Multi-level encryption authentication and data integrity protection method in vehicle cloud communication environment

Through multi-level encryption authentication and data integrity protection methods, the problems of insufficient identity authentication, imperfect data encryption and response delay in vehicle-cloud communication are solved, real-time protection and rapid response of data are achieved, and the security and adaptability of the system are improved.

CN120751370APending Publication Date: 2025-10-03SHANDONG JIANZHU UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511056091.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-30
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

The existing vehicle-to-cloud communication system has problems such as insufficient identity authentication, incomplete data encryption, lack of data integrity guarantee and system response delay, which makes the data vulnerable to man-in-the-middle attacks, leakage and tampering, and lacks real-time anomaly detection and response mechanisms.

Method used

It adopts a multi-level encryption and authentication method, including two-way identity authentication, symmetric encryption, digital signature and abnormal response mechanism, combined with digital certificates, AES-256 encryption and RSA signature to achieve confidentiality, integrity and credibility of data transmission, and supports dynamic key update and hierarchical protection.

Benefits of technology

It significantly improves the security and anti-attack capabilities of vehicle-to-cloud communications, ensures real-time protection and rapid response during data transmission, reduces the risk of data leakage and tampering, and adapts to the high concurrency requirements of large-scale Internet of Vehicles environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
Patent Text Reader

Abstract

The invention discloses a multi-level encryption authentication and data integrity protection method in a vehicle cloud communication environment, and aims to guarantee communication security between an electric vehicle and a cloud platform. According to the method, a unique digital certificate is allocated to each electric vehicle, and identity verification of a vehicle end and a cloud platform is realized in combination with a two-way TLS handshake protocol. In the data transmission process, the transmission content is encrypted by adopting a symmetric encryption algorithm, so that the confidentiality of the data is ensured. Meanwhile, the integrity of information in the data transmission process is ensured by using a digital signature technology, and tampering is prevented. And if the data verification fails, an early warning mechanism is triggered, and abnormal information is fed back to a related supervision platform through the V2X communication system, so that instant response and fault positioning are realized. According to the method, potential safety hazards such as man-in-the-middle attack and data leakage in the communication process can be effectively prevented, and the safety and data integrity of an Internet of Vehicles system are improved. The method is widely applied to scenes such as intelligent transportation, motorcade management and electric vehicle remote monitoring.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to vehicle networking and information security technology, and in particular to a method for ensuring the security, authentication and integrity of communication data between an electric vehicle and a cloud platform. Background Art

[0002] With the rapid development of intelligent connected technologies and vehicle-to-everything (V2X), the interaction between vehicle-to-everything (V2X) and cloud platforms has become a core component of modern applications such as electric vehicles (EVs), intelligent transportation, and fleet management. EVs not only require real-time data sharing via V2X-cloud communication, including information such as vehicle status, battery management, and driving trajectory, but also require centralized analysis and processing within the cloud platform to support multiple functions, including remote monitoring, fault diagnosis, and driver behavior optimization. However, large-scale V2X-cloud communication presents a range of security and privacy issues, necessitating innovative technical solutions to enhance the system's resilience to attacks.

[0003] In the existing vehicle-to-cloud communication system, there are the following technical difficulties and challenges.

[0004] Insufficient identity authentication: Many communications between in-vehicle devices and cloud platforms lack effective authentication mechanisms, making them vulnerable to man-in-the-middle attacks, leading to data tampering or forgery.

[0005] Imperfect data encryption: The data encryption algorithm during the communication process is not strong enough or cannot adapt to the high concurrency requirements of large-scale Internet of Vehicles applications, posing a risk of leakage.

[0006] Data integrity cannot be guaranteed: Currently, most systems are unable to effectively verify the integrity of data during transmission, resulting in failure to promptly detect malicious data modifications.

[0007] System response delay: The existing anomaly detection and response mechanism is relatively lagging, failing to promptly process and issue alerts when data leakage or tampering occurs.

[0008] As the scale of the Internet of Vehicles (IoV) continues to expand, security, privacy protection, and reliability have become among its most significant challenges. Especially in areas such as electric vehicles, intelligent transportation, and fleet management, vehicle-to-cloud communications involve the exchange of massive amounts of real-time data and highly sensitive information. Ensuring the confidentiality, integrity, and legitimacy of this data has become a key issue in the design of in-vehicle communication systems. To ensure the long-term stability and growth of IoV systems, the adoption of multi-layered security technologies is urgently needed to enhance their overall safety.

