C-v2x-based cloud global quantum secure communication system for vehicle and road

By configuring pairing keys in the vehicle-road-cloud system, direct quantum-secure communication between vehicles and roadside equipment is achieved, solving the problems of communication latency and complexity in the Internet of Vehicles with full-domain quantum secure networks, and ensuring continuous secure communication of vehicles during movement.

CN119865316BActive Publication Date: 2025-11-07MATRICTIME DIGITAL TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510032131.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-11-07
Estimated Expiration
2045-01-09

AI Technical Summary

Technical Problem

Quantum-secure networks face challenges in communication scenarios involving mobile devices such as vehicle-to-everything (V2X) networks, including increased communication latency and complexity. In particular, they cannot achieve continuous and stable communication when vehicles move across regions or cities.

Method used

A C-V2X-based vehicle-road-cloud full-domain quantum secure communication system is adopted. By pre-configuring pairing keys in the vehicle OBU, roadside unit (RSU), and cloud platform, direct quantum secure communication between the vehicle and the roadside unit is realized, reducing the dependence on the access base station. Direct communication is carried out using the third pairing key between the RSU and the adjacent RSU. The OBU and the RSU determine the fifth pairing key through negotiation or by the adjacent RSU.

Benefits of technology

It enables continuous and secure interaction between vehicles and road infrastructure, improves the system's flexibility and reliability, avoids the time and resource consumption caused by key relay, and ensures the safe operation of vehicles.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119865316B_ABST
    Figure CN119865316B_ABST
Patent Text Reader

Abstract

The application discloses a C-V2X-based vehicle-road cloud global quantum security communication system. Through the vehicle machine system OBU configured with a quantum security module, the roadside device RSU configured with a quantum security encryption card and the cloud platform built with global quantum security service, comprehensive global quantum security upgrade is realized for the cloud platform, the RSU and the OBU, and a hardware foundation is provided for realizing the construction of a highly secure, seamless and global quantum security communication environment. Through the first pairing key between the OBU and the first access base station, the second pairing key between the RSU and the second access base station, the third pairing key between the RSU and the adjacent RSU and the fifth pairing key between the OBU and the RSU. The multi-level key system enhances the confidentiality and integrity of communication, so that any ring communication can be effectively protected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security and quantum encryption technology, and particularly relates to a C-V2X-based vehicle-road cloud global quantum secure communication system. BACKGROUND

[0002] With the rapid development of information technology, information security problems are increasingly prominent, and traditional encryption technology is not up to the task when facing new attack methods such as quantum computing. Therefore, a global quantum secure network has emerged as the times require. This system uses the non-cloning and high security of quantum communication to achieve information encryption, relay, key generation and distribution, providing a new solution for information security. Under this framework, all encryption ends must continue to rely on global quantum secure services if they want to communicate securely. This global quantum secure service covers two major components: access base stations and key centers. The access base station is responsible for the access, authentication, and key relay of global quantum secure terminals, ensuring that global quantum secure terminals access the global quantum secure network legally and securely. The key center is focused on the generation, management, and distribution of quantum keys, providing unpredictable and highly secure keys for both parties.

[0003] In the process of global quantum secure communication, once the symmetric key is shared between the two parties, subsequent global quantum secure communication will be based on this symmetric key. However, in order to simplify key management and reduce the number of key pairs, the global quantum secure system adopts the method of forming a paired key between the terminal and the access base station. This paired key allows any two quantum secure terminals accessing the global quantum secure network to relay keys through their respective access base stations, thereby achieving global quantum secure communication.

[0004] However, although the global quantum secure network performs well in some scenarios, it faces challenges in some specific situations. In particular, for mobile devices or scenarios that require cross-regional and cross-city communication, such as the Internet of Vehicles, the limitations of the global quantum secure network become apparent. In the Internet of Vehicles, vehicles are constantly moving and may even cross multiple regions and cities. If key relay still relies on access base stations, when the vehicle moves to a new region or city, it needs to establish a connection and key relay relationship with the new access base station. This not only increases communication delay and complexity, but also may not be able to achieve continuous and stable communication due to the coverage limitations of access base stations.

[0005] Therefore, for communication scenarios of devices that may move, such as the Internet of Vehicles, a more flexible and efficient global quantum secure communication solution is needed to overcome the limitations of existing technology. SUMMARY

[0006] This application provides a C-V2X-based vehicle-road-cloud full-domain quantum secure communication system to realize full-domain quantum secure communication between vehicles, cloud platforms and roadside equipment in the C-V2X vehicle-road-cloud system.

[0007] This application provides a C-V2X-based vehicle-road-cloud full-domain quantum-safe communication system. The system includes: an onboard unit (OBU) equipped with a quantum-safe module, a roadside unit (RSU) equipped with a quantum-safe encryption card, and a cloud platform providing full-domain quantum-safe services. The OBU is pre-configured with a symmetrical first pairing key between itself and a first access base station in the full-domain quantum-safe service, and upon startup, the OBU connects to the first access base station using the first pairing key. The RSU is pre-configured with a symmetrical second pairing key between itself and a second access base station in the full-domain quantum-safe service, and upon startup, the RSU connects to the second access base station using the second pairing key. Furthermore, the RSU is pre-configured with symmetrical third pairing keys between itself and all adjacent RSUs.

[0008] The OBU and the cloud platform communicate via quantum-secure communication through the first access base station;

[0009] The RSU and the cloud platform communicate via quantum-secure communication through the second access base station;

[0010] The RSU communicates directly with any adjacent RSU using a symmetrical third pairing key between the two parties, enabling quantum-secure communication.

[0011] In the case of the OBU within the service area of ​​the RSU:

[0012] If the OBU does not store a fourth pairing key symmetrical to any adjacent RSU, and does not store a fifth pairing key symmetrical to the RSU, then the OBU negotiates and determines the fifth pairing key with the RSU through the global quantum security service; wherein, the fifth pairing key is generated by the RSU itself; the OBU directly conducts quantum-secure communication with the RSU based on the fifth pairing key;

[0013] If the OBU stores a fourth pairing key symmetric to any neighboring RSU of the RSU, and does not store a fifth pairing key symmetric to the RSU, the OBU determines, through the neighboring RSU, a fifth pairing key symmetric between the OBU and the RSU; wherein the fifth pairing key is determined based on a third pairing key between the neighboring RSU and the RSU; and the OBU directly performs quantum secure communication with the RSU based on the fifth pairing key;

[0014] If the OBU stores a fifth pairing key symmetric to the RSU, the OBU directly performs quantum secure communication with the RSU based on the fifth pairing key.

