u65e0\u6cd5\u786e\u4fdd\u6570\u636e\u5b8c\u6574\u6027&#xff0c;\u5982\u540c\u4fe1\u4ef6\u5728\u90ae\u9012\u9014\u4e2d\u88ab\u7be1\u6539\u5185\u5bb9\u3002<\/p>\n<h3>\u7b2c\u4e8c\u90e8\u5206&#xff1a;TLS\u534f\u8bae\u7684\u6838\u5fc3\u539f\u7406\u2014\u2014\u5bc6\u7801\u5b66\u7684\u4e09\u91cd\u594f<\/h3>\n<h4>2.1 TLS\u7684\u8bbe\u8ba1\u54f2\u5b66&#xff1a;\u5e73\u8861\u5b89\u5168\u4e0e\u6548\u7387<\/h4>\n<p>TLS\u4e0d\u662f\u5355\u4e00\u6280\u672f&#xff0c;\u800c\u662f\u591a\u79cd\u5bc6\u7801\u5b66\u6280\u672f\u7684\u7cbe\u5999\u7ec4\u5408&#xff1a;<\/p>\n<p>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u2502                  TLS\u5b89\u5168\u4e09\u8981\u7d20                            \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502  \u8eab\u4efd\u8ba4\u8bc1    \u2502     \u6570\u636e\u52a0\u5bc6         \u2502    \u5b8c\u6574\u6027\u4fdd\u62a4        \u2502<br \/>\n\u2502  (\u6211\u662f\u8c01)    \u2502   (\u5185\u5bb9\u4fdd\u5bc6)         \u2502   (\u5185\u5bb9\u672a\u88ab\u7be1\u6539)     \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502 \u975e\u5bf9\u79f0\u52a0\u5bc6   \u2502 \u5bf9\u79f0\u52a0\u5bc6             \u2502 \u54c8\u5e0c\u51fd\u6570            \u2502<br \/>\n\u2502 \u6570\u5b57\u8bc1\u4e66     \u2502 \u4f1a\u8bdd\u5bc6\u94a5             \u2502 \u6d88\u606f\u8ba4\u8bc1\u7801(MAC)     \u2502<br \/>\n\u2502 \u6570\u5b57\u7b7e\u540d     \u2502                     \u2502                     \u2502<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<\/p>\n<h4>2.2 \u975e\u5bf9\u79f0\u52a0\u5bc6 vs \u5bf9\u79f0\u52a0\u5bc6&#xff1a;\u5206\u5de5\u7684\u827a\u672f<\/h4>\n<p>\u7c7b\u6bd4\u7406\u89e3&#xff1a;<\/p>\n<ul>\n<li>\u975e\u5bf9\u79f0\u52a0\u5bc6&#xff1a;\u50cf\u4fdd\u9669\u7bb1\u7684\u8bbe\u8ba1\u56fe&#xff0c;\u516c\u5f00\u5206\u53d1\u4e5f\u6ca1\u5173\u7cfb&#xff08;\u516c\u94a5&#xff09;&#xff0c;\u4f46\u53ea\u6709\u62e5\u6709\u7279\u6b8a\u5de5\u5177\u7684\u4eba&#xff08;\u79c1\u94a5&#xff09;\u624d\u80fd\u5236\u9020\u5f00\u9501\u5de5\u5177<\/li>\n<li>\u5bf9\u79f0\u52a0\u5bc6&#xff1a;\u50cf\u4fdd\u9669\u7bb1\u7684\u5b9e\u9645\u94a5\u5319&#xff0c;\u5fc5\u987b\u7edd\u5bf9\u4fdd\u5bc6&#xff0c;\u4f46\u5f00\u9501\u5173\u9501\u90fd\u5f88\u5feb<\/li>\n<\/ul>\n<p>TLS\u7684\u667a\u6167\u5728\u4e8e&#xff1a;\u7528\u975e\u5bf9\u79f0\u52a0\u5bc6\u5b89\u5168\u5730\u4f20\u9012\u5bf9\u79f0\u52a0\u5bc6\u7684\u94a5\u5319&#xff0c;\u7136\u540e\u7528\u5bf9\u79f0\u52a0\u5bc6\u9ad8\u6548\u5730\u4fdd\u62a4\u5927\u91cf\u6570\u636e\u3002<\/p>\n<h4>2.3 TLS\u63e1\u624b\u534f\u8bae\u8be6\u89e3&#xff1a;\u6c7d\u8f66\u4e0e\u670d\u52a1\u5668\u7684&#034;\u5b89\u5168\u63e1\u624b&#034;<\/h4>\n<p>\u8ba9\u6211\u4eec\u8ddf\u968f\u4e00\u6b21\u5b8c\u6574\u7684TLS 1.3\u63e1\u624b\u8fc7\u7a0b&#xff08;\u73b0\u4ee3\u8f66\u8f7d\u7cfb\u7edf\u591a\u91c7\u7528\u6b64\u7248\u672c&#xff09;&#xff1a;<\/p>\n<p>OEM\u670d\u52a1\u5668\u8f66\u8f86(\u5ba2\u6237\u7aef)OEM\u670d\u52a1\u5668\u8f66\u8f86(\u5ba2\u6237\u7aef)#mermaid-svg-rJLqaLtBSpiwqk81{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-rJLqaLtBSpiwqk81 .error-icon{fill:#552222;}#mermaid-svg-rJLqaLtBSpiwqk81 .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-rJLqaLtBSpiwqk81 .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-rJLqaLtBSpiwqk81 .marker{fill:#333333;stroke:#333333;}#mermaid-svg-rJLqaLtBSpiwqk81 .marker.cross{stroke:#333333;}#mermaid-svg-rJLqaLtBSpiwqk81 svg{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-rJLqaLtBSpiwqk81 p{margin:0;}#mermaid-svg-rJLqaLtBSpiwqk81 .actor{stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);fill:#ECECFF;}#mermaid-svg-rJLqaLtBSpiwqk81 text.actor&gt;tspan{fill:black;stroke:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .actor-line{stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);}#mermaid-svg-rJLqaLtBSpiwqk81 .innerArc{stroke-width:1.5;stroke-dasharray:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .messageLine0{stroke-width:1.5;stroke-dasharray:none;stroke:#333;}#mermaid-svg-rJLqaLtBSpiwqk81 .messageLine1{stroke-width:1.5;stroke-dasharray:2,2;stroke:#333;}#mermaid-svg-rJLqaLtBSpiwqk81 #arrowhead path{fill:#333;stroke:#333;}#mermaid-svg-rJLqaLtBSpiwqk81 .sequenceNumber{fill:white;}#mermaid-svg-rJLqaLtBSpiwqk81 #sequencenumber{fill:#333;}#mermaid-svg-rJLqaLtBSpiwqk81 #crosshead path{fill:#333;stroke:#333;}#mermaid-svg-rJLqaLtBSpiwqk81 .messageText{fill:#333;stroke:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .labelBox{stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);fill:#ECECFF;}#mermaid-svg-rJLqaLtBSpiwqk81 .labelText,#mermaid-svg-rJLqaLtBSpiwqk81 .labelText&gt;tspan{fill:black;stroke:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .loopText,#mermaid-svg-rJLqaLtBSpiwqk81 .loopText&gt;tspan{fill:black;stroke:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .loopLine{stroke-width:2px;stroke-dasharray:2,2;stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);fill:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);}#mermaid-svg-rJLqaLtBSpiwqk81 .note{stroke:#aaaa33;fill:#fff5ad;}#mermaid-svg-rJLqaLtBSpiwqk81 .noteText,#mermaid-svg-rJLqaLtBSpiwqk81 .noteText&gt;tspan{fill:black;stroke:none;}#mermaid-svg-rJLqaLtBSpiwqk81 .activation0{fill:#f4f4f4;stroke:#666;}#mermaid-svg-rJLqaLtBSpiwqk81 .activation1{fill:#f4f4f4;stroke:#666;}#mermaid-svg-rJLqaLtBSpiwqk81 .activation2{fill:#f4f4f4;stroke:#666;}#mermaid-svg-rJLqaLtBSpiwqk81 .actorPopupMenu{position:absolute;}#mermaid-svg-rJLqaLtBSpiwqk81 .actorPopupMenuPanel{position:absolute;fill:#ECECFF;box-shadow:0px 8px 16px 0px rgba(0,0,0,0.2);filter:drop-shadow(3px 5px 2px rgb(0 0 0 \/ 0.4));}#mermaid-svg-rJLqaLtBSpiwqk81 .actor-man line{stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);fill:#ECECFF;}#mermaid-svg-rJLqaLtBSpiwqk81 .actor-man circle,#mermaid-svg-rJLqaLtBSpiwqk81 line{stroke:hsl(259.6261682243, 59.7765363128%, 87.9019607843%);fill:#ECECFF;stroke-width:2px;}#mermaid-svg-rJLqaLtBSpiwqk81 :root{&#8211;mermaid-font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;}\u7b2c\u4e00\u9636\u6bb5&#xff1a;\u6253\u62db\u547c\u548c\u4ea4\u6362\u53c2\u65701. TLS\u7248\u672c(1.3)2. \u5ba2\u6237\u7aef\u968f\u673a\u65703. \u652f\u6301\u7684\u5bc6\u7801\u5957\u4ef6\u5217\u88684. \u5bc6\u94a5\u5171\u4eab\u53c2\u65701. \u9009\u5b9aTLS\u7248\u672c2. \u670d\u52a1\u5668\u968f\u673a\u65703. \u9009\u5b9a\u5bc6\u7801\u5957\u4ef64. \u670d\u52a1\u5668\u7684\u5bc6\u94a5\u5171\u4eab\u53c2\u6570\u52a0\u5bc6\u7684\u6269\u5c55\u4fe1\u606f\u670d\u52a1\u5668\u7684\u6570\u5b57\u8bc1\u4e66\u94fe\u7528\u79c1\u94a5\u7b7e\u540d&#xff0c;\u8bc1\u660e\u8bc1\u4e66\u6240\u6709\u6743&#034;\u6211\u8bf4\u5b8c\u4e86&#034;\u4fe1\u53f7\u7b2c\u4e8c\u9636\u6bb5&#xff1a;\u5ba2\u6237\u7aef\u9a8c\u8bc1\u548c\u786e\u8ba4\u5982\u679c\u8981\u6c42\u53cc\u5411\u8ba4\u8bc1&#xff0c;\u53d1\u9001\u5ba2\u6237\u7aef\u8bc1\u4e66\u5ba2\u6237\u7aef\u8bc1\u4e66\u9a8c\u8bc1\u7b2c\u4e09\u9636\u6bb5&#xff1a;\u5e94\u7528\u6570\u636e\u4f20\u8f93ClientHelloServerHelloEncryptedExtensionsCertificateCertificateVerifyFinishedCertificate(\u53ef\u9009)CertificateVerify(\u53ef\u9009)Finished\u52a0\u5bc6\u7684\u5e94\u7528\u6570\u636e(\u5982\u8f66\u8f86\u72b6\u6001)\u52a0\u5bc6\u7684\u5e94\u7528\u6570\u636e(\u5982\u8f6f\u4ef6\u66f4\u65b0)<\/p>\n<h5>\u5173\u952e\u6b65\u9aa4\u7684\u6df1\u5165\u89e3\u8bfb&#xff1a;<\/h5>\n<p>\u6b65\u9aa41&#xff1a;ClientHello &#8211; \u201c\u4f60\u597d&#xff0c;\u6211\u652f\u6301\u8fd9\u4e9b\u5b89\u5168\u65b9\u6848\u201d<\/p>\n<p><span class=\"token comment\">\/\/ \u7c7b\u6bd4\u6570\u636e\u7ed3\u6784&#xff08;\u975e\u5b9e\u9645\u4ee3\u7801&#xff09;<\/span><br \/>\n<span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">ClientHello<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token class-name\">uint8_t<\/span> protocol_version <span class=\"token operator\">&#061;<\/span> TLS_1_3<span class=\"token punctuation\">;<\/span>  <span class=\"token comment\">\/\/ \u534f\u8bae\u7248\u672c<\/span><br \/>\n    Random random<span class=\"token punctuation\">;<\/span>                      <span class=\"token comment\">\/\/ 32\u5b57\u8282\u968f\u673a\u6570&#xff0c;\u9632\u6b62\u91cd\u653e\u653b\u51fb<\/span><br \/>\n    CipherSuite cipher_suites<span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span> <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">{<\/span>     <span class=\"token comment\">\/\/ \u652f\u6301\u7684\u5bc6\u7801\u5957\u4ef6\u5217\u8868<\/span><br \/>\n        TLS_AES_256_GCM_SHA384<span class=\"token punctuation\">,<\/span>        <span class=\"token comment\">\/\/ \u9996\u9009&#xff1a;AES-256\u52a0\u5bc6&#xff0c;SHA384\u54c8\u5e0c<\/span><br \/>\n        TLS_CHACHA20_POLY1305_SHA256<span class=\"token punctuation\">,<\/span>  <span class=\"token comment\">\/\/ \u5907\u9009&#xff1a;ChaCha20\u52a0\u5bc6<\/span><br \/>\n        TLS_AES_128_GCM_SHA256         <span class=\"token comment\">\/\/ \u5907\u9009&#xff1a;AES-128\u52a0\u5bc6<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    KeyShareEntry key_share<span class=\"token punctuation\">;<\/span>            <span class=\"token comment\">\/\/ \u5bc6\u94a5\u5171\u4eab\u53c2\u6570&#xff08;\u692d\u5706\u66f2\u7ebf\u70b9&#xff09;<\/span><br \/>\n    SNI server_name <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;oem.auto.com&#034;<\/span><span class=\"token punctuation\">;<\/span>  <span class=\"token comment\">\/\/ \u670d\u52a1\u5668\u540d\u79f0\u6307\u793a<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>\u4e3a\u4ec0\u4e48\u9700\u8981\u968f\u673a\u6570&#xff1f;<\/p>\n<ul>\n<li>\u9632\u6b62\u91cd\u653e\u653b\u51fb&#xff1a;\u9ed1\u5ba2\u8bb0\u5f55\u4e00\u6b21\u63e1\u624b\u8fc7\u7a0b&#xff0c;\u4e0b\u6b21\u76f4\u63a5\u91cd\u653e&#xff0c;\u53ef\u80fd\u7834\u89e3\u4f1a\u8bdd<\/li>\n<li>\u589e\u52a0\u968f\u673a\u6027&#xff1a;\u786e\u4fdd\u6bcf\u6b21\u4f1a\u8bdd\u5bc6\u94a5\u90fd\u4e0d\u540c&#xff0c;\u5373\u4f7f\u957f\u671f\u5bc6\u94a5\u6cc4\u9732\u4e5f\u4e0d\u5f71\u54cd\u5386\u53f2\u4f1a\u8bdd<\/li>\n<\/ul>\n<p>\u6b65\u9aa44-5&#xff1a;\u8bc1\u4e66\u4ea4\u6362\u4e0e\u9a8c\u8bc1 &#8211; \u201c\u8bc1\u660e\u4f60\u662f\u771f\u670d\u52a1\u5668\u201d<\/p>\n<p>\u8fd9\u662fTLS\u4e2d\u6700\u5173\u952e\u7684\u8eab\u4efd\u9a8c\u8bc1\u73af\u8282\u3002OEM\u670d\u52a1\u5668\u7684\u8bc1\u4e66\u901a\u5e38\u7531\u53ef\u4fe1\u7684CA&#xff08;\u8bc1\u4e66\u9881\u53d1\u673a\u6784&#xff09;\u7b7e\u53d1&#xff1a;<\/p>\n<p>\u8bc1\u4e66\u4fe1\u4efb\u94fe\u793a\u4f8b&#xff1a;<br \/>\n\u8f66\u8f86\u4fe1\u4efb\u6839CA \u2190 \u6839CA\u7b7e\u540d\u4e2d\u95f4CA \u2190 \u4e2d\u95f4CA\u7b7e\u540dOEM\u670d\u52a1\u5668\u8bc1\u4e66 \u2190 OEM\u670d\u52a1\u5668<\/p>\n<p>\u8f66\u8f86\u5982\u4f55\u9a8c\u8bc1\u8bc1\u4e66&#xff1f;<\/p>\n<li>\u68c0\u67e5\u6709\u6548\u671f&#xff1a;\u8bc1\u4e66\u662f\u5426\u5728\u6709\u6548\u671f\u5185&#xff1f;<\/li>\n<li>\u68c0\u67e5\u57df\u540d&#xff1a;\u8bc1\u4e66\u4e2d\u7684\u57df\u540d\u662f\u5426\u4e0e\u8fde\u63a5\u7684\u670d\u52a1\u5668\u5339\u914d&#xff1f;<\/li>\n<li>\u9a8c\u8bc1\u7b7e\u540d&#xff1a;\u7528\u4e0a\u4e00\u7ea7CA\u7684\u516c\u94a5\u9a8c\u8bc1\u5f53\u524d\u8bc1\u4e66\u7684\u7b7e\u540d<\/li>\n<li>\u68c0\u67e5\u540a\u9500\u72b6\u6001&#xff1a;\u901a\u8fc7OCSP\u6216CRL\u68c0\u67e5\u8bc1\u4e66\u662f\u5426\u88ab\u540a\u9500<\/li>\n<p>\u6b65\u9aa46-7&#xff1a;\u5bc6\u94a5\u534f\u5546 &#8211; \u201c\u751f\u6210\u53ea\u6709\u6211\u4eec\u77e5\u9053\u7684\u79d8\u5bc6\u201d<\/p>\n<p>TLS 