Remote control method, device, equipment, vehicle, storage medium and program product
By introducing a business certificate synchronization and signing mechanism in vehicles and mobile devices, the problem of private key leakage is solved, and the security of remote command transmission and vehicle operation is enhanced.
Patent Information
- Application Number
- CN202511180836.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-11-11
AI Technical Summary
In existing technologies, the private key for remote vehicle control is easily leaked or stolen, leading to inadequate protection of remote command transmission and affecting the security of remote control.
By introducing a business certificate synchronization and signing mechanism in mobile devices and vehicles, the secure transmission of remote commands between the business cloud platform and the business execution unit is ensured. Business certificates are used for signing and verification, decoupling third-party businesses from existing businesses and improving information security.
It improves the information security of remote command transmission, ensures the security of remote vehicle operation, prevents the risk of private key leakage or theft, and enhances end-to-end business security.
Smart Images

Figure CN120934771A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of vehicle technology, and more specifically to a remote control method, device, equipment, vehicle, storage medium, and program product. Background Technology
[0002] With the development of intelligent connected vehicles, their remote service scenarios have evolved from relatively simple functions such as "opening and closing doors" and "status inquiry" to more complex scenarios such as "parking assistance" and "memory parking," providing users with a more intelligent and convenient experience. Nowadays, complex remote services typically involve the vehicle, mobile devices, and mobile cloud platforms, increasing information security risks during remote command transmission.
[0003] In existing technologies, by introducing digest algorithms and encryption algorithms, identity authentication between mobile cloud platforms, mobile terminals and vehicle terminals, as well as encrypted transmission protection of remote commands are achieved to control vehicles.
[0004] In another approach, based on the preset security level and encryption algorithm of each remote command, a random number and the private key of the Electronic Control Unit (ECU) in the vehicle are generated to encrypt and decrypt the remote commands transmitted in the multi-terminal control scenario in order to control the vehicle.
[0005] However, both of these methods require the vehicle to hold a private key. During storage and use, the private key is easily leaked or stolen, which can lead to inadequate protection of remote command transmission and affect the security of remotely controlled vehicles. Summary of the Invention
[0006] One objective of this invention is to provide a remote control method that can improve the information security of remote command transmission and ensure the safety of remote vehicle control; another objective is to provide a remote control method; a third objective is to provide a remote control device; a fourth objective is to provide a remote control device; a fifth objective is to provide a business execution unit; a sixth objective is to provide a mobile terminal; a seventh objective is to provide a vehicle; an eighth objective is to provide a computer-readable storage medium; and a ninth objective is to provide a computer program product.
[0007] To achieve the above objectives, the technical solution adopted by the present invention is as follows:
[0008] A remote control method is applied to a business execution unit in a vehicle. The method includes: receiving a business certificate sent by a mobile terminal and generating a first synchronization result of the business certificate; wherein the business certificate is obtained from a mobile terminal cloud platform based on the user's remote business login account after a user inputs a remote business login operation; the first synchronization result indicates successful synchronization of the business certificate; sending the first synchronization result to the mobile terminal; wherein the first synchronization result is used to sign a remote instruction; the remote instruction is generated based on a user input remote business function operation; receiving the signed remote instruction sent by the mobile terminal through a business component via a business cloud platform; and verifying the signed remote instruction to obtain a first verification result of the signed remote instruction; if the first verification result indicates successful verification of the signed remote instruction, then executing the vehicle operation corresponding to the signed remote instruction.
[0009] Further, receiving the service certificate sent by the mobile terminal and generating the first synchronization result of the service certificate includes: receiving the service certificate sent by the mobile terminal through the vehicle terminal; performing verification processing on the service certificate to obtain a second verification result of the service certificate; if it is determined that the second verification result indicates that the service certificate verification is successful, then saving the service certificate and generating the first synchronization result of the service certificate.
[0010] Further, the step of verifying the business certificate to obtain a second verification result of the business certificate includes: verifying the business certificate according to a pre-stored root certificate to obtain a second verification result of the business certificate.
[0011] Furthermore, the method further includes: if it is determined that the second verification result indicates that the business certificate verification has failed, then generating a first verification log of the business certificate and generating a second synchronization result of the business certificate; wherein the second synchronization result includes business certificate synchronization failure; sending the second synchronization result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the second synchronization result to the mobile terminal; the second synchronization result is used to re-execute the business certificate synchronization process.