[0015] In a possible implementation, the OBU negotiates and determines the fifth pairing key with the RSU through the global quantum secure service, and specifically includes:

[0016] Step 1, the OBU discovers the RSU through direct communication, acquires an RSU identity of the RSU, and encrypts a direct communication request message based on the first pairing key; wherein the direct communication request message carries the RSU identity of the RSU and an OBU identity of the OBU in the global quantum secure service;

[0017] Step 2, the OBU sends the encrypted direct communication request message to the first access base station;

[0018] Step 3, the first access base station decrypts the encrypted direct communication request message based on the locally stored first pairing key, to obtain the RSU identity and the OBU identity;

[0019] Step 4, the first access base station performs an authentication operation on the OBU based on the OBU identity, to determine whether the OBU has the right of direct communication;

[0020] Step 5, if the first access base station determines that the OBU has the right of direct communication, the first access base station relays the direct communication request message to the second access base station according to the RSU identity;

[0021] Step 6, the second access base station acquires a second pairing key symmetric to the RSU based on the RSU identity carried in the received direct communication request message, and encrypts the direct communication request message based on the second pairing key;

[0022] Step 7, the second access base station sends the encrypted direct communication request message to the RSU;

[0023] Step 8, the RSU uses a second pairing key symmetric with the second access base station to decrypt the received encrypted direct communication request message;

[0024] Step 9, the RSU creates a local session key pool according to the OBU identity carried in the direct communication request message, and allocates a local session key pool identifier;

[0025] Step 10, the RSU calls a local random number generator to generate a quantum secure true random number key for the session key pool as a fifth pairing key symmetric with the OBU;

[0026] Step 11, the RSU encrypts the generated direct communication response message based on the second pairing key; wherein the direct communication response message carries the fifth pairing key, the OBU identity and the RSU identity;

[0027] Step 12, the RSU sends the encrypted direct communication response message to the second access base station;

[0028] Step 13, the second access base station decrypts the received encrypted direct communication response message based on the second pairing key;

[0029] Step 14, the second access base station relays the direct communication response message to the first access base station based on the OBU identity carried in the direct communication response message;

[0030] Step 15, the first access base station selects a connection with the OBU based on the OBU identity carried in the received direct communication response message;

[0031] Step 16, the first access base station encrypts the direct communication response message based on the first pairing key symmetric with the OBU;

[0032] Step 17, the first access base station transmits the encrypted direct communication response message to the OBU through the connection;

[0033] Step 18, the OBU decrypts the received encrypted direct communication response message based on the first pairing key, and saves the fifth pairing key corresponding to the RSU identity obtained after decryption.

[0034] In a possible implementation, the OBU determines the fifth pairing key symmetric between the OBU and the RSU through the adjacent RSU, comprising:

[0035] Step 1, the OBU encrypts the generated key request message based on a fourth pairing key symmetric with the adjacent RSU; wherein the key request message carries a first RSU identity of the RSU and an OBU identity of the OBU;

[0036] Step 2, the OBU sends the encrypted key request message to the adjacent RSU;

[0037] Step 3, the adjacent RSU locates the fourth pairing key symmetric with the OBU based on the OBU identity carried in the received encrypted key request message, and decrypts the encrypted key request message based on the fourth pairing key;

[0038] Step 4, the adjacent RSU determines a third pairing key symmetric with the RSU according to the first RSU identity carried in the key request message;

[0039] Step 5, the adjacent RSU determines the fifth pairing key from the third pairing key;

[0040] Step 6, the adjacent RSU encrypts a generated key request response message based on the fourth pairing key; wherein the key request response message carries the fifth pairing key, the first RSU identity and a second RSU identity of the adjacent RSU;

[0041] Step 7, the adjacent RSU sends the encrypted key request response message to the OBU;

[0042] Step 8, the OBU locates the fourth pairing key symmetric with the adjacent RSU based on the RSU identity of the adjacent RSU carried in the received encrypted key request response message, and decrypts the encrypted key request response message based on the fourth pairing key;

[0043] Step 9, the OBU saves the fifth pairing key obtained by decryption and the RSU identity of the RSU.

[0044] In a possible implementation, the OBU directly performs quantum secure communication with the RSU based on the fifth pairing key, comprising:

[0045] The OBU encrypts a first message to be sent to the RSU based on a fifth pairing key symmetric with the RSU to obtain first message ciphertext; wherein the first message ciphertext carries an OBU identity of the OBU; the OBU sends the first message ciphertext to the RSU; the RSU determines the fifth pairing key symmetric with the OBU based on the OBU identity carried in the received first message ciphertext, and decrypts the first message ciphertext based on the fifth pairing key to obtain the first message; and

[0046] The RSU encrypts a second message to be sent to the OBU based on a fifth pairing key symmetric with the OBU to obtain second message ciphertext; wherein the second message ciphertext carries an RSU identity of the RSU; the RSU sends the second message ciphertext to the OBU; the OBU determines the fifth pairing key symmetric with the RSU based on the RSU identity carried in the received second message ciphertext, and decrypts the second message ciphertext based on the fifth pairing key to obtain the second message.

[0047] In a possible implementation, when the fifth pairing key is insufficient, the OBU initiates a key supplement process to the RSU, which includes:

[0048] Step 1, the OBU encrypts a generated first key supplement request message based on the fifth pairing key; wherein the first key supplement request message carries an OBU identity of the OBU;

[0049] Step 2, the OBU sends the encrypted first key supplement request message to the RSU;

[0050] Step 3, the RSU determines the fifth pairing key symmetric with the OBU based on the OBU identity carried in the received encrypted first key supplement request message, and decrypts the encrypted first key supplement request message based on the fifth pairing key;

[0051] Step 4, the RSU calls a local random number generator to generate a first supplement key;

[0052] Step 5, the RSU encrypts a generated first key supplement response message based on the fifth pairing key; wherein the first key supplement response message carries an RSU identity of the RSU and the first supplement key;

[0053] Step 6, the RSU sends the encrypted first key supplement response message to the OBU;

[0054] Step 7, the OBU determines a fifth pairing key symmetrical to the RSU based on the RSU identity carried in the received encrypted first key supplement response message, and decrypts the encrypted first key supplement response message based on the fifth pairing key, and supplements the fifth pairing key based on the decrypted first supplement key.

[0055] In a possible implementation, when the second pairing key is insufficient, the RSU supplements the second pairing key through the global quantum security service, specifically including:

[0056] Step 1, when determining that the second pairing key is insufficient, the RSU encrypts a generated second key supplement request message based on the second pairing key; wherein the second key supplement request message carries an RSU identity of the RSU;

[0057] Step 2, the RSU sends the encrypted second key supplement request message to the second access base station;

[0058] Step 3, the second access base station determines a second pairing key symmetrical to the RSU based on the RSU identity carried in the received encrypted second key supplement request message, and decrypts the encrypted second key supplement request message based on the second pairing key;

[0059] Step 4, the second access base station allocates a key center for the RSU in the global quantum security service;

[0060] Step 5, the second access base station sends a key distribution request message to the key center; wherein the key distribution request message carries the RSU identity;

[0061] Step 6, the key center creates a key pool for the RSU based on the RSU identity carried in the received key distribution request message, generates an encryption key and a second supplement key, and allocates a key index;

[0062] Step 7, the key center returns a key distribution response message to the second access base station; wherein the key distribution response message carries the encryption key, the RSU identity and the key index;

[0063] Step 8, the second access base station determines a connection with the RSU based on the RSU identity carried in the received key distribution response message;

[0064] Step 9, the second access base station constructs a second key supplement response message based on the key distribution response message; wherein the second key supplement response message carries the encryption key, the key index and the key center information of the key center;

[0065] Step 10, the second access base station encrypts the second key supplement response message through the second pairing key;

[0066] Step 11, the second access base station sends the encrypted second key supplement response message to the RSU through the connection;

[0067] Step 12, the RSU decrypts the received encrypted second key supplement response message based on the second pairing key to obtain the encryption key, the key index and the key center information;

[0068] Step 13, the RSU constructs a key download request message; wherein the key download request message carries the key index and the RSU identity;

[0069] Step 14, the RSU encrypts the key download request message through the encryption key;

[0070] Step 15, the RSU sends the encrypted key download request message to the key center according to the key center information;

[0071] Step 16, the key center locates the encryption key symmetric with the RSU based on the RSU identity carried by the received encrypted key download request message, and decrypts the encrypted key download request message based on the encryption key to obtain the key index;

[0072] Step 17, the key center finds the corresponding key pool according to the key index, and encrypts the generated key download response message based on the encryption key; wherein the key download response message carries the second supplement key in the key pool;

[0073] Step 18, the key center sends the encrypted key download response message to the RSU;

[0074] Step 19, the RSU decrypts the received encrypted key download response message based on the encryption key to obtain the second supplement key, and supplements the second pairing key based on the second supplement key.