1.3\u4f7f\u7528\u692d\u5706\u66f2\u7ebf\u8fea\u83f2-\u8d6b\u5c14\u66fc&#xff08;ECDHE&#xff09; \u7b97\u6cd5&#xff0c;\u5176\u6570\u5b66\u539f\u7406\u662f&#xff1a;<\/p>\n<ul>\n<li>\u8f66\u8f86\u548c\u670d\u52a1\u5668\u5404\u81ea\u751f\u6210\u4e34\u65f6\u5bc6\u94a5\u5bf9&#xff08;\u516c\u79c1\u94a5&#xff09;<\/li>\n<li>\u4ea4\u6362\u516c\u94a5<\/li>\n<li>\u5404\u81ea\u7528\u5bf9\u65b9\u7684\u516c\u94a5\u548c\u81ea\u5df1\u7684\u79c1\u94a5\u8ba1\u7b97&#xff0c;\u5f97\u5230\u76f8\u540c\u7684\u5171\u4eab\u79d8\u5bc6<\/li>\n<\/ul>\n<p>\u795e\u5947\u4e4b\u5904&#xff1a;\u5373\u4f7f\u9ed1\u5ba2\u622a\u83b7\u4e86\u6240\u6709\u901a\u4fe1\u5185\u5bb9&#xff0c;\u6ca1\u6709\u79c1\u94a5\u4e5f\u65e0\u6cd5\u8ba1\u7b97\u51fa\u5171\u4eab\u79d8\u5bc6\u3002\u8fd9\u63d0\u4f9b\u4e86\u524d\u5411\u5b89\u5168\u6027&#xff1a;\u5373\u4f7f\u670d\u52a1\u5668\u7684\u957f\u671f\u79c1\u94a5\u6cc4\u9732&#xff0c;\u4ee5\u524d\u7684\u4f1a\u8bdd\u8bb0\u5f55\u4e5f\u65e0\u6cd5\u89e3\u5bc6\u3002<\/p>\n<h3>\u7b2c\u4e09\u90e8\u5206&#xff1a;\u8f66\u8f7dTLS\u7684\u7279\u6b8a\u8003\u8651\u4e0e\u4f18\u5316<\/h3>\n<h4>3.1 \u8f66\u8f7d\u73af\u5883\u7684\u72ec\u7279\u6311\u6218<\/h4>\n<p>\u8f66\u8f7d\u7f51\u7edc\u4e0d\u662f\u666e\u901a\u7684\u8ba1\u7b97\u673a\u7f51\u7edc&#xff0c;\u5b83\u6709\u7279\u6b8a\u9700\u6c42&#xff1a;<\/p>\n<p>\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u2502             \u8f66\u8f7dTLS\u7684\u7279\u6b8a\u9700\u6c42\u4e0e\u89e3\u51b3\u65b9\u6848                     \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502     \u6311\u6218         \u2502             \u89e3\u51b3\u65b9\u6848                  \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502 \u7f51\u7edc\u4e0d\u7a33\u5b9a       \u2502 \u4f1a\u8bdd\u6062\u590d\u673a\u5236\u30010-RTT&#xff08;\u96f6\u5f80\u8fd4\u65f6\u95f4&#xff09;         \u2502<br \/>\n\u2502 \u8ba1\u7b97\u8d44\u6e90\u6709\u9650     \u2502 \u786c\u4ef6\u5b89\u5168\u6a21\u5757(HSM)\u3001\u4f18\u5316\u7684\u5bc6\u7801\u5957\u4ef6          \u2502<br \/>\n\u2502 \u5b9e\u65f6\u6027\u8981\u6c42\u9ad8     \u2502 \u7b80\u5316\u63e1\u624b\u6d41\u7a0b\u3001\u9884\u5171\u4eab\u5bc6\u94a5(PSK)              \u2502<br \/>\n\u2502 \u751f\u547d\u5468\u671f\u957f       \u2502 \u8bc1\u4e66\u957f\u671f\u6709\u6548\u6027\u7ba1\u7406\u3001\u5bc6\u94a5\u8f6e\u6362\u673a\u5236           \u2502<br \/>\n\u2502 \u6cd5\u89c4\u5408\u89c4\u8981\u6c42     \u2502 \u7b26\u5408UNECE WP.29\u7b49\u6c7d\u8f66\u7f51\u7edc\u5b89\u5168\u6cd5\u89c4         \u2502<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2534\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<\/p>\n<h4>3.2 \u4f1a\u8bdd\u6062\u590d\u4e0e0-RTT&#xff1a;\u8ba9\u91cd\u8fde\u66f4\u5feb<\/h4>\n<p>\u8f66\u8f86\u8fdb\u51fa\u96a7\u9053\u3001\u5730\u4e0b\u8f66\u5e93\u65f6&#xff0c;\u7f51\u7edc\u4f1a\u9891\u7e41\u4e2d\u65ad\u91cd\u8fde\u3002TLS\u63d0\u4f9b\u4e86\u4e24\u79cd\u4f18\u5316&#xff1a;<\/p>\n<p>\u4f1a\u8bdd\u6062\u590d&#xff1a;<\/p>\n<p>#mermaid-svg-YWWATN7wCB4B6y24{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;fill:#333;}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#mermaid-svg-YWWATN7wCB4B6y24 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#mermaid-svg-YWWATN7wCB4B6y24 .error-icon{fill:#552222;}#mermaid-svg-YWWATN7wCB4B6y24 .error-text{fill:#552222;stroke:#552222;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-thickness-normal{stroke-width:1px;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-thickness-thick{stroke-width:3.5px;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-pattern-solid{stroke-dasharray:0;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-thickness-invisible{stroke-width:0;fill:none;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-pattern-dashed{stroke-dasharray:3;}#mermaid-svg-YWWATN7wCB4B6y24 .edge-pattern-dotted{stroke-dasharray:2;}#mermaid-svg-YWWATN7wCB4B6y24 .marker{fill:#333333;stroke:#333333;}#mermaid-svg-YWWATN7wCB4B6y24 .marker.cross{stroke:#333333;}#mermaid-svg-YWWATN7wCB4B6y24 svg{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:16px;}#mermaid-svg-YWWATN7wCB4B6y24 p{margin:0;}#mermaid-svg-YWWATN7wCB4B6y24 .label{font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;color:#333;}#mermaid-svg-YWWATN7wCB4B6y24 .cluster-label text{fill:#333;}#mermaid-svg-YWWATN7wCB4B6y24 .cluster-label span{color:#333;}#mermaid-svg-YWWATN7wCB4B6y24 .cluster-label span p{background-color:transparent;}#mermaid-svg-YWWATN7wCB4B6y24 .label text,#mermaid-svg-YWWATN7wCB4B6y24 span{fill:#333;color:#333;}#mermaid-svg-YWWATN7wCB4B6y24 .node rect,#mermaid-svg-YWWATN7wCB4B6y24 .node circle,#mermaid-svg-YWWATN7wCB4B6y24 .node ellipse,#mermaid-svg-YWWATN7wCB4B6y24 .node polygon,#mermaid-svg-YWWATN7wCB4B6y24 .node path{fill:#ECECFF;stroke:#9370DB;stroke-width:1px;}#mermaid-svg-YWWATN7wCB4B6y24 .rough-node .label text,#mermaid-svg-YWWATN7wCB4B6y24 .node .label text,#mermaid-svg-YWWATN7wCB4B6y24 .image-shape .label,#mermaid-svg-YWWATN7wCB4B6y24 .icon-shape .label{text-anchor:middle;}#mermaid-svg-YWWATN7wCB4B6y24 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#mermaid-svg-YWWATN7wCB4B6y24 .rough-node .label,#mermaid-svg-YWWATN7wCB4B6y24 .node .label,#mermaid-svg-YWWATN7wCB4B6y24 .image-shape .label,#mermaid-svg-YWWATN7wCB4B6y24 .icon-shape .label{text-align:center;}#mermaid-svg-YWWATN7wCB4B6y24 .node.clickable{cursor:pointer;}#mermaid-svg-YWWATN7wCB4B6y24 .root .anchor path{fill:#333333!important;stroke-width:0;stroke:#333333;}#mermaid-svg-YWWATN7wCB4B6y24 .arrowheadPath{fill:#333333;}#mermaid-svg-YWWATN7wCB4B6y24 .edgePath .path{stroke:#333333;stroke-width:2.0px;}#mermaid-svg-YWWATN7wCB4B6y24 .flowchart-link{stroke:#333333;fill:none;}#mermaid-svg-YWWATN7wCB4B6y24 .edgeLabel{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-YWWATN7wCB4B6y24 .edgeLabel p{background-color:rgba(232,232,232, 0.8);}#mermaid-svg-YWWATN7wCB4B6y24 .edgeLabel rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-YWWATN7wCB4B6y24 .labelBkg{background-color:rgba(232, 232, 232, 0.5);}#mermaid-svg-YWWATN7wCB4B6y24 .cluster rect{fill:#ffffde;stroke:#aaaa33;stroke-width:1px;}#mermaid-svg-YWWATN7wCB4B6y24 .cluster text{fill:#333;}#mermaid-svg-YWWATN7wCB4B6y24 .cluster span{color:#333;}#mermaid-svg-YWWATN7wCB4B6y24 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;font-size:12px;background:hsl(80, 100%, 96.2745098039%);border:1px solid #aaaa33;border-radius:2px;pointer-events:none;z-index:100;}#mermaid-svg-YWWATN7wCB4B6y24 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:#333;}#mermaid-svg-YWWATN7wCB4B6y24 rect.text{fill:none;stroke-width:0;}#mermaid-svg-YWWATN7wCB4B6y24 .icon-shape,#mermaid-svg-YWWATN7wCB4B6y24 .image-shape{background-color:rgba(232,232,232, 0.8);text-align:center;}#mermaid-svg-YWWATN7wCB4B6y24 .icon-shape p,#mermaid-svg-YWWATN7wCB4B6y24 .image-shape p{background-color:rgba(232,232,232, 0.8);padding:2px;}#mermaid-svg-YWWATN7wCB4B6y24 .icon-shape rect,#mermaid-svg-YWWATN7wCB4B6y24 .image-shape rect{opacity:0.5;background-color:rgba(232,232,232, 0.8);fill:rgba(232,232,232, 0.8);}#mermaid-svg-YWWATN7wCB4B6y24 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#mermaid-svg-YWWATN7wCB4B6y24 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#mermaid-svg-YWWATN7wCB4B6y24 :root{&#8211;mermaid-font-family:\\&#8221;trebuchet ms\\&#8221;,verdana,arial,sans-serif;}<span class=\"edgeLabel\"><\/span><span class=\"edgeLabel\"><\/span><span class=\"edgeLabel\"><\/span><span class=\"edgeLabel\"><\/span><span class=\"edgeLabel\"><\/span><span class=\"edgeLabel\"><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u5b8c\u6574TLS\u63e1\u624b<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u5efa\u7acb\u4e3b\u5bc6\u94a5MS<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u670d\u52a1\u5668\u53d1\u9001\u4f1a\u8bdd\u51ed\u8bc1SessionTicket<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u7f51\u7edc\u65ad\u5f00<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u91cd\u65b0\u8fde\u63a5<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u5ba2\u6237\u7aef\u53d1\u9001SessionTicket<\/p>\n<p><\/span><span class=\"nodeLabel\"><\/p>\n<p>\u8df3\u8fc7\u5bc6\u94a5\u4ea4\u6362 \u76f4\u63a5\u6062\u590d\u4f1a\u8bdd<\/p>\n<p><\/span><\/p>\n<p>0-RTT&#xff08;\u96f6\u5f80\u8fd4\u65f6\u95f4&#xff09;&#xff1a;<br \/>\n\u5141\u8bb8\u5ba2\u6237\u7aef\u5728\u7b2c\u4e00\u4e2a\u6d88\u606f\u4e2d\u5c31\u53d1\u9001\u52a0\u5bc6\u6570\u636e&#xff0c;\u9002\u7528\u4e8e\u4e4b\u524d\u8fde\u63a5\u8fc7\u7684\u670d\u52a1\u5668\u3002\u4f46\u8981\u6ce8\u610f\u9632\u6b62\u91cd\u653e\u653b\u51fb\u3002<\/p>\n<h4>3.3 \u786c\u4ef6\u5b89\u5168\u6a21\u5757&#xff08;HSM&#xff09;&#xff1a;\u8f66\u8f7d\u5b89\u5168\u7684\u786c\u4ef6\u57fa\u7840<\/h4>\n<p>\u8f66\u8f7dHSM\u662f\u4e13\u95e8\u7684\u5b89\u5168\u82af\u7247&#xff0c;\u63d0\u4f9b&#xff1a;<\/p>\n<ul>\n<li>\u5b89\u5168\u5bc6\u94a5\u5b58\u50a8&#xff1a;\u79c1\u94a5\u6c38\u8fdc\u4e0d\u51faHSM<\/li>\n<li>\u5feb\u901f\u52a0\u89e3\u5bc6&#xff1a;\u786c\u4ef6\u52a0\u901f\u7684AES\u3001ECC\u8fd0\u7b97<\/li>\n<li>\u771f\u968f\u673a\u6570\u751f\u6210&#xff1a;\u7269\u7406\u71b5\u6e90\u751f\u6210\u9ad8\u8d28\u91cf\u968f\u673a\u6570<\/li>\n<li>\u9632\u7be1\u6539\u8bbe\u8ba1&#xff1a;\u68c0\u6d4b\u5230\u7269\u7406\u653b\u51fb\u65f6\u81ea\u52a8\u64e6\u9664\u5bc6\u94a5<\/li>\n<\/ul>\n<h3>\u7b2c\u56db\u90e8\u5206&#xff1a;\u5b9e\u6218\u6848\u4f8b\u2014\u2014\u7535\u52a8\u6c7d\u8f66\u7684OTA\u8f6f\u4ef6\u66f4\u65b0<\/h3>\n<p>\u8ba9\u6211\u4eec\u901a\u8fc7\u4e00\u4e2a\u771f\u5b9e\u573a\u666f&#xff0c;\u770b\u770bTLS\u5982\u4f55\u4fdd\u62a4\u8f66\u8f86\u7684\u8f6f\u4ef6\u66f4\u65b0&#xff1a;<\/p>\n<h4>4.1 \u573a\u666f\u63cf\u8ff0<\/h4>\n<p>\u67d0\u7535\u52a8\u6c7d\u8f66\u5236\u9020\u5546&#034;\u672a\u6765\u6c7d\u8f66&#034;\u8981\u5411\u5df2\u552e\u8f66\u8f86\u63a8\u9001\u91cd\u8981\u7684\u7535\u6c60\u7ba1\u7406\u7cfb\u7edf\u66f4\u65b0\u3002\u6574\u4e2a\u6d41\u7a0b\u5fc5\u987b&#xff1a;<\/p>\n<li>\u4fdd\u5bc6&#xff1a;\u66f4\u65b0\u5305\u4e0d\u88ab\u7a83\u53d6\u6216\u5206\u6790<\/li>\n<li>\u5b8c\u6574&#xff1a;\u66f4\u65b0\u5305\u4e0d\u88ab\u7be1\u6539<\/li>\n<li>\u53ef\u9760&#xff1a;\u786e\u4fdd\u6b63\u786e\u7684\u8f66\u8f86\u6536\u5230\u6b63\u786e\u7684\u66f4\u65b0<\/li>\n<li>\u53ef\u5ba1\u8ba1&#xff1a;\u8bb0\u5f55\u6240\u6709\u66f4\u65b0\u6d3b\u52a8<\/li>\n<h4>4.2 \u5b8c\u6574\u6d41\u7a0b\u5b9e\u73b0<\/h4>\n<p>\u4ee5\u4e0b\u662f\u7b80\u5316\u7684\u5b9e\u73b0\u793a\u4f8b&#xff0c;\u5c55\u793a\u8f66\u8f86\u5982\u4f55\u5b89\u5168\u5730\u4eceOEM\u670d\u52a1\u5668\u83b7\u53d6\u66f4\u65b0&#xff1a;<\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;file secure_ota_update.c<br \/>\n * &#064;brief \u5b89\u5168\u7684OTA\u66f4\u65b0\u5ba2\u6237\u7aef\u5b9e\u73b0<br \/>\n * &#064;author \u672a\u6765\u6c7d\u8f66\u5b89\u5168\u56e2\u961f<br \/>\n * &#064;date 2023<br \/>\n *<br \/>\n * \u6b64\u4ee3\u7801\u6f14\u793a\u4e86\u8f66\u8f86\u5982\u4f55\u901a\u8fc7TLS\u5b89\u5168\u5730\u4e0b\u8f7d\u8f6f\u4ef6\u66f4\u65b0<br \/>\n * \u5305\u542b\u5b8c\u6574\u7684\u4e3b\u51fd\u6570\u548cMakefile&#xff0c;\u53ef\u76f4\u63a5\u7f16\u8bd1\u8fd0\u884c<br \/>\n *\/<\/span><\/p>\n<p><span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;stdio.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;stdlib.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;string.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;unistd.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;time.h&gt;<\/span><\/span><\/p>\n<p><span class=\"token comment\">\/* OpenSSL\u5934\u6587\u4ef6 *\/<\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;openssl\/ssl.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;openssl\/err.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;openssl\/x509_vfy.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;openssl\/pem.h&gt;<\/span><\/span><\/p>\n<p><span class=\"token comment\">\/* \u7f51\u7edc\u5934\u6587\u4ef6 *\/<\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;sys\/socket.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;netinet\/in.