[0009] Therefore, developing a technical solution based on multi-level encryption authentication and data integrity protection can effectively solve the above problems and ensure that all links in the data transmission process are fully protected, which has become an important requirement for improving the security of the vehicle-cloud communication system. Summary of the Invention

[0010] This invention provides a multi-level encryption authentication and data integrity protection method for vehicle-to-cloud communication environments. By combining digital certificates, symmetric encryption, digital signatures, and an exception response mechanism, it aims to effectively safeguard data security between onboard devices and the cloud platform. This method ensures the confidentiality, integrity, and reliability of data during transmission, prevents malicious tampering and data forgery, enhances the system's anti-attack capabilities, and triggers real-time alarms in the event of data leaks or tampering, providing rapid response.

[0011] The technical solution of the present invention mainly includes the following steps: For bidirectional authentication, the present invention assigns a unique digital certificate to each vehicle, and the onboard device and cloud platform perform identity authentication via a two-way TLS handshake. During this process, the onboard device and cloud platform exchange and verify certificates using PKI (public key infrastructure), ensuring the legitimacy of both parties and preventing unauthorized devices from accessing the communication network.

[0012] Regarding data encryption and transmission protection, all data transmitted between in-vehicle devices and the cloud platform is encrypted using a symmetric encryption algorithm. Data encryption uses a 256-bit key to ensure that data cannot be eavesdropped or tampered with by third parties during transmission. Key management adopts high security standards, and keys are regularly updated to enhance encryption strength.

[0013] Regarding digital signatures and data integrity verification, during data transmission, the onboard device uses digital signature technology to sign the data to ensure that the data has not been tampered with during transmission. The digital signature uses the RSA algorithm, and the signature information is transmitted to the cloud platform along with the original data. The cloud platform verifies the validity of the signature using the public key to ensure data integrity and source reliability.

[0014] The anomaly detection and response mechanism, described above, involves the cloud platform performing an integrity check on the data after receiving the encrypted data and verifying the signature. If the data is tampered with or verification fails, the anomaly response mechanism is triggered, sending a prompt alert to the monitoring system and onboard devices. The system also supports event logging, device information feedback, and fault location.

[0015] This solution incorporates a dynamic key update mechanism to ensure the system maintains high security throughout long-term operation. Key management is performed via a secure channel, supporting both periodic and on-demand key updates. Each in-vehicle device receives key update information from the cloud platform, ensuring the long-term effectiveness and security of encrypted transmission.

[0016] This solution employs a hierarchical data security strategy based on the importance and sensitivity of different data types. Specifically, different levels of encryption and authentication are applied to non-sensitive data uploaded by vehicles (such as driving speed and traffic flow) and sensitive data (such as battery management data, driving behavior, and location trajectories).

[0017] To address future security threats, this system supports a security upgrade mechanism. The cloud platform automatically updates encryption algorithms, authentication protocols, key management policies, and more based on the latest network security standards and attack prevention requirements. Furthermore, the system dynamically adjusts encryption strength and authentication processes based on new security incidents or technical vulnerabilities, maintaining a high level of security and adaptability.

[0018] Compared with the prior art, the present invention has the following significant technical advantages and beneficial effects.

[0019] This invention significantly enhances the security of vehicle-to-cloud communications through multi-layered security measures, including bidirectional identity authentication, symmetric encryption, digital signatures, and data integrity verification. Compared to traditional single encryption or authentication mechanisms, this invention employs multiple layers of protection to effectively prevent security threats such as man-in-the-middle attacks (MITM), data tampering, and data leakage, ensuring that every data packet between the vehicle device and the cloud platform is fully protected.

[0020] This invention incorporates a real-time anomaly detection mechanism on the cloud platform, enabling timely identification and response to anomalies during data transmission. Upon detecting data tampering or verification failure, the system immediately triggers an alarm and transmits fault information to the relevant platform via the V2X communication system. This feature, often lacking in traditional vehicle-to-cloud communication systems, effectively reduces security risks caused by data leakage or tampering and enhances the system's anti-attack capabilities.

[0021] This invention supports a dynamic key update mechanism, ensuring that encrypted communications maintain high security over the long term. Traditional key management systems can pose risks of long-term key use. By regularly updating keys and key exchange protocols, this invention effectively prevents key leakage or cracking, improving the long-term security and adaptability of vehicle-to-cloud communication systems.