[0075] In a possible implementation, when the third pairing key between the RSU and any adjacent RSU is insufficient, the RSU initiates a key supplement process to the adjacent RSU, which includes:

[0076] Step 1, when the third pairing key between the RSU and any adjacent RSU is insufficient, the RSU encrypts a third key supplement request message based on the third pairing key with the adjacent RSU; wherein the third key supplement request message carries a first RSU identity of the RSU;

[0077] Step 2, the RSU sends the encrypted third key supplement request message to the adjacent RSU;

[0078] Step 3, the adjacent RSU determines the third pairing key with the RSU based on the first RSU identity carried in the received encrypted third key supplement request message, and decrypts the encrypted third key supplement request message based on the third pairing key;

[0079] Step 4, the adjacent RSU calls a local random number generator to generate a third supplement key;

[0080] Step 5, the adjacent RSU encrypts a third key supplement response message based on the third pairing key; wherein the third key supplement response message carries the third supplement key and a second RSU identity of the adjacent RSU;

[0081] Step 6, the RSU sends the encrypted third key supplement response message to the RSU;

[0082] Step 7, the RSU determines the third pairing key with the adjacent RSU based on the second RSU identity carried in the received encrypted third key supplement response message, and decrypts the encrypted third key supplement response message based on the third pairing key, and supplements the third pairing key based on the decrypted third supplement key.

[0083] The beneficial effects of the present application are as follows:

[0084] 1. By configuring the OBU with a quantum security module, the RSU with a quantum security encryption card, and the cloud platform with a global quantum security service, the cloud platform, the RSU and the OBU are comprehensively upgraded with global quantum security, providing a hardware foundation for building a highly secure, seamless global quantum security communication environment.

[0085] 2. Through the first pairing key between the OBU and the first access base station, the second pairing key between the RSU and the second access base station, the third pairing key between the RSU and the adjacent RSU, and the fifth pairing key between the OBU and the RSU. This multi-level key system enhances the confidentiality and integrity of communication, so that the communication of any ring can be effectively protected.

[0086] 3. Through the global quantum security service and the RSU to negotiate a new fifth pairing key, so that even if the OBU has not established secure communication with the current RSU and any adjacent RSU of the RSU before, the OBU can quickly and securely obtain the symmetric fifth pairing key between the OBU and the RSU within the service range of the current RSU, so as to realize quantum secure communication with the RSU.

[0087] 4. Through the OBU to determine the symmetric fifth pairing key between the OBU and the RSU through the adjacent RSU, so that the OBU can quickly and securely obtain the symmetric pairing key between the OBU and the current service RSU without key relay, so as to ensure continuous and secure interaction between the vehicle and the road infrastructure, and avoid time and resource consumption through global quantum security service for key relay. This not only improves the flexibility and reliability of the system, but also provides a strong guarantee for the safe driving of the vehicle. BRIEF DESCRIPTION OF DRAWINGS

[0088] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.

[0089] Figure 1 A structure diagram of a C-V2X vehicle-road cloud system is provided for the embodiments of the present application;

[0090] Figure 2 A structure diagram of a C-V2X vehicle-road cloud global quantum security communication system is provided for the embodiments of the present application;

[0091] Figure 3 An OBU and RSU are both pre-stored with a symmetric pairing key with a global quantum service, as shown in the diagram;

[0092] Figure 4 A diagram showing that the RSUs save symmetric third pairing keys is provided for the embodiments of the present application;

[0093] Figure 5A specific OBU provided by the embodiment of the present application determines the fifth pairing key between the OBU and the RSU through the global quantum security service and negotiates with the RSU.

[0094] Figure 6 A scene diagram of OBU mobile switching RSU provided by the embodiment of the present application;

[0095] Figure 7 A flowchart of the fifth pairing key between the OBU and the RSU provided by the embodiment of the present application through the adjacent RSU;

[0096] Figure 8 A flowchart of the direct quantum security communication between the OBU and the RSU provided by the embodiment of the present application;

[0097] Figure 9 A flowchart of the key supplement process initiated by the OBU to the currently serving RSU when the fifth pairing key is insufficient provided by the embodiment of the present application;

[0098] Figure 10 A flowchart of the second pairing key supplement process initiated by the RSU through the global quantum security service when the second pairing key is insufficient provided by the embodiment of the present application;

[0099] Figure 11 A flowchart of the key supplement process initiated by the RSU to the adjacent RSU when the third pairing key between the RSU and any adjacent RSU is insufficient provided by the embodiment of the present application. DETAILED DESCRIPTION

[0100] In order to make the objects, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.

[0101] The global quantum security network can support secure and efficient quantum communication between any quantum security terminals accessing the encryption system, regardless of geographical location. A core of the global quantum security network is to use the access base station as the communication hub to access the global quantum security network, and to realize the key relay between the global quantum security terminals accessing the global quantum security network.

[0102] In the access process, when a quantum security terminal accesses an access base station, the access base station will allocate an access identifier to the terminal, that is, a unique terminal identifier of the entire global quantum security network, to identify the terminal. The access identifier carries the information of the country, operator, region, cell, access base station and terminal. With the access identifier, the terminal can be determined in the global quantum security network within the time range of the terminal having the identifier. The quantum security terminal can then apply for services and request message resources from the global quantum security network through the access base station.

[0103] In the key relay process, the encryption end relays the key to the decryption end access base station through the global quantum security network via the encryption end access base station, and then the decryption end access base station forwards the key to the decryption end, so as to form a symmetric quantum security key between the encryption end and the decryption end, and to encrypt and decrypt the communication. The global quantum security network also includes a key center, which mainly distributes keys, that is, quantum keys, to quantum security terminals accessing the global quantum security network.

[0104] In the global quantum security communication process, once the symmetric key is shared between the two communication parties, the subsequent global quantum security communication will be based on the symmetric key. However, in order to simplify key management and reduce the number of key pairs, the global quantum security system adopts the mode of forming a paired key between the terminal and the access base station. This paired key enables any two quantum security terminals accessing the global quantum security network to perform key relay through the access base stations accessed by each terminal, thereby realizing global quantum security communication.

[0105] However, although the global quantum security network performs well in some scenarios, it faces challenges in some specific situations. In particular, for mobile devices or scenarios that require cross-regional or cross-city communication, such as vehicle networking, the limitations of the global quantum security network are revealed. Figure 1A structural schematic diagram of a C-V2X vehicle-road cloud system is provided for an embodiment of the present application. The C-V2X (Cellular Vehicle-to-Everything) vehicle-road cloud system is mainly composed of an on-board unit (OBU), a road side unit (RSU), a network, and a cloud platform. In this system, the network can include fixed networks and 4G / 5G communication technologies, and the road side unit can include mobile edge computing (MEC) functions to make data processing more efficient. The RSU can connect to the fixed network in the network through the Uu interface and communicate with the cloud platform, while the OBU can communicate with the RSU or other OBUs, or even directly with the cloud platform. This communication mode includes direct communication between the OBU and the RSU through the PC5 interface, direct communication between the OBU and the OBU, and communication between the OBU and the cloud platform through the Uu interface. When the OBU moves, the RSU for OBU communication will change, which means that during the movement of the OBU, the RSU interacting with the OBU is constantly changing, and the direct communication between the RSU and the OBU does not go through the access and transfer of other devices, belonging to the mode of automatic discovery, automatic connection, and automatic communication. During the movement of the vehicle, the RSU for OBU communication will change, that is, the RSU interacting with the OBU will be constantly replaced during the movement of the OBU. This direct communication mode between the RSU and the OBU does not go through the access and transfer of other devices, realizing automatic discovery, automatic connection, and automatic communication. However, if the global quantum secure communication technology is directly applied in this system, it needs to rely on the access base station in the global quantum secure network for key relay, so when the vehicle moves to a new area or city, it needs to establish a connection and key relay relationship with the new access base station. This not only increases the delay and complexity of communication, but also may not be able to realize continuous and stable communication due to the coverage limit of the access base station.