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;arpa\/inet.h&gt;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">include<\/span> <span class=\"token string\">&lt;netdb.h&gt;<\/span><\/span><\/p>\n<p><span class=\"token comment\">\/* \u8f66\u8f86\u4fe1\u606f *\/<\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">define<\/span> <span class=\"token macro-name\">VEHICLE_ID<\/span> <span class=\"token string\">&#034;VIN_ABC123DEF456789&#034;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">define<\/span> <span class=\"token macro-name\">VEHICLE_MODEL<\/span> <span class=\"token string\">&#034;FUTURE_CAR_X&#034;<\/span><\/span><br \/>\n<span class=\"token macro property\"><span class=\"token directive-hash\">#<\/span><span class=\"token directive keyword\">define<\/span> <span class=\"token macro-name\">FIRMWARE_VERSION<\/span> <span class=\"token string\">&#034;1.2.3&#034;<\/span><\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u521d\u59cb\u5316OpenSSL\u5e93<br \/>\n *<br \/>\n * \u521d\u59cb\u5316OpenSSL&#xff0c;\u52a0\u8f7d\u7b97\u6cd5\u548c\u9519\u8bef\u4fe1\u606f<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">void<\/span> <span class=\"token function\">init_openssl<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token function\">SSL_library_init<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">OpenSSL_add_all_algorithms<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">SSL_load_error_strings<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">ERR_load_crypto_strings<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u521b\u5efaSSL\u4e0a\u4e0b\u6587<br \/>\n *<br \/>\n * \u521b\u5efa\u5e76\u914d\u7f6eSSL_CTX\u5bf9\u8c61&#xff0c;\u8bbe\u7f6e\u534f\u8bae\u7248\u672c\u3001\u9a8c\u8bc1\u6a21\u5f0f\u7b49<br \/>\n *<br \/>\n * &#064;param ca_cert_path CA\u8bc1\u4e66\u8def\u5f84<br \/>\n * &#064;param client_cert_path \u5ba2\u6237\u7aef\u8bc1\u4e66\u8def\u5f84&#xff08;\u53ef\u4e3aNULL&#xff09;<br \/>\n * &#064;param client_key_path \u5ba2\u6237\u7aef\u79c1\u94a5\u8def\u5f84&#xff08;\u53ef\u4e3aNULL&#xff09;<br \/>\n * &#064;return SSL_CTX* \u521d\u59cb\u5316\u597d\u7684SSL\u4e0a\u4e0b\u6587<br \/>\n *\/<\/span><br \/>\nSSL_CTX<span class=\"token operator\">*<\/span> <span class=\"token function\">create_ssl_context<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> ca_cert_path<span class=\"token punctuation\">,<\/span><br \/>\n                           <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> client_cert_path<span class=\"token punctuation\">,<\/span><br \/>\n                           <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> client_key_path<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> SSL_METHOD <span class=\"token operator\">*<\/span>method <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">TLS_client_method<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    SSL_CTX <span class=\"token operator\">*<\/span>ctx <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_CTX_new<\/span><span class=\"token punctuation\">(<\/span>method<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>ctx<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u521b\u5efaSSL\u4e0a\u4e0b\u6587\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">ERR_print_errors_fp<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bbe\u7f6e\u6700\u5c0fTLS\u7248\u672c\u4e3a1.2&#xff0c;\u63a8\u83501.3 *\/<\/span><br \/>\n    <span class=\"token function\">SSL_CTX_set_min_proto_version<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> TLS1_2_VERSION<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u52a0\u8f7d\u53d7\u4fe1\u4efb\u7684CA\u8bc1\u4e66 *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_CTX_load_verify_locations<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> ca_cert_path<span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u52a0\u8f7dCA\u8bc1\u4e66: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> ca_cert_path<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bbe\u7f6e\u9a8c\u8bc1\u6a21\u5f0f&#xff1a;\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66 *\/<\/span><br \/>\n    <span class=\"token function\">SSL_CTX_set_verify<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> SSL_VERIFY_PEER<span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">SSL_CTX_set_verify_depth<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> <span class=\"token number\">4<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span> <span class=\"token comment\">\/* \u6700\u5927\u8bc1\u4e66\u94fe\u6df1\u5ea6 *\/<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u5982\u679c\u63d0\u4f9b\u4e86\u5ba2\u6237\u7aef\u8bc1\u4e66&#xff0c;\u5219\u52a0\u8f7d *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>client_cert_path <span class=\"token operator\">&amp;&amp;<\/span> client_key_path<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_CTX_use_certificate_file<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> client_cert_path<span class=\"token punctuation\">,<\/span> SSL_FILETYPE_PEM<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u52a0\u8f7d\u5ba2\u6237\u7aef\u8bc1\u4e66\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><\/p>\n<p>        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_CTX_use_PrivateKey_file<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> client_key_path<span class=\"token punctuation\">,<\/span> SSL_FILETYPE_PEM<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u52a0\u8f7d\u5ba2\u6237\u7aef\u79c1\u94a5\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><\/p>\n<p>        <span class=\"token comment\">\/* \u9a8c\u8bc1\u5ba2\u6237\u7aef\u8bc1\u4e66\u548c\u79c1\u94a5\u5339\u914d *\/<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_CTX_check_private_key<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u5ba2\u6237\u7aef\u8bc1\u4e66\u548c\u79c1\u94a5\u4e0d\u5339\u914d\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><\/p>\n<p>        <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5df2\u52a0\u8f7d\u5ba2\u6237\u7aef\u8bc1\u4e66&#xff0c;\u542f\u7528\u53cc\u5411\u8ba4\u8bc1\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bbe\u7f6e\u5bc6\u7801\u5957\u4ef6&#xff08;\u4f18\u5148\u4f7f\u7528\u524d\u5411\u5b89\u5168\u7684ECDHE\u5957\u4ef6&#xff09; *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_CTX_set_cipher_list<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;ECDHE-ECDSA-AES256-GCM-SHA384:&#034;<\/span><br \/>\n                                     <span class=\"token string\">&#034;ECDHE-RSA-AES256-GCM-SHA384:&#034;<\/span><br \/>\n                                     <span class=\"token string\">&#034;ECDHE-ECDSA-CHACHA20-POLY1305:&#034;<\/span><br \/>\n                                     <span class=\"token string\">&#034;ECDHE-RSA-CHACHA20-POLY1305&#034;<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u8bbe\u7f6e\u5bc6\u7801\u5957\u4ef6\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">return<\/span> ctx<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u5efa\u7acbTCP\u8fde\u63a5<br \/>\n *<br \/>\n * \u8fde\u63a5\u5230\u6307\u5b9a\u7684\u670d\u52a1\u5668\u548c\u7aef\u53e3<br \/>\n *<br \/>\n * &#064;param hostname \u670d\u52a1\u5668\u4e3b\u673a\u540d<br \/>\n * &#064;param port \u670d\u52a1\u5668\u7aef\u53e3<br \/>\n * &#064;return int \u6210\u529f\u8fd4\u56desocket\u63cf\u8ff0\u7b26&#xff0c;\u5931\u8d25\u8fd4\u56de-1<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">create_tcp_connection<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> hostname<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">int<\/span> port<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">hostent<\/span> <span class=\"token operator\">*<\/span>server<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">sockaddr_in<\/span> serv_addr<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> sockfd<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u521b\u5efasocket *\/<\/span><br \/>\n    sockfd <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">socket<\/span><span class=\"token punctuation\">(<\/span>AF_INET<span class=\"token punctuation\">,<\/span> SOCK_STREAM<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>sockfd <span class=\"token operator\">&lt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u521b\u5efasocket\u5931\u8d25&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u89e3\u6790\u4e3b\u673a\u540d *\/<\/span><br \/>\n    server <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">gethostbyname<\/span><span class=\"token punctuation\">(<\/span>hostname<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>server <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u89e3\u6790\u4e3b\u673a\u540d: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> hostname<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">close<\/span><span class=\"token punctuation\">(<\/span>sockfd<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bbe\u7f6e\u670d\u52a1\u5668\u5730\u5740 *\/<\/span><br \/>\n    <span class=\"token function\">memset<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>serv_addr<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>serv_addr<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    serv_addr<span class=\"token punctuation\">.<\/span>sin_family <span class=\"token operator\">&#061;<\/span> AF_INET<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">memcpy<\/span><span class=\"token punctuation\">(<\/span><span class=\"token operator\">&amp;<\/span>serv_addr<span class=\"token punctuation\">.<\/span>sin_addr<span class=\"token punctuation\">.<\/span>s_addr<span class=\"token punctuation\">,<\/span> server<span class=\"token operator\">-&gt;<\/span>h_addr<span class=\"token punctuation\">,<\/span> server<span class=\"token operator\">-&gt;<\/span>h_length<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    serv_addr<span class=\"token punctuation\">.<\/span>sin_port <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">htons<\/span><span class=\"token punctuation\">(<\/span>port<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8fde\u63a5\u670d\u52a1\u5668 *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">connect<\/span><span class=\"token punctuation\">(<\/span>sockfd<span class=\"token punctuation\">,<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token keyword\">struct<\/span> <span class=\"token class-name\">sockaddr<\/span><span class=\"token operator\">*<\/span><span class=\"token punctuation\">)<\/span><span class=\"token operator\">&amp;<\/span>serv_addr<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>serv_addr<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&lt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u8fde\u63a5\u670d\u52a1\u5668\u5931\u8d25&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">close<\/span><span class=\"token punctuation\">(<\/span>sockfd<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u6210\u529f\u8fde\u63a5\u5230 %s:%d\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> hostname<span class=\"token punctuation\">,<\/span> port<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> sockfd<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66<br \/>\n *<br \/>\n * \u68c0\u67e5\u670d\u52a1\u5668\u8bc1\u4e66\u7684\u6709\u6548\u6027&#xff0c;\u5305\u62ec\u57df\u540d\u5339\u914d\u3001\u6709\u6548\u671f\u7b49<br \/>\n *<br \/>\n * &#064;param ssl SSL\u8fde\u63a5\u5bf9\u8c61<br \/>\n * &#064;param expected_hostname \u9884\u671f\u7684\u670d\u52a1\u5668\u4e3b\u673a\u540d<br \/>\n * &#064;return int \u6210\u529f\u8fd4\u56de0&#xff0c;\u5931\u8d25\u8fd4\u56de-1<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">verify_server_certificate<\/span><span class=\"token punctuation\">(<\/span>SSL<span class=\"token operator\">*<\/span> ssl<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> expected_hostname<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    X509 <span class=\"token operator\">*<\/span>cert<span class=\"token punctuation\">;<\/span><br \/>\n    X509_NAME <span class=\"token operator\">*<\/span>subject_name<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">char<\/span> common_name<span class=\"token punctuation\">[<\/span><span class=\"token number\">256<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> verify_result<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u83b7\u53d6\u670d\u52a1\u5668\u8bc1\u4e66 *\/<\/span><br \/>\n    cert <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_get_peer_certificate<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>cert<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u670d\u52a1\u5668\u672a\u63d0\u4f9b\u8bc1\u4e66\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u83b7\u53d6\u8bc1\u4e66\u9a8c\u8bc1\u7ed3\u679c *\/<\/span><br \/>\n    verify_result <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_get_verify_result<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>verify_result <span class=\"token operator\">!