[0022] This invention proposes a tiered protection scheme based on data sensitivity, employing different encryption and authentication methods for different types of data. Sensitive data (such as battery management and location tracking) utilizes high-strength protection such as AES-256 encryption and RSA digital signatures, while non-sensitive data can utilize more lightweight encryption strategies. This flexible security strategy maximizes the protection of sensitive data while ensuring system performance.

[0023] This multi-layered security mechanism is suitable for communication between in-vehicle devices of varying sizes and types and the cloud platform, offering excellent scalability. Whether it's in-vehicle devices, electric vehicles, or even, in the future, even broader intelligent transportation systems and fleet management platforms, the technical solution of this invention can be effectively integrated and provide efficient security protection to meet the needs of a wide range of application scenarios.

[0024] This invention uses the two-way TLS protocol for identity authentication, combined with AES-256 encryption and RSA digital signatures, which not only ensures the confidentiality and integrity of the data, but also optimizes the performance of the encryption algorithm while ensuring high security. It adapts to the needs of high-concurrency data transmission in large-scale vehicle-cloud communication environments, and provides a more efficient and secure solution compared to traditional encryption methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to clearly illustrate the technical solutions in the embodiments of the present invention, the drawings required in the description of the embodiments will be introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0026] Figure 1 This is a flow chart of the multi-level encryption authentication and data integrity protection method in the vehicle-to-cloud communication environment of the present invention. Specific implementation plan

[0027] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments are not intended to limit the present invention.

[0028] The present invention will be described in further detail below with reference to the accompanying drawings.

[0029] like Figure 1 As shown in the figure, upon startup, the in-vehicle device first authenticates with the cloud platform using the mutual TLS protocol. Certificates are exchanged and verified between the in-vehicle device and the cloud platform to ensure the legitimacy of both identities. During this process, the in-vehicle device uses a digital certificate issued by a trusted certificate authority (CA). The cloud platform also uses the digital certificate to verify the identity of the in-vehicle device, preventing unauthorized devices from accessing the communication network.

[0030] After successful identity authentication, the onboard device begins transmitting vehicle operating data (such as battery SOC, fault diagnosis information, and location trajectory) to the cloud platform via an encrypted channel. Data encryption utilizes the AES-256 symmetric encryption algorithm, as shown in the encryption module in the attached figure. After encryption, the onboard device transmits the ciphertext data to the cloud platform via a secure channel. This process ensures that data cannot be eavesdropped or tampered with during transmission, ensuring confidentiality.

[0031] The AES-256 symmetric encryption algorithm, AES is a block encryption algorithm. A 256-bit key corresponds to 14 encryption rounds. The core process includes four steps: round key addition, byte replacement, row shift, and column mixing. The core formula and principle are as follows.

[0032] (1) Round key addition: XOR the state matrix with the round key (generated by expanding the 256-bit master key) byte by byte.

[0033]

[0034] in, is the matrix row and column index, The round keys are generated from the master key through the key expansion algorithm, and a total of 15 round keys are generated from the 256-bit key.

[0035] (2) Byte replacement: Perform nonlinear replacement on each byte in the state matrix through S-box (8×8 byte replacement table).

[0036]

[0037] The S-box is the core nonlinear component of AES and is implemented through inverse affine transformation and finite field inversion.

[0038] (3) Row shift: Circularly shift the rows of the state matrix (row 0 remains unchanged, row 1 is shifted left by 1 bit, row 2 is shifted left by 2 bits, and row 3 is shifted left by 3 bits).

[0039]

[0040]

[0041]

[0042] (4) Column mixing: Through matrix multiplication in the finite field GF(2 8 ) to mix the columns (not executed in the last round): Let a column of the state matrix be , after mixing ,but.

[0043]

[0044]

[0045]

[0046]

[0047] Among them, 01, 01, 03 are GF(2 8 ), · is the finite field multiplication, and ⊕ is the exclusive OR.

[0048] When data is transmitted between the vehicle device and the vehicle terminal, the vehicle terminal also digitally signs the data using the private key of the RSA algorithm to generate signature data. As shown in the signature generation module in the attached figure, the vehicle device transmits the data and signature to the cloud platform. The cloud platform verifies the signature using the vehicle device's public key to ensure data integrity. If the data is tampered with or corrupted during transmission, the cloud platform detects the signature verification failure and immediately triggers the exception response mechanism.

[0049] The RSA algorithm key generation: select two large prime numbers.

[0050] Calculation module:

[0051] Compute Euler's function:

[0052] Choose a public key exponent e (satisfying ).

[0053] Calculate the private key exponent d (satisfying ,Right now yes In the model The inverse element below.

[0054] Public Key: ; Private key: .