[0106] Based on this, the present application provides a C-V2X-based vehicle-road cloud global quantum secure communication system to realize global quantum secure communication between vehicles, cloud platforms, and road side devices in the C-V2X vehicle-road cloud system.

[0107] Embodiment 1:

[0108] Figure 2A structure schematic diagram of a C-V2X-based vehicle-road cloud global quantum security communication system provided for an embodiment of the application, the system comprising: an OBU 110 configured with a quantum security module, an RSU 120 configured with a quantum security encryption card, and a cloud platform 130 configured with a global quantum security service; wherein the OBU 110 is preconfigured with a first pairing key between the OBU 110 and a first access base station in the global quantum service, and after the OBU 110 is started, the OBU 110 accesses the first access base station through the first pairing key; the RSU 120 is preconfigured with a second pairing key between the RSU 120 and a second access base station in the global quantum service, and after the RSU 120 is started, the RSU 120 accesses the second access base station through the second pairing key; and the RSU 120 is further preconfigured with a third pairing key between the RSU 120 and all adjacent RSUs 120 respectively;

[0109] The OBU 110 and the cloud platform 130 perform quantum security communication through the first access base station;

[0110] The RSU 120 and the cloud platform 130 perform quantum security communication through the second access base station;

[0111] The RSU 120 and any adjacent RSU 120 perform quantum security communication directly through the third pairing key between them;

[0112] If the OBU 110 is within the service range of the RSU 120, and the OBU 110 does not save a fourth pairing key symmetric to any adjacent RSU 120 of the RSU 120, the OBU 110 determines a fifth pairing key with the RSU 120 through the global quantum security service; wherein the fifth pairing key is generated by the RSU 120; the OBU 110 performs quantum security communication with the RSU 120 directly based on the fifth pairing key;

[0113] If the OBU 110 is within the service range of the RSU 120, and the OBU 110 saves a fourth pairing key symmetric to any adjacent RSU 120 of the RSU 120, the OBU 110 determines a fifth pairing key between the OBU 110 and the RSU 120 through the adjacent RSU 120; wherein the fifth pairing key is determined based on the third pairing key between the adjacent RSU 120 and the RSU 120.

[0114] In the present application, the C-V2X-based global quantum secure communication system of the cloud (hereinafter referred to as the system) is committed to building a highly secure and seamless global quantum secure communication environment. To achieve this goal, the system first upgrades the cloud platform 130, RSU 120 and OBU 110 comprehensively.

[0115] For the cloud platform 130, the cloud platform 130 as the core of the system can be upgraded by building a global quantum security service. This global quantum security service includes a series of key components such as access base station, key center and quantum security server, and each component plays an indispensable role. Among them, the access base station is responsible for providing access and authentication services for various terminals (including RSU 120 equipped with quantum security encryption card and OBU 110 equipped with quantum security module). The key center is responsible for generating and distributing symmetric keys for each terminal based on quantum security services. And the quantum security server is responsible for the quantum security encryption of the data of the cloud platform 130, and receives the key distribution from the key center to ensure the data security of the cloud platform 130.

[0116] For RSU 120, RSU 120 can be upgraded by configuring a quantum security encryption card. The quantum security encryption card is responsible for data encryption from RSU 120 to cloud platform 130, and receives key distribution from the global quantum security service. At the same time, the quantum security encryption card also has the ability to generate and distribute quantum keys when RSU 120 communicates directly with other devices.

[0117] For OBU 110, OBU 110 is upgraded by configuring a quantum security module, which is responsible for data encryption between OBU 110 and cloud platform 130, and receives key distribution from the global quantum security service. In addition, the quantum security module is also responsible for receiving key distribution from the RSU 120 directly communicating with it, and directly communicating with the RSU 120 for quantum security encryption.

[0118] In the C-V2X-based global quantum secure communication system of the cloud, OBU 110 and RSU 120 are pre-configured with symmetric pairing keys with the access base station in the global quantum service. These pairing keys not only enable OBU 110 and RSU 120 to securely access the global quantum security service, but also enable quantum secure communication through key relay via the access base station in the service. Figure 3The OBU 110 and the RSU 120 provided by the embodiment of the present application are both preconfigured with a pairing key symmetric to the global quantum service. The OBU 110 is preconfigured with a pairing key (denoted as a first pairing key) symmetric between the OBU 110 and an access base station (for the convenience of description, the access base station accessed by the OBU 110 is denoted as a first access base station) in the global quantum security service. The RSU 120 is preconfigured with a pairing key (denoted as a second pairing key) symmetric between the RSU 120 and an access base station (for the convenience of description, the access base station accessed by the RSU 120 is denoted as a second access base station) in the global quantum security service.

[0119] Meanwhile, in order to realize direct quantum security communication between the RSUs 120, the RSU 120 is further preconfigured with a third pairing key symmetric between the RSU 120 and all adjacent RSUs 120 thereof, so that they can directly perform quantum security communication. Figure 4 The RSU 120 provided by the embodiment of the present application is preconfigured with a third pairing key symmetric between the RSU 120 and an adjacent RSU 120 thereof. If the RSU 120 has only one adjacent RSU 120, the RSU 120 is preconfigured with a third pairing key symmetric between the RSU 120 and the adjacent RSU 120, and the third pairing key is stored in correspondence with the RSU identity (such as a UID) of the adjacent RSU 120. If the RSU 120 has multiple adjacent RSUs 120, such as at an intersection, the RSU 120 is preconfigured with a third pairing key symmetric between the RSU 120 and each adjacent RSU 120, and the third pairing key is stored in correspondence with the RSU identity of the adjacent RSU 120. Whether the RSU 120 is in a simple linear arrangement or a complex intersection such as an intersection, each RSU 120 can accurately identify and apply the corresponding third pairing key according to the RSU identity of the adjacent RSU 120. Based on this, for any RSU 120, the RSU 120 and any adjacent RSU 120 can directly perform quantum security communication through the third pairing key symmetric between the two.

[0120] It should be noted that the first access base station can be the same as the second access base station, or can be different from the second access base station.

[0121] After the OBU 110 is powered on, it initiates an access request message to the first access base station based on a first pairing key that is symmetric to the first access base station. The first access base station decrypts the received encrypted access request message based on the first pairing key that is symmetric to the OBU 110. The first access base station performs access authentication on the device identity of the OBU 110 according to the access request message. If the access authentication is successful, the OBU 110 successfully accesses the global quantum secure service, and the OBU 110 can perform quantum secure encrypted communication with the cloud platform 130 through the global quantum secure service. Therefore, the quantum secure communication between the OBU 110 and the cloud platform 130 in the system is performed through the first access base station.

[0122] Similarly, after the RSU 120 is powered on, it initiates an access request message to the second access base station based on a second pairing key that is symmetric to the second access base station. The second access base station decrypts the received encrypted access request message based on the second pairing key that is symmetric to the RSU 120. The second access base station performs access authentication on the device identity of the RSU 120 according to the access request message. If the access authentication is successful, the RSU 120 successfully accesses the global quantum secure service, and the RSU 120 can perform quantum secure encrypted communication with the cloud platform 130 through the global quantum secure service. Therefore, the quantum secure communication between the RSU 120 and the cloud platform 130 in the system is performed through the second access base station.

[0123] It should be noted that the process of access authentication on the device identity by the access base station (including the first access base station and the second access base station) can refer to the prior art, and will not be described in detail here.