&#061;<\/span> X509_V_OK<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u8bc1\u4e66\u9a8c\u8bc1\u5931\u8d25: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                <span class=\"token function\">X509_verify_cert_error_string<\/span><span class=\"token punctuation\">(<\/span>verify_result<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">X509_free<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u68c0\u67e5\u8bc1\u4e66\u4e2d\u7684CN&#xff08;\u901a\u7528\u540d&#xff09;\u662f\u5426\u5339\u914d\u9884\u671f\u7684\u4e3b\u673a\u540d *\/<\/span><br \/>\n    subject_name <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">X509_get_subject_name<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">X509_NAME_get_text_by_NID<\/span><span class=\"token punctuation\">(<\/span>subject_name<span class=\"token punctuation\">,<\/span> NID_commonName<span class=\"token punctuation\">,<\/span><br \/>\n                                  common_name<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>common_name<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&lt;&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u4ece\u8bc1\u4e66\u4e2d\u83b7\u53d6CN\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">X509_free<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">strcasecmp<\/span><span class=\"token punctuation\">(<\/span>common_name<span class=\"token punctuation\">,<\/span> expected_hostname<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u8bc1\u4e66CN\u4e0d\u5339\u914d: \u671f\u671b &#039;%s&#039;, \u5b9e\u9645 &#039;%s&#039;\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                expected_hostname<span class=\"token punctuation\">,<\/span> common_name<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">X509_free<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u68c0\u67e5\u8bc1\u4e66\u6709\u6548\u671f *\/<\/span><br \/>\n    ASN1_TIME <span class=\"token operator\">*<\/span>not_before <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">X509_get_notBefore<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    ASN1_TIME <span class=\"token operator\">*<\/span>not_after <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">X509_get_notAfter<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u670d\u52a1\u5668\u8bc1\u4e66\u9a8c\u8bc1\u901a\u8fc7:\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;  \u9881\u53d1\u7ed9: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> common_name<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;  \u6709\u6548\u671f: &#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">ASN1_TIME_print_fp<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stdout<\/span><span class=\"token punctuation\">,<\/span> not_before<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034; \u5230 &#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">ASN1_TIME_print_fp<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stdout<\/span><span class=\"token punctuation\">,<\/span> not_after<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token function\">X509_free<\/span><span class=\"token punctuation\">(<\/span>cert<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u53d1\u9001\u8f66\u8f86\u4fe1\u606f<br \/>\n *<br \/>\n * \u53d1\u9001\u8f66\u8f86\u8eab\u4efd\u4fe1\u606f\u548c\u5f53\u524d\u56fa\u4ef6\u7248\u672c\u5230\u670d\u52a1\u5668<br \/>\n *<br \/>\n * &#064;param ssl SSL\u8fde\u63a5\u5bf9\u8c61<br \/>\n * &#064;param vehicle_id \u8f66\u8f86\u8bc6\u522b\u7801<br \/>\n * &#064;param model \u8f66\u578b<br \/>\n * &#064;param current_version \u5f53\u524d\u56fa\u4ef6\u7248\u672c<br \/>\n * &#064;return int \u6210\u529f\u8fd4\u56de0&#xff0c;\u5931\u8d25\u8fd4\u56de-1<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">send_vehicle_info<\/span><span class=\"token punctuation\">(<\/span>SSL<span class=\"token operator\">*<\/span> ssl<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> vehicle_id<span class=\"token punctuation\">,<\/span><br \/>\n                     <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> model<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> current_version<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    <span class=\"token keyword\">char<\/span> request<span class=\"token punctuation\">[<\/span><span class=\"token number\">1024<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> len<span class=\"token punctuation\">,<\/span> bytes_written<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u6784\u9020\u8bf7\u6c42 *\/<\/span><br \/>\n    len <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">snprintf<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>request<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                  <span class=\"token string\">&#034;GET \/ota\/check-update HTTP\/1.1\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;Host: oem.auto.com\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;User-Agent: FutureCar-OTA-Client\/1.0\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;X-Vehicle-ID: %s\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;X-Vehicle-Model: %s\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;X-Current-Version: %s\\\\r\\\\n&#034;<\/span><br \/>\n                  <span class=\"token string\">&#034;\\\\r\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                  vehicle_id<span class=\"token punctuation\">,<\/span> model<span class=\"token punctuation\">,<\/span> current_version<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u53d1\u9001\u8bf7\u6c42 *\/<\/span><br \/>\n    bytes_written <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_write<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> request<span class=\"token punctuation\">,<\/span> len<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>bytes_written <span class=\"token operator\">&lt;&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">int<\/span> err <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_get_error<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> bytes_written<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u53d1\u9001\u8bf7\u6c42\u5931\u8d25&#xff0c;SSL\u9519\u8bef: %d\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> err<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5df2\u53d1\u9001\u8f66\u8f86\u4fe1\u606f\u8bf7\u6c42\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">return<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u4e0b\u8f7d\u56fa\u4ef6\u66f4\u65b0<br \/>\n *<br \/>\n * \u4ece\u670d\u52a1\u5668\u4e0b\u8f7d\u56fa\u4ef6\u66f4\u65b0\u5305&#xff0c;\u5e76\u9a8c\u8bc1\u5b8c\u6574\u6027<br \/>\n *<br \/>\n * &#064;param ssl SSL\u8fde\u63a5\u5bf9\u8c61<br \/>\n * &#064;param save_path \u4fdd\u5b58\u8def\u5f84<br \/>\n * &#064;return int \u6210\u529f\u8fd4\u56de0&#xff0c;\u5931\u8d25\u8fd4\u56de-1<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">download_firmware<\/span><span class=\"token punctuation\">(<\/span>SSL<span class=\"token operator\">*<\/span> ssl<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> save_path<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    FILE <span class=\"token operator\">*<\/span>fp<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">char<\/span> buffer<span class=\"token punctuation\">[<\/span><span class=\"token number\">4096<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> bytes_read<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">size_t<\/span> total_bytes <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">time_t<\/span> start_time<span class=\"token punctuation\">,<\/span> current_time<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u6253\u5f00\u6587\u4ef6\u7528\u4e8e\u4fdd\u5b58\u56fa\u4ef6 *\/<\/span><br \/>\n    fp <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fopen<\/span><span class=\"token punctuation\">(<\/span>save_path<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;wb&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>fp<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u65e0\u6cd5\u521b\u5efa\u56fa\u4ef6\u6587\u4ef6&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5f00\u59cb\u4e0b\u8f7d\u56fa\u4ef6&#8230;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    start_time <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">time<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bfb\u53d6\u670d\u52a1\u5668\u54cd\u5e94 *\/<\/span><br \/>\n    <span class=\"token keyword\">while<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        bytes_read <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_read<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> buffer<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>buffer<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>bytes_read <span class=\"token operator\">&gt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token comment\">\/* \u5199\u5165\u6587\u4ef6 *\/<\/span><br \/>\n            <span class=\"token class-name\">size_t<\/span> written <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fwrite<\/span><span class=\"token punctuation\">(<\/span>buffer<span class=\"token punctuation\">,<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">,<\/span> bytes_read<span class=\"token punctuation\">,<\/span> fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>written <span class=\"token operator\">!