[0012] Further, the mobile terminal is used to sign the remote instruction according to the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; the verification processing of the signed remote instruction to obtain the first verification result of the signed remote instruction includes: verifying the signed remote instruction according to the public key in the public-private key pair of the business certificate to obtain the first verification result.
[0013] Furthermore, the method further includes: if it is determined that the first verification result indicates that the verification of the signed remote instruction has failed, then generating a second verification log corresponding to the signed remote instruction; and generating an execution failure result corresponding to the signed remote instruction; and sending the execution failure result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the execution failure result to the mobile terminal; and the execution failure result is used for functional anomaly handling.
[0014] Furthermore, the method further includes: if it is determined that the business certificate has expired, generating a business certificate synchronization request; sending the business certificate synchronization request to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the business certificate synchronization request to the mobile terminal; the business certificate synchronization request is used to re-execute the business certificate synchronization process.
[0015] A remote control method is applied to a business execution unit in a vehicle. The method includes: responding to a user-inputted remote business login operation, obtaining a business certificate corresponding to the remote business login operation from a mobile cloud platform based on the user's remote business login account; sending the business certificate to the vehicle's business execution unit; wherein the business certificate is used to generate a first synchronization result of the business certificate; the first synchronization result indicates that the business certificate has been successfully synchronized; receiving the first synchronization result sent by the business execution unit; responding to a user-inputted remote business function operation, generating a remote instruction; and signing the remote instruction according to the business certificate to obtain a signed remote instruction; and sending the signed remote instruction to the business execution unit through a business cloud platform based on a business component; wherein the signed remote instruction is used to obtain a first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when it indicates that the signed remote instruction has been successfully verified.
[0016] Furthermore, the step of generating a remote instruction in response to a user-input remote business function operation includes: based on the business component, saving the first synchronization result of the business certificate; and displaying the business interface; based on the business component, generating a remote instruction corresponding to the remote business function operation in response to a user's remote business function operation on the business interface.
[0017] Furthermore, the method further includes: receiving a second synchronization result of the business certificate sent by the business execution unit through the business cloud platform; wherein the second synchronization result is generated based on the second verification result of the business certificate indicating that the business certificate verification failed; the second synchronization result indicates that the business certificate synchronization failed; determining the cumulative number of synchronization failures of the user based on the business component; if it is determined that the cumulative number of synchronization failures of the user is greater than or equal to a preset number, then stopping the user from continuing to request synchronization of the business certificate; and updating the synchronization information of the business certificate.
[0018] Furthermore, the method also includes: if it is determined that the user's cumulative number of verification failures is less than the preset number, then the business certificate is sent to the business execution unit through the business cloud platform.
[0019] Further, the step of responding to a user's input remote business login operation by obtaining the business certificate corresponding to the remote business login operation from the mobile cloud platform based on the user's remote business login account includes: responding to the user's input remote business login operation by determining the user's remote business permissions based on the user's remote business login account; generating a certificate signing request based on the user's remote business permissions; sending the certificate signing request to the mobile cloud platform; wherein the certificate signing request includes a public-private key pair and vehicle identification information; the certificate signing request is used to request the acquisition of a business certificate; receiving the business certificate sent by the mobile cloud platform; and performing verification processing on the business certificate based on a pre-stored root certificate to obtain a third verification result of the business certificate; if the third verification result indicates that the business certificate verification is successful, then the business certificate is saved.
[0020] Furthermore, generating a certificate signing request based on the user's remote business permissions includes: determining the user's business certificate storage information based on the user's remote business permissions; if the user's business certificate storage information indicates that the user has not stored a business certificate or that the business certificate stored by the user has expired, then generating the certificate signing request.
[0021] Furthermore, the method also includes: if it is determined that the third verification result of the business certificate indicates that the business certificate verification has failed, then a verification failure log of the business certificate is generated, and the cumulative number of verification failures of the user is determined; if it is determined that the cumulative number of verification failures of the user is less than a preset number, then a certificate signing request is regenerated.
[0022] Furthermore, the method also includes: if it is determined that the user's cumulative number of verification failures is greater than or equal to the preset number, then the user is stopped from continuing to request to obtain a business certificate; in response to the user's remote business entry operation on the vehicle control interface, a function exception handling method is executed.