[0124] In actual application scenarios, when the OBU 110 is within the service range of the current RSU 120, in order to ensure that the OBU 110 can perform secure and efficient quantum secure communication with the current serving RSU 120, a series of measures need to be taken to negotiate and determine the pairing key (referred to as the fifth pairing key) that is symmetric between the OBU 110 and the RSU 120. The following describes two cases of the OBU 110 obtaining the fifth pairing key:

[0125] Case one, the OBU 110 negotiates and determines the fifth pairing key with the RSU 120 through the global quantum secure service.

[0126] In consideration of the possibility that the OBU 110 accesses the global quantum security service for the first time, or, due to network instability, traffic accidents, etc., the OBU 110 loses contact with the previously directly communicated RSU 120 and instead appears within the coverage of the currently serving RSU 120. For these situations, the OBU 110, although within the service range of the current RSU 120, does not have the ability to directly quantum security encryption communication with the RSU 120, such as PC2-based direct communication, and the OBU 110 also does not have the ability to directly quantum security encryption communication with any adjacent RSU 120 of the RSU 120. That is, the OBU 110 does not save the fifth pairing key symmetric to the RSU 120, nor does it save the pairing key (denoted as the fourth pairing key) symmetric to any adjacent RSU 120 of the RSU 120. For this case, the OBU 110 and the RSU 120 can negotiate and determine the fifth pairing key through the global quantum security service, that is, the OBU 110 and the RSU 120 can indirectly contact each other through the global quantum security service, and use the quantum security communication capability provided by the service to perform key negotiation.

[0127] In a possible implementation, Figure 5 A specific OBU 110 provided by the embodiment of the present application negotiates and determines the fifth pairing key with the RSU 120 through the global quantum security service. The flowchart of the process includes:

[0128] Step 1, the OBU 110 discovers the RSU 120 through direct communication, obtains the RSU identity of the RSU 120, and encrypts the direct communication request message based on the first pairing key; wherein the direct communication request message carries the RSU identity of the RSU 120 and the OBU identity of the OBU 110 in the global quantum security service.

[0129] Step 2, the OBU 110 sends the encrypted direct communication request message to the first access base station.

[0130] Step 3, the first access base station decrypts the encrypted direct communication request message based on the locally saved first pairing key to obtain the RSU identity and the OBU identity.

[0131] Step 4, the first access base station performs an authentication operation on the OBU 110 based on the OBU identity to determine whether the OBU 110 has the right to directly communicate.

[0132] For example, the first access base station can check whether the OBU identity (such as device ID, serial number, network access identifier, etc.) provided by the OBU 110 matches the information registered in the system.

[0133] Step 5, if the first access base station determines that the OBU 110 has the right to direct communication, then according to the RSU identity, the direct communication request message is relayed to the second access base station.

[0134] If the first access base station is determined to be the second access base station according to the RSU identity, the direct communication request message does not need to be relayed, and step 6 is performed.

[0135] Step 6, the second access base station obtains the second pairing key symmetric to the RSU 120 based on the RSU identity carried in the received direct communication request message, and encrypts the direct communication request message based on the second pairing key.

[0136] Step 7, the second access base station sends the encrypted direct communication request message to the RSU 120.

[0137] Step 8, the RSU 120 decrypts the received encrypted direct communication request message using the second pairing key symmetric to the second access base station.

[0138] Step 9, the RSU 120 creates a local session key pool according to the OBU identity carried in the direct communication request message, and assigns a local session key pool identifier.

[0139] Step 10, the RSU 120 calls a local random number generator to generate a quantum secure true random number key for the session key pool as a fifth pairing key symmetric to the OBU 110.

[0140] Step 11, the RSU 120 encrypts the generated direct communication response message based on the second pairing key; wherein the direct communication response message carries the fifth pairing key, the OBU identity and the RSU identity of the RSU 120.

[0141] Step 12, the RSU 120 sends the encrypted direct communication response message to the second access base station.

[0142] Step 13, the second access base station decrypts the received encrypted direct communication response message based on the second pairing key.

[0143] Step 14, the second access base station relays the direct communication response message to the first access base station based on the OBU identity carried in the direct communication response message.

[0144] Step 15, the first access base station selects the connection with the OBU 110 based on the OBU identity carried in the received direct communication response message.

[0145] Step 16, the first access base station encrypts the direct communication response message based on the first pairing key symmetric to the OBU 110.

[0146] Step 17, the first access base station transmits the encrypted direct communication response message to the OBU 110 through the connection.

[0147] Step 18, the OBU 110 decrypts the received encrypted direct communication response message based on the first pairing key, and saves the fifth pairing key obtained by decryption corresponding to the RSU identity.

[0148] In this way, even if the OBU 110 has not established secure communication with the current RSU 120 and any adjacent RSU 120 of the RSU 120 before, the fifth pairing key symmetric between the OBU 110 and the RSU 120 can be quickly and securely obtained in the service range of the current RSU 120, so as to realize quantum secure communication between the OBU 110 and the RSU 120.

[0149] Case two, the OBU 110 determines the fifth pairing key symmetric between the OBU 110 and the RSU 120 through any adjacent RSU 120 of the RSU 120.

[0150] Since the OBU 110 is a mobile device, it is not always served by the same RSU 120. With the movement of the OBU 110, it may enter the service range of a new RSU 120, at which time the RSU 120 needs to be switched. In this process, the OBU 110 must establish direct quantum secure communication between the OBU 110 and a certain adjacent RSU 120 of the RSU 120, but has not established direct quantum secure communication with the RSU 120. Figure 6 A scene diagram for the OBU 110 to switch the RSU 120 is provided for the embodiment of the application. The OBU 110 moves from A to B, and the connected RSU 120 is switched from RSU 120a to RSU 120b. That is, the OBU 110 saves the fourth pairing key symmetric between the OBU 110 and a certain adjacent RSU 120 of the current serving RSU 120, and does not save the fifth pairing key symmetric between the OBU 110 and the current serving RSU 120. For this case, the OBU 110 can determine the fifth pairing key symmetric between the OBU 110 and the current serving RSU 120 through the adjacent RSU 120.

[0151] In a possible implementation manner, Figure 7 A specific flowchart for the OBU 110 to determine the fifth pairing key symmetric between the OBU 110 and the RSU 120 through the adjacent RSU 120 is provided for the embodiment of the application. The flowchart includes:

[0152] Step 1, the OBU 110 encrypts the generated key request message based on the fourth pairing key symmetrical to the adjacent RSU 120; wherein the key request message carries the RSU identity of the current serving RSU 120 (denoted as a first RSU identity) and the OBU identity of the OBU 110.

[0153] Step 2, the OBU 110 sends the encrypted key request message to the adjacent RSU 120.

[0154] Step 3, the adjacent RSU 120 locates the fourth pairing key symmetrical to the OBU 110 based on the OBU identity carried in the received encrypted key request message, and decrypts the encrypted key request message based on the fourth pairing key.

[0155] Step 4, the adjacent RSU 120 determines the third pairing key symmetrical to the RSU 120 according to the first RSU identity carried in the key request message.

[0156] Step 5, the adjacent RSU 120 determines the fifth pairing key from the third pairing key.

[0157] For example, the adjacent RSU 120 determines the quantum key of the key size in the third pairing key as the fifth pairing key according to the pre-configured key size. Wherein the setting rule of the key size can be flexibly set according to actual needs, which is not limited here.

[0158] Step 6, the adjacent RSU 120 encrypts the generated key request response message based on the fourth pairing key; wherein the key request response message carries the fifth pairing key, the first RSU identity, and the RSU identity of the adjacent RSU 120 (denoted as a second RSU identity).