&#061;<\/span> bytes_read<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n                <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u5199\u5165\u6587\u4ef6\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token punctuation\">}<\/span><\/p>\n<p>            total_bytes <span class=\"token operator\">&#043;&#061;<\/span> bytes_read<span class=\"token punctuation\">;<\/span><\/p>\n<p>            <span class=\"token comment\">\/* \u6bcf\u4e0b\u8f7d1MB\u6253\u5370\u4e00\u6b21\u8fdb\u5ea6 *\/<\/span><br \/>\n            <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>total_bytes <span class=\"token operator\">%<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token number\">1024<\/span><span class=\"token operator\">*<\/span><span class=\"token number\">1024<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">&lt;<\/span> <span class=\"token number\">4096<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n                current_time <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">time<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token keyword\">double<\/span> elapsed <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">difftime<\/span><span class=\"token punctuation\">(<\/span>current_time<span class=\"token punctuation\">,<\/span> start_time<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token keyword\">double<\/span> speed <span class=\"token operator\">&#061;<\/span> <span class=\"token punctuation\">(<\/span>total_bytes <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token punctuation\">(<\/span>elapsed <span class=\"token operator\">&gt;<\/span> <span class=\"token number\">0<\/span> <span class=\"token operator\">?<\/span> elapsed <span class=\"token operator\">:<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5df2\u4e0b\u8f7d: %.2f MB, \u901f\u5ea6: %.2f MB\/s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n                      total_bytes <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span><span class=\"token punctuation\">,<\/span> speed<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token punctuation\">}<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span> <span class=\"token keyword\">else<\/span> <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>bytes_read <span class=\"token operator\">&#061;&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token comment\">\/* \u8fde\u63a5\u5173\u95ed *\/<\/span><br \/>\n            <span class=\"token keyword\">break<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span> <span class=\"token keyword\">else<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token comment\">\/* \u8bfb\u53d6\u9519\u8bef *\/<\/span><br \/>\n            <span class=\"token keyword\">int<\/span> err <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_get_error<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> bytes_read<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u8bfb\u53d6\u6570\u636e\u5931\u8d25&#xff0c;SSL\u9519\u8bef: %d\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> err<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token keyword\">return<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    current_time <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">time<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">double<\/span> elapsed <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">difftime<\/span><span class=\"token punctuation\">(<\/span>current_time<span class=\"token punctuation\">,<\/span> start_time<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u56fa\u4ef6\u4e0b\u8f7d\u5b8c\u6210!\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u603b\u5927\u5c0f: %.2f MB\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> total_bytes <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u8017\u65f6: %.2f \u79d2\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> elapsed<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5e73\u5747\u901f\u5ea6: %.2f MB\/s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span><br \/>\n          <span class=\"token punctuation\">(<\/span>total_bytes <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token number\">1024.0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">\/<\/span> <span class=\"token punctuation\">(<\/span>elapsed <span class=\"token operator\">&gt;<\/span> <span class=\"token number\">0<\/span> <span class=\"token operator\">?<\/span> elapsed <span class=\"token operator\">:<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">return<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u9a8c\u8bc1\u56fa\u4ef6\u7b7e\u540d<br \/>\n *<br \/>\n * \u4f7f\u7528\u516c\u94a5\u9a8c\u8bc1\u56fa\u4ef6\u7684\u6570\u5b57\u7b7e\u540d&#xff0c;\u786e\u4fdd\u5b8c\u6574\u6027\u548c\u6765\u6e90<br \/>\n *<br \/>\n * &#064;param firmware_path \u56fa\u4ef6\u6587\u4ef6\u8def\u5f84<br \/>\n * &#064;param signature_path \u7b7e\u540d\u6587\u4ef6\u8def\u5f84<br \/>\n * &#064;param public_key_path \u516c\u94a5\u8def\u5f84<br \/>\n * &#064;return int \u6210\u529f\u8fd4\u56de0&#xff0c;\u5931\u8d25\u8fd4\u56de-1<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">verify_firmware_signature<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> firmware_path<span class=\"token punctuation\">,<\/span><br \/>\n                             <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> signature_path<span class=\"token punctuation\">,<\/span><br \/>\n                             <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span><span class=\"token operator\">*<\/span> public_key_path<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    FILE <span class=\"token operator\">*<\/span>fp<span class=\"token punctuation\">;<\/span><br \/>\n    EVP_PKEY <span class=\"token operator\">*<\/span>public_key <span class=\"token operator\">&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    EVP_MD_CTX <span class=\"token operator\">*<\/span>md_ctx <span class=\"token operator\">&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">unsigned<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>signature <span class=\"token operator\">&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token class-name\">size_t<\/span> signature_len<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">unsigned<\/span> <span class=\"token keyword\">char<\/span> file_hash<span class=\"token punctuation\">[<\/span>EVP_MAX_MD_SIZE<span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">unsigned<\/span> <span class=\"token keyword\">int<\/span> hash_len<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> ret <span class=\"token operator\">&#061;<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bfb\u53d6\u516c\u94a5 *\/<\/span><br \/>\n    fp <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fopen<\/span><span class=\"token punctuation\">(<\/span>public_key_path<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;r&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>fp<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u65e0\u6cd5\u6253\u5f00\u516c\u94a5\u6587\u4ef6&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    public_key <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">PEM_read_PUBKEY<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>public_key<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u8bfb\u53d6\u516c\u94a5\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bfb\u53d6\u7b7e\u540d *\/<\/span><br \/>\n    fp <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fopen<\/span><span class=\"token punctuation\">(<\/span>signature_path<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;rb&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>fp<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u65e0\u6cd5\u6253\u5f00\u7b7e\u540d\u6587\u4ef6&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">fseek<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token constant\">SEEK_END<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    signature_len <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">ftell<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">fseek<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">,<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token constant\">SEEK_SET<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    signature <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">malloc<\/span><span class=\"token punctuation\">(<\/span>signature_len<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>signature<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u5185\u5b58\u5206\u914d\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">fread<\/span><span class=\"token punctuation\">(<\/span>signature<span class=\"token punctuation\">,<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">,<\/span> signature_len<span class=\"token punctuation\">,<\/span> fp<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> signature_len<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u8bfb\u53d6\u7b7e\u540d\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8ba1\u7b97\u56fa\u4ef6\u6587\u4ef6\u7684\u54c8\u5e0c\u503c *\/<\/span><br \/>\n    md_ctx <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">EVP_MD_CTX_new<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>md_ctx<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u521b\u5efa\u54c8\u5e0c\u4e0a\u4e0b\u6587\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">EVP_DigestInit_ex<\/span><span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">,<\/span> <span class=\"token function\">EVP_sha256<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u521d\u59cb\u5316\u54c8\u5e0c\u8ba1\u7b97\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    fp <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fopen<\/span><span class=\"token punctuation\">(<\/span>firmware_path<span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;rb&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>fp<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">perror<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u65e0\u6cd5\u6253\u5f00\u56fa\u4ef6\u6587\u4ef6&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token keyword\">while<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span><span class=\"token function\">feof<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">unsigned<\/span> <span class=\"token keyword\">char<\/span> buffer<span class=\"token punctuation\">[<\/span><span class=\"token number\">8192<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token class-name\">size_t<\/span> bytes_read <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">fread<\/span><span class=\"token punctuation\">(<\/span>buffer<span class=\"token punctuation\">,<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">sizeof<\/span><span class=\"token punctuation\">(<\/span>buffer<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">,<\/span> fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>bytes_read <span class=\"token operator\">&gt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n            <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">EVP_DigestUpdate<\/span><span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">,<\/span> buffer<span class=\"token punctuation\">,<\/span> bytes_read<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n                <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u54c8\u5e0c\u8ba1\u7b97\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n                <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n            <span class=\"token punctuation\">}<\/span><br \/>\n        <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">fclose<\/span><span class=\"token punctuation\">(<\/span>fp<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">EVP_DigestFinal_ex<\/span><span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">,<\/span> file_hash<span class=\"token punctuation\">,<\/span> <span class=\"token operator\">&amp;<\/span>hash_len<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u65e0\u6cd5\u5b8c\u6210\u54c8\u5e0c\u8ba1\u7b97\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u9a8c\u8bc1\u7b7e\u540d *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">EVP_PKEY_verify<\/span><span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">,<\/span> signature<span