[0023] Further, sending the business certificate to the vehicle's business execution unit includes: based on the business component, in response to a user's remote business entry operation on the vehicle control interface, determining the synchronization information of the business certificate corresponding to the remote business entry operation; if the synchronization information of the business certificate indicates that the business certificate is not synchronized, then sending the business certificate to the business cloud platform; wherein, the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal; the business certificate is used for synchronization processing.
[0024] Further, the step of signing the remote instruction according to the business certificate to obtain the signed remote instruction includes: signing the remote instruction according to the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; wherein, the business execution unit is used to verify the signed remote instruction according to the public key in the public-private key pair corresponding to the business certificate.
[0025] Furthermore, the method further includes: receiving a business certificate synchronization request sent by the business execution unit through the business cloud platform; wherein the business certificate synchronization request is generated based on the expiration of the business certificate; obtaining the business certificate based on the business component; and sending the business certificate to the business cloud platform; wherein the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal for business certificate synchronization processing.
[0026] Furthermore, the method also includes: receiving an execution failure result sent by the business execution unit through the business cloud platform; wherein the execution failure result is generated when the verification of the signed remote instruction fails based on the first verification result of the signed remote instruction; and executing an abnormal function handling method according to the execution failure result.
[0027] A remote control device is applied to a business execution unit in a vehicle. The device includes: a receiving module for receiving a business certificate sent by a mobile terminal and generating a first synchronization result of the business certificate; wherein the business certificate is obtained from a mobile cloud platform based on the user's remote business login account after the user inputs a remote business login operation; the first synchronization result indicates that the business certificate is successfully synchronized; a sending module for sending the first synchronization result to the mobile terminal; wherein the first synchronization result is used to sign a remote instruction; the remote instruction is generated based on a remote business function operation input by the user; a verification module for receiving the signed remote instruction sent by the mobile terminal through a business component via a business cloud platform; and verifying the signed remote instruction to obtain a first verification result of the signed remote instruction; and an execution module for executing the vehicle operation corresponding to the signed remote instruction if it is determined that the first verification result indicates that the signed remote instruction has been successfully verified.
[0028] Furthermore, the receiving module is specifically configured to: receive the service certificate sent by the mobile terminal through the vehicle terminal; perform verification processing on the service certificate to obtain a second verification result of the service certificate; if it is determined that the second verification result indicates that the service certificate verification is successful, then save the service certificate and generate a first synchronization result of the service certificate.
[0029] Furthermore, the receiving module is specifically used to: perform verification processing on the business certificate based on the pre-stored root certificate to obtain a second verification result of the business certificate.
[0030] Furthermore, the receiving module is specifically configured to: if it is determined that the second verification result indicates that the business certificate verification has failed, generate a first verification log of the business certificate and generate a second synchronization result of the business certificate; wherein the second synchronization result includes business certificate synchronization failure; send the second synchronization result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the second synchronization result to the mobile terminal; the second synchronization result is used to re-execute the business certificate synchronization process.
[0031] Furthermore, the mobile terminal is used to sign the remote instruction based on the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; the verification module is specifically used to: perform verification processing on the signed remote instruction based on the public key in the public-private key pair of the business certificate to obtain the first verification result.
[0032] Furthermore, the device is also configured to: if it is determined that the first verification result indicates that the verification of the signed remote instruction has failed, generate a second verification log corresponding to the signed remote instruction; and generate an execution failure result corresponding to the signed remote instruction; and send the execution failure result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is configured to send the execution failure result to the mobile terminal; and the execution failure result is used for functional anomaly handling.
[0033] Furthermore, the device is also configured to: generate a business certificate synchronization request if it is determined that the business certificate has expired; send the business certificate synchronization request to the business cloud platform through the vehicle terminal; wherein the business cloud platform is configured to send the business certificate synchronization request to the mobile terminal; the business certificate synchronization request is used to re-execute the business certificate synchronization process.