[0159] Step 7, the adjacent RSU 120 sends the encrypted key request response message to the OBU 110.

[0160] Step 8, the OBU 110 locates the fourth pairing key symmetrical to the adjacent RSU 120 based on the RSU identity of the adjacent RSU 120 carried in the received encrypted key request response message, and decrypts the encrypted key request response message based on the fourth pairing key.

[0161] Step 9, the OBU 110 saves the fifth pairing key and the RSU identity of the RSU 120 corresponding to the decrypted fifth pairing key.

[0162] In this way, the OBU 110 quickly and safely obtains the symmetric pairing key with the current serving RSU 120 without key relay, even when performing RSU 120 switching, thereby ensuring continuous and secure interaction between the vehicle and the road infrastructure, avoiding time and resource consumption through global quantum secure service for key relay. This not only improves the flexibility and reliability of the system, but also provides strong protection for the safe driving of the vehicle.

[0163] Based on the above two cases, the OBU 110 can obtain the fifth pairing key symmetric with the currently serving RSU 120. Based on this, in the case where the OBU 110 stores the fifth pairing key symmetric with the currently serving RSU 120, the OBU 110 can perform direct quantum secure communication with the RSU 120 based on the fifth pairing key.

[0164] Exemplary, Figure 8 The specific flowchart of the direct quantum secure communication between the OBU 110 and the RSU 120 provided by the embodiment of the present application is as follows:

[0165] The OBU 110 encrypts the first message to be sent to the RSU 120 based on the fifth pairing key symmetric with the RSU 120 to obtain a first message ciphertext. The first message ciphertext carries the OBU identity of the OBU 110. The OBU 110 sends the first message ciphertext to the RSU 120. The RSU 120 determines the fifth pairing key symmetric with the OBU 110 based on the OBU identity carried by the received first message ciphertext, and decrypts the first message ciphertext based on the fifth pairing key to obtain the first message.

[0166] The RSU 120 encrypts the second message to be sent to the OBU 110 based on the fifth pairing key symmetric with the OBU 110 to obtain a second message ciphertext. The second message ciphertext carries the RSU identity of the RSU 120. The RSU 120 sends the second message ciphertext to the OBU 110. The OBU 110 determines the fifth pairing key symmetric with the RSU 120 based on the RSU identity carried by the received second message ciphertext, and decrypts the second message ciphertext based on the fifth pairing key to obtain the second message.

[0167] The beneficial effects of the present application are as follows:

[0168] 1. By configuring the OBU 110 with a quantum security module, the RSU 120 with a quantum security encryption card, and the cloud platform 130 with a global quantum security service, comprehensive global quantum security upgrades are achieved for the cloud platform 130, RSU 120, and OBU 110, providing a hardware foundation for building a highly secure, seamless global quantum security communication environment.

[0169] 2. The first pairing key between the OBU and the first access base station, the second pairing key between the RSU and the second access base station, the third pairing key between the RSU and the adjacent RSU, and the fifth pairing key between the OBU and the RSU. This multi-level key system enhances the confidentiality and integrity of communication, making any ring communication effectively protected.

[0170] 3. By negotiating with the global quantum security service and the RSU to determine the new fifth pairing key, even if the OBU 110 has not established secure communication with the current RSU 120 and any adjacent RSU 120, the OBU 110 can quickly and securely obtain the symmetric fifth pairing key between the OBU 110 and the RSU 120 within the service range of the current RSU 120, thereby realizing quantum secure communication with the RSU 120.

[0171] 4. By the OBU 110 determining the symmetric fifth pairing key between the OBU 110 and the RSU 120 through the adjacent RSU 120, the OBU 110 can quickly and securely obtain the symmetric pairing key with the current service RSU 120 without key relay, ensuring continuous and secure interaction between the vehicle and the road infrastructure, and avoiding time and resource consumption through global quantum security service key relay. This not only improves the flexibility and reliability of the system, but also provides a strong guarantee for the safe driving of vehicles.

[0172] Embodiment 2:

[0173] In this application, the OBU is usually installed on the vehicle, while the RSU is deployed in the road infrastructure, and data exchange can be carried out between the two, such as vehicle identification, toll collection, traffic information push, etc. In order to ensure the secure transmission of these sensitive information, both parties will use the symmetric fifth pairing key for quantum secure encrypted communication. However, with the increase of the number of communications, the fifth pairing key may gradually be consumed, therefore, in order to ensure the continuity and stability of the direct quantum secure communication between the OBU and the RSU, on the basis of the above embodiment, in this application, a mechanism is needed to dynamically supplement new keys. Exemplarily, the OBU can initiate a key supplement process to the RSU, thereby requesting the RSU to call the local random number generator to supplement the fifth pairing key.

[0174] In a possible implementation, Figure 9 The specific schematic diagram of the OBU initiating a key supplement process to the currently served RSU when the fifth pairing key is insufficient is provided for the embodiments of the application, and the process includes:

[0175] Step 1, the OBU encrypts the generated first key supplement request message based on the fifth pairing key. Wherein, the first key supplement request message carries the OBU identity of the OBU.

[0176] Step 2, the OBU sends the encrypted first key supplement request message to the RSU.

[0177] Step 3, the RSU determines the symmetric fifth pairing key with the OBU based on the OBU identity carried in the received encrypted first key supplement request message, and decrypts the encrypted first key supplement request message based on the fifth pairing key.

[0178] Step 4, the RSU calls the local random number generator to generate the first supplement key.

[0179] Step 5, the RSU encrypts the generated first key supplement response message based on the fifth pairing key; wherein, the first key supplement response message carries the RSU identity of the RSU and the first supplement key.

[0180] Step 6, the RSU sends the encrypted first key supplement response message to the OBU.

[0181] Step 7, the OBU determines the symmetric fifth pairing key with the RSU based on the RSU identity carried in the received encrypted first key supplement response message, and decrypts the encrypted first key supplement response message based on the fifth pairing key, and supplements the fifth pairing key based on the first supplement key obtained by decryption.

[0182] Through the flow, the OBU and the RSU can safely supplement a new fifth pairing key without interrupting direct quantum secure communication, thereby effectively improving the continuity and stability of direct quantum secure communication between the OBU and the RSU and improving the security and reliability of the entire system.

[0183] Embodiment 3

[0184] In an actual application scenario, when the RSU in the system performs quantum secure communication with the second access base station in the global quantum secure service, the second pairing key symmetric to the second access base station will be continuously consumed. Therefore, in order to ensure the continuity and stability of the connection between the RSU and the global quantum secure service, on the basis of the above embodiments, in the present application, the second access base station can initiate a key supplement request to the global quantum secure service in time to supplement the second pairing key when it is determined that the second pairing key is insufficient.

[0185] In a possible implementation manner, Figure 10 A specific flow diagram for supplementing a second pairing key by an RSU through a global quantum secure service when the second pairing key is insufficient is provided in the embodiments of the present application, and the flow includes the following steps.

[0186] Step 1, when the second pairing key is determined to be insufficient, the RSU encrypts a generated second key supplement request message based on the second pairing key. The second key supplement request message carries an RSU identity of the RSU.

[0187] Step 2, the RSU sends the encrypted second key supplement request message to the second access base station.

[0188] Step 3, the second access base station determines the second pairing key symmetric to the RSU based on the RSU identity carried in the received encrypted second key supplement request message, and decrypts the encrypted second key supplement request message based on the second pairing key.

[0189] Step 4, the second access base station allocates a key center for the RSU in the global quantum secure service.

[0190] Step 5, the second access base station sends a key distribution request message to the key center. The key distribution request message carries the RSU identity.