class=\"token punctuation\">,<\/span> signature_len<span class=\"token punctuation\">,<\/span> file_hash<span class=\"token punctuation\">,<\/span> hash_len<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u56fa\u4ef6\u7b7e\u540d\u9a8c\u8bc1\u5931\u8d25&#xff01;\u53ef\u80fd\u88ab\u7be1\u6539\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u56fa\u4ef6\u7b7e\u540d\u9a8c\u8bc1\u6210\u529f&#xff01;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    ret <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>cleanup<span class=\"token operator\">:<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>public_key<span class=\"token punctuation\">)<\/span> <span class=\"token function\">EVP_PKEY_free<\/span><span class=\"token punctuation\">(<\/span>public_key<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">)<\/span> <span class=\"token function\">EVP_MD_CTX_free<\/span><span class=\"token punctuation\">(<\/span>md_ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>signature<span class=\"token punctuation\">)<\/span> <span class=\"token function\">free<\/span><span class=\"token punctuation\">(<\/span>signature<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">return<\/span> ret<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<p><span class=\"token comment\">\/**<br \/>\n * &#064;brief \u4e3b\u51fd\u6570<br \/>\n *<br \/>\n * \u7a0b\u5e8f\u5165\u53e3&#xff0c;\u534f\u8c03\u6574\u4e2aOTA\u66f4\u65b0\u6d41\u7a0b<br \/>\n *<br \/>\n * &#064;param argc \u53c2\u6570\u4e2a\u6570<br \/>\n * &#064;param argv \u53c2\u6570\u6570\u7ec4<br \/>\n * &#064;return int \u7a0b\u5e8f\u9000\u51fa\u7801<br \/>\n *\/<\/span><br \/>\n<span class=\"token keyword\">int<\/span> <span class=\"token function\">main<\/span><span class=\"token punctuation\">(<\/span><span class=\"token keyword\">int<\/span> argc<span class=\"token punctuation\">,<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>argv<span class=\"token punctuation\">[<\/span><span class=\"token punctuation\">]<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n    SSL_CTX <span class=\"token operator\">*<\/span>ctx <span class=\"token operator\">&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    SSL <span class=\"token operator\">*<\/span>ssl <span class=\"token operator\">&#061;<\/span> <span class=\"token constant\">NULL<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> sockfd <span class=\"token operator\">&#061;<\/span> <span class=\"token operator\">&#8211;<\/span><span class=\"token number\">1<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> ret <span class=\"token operator\">&#061;<\/span> EXIT_FAILURE<span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u547d\u4ee4\u884c\u53c2\u6570 *\/<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>server_hostname <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;oem.auto.com&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">int<\/span> server_port <span class=\"token operator\">&#061;<\/span> <span class=\"token number\">443<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>ca_cert_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/etc\/vehicle\/certs\/ca.crt&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>client_cert_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/etc\/vehicle\/certs\/client.crt&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>client_key_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/etc\/vehicle\/certs\/client.key&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>firmware_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/tmp\/firmware_update.bin&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>signature_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/tmp\/firmware_update.sig&#034;<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">const<\/span> <span class=\"token keyword\">char<\/span> <span class=\"token operator\">*<\/span>public_key_path <span class=\"token operator\">&#061;<\/span> <span class=\"token string\">&#034;\/etc\/vehicle\/certs\/ota_public_key.pem&#034;<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;    \u672a\u6765\u6c7d\u8f66 &#8211; \u5b89\u5168OTA\u66f4\u65b0\u5ba2\u6237\u7aef\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u8f66\u8f86ID: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> VEHICLE_ID<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u8f66\u578b: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> VEHICLE_MODEL<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u5f53\u524d\u56fa\u4ef6\u7248\u672c: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> FIRMWARE_VERSION<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u521d\u59cb\u5316OpenSSL *\/<\/span><br \/>\n    <span class=\"token function\">init_openssl<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u521b\u5efaSSL\u4e0a\u4e0b\u6587 *\/<\/span><br \/>\n    ctx <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">create_ssl_context<\/span><span class=\"token punctuation\">(<\/span>ca_cert_path<span class=\"token punctuation\">,<\/span> client_cert_path<span class=\"token punctuation\">,<\/span> client_key_path<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>ctx<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u521b\u5efaSSL\u4e0a\u4e0b\u6587\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u5efa\u7acbTCP\u8fde\u63a5 *\/<\/span><br \/>\n    sockfd <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">create_tcp_connection<\/span><span class=\"token punctuation\">(<\/span>server_hostname<span class=\"token punctuation\">,<\/span> server_port<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>sockfd <span class=\"token operator\">&lt;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u521b\u5efaSSL\u5bf9\u8c61 *\/<\/span><br \/>\n    ssl <span class=\"token operator\">&#061;<\/span> <span class=\"token function\">SSL_new<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token operator\">!<\/span>ssl<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u521b\u5efaSSL\u5bf9\u8c61\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u5c06SSL\u4e0esocket\u5173\u8054 *\/<\/span><br \/>\n    <span class=\"token function\">SSL_set_fd<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> sockfd<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u8bbe\u7f6e\u670d\u52a1\u5668\u540d\u79f0\u6307\u793a&#xff08;SNI&#xff09; *\/<\/span><br \/>\n    <span class=\"token function\">SSL_set_tlsext_host_name<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> server_hostname<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u6267\u884cTLS\u63e1\u624b *\/<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u6b63\u5728\u8fdb\u884cTLS\u63e1\u624b&#8230;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">SSL_connect<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">1<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;TLS\u63e1\u624b\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token function\">ERR_print_errors_fp<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;TLS\u63e1\u624b\u6210\u529f&#xff01;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u4f7f\u7528\u7684\u534f\u8bae: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token function\">SSL_get_version<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u4f7f\u7528\u7684\u5bc6\u7801\u5957\u4ef6: %s\\\\n&#034;<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token function\">SSL_get_cipher<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66 *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">verify_server_certificate<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> server_hostname<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u670d\u52a1\u5668\u8bc1\u4e66\u9a8c\u8bc1\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u53d1\u9001\u8f66\u8f86\u4fe1\u606f&#xff0c;\u68c0\u67e5\u662f\u5426\u6709\u66f4\u65b0 *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">send_vehicle_info<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> VEHICLE_ID<span class=\"token punctuation\">,<\/span> VEHICLE_MODEL<span class=\"token punctuation\">,<\/span> FIRMWARE_VERSION<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u4e0b\u8f7d\u56fa\u4ef6&#xff08;\u7b80\u5316\u793a\u4f8b&#xff0c;\u5b9e\u9645\u9700\u8981\u89e3\u6790HTTP\u54cd\u5e94\u5934&#xff09; *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">download_firmware<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">,<\/span> firmware_path<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u56fa\u4ef6\u4e0b\u8f7d\u5931\u8d25\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u5173\u95edSSL\u8fde\u63a5 *\/<\/span><br \/>\n    <span class=\"token function\">SSL_shutdown<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\\\\n\u56fa\u4ef6\u4e0b\u8f7d\u5b8c\u6210&#xff0c;\u5f00\u59cb\u9a8c\u8bc1&#8230;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token comment\">\/* \u9a8c\u8bc1\u56fa\u4ef6\u7b7e\u540d *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span><span class=\"token function\">verify_firmware_signature<\/span><span class=\"token punctuation\">(<\/span>firmware_path<span class=\"token punctuation\">,<\/span> signature_path<span class=\"token punctuation\">,<\/span> public_key_path<span class=\"token punctuation\">)<\/span> <span class=\"token operator\">!&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">fprintf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token constant\">stderr<\/span><span class=\"token punctuation\">,<\/span> <span class=\"token string\">&#034;\u56fa\u4ef6\u9a8c\u8bc1\u5931\u8d25&#xff0c;\u653e\u5f03\u5b89\u88c5\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n        <span class=\"token keyword\">goto<\/span> cleanup<span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\\\\n&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;OTA\u66f4\u65b0\u51c6\u5907\u5c31\u7eea&#xff01;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;\u8bf7\u6309\u7167\u8f66\u8f86\u624b\u518c\u6307\u793a\u5b8c\u6210\u5b89\u88c5\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">printf<\/span><span class=\"token punctuation\">(<\/span><span class=\"token string\">&#034;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;\\\\n&#034;<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    ret <span class=\"token operator\">&#061;<\/span> EXIT_SUCCESS<span class=\"token punctuation\">;<\/span><\/p>\n<p>cleanup<span class=\"token operator\">:<\/span><br \/>\n    <span class=\"token comment\">\/* \u6e05\u7406\u8d44\u6e90 *\/<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">SSL_free<\/span><span class=\"token punctuation\">(<\/span>ssl<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>sockfd <span class=\"token operator\">&gt;&#061;<\/span> <span class=\"token number\">0<\/span><span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">close<\/span><span class=\"token punctuation\">(<\/span>sockfd<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><br \/>\n    <span class=\"token keyword\">if<\/span> <span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span> <span class=\"token punctuation\">{<\/span><br \/>\n        <span class=\"token function\">SSL_CTX_free<\/span><span class=\"token punctuation\">(<\/span>ctx<span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token punctuation\">}<\/span><\/p>\n<p>    <span class=\"token function\">EVP_cleanup<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">CRYPTO_cleanup_all_ex_data<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><br \/>\n    <span class=\"token