[0055] Calculate the hash value for the original data M (such as vehicle status data).

[0056]

[0057] Using a private key Sign the hash value.

[0058]

[0059] The signature result Signature is transmitted to the cloud platform together with the original data M.

[0060] After the cloud platform receives the encrypted data and successfully decrypts it, it performs a data integrity check. Receive M and Signature and calculate.

[0061] (Recalculate the hash value).

[0062] Using the public key Decrypt the signature.

[0063]

[0064] like , the signature is valid (the data has not been tampered with and the source is legitimate); otherwise, the verification fails (triggering an abnormality alarm).

[0065] As shown in the data verification module in the attached figure, the cloud platform verifies the digital signature using the public key to confirm whether the data has been tampered with. If signature verification fails or the data fails integrity verification, the cloud platform immediately issues an abnormality alert and transmits the alarm information in real time to the relevant monitoring platform and vehicle terminal via the V2X communication system, ensuring a rapid response. This feature prevents malicious data tampering from going undetected.

[0066] When abnormal data or security incidents are detected, the cloud platform pushes real-time information via V2X communication between the vehicle's onboard equipment and the monitoring platform. The abnormal response module in the accompanying figure shows that when data leaks or tampering occur, the system automatically triggers a feedback mechanism, sending detailed fault information, data timestamps, and anomaly descriptions to the monitoring center and vehicle maintenance personnel. This mechanism ensures immediate response to abnormal events during data transmission, reducing the risks posed by security incidents.

[0067] This invention provides a dynamic key update mechanism to ensure the long-term security of the encryption and authentication processes. The encryption keys between the cloud platform and the vehicle device are regularly updated, and each update is transmitted over a secure channel. Upon receiving the new key, the vehicle device immediately updates its locally stored key, ensuring key security throughout its lifecycle.

[0068] As the system operates, this invention also supports security upgrades. The cloud platform will be regularly updated based on the latest cybersecurity standards and known vulnerabilities, enhancing the system's attack resistance. Vehicle-mounted devices can receive updated encryption algorithms or authentication mechanisms via over-the-air (OTA) downloads, maintaining high system security.

Claims

1. A multi-level encryption authentication and data integrity protection method in a vehicle-cloud communication environment, characterized in that: The following steps are involved: (1) Assign a unique digital certificate to each electric vehicle and perform two-way identity authentication with the cloud platform; (2) Encrypt the data transmission content and use a symmetric encryption algorithm to encrypt the data to ensure confidentiality during the data transmission process; (3) Use digital signature technology to sign the transmitted data to ensure the integrity of the data during transmission; (4) Verify the data signature and decrypt the data on the cloud platform to check the integrity of the data. If the data verification fails, an abnormal alarm is triggered; (5) Feedback abnormal information to relevant regulatory platforms through the V2X communication system to achieve immediate response and fault location.

2. The method according to claim 1, characterized in that The digital certificate is managed using public key infrastructure (PKI) technology and authenticated by a certificate authority (CA).

3. The method according to claim 1, characterized in that The symmetric encryption algorithm is the Advanced Encryption Standard (AES) algorithm, and the key length is 256 bits.

4. The method according to claim 1, wherein The identity authentication process uses a secure handshake process based on the mutual TLS (Transport Layer Security) protocol to ensure two-way authentication between the vehicle terminal and the cloud platform.

5. The method according to claim 1, wherein The digital signature technology adopts the RSA (Rivest–Shamir–Adleman) algorithm, and a public-private key pair is used in the signing process.

6. The method according to claim 1, characterized in that The V2X communication system uses LTE-V, 5G or C-V2X standards to perform data transmission and real-time communication between the vehicle terminal and the cloud platform.

7. The method according to claim 1, characterized in that The abnormal alarm includes abnormal data tags, transmission time, vehicle-mounted equipment information and early warning processing suggestions, and is pushed to relevant equipment and monitoring platforms.

8. The method according to claim 1, characterized in that The data transmission includes various types of data such as vehicle real-time status data, fault diagnosis information, battery management information, driving trajectory, etc.

9. The method according to claim 1, characterized in that The method supports two-way encrypted communication between the vehicle terminal and the cloud platform, ensuring the confidentiality and integrity of each data packet during the communication process.

10. The method according to claim 1, characterized in that The method has online learning and adaptation functions, and dynamically adjusts encryption and authentication strategies based on new communication data and feedback information to improve system security.

Citation Information

Cited By

  • Distributed secure communication protocol data synchronization method and system

    CN121567454A