[0191] Step 6, the key center creates a key pool for the RSU, generates an encryption key and a second supplement key, and allocates a key index based on the RSU identity carried in the received key distribution request message.

[0192] Step 7, the key center replies to the second access base station with a key distribution response message. The key distribution response message carries the encryption key, the RSU identity, and the key index.

[0193] Step 8, the second access base station determines the connection with the RSU based on the RSU identity carried in the received key distribution response message.

[0194] Step 9, the second access base station constructs a second key supplement response message based on the key distribution response message. The second key supplement response message carries the encryption key, the key index, and the key center information of the key center.

[0195] Step 10, the second access base station encrypts the second key supplement response message with the second pairing key.

[0196] Step 11, the second access base station sends the encrypted second key supplement response message to the RSU through the connection.

[0197] Step 12, the RSU decrypts the received encrypted second key supplement response message based on the second pairing key to obtain the encryption key, the key index, and the key center information.

[0198] Step 13, the RSU constructs a key download request message. The key download request message carries the key index and the RSU identity.

[0199] Step 14, the RSU encrypts the key download request message with the encryption key.

[0200] Step 15, the RSU sends the encrypted key download request message to the key center according to the key center information.

[0201] Step 16, the key center locates the encryption key symmetric to the RSU based on the RSU identity carried in the received encrypted key download request message, and decrypts the encrypted key download request message based on the encryption key to obtain the key index.

[0202] Step 17, the key center finds the corresponding key pool according to the key index, and encrypts the generated key download response message based on the encryption key. The key download response message carries the second supplement key in the key pool.

[0203] Step 18, the key center sends the encrypted key download response message to the RSU.

[0204] Step 19, the RSU decrypts the received encrypted key download response message based on the encryption key to obtain the second supplement key, and supplements the second pairing key based on the second supplement key.

[0205] It should be noted that the OBU initiates the key supplement process to the global quantum security service when determining that the first pairing key is insufficient, which is similar to the RSU initiating the key supplement process to the global quantum security service when determining that the second pairing key is insufficient, and details are not repeated here.

[0206] Embodiment 4:

[0207] In actual application scenarios, the symmetric third pairing key between the RSUs will be consumed in the quantum secure communication process between the RSUs and in the process of allocating the fifth pairing key to the OBU. Therefore, the RSU needs to supplement the third pairing key with any adjacent RSU in time to maintain the continuity and security of communication.

[0208] In a possible implementation manner, Figure 11 A specific schematic diagram is provided for the embodiment of the present application when the symmetric third pairing key between the RSU and any adjacent RSU is insufficient, and the RSU initiates a key supplement process to the adjacent RSU, which includes the following steps:

[0209] Step 1, when the symmetric third pairing key between the RSU and any adjacent RSU is insufficient, the RSU encrypts a third key supplement request message based on the symmetric third pairing key with the adjacent RSU. The third key supplement request message carries the first RSU identity of the RSU.

[0210] Step 2, the RSU sends the encrypted third key supplement request message to the adjacent RSU.

[0211] Step 3, the adjacent RSU determines the symmetric third pairing key with the RSU based on the first RSU identity carried in the received encrypted third key supplement request message, and decrypts the encrypted third key supplement request message based on the third pairing key.

[0212] Step 4, the adjacent RSU calls a local random number generator to generate a third supplement key.

[0213] Step 5, the adjacent RSU encrypts a third key supplement response message based on the third pairing key. The third key supplement response message carries the third supplement key and the second RSU identity of the adjacent RSU.

[0214] Step 6, the RSU sends the encrypted third key supplement response message to the RSU.

[0215] Step 7, the RSU determines the third pairing key symmetrical to the adjacent RSU based on the second RSU identity carried in the received encrypted third key supplement response message, and decrypts the encrypted third key supplement response message based on the third pairing key, and supplements the third pairing key based on the third supplement key obtained by decryption.

Claims

1. A C-V2X based cloud global quantum secure communication system for vehicle-to-road, characterized in that, The system comprises: an OBU configured with a quantum security module, an RSU configured with a quantum security encryption card, and a cloud platform configured with a global quantum security service; wherein, the OBU is pre-configured with a first pairing key between the OBU and a first access base station in the global quantum security service, and after the OBU is started, the OBU accesses the first access base station through the first pairing key; the RSU is pre-configured with a second pairing key between the RSU and a second access base station in the global quantum security service, and after the RSU is started, the RSU accesses the second access base station through the second pairing key; and the RSU is further pre-configured with a third pairing key between the RSU and all adjacent RSUs; The quantum security communication between the OBU and the cloud platform is carried out through the first access base station; The quantum security communication between the RSU and the cloud platform is carried out through the second access base station; The quantum security communication between the RSU and any adjacent RSU is carried out directly through the third pairing key between the two parties; In the case that the OBU is in the service range of the RSU: If the OBU does not save a fourth pairing key symmetric with any adjacent RSU of the RSU, and does not save a fifth pairing key symmetric with the RSU, the OBU determines the fifth pairing key with the RSU through the global quantum security service; wherein, the fifth pairing key is generated by the RSU; the OBU directly carries out quantum security communication with the RSU based on the fifth pairing key; If the OBU saves the fourth pairing key symmetric with any adjacent RSU of the RSU, and does not save the fifth pairing key symmetric with the RSU, the OBU determines the fifth pairing key between the OBU and the RSU through the adjacent RSU; wherein, the fifth pairing key is determined based on the third pairing key between the adjacent RSU and the RSU; the OBU directly carries out quantum security communication with the RSU based on the fifth pairing key; If the OBU saves the fifth pairing key symmetric with the RSU, the OBU directly carries out quantum security communication with the RSU based on the fifth pairing key.

2. The system of claim 1, wherein, The OBU determines the fifth pairing key with the RSU through the global quantum security service, specifically comprising: Step 1, the OBU discovers the RSU through direct communication, acquires the RSU identity of the RSU, and encrypts a direct communication request message based on the first pairing key; wherein, the direct communication request message carries the RSU identity of the RSU and the OBU identity of the OBU in the global quantum security service; Step 2, the OBU sends the encrypted direct communication request message to the first access base station; Step 3, the first access base station decrypts the encrypted direct communication request message based on the locally stored first pairing key to obtain the RSU identity and the OBU identity; Step 4, the first access base station authenticates the OBU based on the OBU identity to determine whether the OBU has the right of direct communication; Step 5, if the first access base station determines that the OBU has the right of direct communication, the first access base station relays the direct communication request message to the second access base station according to the RSU identity; Step 6, the second access base station obtains a second pairing key symmetric to the RSU based on the RSU identity carried in the received direct communication request message, and encrypts the direct communication request message based on the second pairing key; Step 7, the second access base station sends the encrypted direct communication request message to the RSU; Step 8, the RSU decrypts the received encrypted direct communication request message using the second pairing key symmetric to the second access base station; Step 9, the RSU creates a local session key pool and allocates a local session key pool identifier according to the OBU identity carried in the direct communication request message; Step 10, the RSU generates a quantum secure true random number key as a fifth pairing key symmetric to the OBU using a local random number generator for the session key pool; Step 11, the RSU encrypts the generated direct communication response message based on the second pairing key; wherein the direct communication response message carries the fifth pairing key, the OBU identity and the RSU identity; Step 12, the RSU sends the encrypted direct communication response message to the second access base station; Step 13, the second access base station decrypts the received encrypted direct communication response message based on the second pairing key; Step 14, the second access base station relays the direct communication response message to the first access base station based on the OBU identity carried in the direct communication response message; Step 15, the first access base station selects a connection with the OBU based on the OBU identity carried in the received direct communication response message; Step 16, the first access base station encrypts the direct communication response message based on the first pairing key symmetric to the OBU; Step 17, the first access base station transmits the encrypted direct communication response message to the OBU through the connection; Step 18, the OBU decrypts the received encrypted direct communication response message based on the first pairing key, and saves the fifth pairing key corresponding to the RSU identity obtained after decryption.