function\">ERR_free_strings<\/span><span class=\"token punctuation\">(<\/span><span class=\"token punctuation\">)<\/span><span class=\"token punctuation\">;<\/span><\/p>\n<p>    <span class=\"token keyword\">return<\/span> ret<span class=\"token punctuation\">;<\/span><br \/>\n<span class=\"token punctuation\">}<\/span><\/p>\n<h4>4.3 \u914d\u5957Makefile<\/h4>\n<p># Makefile for Secure OTA Update Client<br \/>\n# \u672a\u6765\u6c7d\u8f66 &#8211; \u5b89\u5168OTA\u66f4\u65b0\u7cfb\u7edf<\/p>\n<p>CC &#061; gcc<br \/>\nCFLAGS &#061; -Wall -Wextra -O2 -std&#061;c11<br \/>\nLDFLAGS &#061; -lssl -lcrypto<br \/>\nTARGET &#061; secure_ota_client<\/p>\n<p># OpenSSL\u7248\u672c\u68c0\u67e5<br \/>\nOPENSSL_VERSION :&#061; $(shell pkg-config &#8211;modversion openssl 2&gt;\/dev\/null)<br \/>\nifeq ($(OPENSSL_VERSION),)<br \/>\n    $(error OpenSSL\u5f00\u53d1\u5e93\u672a\u5b89\u88c5\u3002\u8bf7\u8fd0\u884c: sudo apt-get install libssl-dev)<br \/>\nelse<br \/>\n    $(info \u68c0\u6d4b\u5230OpenSSL\u7248\u672c: $(OPENSSL_VERSION))<br \/>\n    $(info \u63a8\u8350\u4f7f\u7528OpenSSL 1.1.1\u6216\u66f4\u9ad8\u7248\u672c)<br \/>\nendif<\/p>\n<p># \u6e90\u6587\u4ef6\u548c\u76ee\u6807\u6587\u4ef6<br \/>\nSRCS &#061; secure_ota_update.c<br \/>\nOBJS &#061; $(SRCS:.c&#061;.o)<\/p>\n<p># \u9ed8\u8ba4\u76ee\u6807<br \/>\nall: $(TARGET)<\/p>\n<p># \u94fe\u63a5\u53ef\u6267\u884c\u6587\u4ef6<br \/>\n$(TARGET): $(OBJS)<br \/>\n$(CC) $(OBJS) -o $&#064; $(LDFLAGS)<br \/>\n&#064;echo &#034;\u7f16\u8bd1\u6210\u529f&#xff01;\u53ef\u6267\u884c\u6587\u4ef6: $(TARGET)&#034;<\/p>\n<p># \u7f16\u8bd1\u6e90\u6587\u4ef6<br \/>\n%.o: %.c<br \/>\n$(CC) $(CFLAGS) -c $&lt; -o $&#064;<\/p>\n<p># \u6e05\u7406\u7f16\u8bd1\u6587\u4ef6<br \/>\nclean:<br \/>\nrm -f $(OBJS) $(TARGET)<br \/>\n&#064;echo &#034;\u5df2\u6e05\u7406\u7f16\u8bd1\u6587\u4ef6&#034;<\/p>\n<p># \u5b89\u88c5\u5230\u7cfb\u7edf\u76ee\u5f55&#xff08;\u9700\u8981root\u6743\u9650&#xff09;<br \/>\ninstall: $(TARGET)<br \/>\nsudo cp $(TARGET) \/usr\/local\/bin\/<br \/>\nsudo mkdir -p \/etc\/vehicle\/certs\/<br \/>\n&#064;echo &#034;\u5df2\u5b89\u88c5\u5230\u7cfb\u7edf&#xff0c;\u8bf7\u5c06\u8bc1\u4e66\u6587\u4ef6\u653e\u5165 \/etc\/vehicle\/certs\/&#034;<br \/>\n&#064;echo &#034;\u9700\u8981\u7684\u8bc1\u4e66\u6587\u4ef6:&#034;<br \/>\n&#064;echo &#034;  &#8211; ca.crt (CA\u8bc1\u4e66)&#034;<br \/>\n&#064;echo &#034;  &#8211; client.crt (\u5ba2\u6237\u7aef\u8bc1\u4e66)&#034;<br \/>\n&#064;echo &#034;  &#8211; client.key (\u5ba2\u6237\u7aef\u79c1\u94a5)&#034;<br \/>\n&#064;echo &#034;  &#8211; ota_public_key.pem (OTA\u9a8c\u8bc1\u516c\u94a5)&#034;<\/p>\n<p># \u5378\u8f7d<br \/>\nuninstall:<br \/>\nsudo rm -f \/usr\/local\/bin\/$(TARGET)<br \/>\n&#064;echo &#034;\u5df2\u5378\u8f7d&#034;<\/p>\n<p># \u8fd0\u884c\u6d4b\u8bd5&#xff08;\u9700\u8981\u914d\u7f6e\u6b63\u786e\u7684\u670d\u52a1\u5668\u548c\u8bc1\u4e66&#xff09;<br \/>\nrun-test: $(TARGET)<br \/>\n&#064;echo &#034;\u8fd0\u884cOTA\u5ba2\u6237\u7aef\u6d4b\u8bd5&#8230;&#034;<br \/>\n&#064;echo &#034;\u6ce8\u610f&#xff1a;\u9700\u8981\u5148\u914d\u7f6e\u6b63\u786e\u7684\u8bc1\u4e66\u6587\u4ef6&#034;<br \/>\n&#064;echo &#034;\u8fd0\u884c\u547d\u4ee4: .\/$(TARGET)&#034;<br \/>\n&#064;echo &#034;\u6216\u6307\u5b9a\u53c2\u6570: .\/$(TARGET) &#8211;help&#034;<\/p>\n<p># \u9759\u6001\u5206\u6790<br \/>\nanalyze:<br \/>\ncppcheck &#8211;enable&#061;all &#8211;suppress&#061;missingIncludeSystem $(SRCS)<br \/>\n&#064;echo &#034;\u9759\u6001\u5206\u6790\u5b8c\u6210&#034;<\/p>\n<p># \u5185\u5b58\u68c0\u67e5<br \/>\nmemcheck: $(TARGET)<br \/>\nvalgrind &#8211;leak-check&#061;full &#8211;show-leak-kinds&#061;all .\/$(TARGET) || true<\/p>\n<p># \u5e2e\u52a9\u4fe1\u606f<br \/>\nhelp:<br \/>\n&#064;echo &#034;\u53ef\u7528\u547d\u4ee4:&#034;<br \/>\n&#064;echo &#034;  make all      &#8211; \u7f16\u8bd1\u7a0b\u5e8f&#xff08;\u9ed8\u8ba4&#xff09;&#034;<br \/>\n&#064;echo &#034;  make clean    &#8211; \u6e05\u7406\u7f16\u8bd1\u6587\u4ef6&#034;<br \/>\n&#064;echo &#034;  make install  &#8211; \u5b89\u88c5\u5230\u7cfb\u7edf\u76ee\u5f55&#034;<br \/>\n&#064;echo &#034;  make uninstall- \u5378\u8f7d&#034;<br \/>\n&#064;echo &#034;  make analyze  &#8211; \u8fd0\u884c\u9759\u6001\u5206\u6790&#034;<br \/>\n&#064;echo &#034;  make memcheck &#8211; \u8fd0\u884c\u5185\u5b58\u68c0\u67e5&#034;<br \/>\n&#064;echo &#034;&#034;<br \/>\n&#064;echo &#034;\u7f16\u8bd1\u8981\u6c42:&#034;<br \/>\n&#064;echo &#034;  &#8211; OpenSSL 1.1.1\u6216\u66f4\u9ad8\u7248\u672c&#034;<br \/>\n&#064;echo &#034;  &#8211; GCC\u7f16\u8bd1\u5668&#034;<br \/>\n&#064;echo &#034;&#034;<br \/>\n&#064;echo &#034;\u914d\u7f6e\u8bf4\u660e:&#034;<br \/>\n&#064;echo &#034;  1. \u5c06\u8bc1\u4e66\u6587\u4ef6\u653e\u5165 \/etc\/vehicle\/certs\/&#034;<br \/>\n&#064;echo &#034;  2. \u4fee\u6539\u6e90\u7801\u4e2d\u7684\u670d\u52a1\u5668\u5730\u5740\u548c\u7aef\u53e3&#034;<br \/>\n&#064;echo &#034;  3. \u8fd0\u884c: .\/secure_ota_client&#034;<\/p>\n<p>.PHONY: all clean install uninstall run-test analyze memcheck help<\/p>\n<h4>4.4 \u64cd\u4f5c\u8bf4\u660e<\/h4>\n<h5>\u7f16\u8bd1\u4e0e\u8fd0\u884c<\/h5>\n<li>\n<p>\u73af\u5883\u8981\u6c42&#xff1a;<\/p>\n<p><span class=\"token comment\"># Ubuntu\/Debian<\/span><br \/>\n<span class=\"token function\">sudo<\/span> <span class=\"token function\">apt-get<\/span> update<br \/>\n<span class=\"token function\">sudo<\/span> <span class=\"token function\">apt-get<\/span> <span class=\"token function\">install<\/span> gcc <span class=\"token function\">make<\/span> libssl-dev pkg-config valgrind cppcheck<\/p>\n<p><span class=\"token comment\"># \u68c0\u67e5OpenSSL\u7248\u672c&#xff08;\u9700\u89811.1.1\u6216\u66f4\u9ad8&#xff09;<\/span><br \/>\nopenssl version<\/p>\n<\/li>\n<li>\n<p>\u7f16\u8bd1\u7a0b\u5e8f&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u4e0b\u8f7d\u6e90\u7801<\/span><br \/>\n<span class=\"token function\">git<\/span> clone https:\/\/github.com\/future-auto\/secure-ota-client.git<br \/>\n<span class=\"token builtin class-name\">cd<\/span> secure-ota-client<\/p>\n<p><span class=\"token comment\"># \u7f16\u8bd1<\/span><br \/>\n<span class=\"token function\">make<\/span> clean<br \/>\n<span class=\"token function\">make<\/span><\/p>\n<p><span class=\"token comment\"># \u6216\u4f7f\u7528\u5b8c\u6574\u7f16\u8bd1\u68c0\u67e5<\/span><br \/>\n<span class=\"token function\">make<\/span> analyze  <span class=\"token comment\"># \u9759\u6001\u5206\u6790<\/span><br \/>\n<span class=\"token function\">make<\/span> memcheck <span class=\"token comment\"># \u5185\u5b58\u68c0\u67e5&#xff08;\u9700\u8981\u5148\u7f16\u8bd1&#xff09;<\/span><\/p>\n<\/li>\n<li>\n<p>\u51c6\u5907\u8bc1\u4e66\u6587\u4ef6&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u521b\u5efa\u8bc1\u4e66\u76ee\u5f55<\/span><br \/>\n<span class=\"token function\">sudo<\/span> <span class=\"token function\">mkdir<\/span> -p \/etc\/vehicle\/certs\/<\/p>\n<p><span class=\"token comment\"># \u5c06\u4ee5\u4e0b\u8bc1\u4e66\u6587\u4ef6\u653e\u5165\u76ee\u5f55&#xff1a;<\/span><br \/>\n<span class=\"token comment\"># 1. ca.crt &#8211; \u6839CA\u8bc1\u4e66<\/span><br \/>\n<span class=\"token comment\"># 2. client.crt &#8211; \u8f66\u8f86\u5ba2\u6237\u7aef\u8bc1\u4e66<\/span><br \/>\n<span class=\"token comment\"># 3. client.key &#8211; \u8f66\u8f86\u5ba2\u6237\u7aef\u79c1\u94a5<\/span><br \/>\n<span class=\"token comment\"># 4. ota_public_key.pem &#8211; OTA\u7b7e\u540d\u9a8c\u8bc1\u516c\u94a5<\/span><\/p>\n<p><span class=\"token comment\"># \u793a\u4f8b&#xff1a;\u751f\u6210\u6d4b\u8bd5\u8bc1\u4e66&#xff08;\u4ec5\u7528\u4e8e\u5f00\u53d1\u6d4b\u8bd5&#xff09;<\/span><br \/>\nopenssl genrsa -out \/tmp\/test.key <span class=\"token number\">2048<\/span><br \/>\nopenssl req -new -key \/tmp\/test.key -out \/tmp\/test.csr<br \/>\nopenssl x509 -req -days <span class=\"token number\">365<\/span> -in \/tmp\/test.csr -signkey \/tmp\/test.key -out \/tmp\/test.crt<\/p>\n<\/li>\n<li>\n<p>\u8fd0\u884c\u7a0b\u5e8f&#xff1a;<\/p>\n<p><span class=\"token comment\"># \u76f4\u63a5\u8fd0\u884c&#xff08;\u4f7f\u7528\u9ed8\u8ba4\u914d\u7f6e&#xff09;<\/span><br \/>\n.\/secure_ota_client<\/p>\n<p><span class=\"token comment\"># \u6216\u4fee\u6539\u6e90\u7801\u4e2d\u7684\u914d\u7f6e&#xff1a;<\/span><br \/>\n<span class=\"token comment\"># &#8211; \u670d\u52a1\u5668\u5730\u5740 server_hostname<\/span><br \/>\n<span class=\"token comment\"># &#8211; \u8bc1\u4e66\u8def\u5f84 ca_cert_path \u7b49<\/span><\/p>\n<\/li>\n<li>\n<p>\u9884\u671f\u8f93\u51fa&#xff1a;<\/p>\n<p>&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;<br \/>\n    \u672a\u6765\u6c7d\u8f66 &#8211; \u5b89\u5168OTA\u66f4\u65b0\u5ba2\u6237\u7aef<br \/>\n&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;<br \/>\n\u8f66\u8f86ID: VIN_ABC123DEF456789<br \/>\n\u8f66\u578b: FUTURE_CAR_X<br \/>\n\u5f53\u524d\u56fa\u4ef6\u7248\u672c: 1.2.3<\/p>\n<p>\u6210\u529f\u8fde\u63a5\u5230 oem.auto.com:443<br \/>\n\u6b63\u5728\u8fdb\u884cTLS\u63e1\u624b&#8230;<br \/>\nTLS\u63e1\u624b\u6210\u529f&#xff01;<br \/>\n\u4f7f\u7528\u7684\u534f\u8bae: TLSv1.3<br \/>\n\u4f7f\u7528\u7684\u5bc6\u7801\u5957\u4ef6: TLS_AES_256_GCM_SHA384<br \/>\n\u670d\u52a1\u5668\u8bc1\u4e66\u9a8c\u8bc1\u901a\u8fc7:<br \/>\n    \u9881\u53d1\u7ed9: oem.auto.com<br \/>\n    \u6709\u6548\u671f: Jan  1 00:00:00 2023 GMT \u5230 Dec 31 23:59:59 2024 GMT<br \/>\n\u5df2\u53d1\u9001\u8f66\u8f86\u4fe1\u606f\u8bf7\u6c42<br \/>\n\u5f00\u59cb\u4e0b\u8f7d\u56fa\u4ef6&#8230;<br \/>\n\u5df2\u4e0b\u8f7d: 1.00 MB, \u901f\u5ea6: 2.34 MB\/s<br \/>\n&#8230;<br \/>\n\u56fa\u4ef6\u4e0b\u8f7d\u5b8c\u6210!<br \/>\n\u603b\u5927\u5c0f: 256.34 MB<br \/>\n\u8017\u65f6: 45.23 \u79d2<br \/>\n\u5e73\u5747\u901f\u5ea6: 5.67 MB\/s<\/p>\n<p>\u56fa\u4ef6\u4e0b\u8f7d\u5b8c\u6210&#xff0c;\u5f00\u59cb\u9a8c\u8bc1&#8230;<br \/>\n\u56fa\u4ef6\u7b7e\u540d\u9a8c\u8bc1\u6210\u529f&#xff01;<\/p>\n<p>&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;<br \/>\nOTA\u66f4\u65b0\u51c6\u5907\u5c31\u7eea&#xff01;<br \/>\n\u8bf7\u6309\u7167\u8f66\u8f86\u624b\u518c\u6307\u793a\u5b8c\u6210\u5b89\u88c5<br \/>\n&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;&#061;<\/p>\n<\/li>\n<h5>\u6545\u969c\u6392\u9664<\/h5>\n<li>\n<p>TLS\u63e1\u624b\u5931\u8d25&#xff1a;<\/p>\n<ul>\n<li>\u68c0\u67e5\u8bc1\u4e66\u8def\u5f84\u548c\u6743\u9650<\/li>\n<li>\u9a8c\u8bc1\u670d\u52a1\u5668\u8bc1\u4e66\u662f\u5426\u8fc7\u671f<\/li>\n<li>\u68c0\u67e5\u7f51\u7edc\u8fde\u63a5\u548c\u9632\u706b\u5899\u8bbe\u7f6e<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>\u8bc1\u4e66\u9a8c\u8bc1\u5931\u8d25&#xff1a;<\/p>\n<ul>\n<li>\u786e\u4fdd\u8bc1\u4e66\u94fe\u5b8c\u6574<\/li>\n<li>\u68c0\u67e5\u8bc1\u4e66\u4e2d\u7684CN&#xff08;\u901a\u7528\u540d&#xff09;\u662f\u5426\u5339\u914d\u670d\u52a1\u5668\u57df\u540d<\/li>\n<li>\u9a8c\u8bc1\u8bc1\u4e66\u662f\u5426\u88ab\u540a\u9500<\/li>\n<\/ul>\n<\/li>\n<li>\n<p>\u901f\u5ea6\u6162&#xff1a;<\/p>\n<ul>\n<li>\u68c0\u67e5\u7f51\u7edc\u5e26\u5bbd<\/li>\n<li>\u8003\u8651\u4f7f\u7528\u4f1a\u8bdd\u6062\u590d\u51cf\u5c11\u63e1\u624b\u5f00\u9500<\/li>\n<li>\u4f18\u5316\u7f13\u51b2\u533a\u5927\u5c0f<\/li>\n<\/ul>\n<\/li>\n<h3>\u7b2c\u4e94\u90e8\u5206&#xff1a;\u672a\u6765\u8d8b\u52bf\u4e0e\u6311\u6218<\/h3>\n<h4>5.1 \u540e\u91cf\u5b50\u5bc6\u7801\u5b66&#xff08;PQC&#xff09;<\/h4>\n<p>\u968f\u7740\u91cf\u5b50\u8ba1\u7b97\u7684\u53d1\u5c55&#xff0c;\u5f53\u524d\u7684RSA\u548cECC\u7b97\u6cd5\u53ef\u80fd\u88ab\u7834\u89e3\u3002NIST\u6b63\u5728\u6807\u51c6\u5316\u540e\u91cf\u5b50\u5bc6\u7801\u7b97\u6cd5&#xff1a;<\/p>\n<p>\u672a\u6765\u7684\u8f66\u8f7dTLS\u53ef\u80fd\u5305\u542b&#xff1a;<br \/>\n\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u2502 \u7ecf\u5178\u7b97\u6cd5 &#043; \u540e\u91cf\u5b50\u7b97\u6cd5\u7684\u6df7\u5408\u6a21\u5f0f                \u2502<br \/>\n\u251c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2524<br \/>\n\u2502 \u5bc6\u94a5\u4ea4\u6362&#xff1a;ECDHE &#043; Kyber                      \u2502<br \/>\n\u2502 \u6570\u5b57\u7b7e\u540d&#xff1a;RSA-PSS &#043; Dilithium                \u2502<br \/>\n\u2502 \u8bc1\u4e66&#xff1a;\u53cc\u8bc1\u4e66\u94fe&#xff08;\u4f20\u7edf &#043; PQC&#xff09;                  \u2502<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518<\/p>\n<h4>5.2 \u8f7b\u91cf\u7ea7TLS\u5b9e\u73b0<\/h4>\n<p>\u8f66\u8f7dECU\u8d44\u6e90\u6709\u9650&#xff0c;\u9700\u8981\u4f18\u5316\u7684TLS\u5b9e\u73b0&#xff1a;<\/p>\n<ul>\n<li>DTLS&#xff1a;\u57fa\u4e8eUDP\u7684TLS&#xff0c;\u9002\u5408\u8f66\u8f7d\u4f20\u611f\u5668\u7f51\u7edc<\/li>\n<li>TLS 1.3\u7b80\u5316\u914d\u7f6e&#xff1a;\u51cf\u5c11\u63e1\u624b\u8f6e\u6b21&#xff0c;\u964d\u4f4e\u5ef6\u8fdf<\/li>\n<li>\u786c\u4ef6\u52a0\u901f&#xff1a;\u4e13\u7528\u5bc6\u7801\u5b66\u5904\u7406\u5668<\/li>\n<\/ul>\n<h4>5.3 \u6cd5\u89c4\u4e0e\u6807\u51c6<\/h4>\n<ul>\n<li>UNECE WP.29 R155&#xff1a;\u8981\u6c42\u8f66\u8f86\u5177\u5907\u7f51\u7edc\u5b89\u5168\u7ba1\u7406\u7cfb\u7edf<\/li>\n<li>ISO\/SAE 21434&#xff1a;\u9053\u8def\u8f66\u8f86\u7f51\u7edc\u5b89\u5168\u5de5\u7a0b\u6807\u51c6<\/li>\n<li>AutoSAR&#xff1a;\u6c7d\u8f66\u5f00\u653e\u7cfb\u7edf\u67b6\u6784\u4e2d\u7684\u52a0\u5bc6\u6a21\u5757<\/li>\n<\/ul>\n<h3>\u7ed3\u8bed&#xff1a;\u5b89\u5168\u4e4b\u8def&#xff0c;\u6c38\u65e0\u6b62\u5883<\/h3>\n<p>\u901a\u8fc7\u672c\u6587\u7684\u6df1\u5ea6\u63a2\u7d22&#xff0c;\u6211\u4eec\u770b\u5230\u4e86TLS\u5982\u4f55\u4e3a\u667a\u80fd\u6c7d\u8f66\u4e0eOEM\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u7b51\u8d77\u575a\u56fa\u7684\u5b89\u5168\u9632\u7ebf\u3002\u4ece\u63e1\u624b\u534f\u8bae\u7684\u7cbe\u5999\u8bbe\u8ba1&#xff0c;\u5230\u8bc1\u4e66\u9a8c\u8bc1\u7684\u4e25\u8c28\u6d41\u7a0b&#xff0c;\u518d\u5230\u5b9e\u6218\u4e2d\u7684OTA\u66f4\u65b0\u5b9e\u73b0&#xff0c;TLS\u5c55\u73b0\u4e86\u5bc6\u7801\u5b66\u827a\u672f\u7684\u5b8c\u7f8e\u5e94\u7528\u3002<\/p>\n<p>\u7136\u800c&#xff0c;\u5b89\u5168\u4ece\u6765\u4e0d\u662f\u4e00\u52b3\u6c38\u9038\u7684\u3002\u968f\u7740\u6280\u672f\u7684\u53d1\u5c55&#xff0c;\u65b0\u7684\u5a01\u80c1\u4e0d\u65ad\u51fa\u73b0&#xff0c;\u6211\u4eec\u7684\u9632\u5fa1\u4e5f\u5fc5\u987b\u4e0d\u65ad\u8fdb\u5316\u3002\u672a\u6765\u7684\u8f66\u8f7d\u5b89\u5168\u5c06\u66f4\u52a0\u667a\u80fd\u5316\u3001\u81ea\u52a8\u5316&#xff0c;\u751a\u81f3\u53ef\u80fd\u5f15\u5165\u533a\u5757\u94fe\u3001\u540c\u6001\u52a0\u5bc6\u7b49\u65b0\u6280\u672f\u3002<\/p>\n<p>\u4f5c\u4e3a\u667a\u80fd\u65f6\u4ee3\u7684\u53c2\u4e0e\u8005&#xff0c;\u7406\u89e3\u8fd9\u4e9b\u5b89\u5168\u539f\u7406\u4e0d\u4ec5\u6709\u52a9\u4e8e\u6211\u4eec\u66f4\u597d\u5730\u4f7f\u7528\u6280\u672f&#xff0c;\u4e5f\u8ba9\u6211\u4eec\u5bf9\u6570\u5b57\u4e16\u754c\u7684\u590d\u6742\u6027\u6709\u66f4\u6df1\u7684\u656c\u754f\u3002\u6bd5\u7adf&#xff0c;\u6700\u575a\u56fa\u7684\u5b89\u5168\u9632\u7ebf&#xff0c;\u59cb\u4e8e\u6700\u6df1\u523b\u7684\u7406\u89e3\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5f15\u8a00&#xff1a;\u5f53\u6c7d\u8f66\u5b66\u4f1a\u4e86\\&#8221;\u6084\u6084\u8bdd\\&#8221;<br \/>\n\u60f3\u8c61\u4e00\u4e0b&#xff0c;\u4f60\u9a7e\u9a76\u7740\u4e00\u8f86\u667a\u80fd\u6c7d\u8f66\u884c\u9a76\u5728\u9ad8\u901f\u516c\u8def\u4e0a\u3002\u8f66\u8f86\u6b63\u6084\u6084\u5730\u4e0e\u5236\u9020\u5546\u7684\u670d\u52a1\u5668\\&#8221;\u4ea4\u8c08\\&#8221;&#xff1a;\u62a5\u544a\u8f66\u8f86\u72b6\u6001\u3001\u63a5\u6536\u8f6f\u4ef6\u66f4\u65b0\u3001\u83b7\u53d6\u5b9e\u65f6\u8def\u51b5\u3002\u4f46\u8fd9\u6bb5\u5bf9\u8bdd\u5982\u679c\u88ab\u6076\u610f\u7a83\u542c\u8005\u542c\u5230\u4f1a\u600e\u6837&#xff1f;\u4ed6\u4eec\u53ef\u80fd\u77e5\u9053\u4f60\u7684\u4f4d\u7f6e\u3001\u9a7e\u9a76\u4e60\u60ef&#xff0c;\u751a\u81f3\u80fd\u8fdc\u7a0b\u63a7\u5236\u4f60\u7684\u8f66\u8f86\u3002TLS&#xff08;\u4f20\u8f93\u5c42\u5b89\u5168\u534f\u8bae&#xff09;\u5c31\u662f\u4e3a\u8fd9\u79cd\u5bf9\u8bdd\u914d\u4e0a\u7684\\&#8221;\u52a0\u5bc6\u8033\u673a\\&#8221;&#xff0c;\u8ba9\u6c7d\u8f66\u4e0e\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u65e2\u79c1\u5bc6\u53c8\u53ef\u9760\u3002<br \/>\n\u4eca\u5929&amp;#xff0c<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[43,78],"topic":[],"class_list":["post-62253","post","type-post","status-publish","format-standard","hentry","category-server","tag-43","tag-78"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v20.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.wsisp.com\/helps\/62253.html\" \/>\n<meta property=\"og:locale\" content=\"zh_CN\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"og:description\" content=\"\u5f15\u8a00&#xff1a;\u5f53\u6c7d\u8f66\u5b66\u4f1a\u4e86&quot;\u6084\u6084\u8bdd&quot; \u60f3\u8c61\u4e00\u4e0b&#xff0c;\u4f60\u9a7e\u9a76\u7740\u4e00\u8f86\u667a\u80fd\u6c7d\u8f66\u884c\u9a76\u5728\u9ad8\u901f\u516c\u8def\u4e0a\u3002\u8f66\u8f86\u6b63\u6084\u6084\u5730\u4e0e\u5236\u9020\u5546\u7684\u670d\u52a1\u5668&quot;\u4ea4\u8c08&quot;&#xff1a;\u62a5\u544a\u8f66\u8f86\u72b6\u6001\u3001\u63a5\u6536\u8f6f\u4ef6\u66f4\u65b0\u3001\u83b7\u53d6\u5b9e\u65f6\u8def\u51b5\u3002\u4f46\u8fd9\u6bb5\u5bf9\u8bdd\u5982\u679c\u88ab\u6076\u610f\u7a83\u542c\u8005\u542c\u5230\u4f1a\u600e\u6837&#xff1f;\u4ed6\u4eec\u53ef\u80fd\u77e5\u9053\u4f60\u7684\u4f4d\u7f6e\u3001\u9a7e\u9a76\u4e60\u60ef&#xff0c;\u751a\u81f3\u80fd\u8fdc\u7a0b\u63a7\u5236\u4f60\u7684\u8f66\u8f86\u3002TLS&#xff08;\u4f20\u8f93\u5c42\u5b89\u5168\u534f\u8bae&#xff09;\u5c31\u662f\u4e3a\u8fd9\u79cd\u5bf9\u8bdd\u914d\u4e0a\u7684&quot;\u52a0\u5bc6\u8033\u673a&quot;&#xff0c;\u8ba9\u6c7d\u8f66\u4e0e\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u65e2\u79c1\u5bc6\u53c8\u53ef\u9760\u3002 \u4eca\u5929&amp;#xff0c\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.wsisp.com\/helps\/62253.html\" \/>\n<meta property=\"og:site_name\" content=\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-19T08:34:27+00:00\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u4f5c\u8005\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4\" \/>\n\t<meta name=\"twitter:data2\" content=\"16 \u5206\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/62253.html\",\"url\":\"https:\/\/www.wsisp.com\/helps\/62253.html\",\"name\":\"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"isPartOf\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\"},\"datePublished\":\"2026-01-19T08:34:27+00:00\",\"dateModified\":\"2026-01-19T08:34:27+00:00\",\"author\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.wsisp.com\/helps\/62253.html#breadcrumb\"},\"inLanguage\":\"zh-Hans\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.wsisp.com\/helps\/62253.html\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/62253.html#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"\u9996\u9875\",\"item\":\"https:\/\/www.wsisp.com\/helps\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#website\",\"url\":\"https:\/\/www.wsisp.com\/helps\/\",\"name\":\"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3\",\"description\":\"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"zh-Hans\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"zh-Hans\",\"@id\":\"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"contentUrl\":\"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery\",\"caption\":\"admin\"},\"sameAs\":[\"http:\/\/wp.wsisp.com\"],\"url\":\"https:\/\/www.wsisp.com\/helps\/author\/admin\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.wsisp.com\/helps\/62253.html","og_locale":"zh_CN","og_type":"article","og_title":"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","og_description":"\u5f15\u8a00&#xff1a;\u5f53\u6c7d\u8f66\u5b66\u4f1a\u4e86\"\u6084\u6084\u8bdd\" \u60f3\u8c61\u4e00\u4e0b&#xff0c;\u4f60\u9a7e\u9a76\u7740\u4e00\u8f86\u667a\u80fd\u6c7d\u8f66\u884c\u9a76\u5728\u9ad8\u901f\u516c\u8def\u4e0a\u3002\u8f66\u8f86\u6b63\u6084\u6084\u5730\u4e0e\u5236\u9020\u5546\u7684\u670d\u52a1\u5668\"\u4ea4\u8c08\"&#xff1a;\u62a5\u544a\u8f66\u8f86\u72b6\u6001\u3001\u63a5\u6536\u8f6f\u4ef6\u66f4\u65b0\u3001\u83b7\u53d6\u5b9e\u65f6\u8def\u51b5\u3002\u4f46\u8fd9\u6bb5\u5bf9\u8bdd\u5982\u679c\u88ab\u6076\u610f\u7a83\u542c\u8005\u542c\u5230\u4f1a\u600e\u6837&#xff1f;\u4ed6\u4eec\u53ef\u80fd\u77e5\u9053\u4f60\u7684\u4f4d\u7f6e\u3001\u9a7e\u9a76\u4e60\u60ef&#xff0c;\u751a\u81f3\u80fd\u8fdc\u7a0b\u63a7\u5236\u4f60\u7684\u8f66\u8f86\u3002TLS&#xff08;\u4f20\u8f93\u5c42\u5b89\u5168\u534f\u8bae&#xff09;\u5c31\u662f\u4e3a\u8fd9\u79cd\u5bf9\u8bdd\u914d\u4e0a\u7684\"\u52a0\u5bc6\u8033\u673a\"&#xff0c;\u8ba9\u6c7d\u8f66\u4e0e\u670d\u52a1\u5668\u4e4b\u95f4\u7684\u901a\u4fe1\u65e2\u79c1\u5bc6\u53c8\u53ef\u9760\u3002 \u4eca\u5929&amp;#xff0c","og_url":"https:\/\/www.wsisp.com\/helps\/62253.html","og_site_name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","article_published_time":"2026-01-19T08:34:27+00:00","author":"admin","twitter_card":"summary_large_image","twitter_misc":{"\u4f5c\u8005":"admin","\u9884\u8ba1\u9605\u8bfb\u65f6\u95f4":"16 \u5206"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.wsisp.com\/helps\/62253.html","url":"https:\/\/www.wsisp.com\/helps\/62253.html","name":"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790 - \u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","isPartOf":{"@id":"https:\/\/www.wsisp.com\/helps\/#website"},"datePublished":"2026-01-19T08:34:27+00:00","dateModified":"2026-01-19T08:34:27+00:00","author":{"@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41"},"breadcrumb":{"@id":"https:\/\/www.wsisp.com\/helps\/62253.html#breadcrumb"},"inLanguage":"zh-Hans","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.wsisp.com\/helps\/62253.html"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.wsisp.com\/helps\/62253.html#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"\u9996\u9875","item":"https:\/\/www.wsisp.com\/helps"},{"@type":"ListItem","position":2,"name":"TLS\u52a0\u5bc6\u901a\u4fe1\u5728\u8f66\u8f7d\u7f51\u7edc\u4e0eOEM\u670d\u52a1\u5668\u4e2d\u7684\u6df1\u5ea6\u89e3\u6790"}]},{"@type":"WebSite","@id":"https:\/\/www.wsisp.com\/helps\/#website","url":"https:\/\/www.wsisp.com\/helps\/","name":"\u7f51\u7855\u4e92\u8054\u5e2e\u52a9\u4e2d\u5fc3","description":"\u9999\u6e2f\u670d\u52a1\u5668_\u9999\u6e2f\u4e91\u670d\u52a1\u5668\u8d44\u8baf_\u670d\u52a1\u5668\u5e2e\u52a9\u6587\u6863_\u670d\u52a1\u5668\u6559\u7a0b","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.wsisp.com\/helps\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"zh-Hans"},{"@type":"Person","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/358e386c577a3ab51c4493330a20ad41","name":"admin","image":{"@type":"ImageObject","inLanguage":"zh-Hans","@id":"https:\/\/www.wsisp.com\/helps\/#\/schema\/person\/image\/","url":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","contentUrl":"https:\/\/gravatar.wp-china-yes.net\/avatar\/?s=96&d=mystery","caption":"admin"},"sameAs":["http:\/\/wp.wsisp.com"],"url":"https:\/\/www.wsisp.com\/helps\/author\/admin"}]}},"_links":{"self":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/62253","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/comments?post=62253"}],"version-history":[{"count":0,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/posts\/62253\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/media?parent=62253"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/categories?post=62253"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/tags?post=62253"},{"taxonomy":"topic","embeddable":true,"href":"https:\/\/www.wsisp.com\/helps\/wp-json\/wp\/v2\/topic?post=62253"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}