3. The system of claim 1, wherein, The OBU determines the fifth pairing key symmetric to the OBU and the RSU through the adjacent RSU, comprising: Step 1, the OBU encrypts the generated key request message based on a fourth pairing key symmetric with the adjacent RSU; wherein the key request message carries a first RSU identity of the RSU and an OBU identity of the OBU; Step 2, the OBU sends the encrypted key request message to the adjacent RSU; Step 3, the adjacent RSU locates the fourth pairing key symmetric with the OBU based on the OBU identity carried in the received encrypted key request message, and decrypts the encrypted key request message based on the fourth pairing key; Step 4, the adjacent RSU determines a third pairing key symmetric with the RSU according to the first RSU identity carried in the key request message; Step 5, the adjacent RSU determines the fifth pairing key from the third pairing key; Step 6, the adjacent RSU encrypts the generated key request response message based on the fourth pairing key; wherein the key request response message carries the fifth pairing key, the first RSU identity and a second RSU identity of the adjacent RSU; Step 7, the adjacent RSU sends the encrypted key request response message to the OBU; Step 8, the OBU locates the fourth pairing key symmetric with the adjacent RSU based on the RSU identity of the adjacent RSU carried in the received encrypted key request response message, and decrypts the encrypted key request response message based on the fourth pairing key; Step 9, the OBU saves the fifth pairing key and the RSU identity corresponding to the decrypted fifth pairing key.

4. The system of any of claims 1-3, wherein, The OBU directly performs quantum secure communication with the RSU based on the fifth pairing key, comprising: The OBU encrypts a first message to be sent to the RSU based on a fifth pairing key symmetric with the RSU to obtain first message ciphertext; wherein the first message ciphertext carries an OBU identity of the OBU; the OBU sends the first message ciphertext to the RSU; the RSU determines the fifth pairing key symmetric with the OBU based on the OBU identity carried in the received first message ciphertext, and decrypts the first message ciphertext based on the fifth pairing key to obtain the first message; and The RSU encrypts a second message to be sent to the OBU based on a fifth pairing key symmetric with the OBU to obtain second message ciphertext; wherein the second message ciphertext carries an RSU identity of the RSU; the RSU sends the second message ciphertext to the OBU; the OBU determines the fifth pairing key symmetric with the RSU based on the RSU identity carried in the received second message ciphertext, and decrypts the second message ciphertext based on the fifth pairing key to obtain the second message.

5. The system of claim 1, wherein, When the fifth pairing key is insufficient, the OBU initiates a key supplement process to the RSU, and the process includes: Step 1, the OBU encrypts a generated first key supplement request message based on the fifth pairing key; wherein the first key supplement request message carries an OBU identity of the OBU; Step 2, the OBU sends the encrypted first key supplement request message to the RSU; Step 3, the RSU determines a fifth pairing key symmetric to the OBU based on the OBU identity carried in the received encrypted first key supplement request message, and decrypts the encrypted first key supplement request message based on the fifth pairing key; Step 4, the RSU calls a local random number generator to generate a first supplement key; Step 5, the RSU encrypts a generated first key supplement response message based on the fifth pairing key; wherein the first key supplement response message carries an RSU identity of the RSU and the first supplement key; Step 6, the RSU sends the encrypted first key supplement response message to the OBU; Step 7, the OBU determines a fifth pairing key symmetric to the RSU based on the RSU identity carried in the received encrypted first key supplement response message, and decrypts the encrypted first key supplement response message based on the fifth pairing key, and supplements the fifth pairing key based on the first supplement key obtained by decryption.

6. The system of claim 1, wherein, When the second pairing key is insufficient, the RSU supplements the second pairing key through the global quantum security service, and specifically includes: Step 1, when determining that the second pairing key is insufficient, the RSU encrypts a generated second key supplement request message based on the second pairing key; wherein the second key supplement request message carries an RSU identity of the RSU; Step 2, the RSU sends the encrypted second key supplement request message to the second access base station; Step 3, the second access base station determines a second pairing key symmetric to the RSU based on the RSU identity carried in the received encrypted second key supplement request message, and decrypts the encrypted second key supplement request message based on the second pairing key; Step 4, the second access base station allocates a key center for the RSU in the global quantum security service; Step 5, the second access base station sends a key distribution request message to the key center; wherein the key distribution request message carries the RSU identity; Step 6, the key center creates a key pool for the RSU based on the RSU identity carried in the received key distribution request message, generates an encryption key and a second supplement key, and allocates a key index; Step 7, the key center returns a key distribution response message to the second access base station; wherein the key distribution response message carries the encryption key, the RSU identity and the key index; Step 8, the second access base station determines the connection with the RSU based on the RSU identity carried in the received key distribution response message; Step 9, the second access base station constructs a second key supplement response message based on the key distribution response message; wherein the second key supplement response message carries the encryption key, the key index and the key center information of the key center; Step 10, the second access base station encrypts the second key supplement response message through the second pairing key; Step 11, the second access base station sends the encrypted second key supplement response message to the RSU through the connection; Step 12, the RSU decrypts the received encrypted second key supplement response message based on the second pairing key to obtain the encryption key, the key index and the key center information; Step 13, the RSU constructs a key download request message; wherein the key download request message carries the key index and the RSU identity; Step 14, the RSU encrypts the key download request message through the encryption key; Step 15, the RSU sends the encrypted key download request message to the key center according to the key center information; Step 16, the key center locates the encryption key symmetric to the RSU based on the RSU identity carried in the received encrypted key download request message, and decrypts the encrypted key download request message based on the encryption key to obtain the key index; Step 17, the key center finds the corresponding key pool according to the key index, and encrypts the generated key download response message based on the encryption key; wherein the key download response message carries a second supplement key in the key pool; Step 18, the key center sends the encrypted key download response message to the RSU; Step 19, the RSU decrypts the received encrypted key download response message based on the encryption key to obtain the second supplement key, and supplements the second pairing key based on the second supplement key.

7. The system of claim 1, wherein, When the symmetric third pairing key between the RSU and any adjacent RSU is insufficient, the RSU initiates a key supplement process to the adjacent RSU, and the process includes: Step 1, when the symmetric third pairing key between the RSU and any adjacent RSU is insufficient, the RSU encrypts a third key supplement request message based on the symmetric third pairing key with the adjacent RSU; wherein the third key supplement request message carries a first RSU identity of the RSU; Step 2, the RSU sends the encrypted third key supplement request message to the adjacent RSU; Step 3, the adjacent RSU determines a third pairing key symmetric to the RSU based on the first RSU identity carried in the received encrypted third key supplement request message, and decrypts the encrypted third key supplement request message based on the third pairing key; Step 4, the adjacent RSU calls a local random number generator to generate a third supplement key; Step 5, the adjacent RSU encrypts a third key supplement response message based on the third pairing key; wherein the third key supplement response message carries the third supplement key and a second RSU identity of the adjacent RSU; Step 6, the RSU sends the encrypted third key supplement response message to the RSU; Step 7, the RSU determines a third pairing key symmetric to the adjacent RSU based on the second RSU identity carried in the received encrypted third key supplement response message, and decrypts the encrypted third key supplement response message based on the third pairing key, and supplements the third pairing key based on the decrypted third supplement key.

Citation Information

Patent Citations

  • Anti-quantum computing distributed Internet of Vehicles method and system based on identity secret sharing

    CN110881177A

  • Vehicle cloud communication method and communication system in multi-cloud environment

    CN117812585A