[0034] A remote control device applied to a mobile terminal; the device includes: a generation module, configured to, in response to a user-inputted remote service login operation, obtain a service certificate corresponding to the remote service login operation from a mobile terminal cloud platform based on the user's remote service login account; a first sending module, configured to send the service certificate to a vehicle's service execution unit; wherein the service certificate is used to generate a first synchronization result of the service certificate; the first synchronization result indicates successful synchronization of the service certificate; a receiving module, configured to receive the first synchronization result sent by the service execution unit; a signing module, configured to, in response to a user-inputted remote service function operation, generate a remote instruction; and sign the remote instruction according to the service certificate to obtain a signed remote instruction; a second sending module, configured to, based on a service component, send the signed remote instruction to the service execution unit via a service cloud platform; wherein the signed remote instruction is used to obtain a first verification result of the signed remote instruction; the first verification result is used to execute the remote service function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
[0035] Furthermore, the signature module is specifically used for: based on the business component, saving the first synchronization result of the business certificate; and displaying the business interface; based on the business component, in response to a user's remote business function operation on the business interface, generating a remote instruction corresponding to the remote business function operation.
[0036] Further, the signature module is specifically configured to: receive a second synchronization result of the business certificate sent by the business execution unit through the business cloud platform; wherein the second synchronization result is generated based on the second verification result of the business certificate indicating that the business certificate verification failed; the second synchronization result indicates that the business certificate synchronization failed; determine the cumulative number of synchronization failures of the user based on the business component; if it is determined that the cumulative number of synchronization failures of the user is greater than or equal to a preset number, then stop the user from continuing to request synchronization of the business certificate; and update the synchronization information of the business certificate.
[0037] Furthermore, the signature module is specifically used to: if it is determined that the user's cumulative number of verification failures is less than the preset number, then send the business certificate to the business execution unit through the business cloud platform.
[0038] Further, the generation module is specifically configured to: respond to a user's input of a remote business login operation, determine the user's remote business permissions based on the user's remote business login account; generate a certificate signing request based on the user's remote business permissions; send the certificate signing request to the mobile cloud platform; wherein the certificate signing request includes a public-private key pair and vehicle identification information; the certificate signing request is used to request a business certificate; receive the business certificate sent by the mobile cloud platform; and perform verification processing on the business certificate based on a pre-stored root certificate to obtain a third verification result of the business certificate; if the third verification result indicates that the business certificate verification is successful, then save the business certificate.
[0039] Furthermore, the generation module is specifically used to: determine the user's business certificate storage information based on the user's remote business permissions; if the user's business certificate storage information indicates that the user has not stored a business certificate or the business certificate stored by the user has expired, then generate the certificate signing request.
[0040] Furthermore, the generation module is specifically configured to: if it is determined that the third verification result of the business certificate indicates that the business certificate verification has failed, generate a verification failure log of the business certificate and determine the cumulative number of verification failures of the user; if it is determined that the cumulative number of verification failures of the user is less than a preset number, regenerate the certificate signing request.
[0041] Furthermore, the generation module is also specifically used to: if it is determined that the user's cumulative number of verification failures is greater than or equal to the preset number, then stop the user from continuing to request to obtain a business certificate; and in response to the user's remote business entry operation on the vehicle control interface, execute a function exception handling method.
[0042] Further, the first sending module is specifically used for: based on the business component, in response to a user's remote business entry operation on the vehicle control interface, determining the synchronization information of the business certificate corresponding to the remote business entry operation; if it is determined that the synchronization information of the business certificate indicates that the business certificate is not synchronized, then sending the business certificate to the business cloud platform; wherein, the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal; the business certificate is used for synchronization processing.
[0043] Furthermore, the signature module is specifically used to: sign the remote instruction based on the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; wherein, the business execution unit is used to verify the signed remote instruction based on the public key in the public-private key pair corresponding to the business certificate.
[0044] Furthermore, the device is also configured to: receive a business certificate synchronization request sent by the business execution unit through the business cloud platform; wherein the business certificate synchronization request is generated based on the expiration of the business certificate; obtain the business certificate based on the business component; and send the business certificate to the business cloud platform; wherein the business cloud platform is configured to send the business certificate to the business execution unit through the vehicle terminal for business certificate synchronization processing.
[0045] Furthermore, the device is also used to: receive an execution failure result sent by the business execution unit through the business cloud platform; wherein the execution failure result is generated when the verification of the signed remote instruction fails based on the first verification result of the signed remote instruction; and execute an abnormal function handling method according to the execution failure result.
[0046] A business execution unit includes: a memory and a processor; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.
[0047] A mobile device includes: a memory and a processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory, causing the processor to perform the second aspect and / or various possible implementations of the second aspect as described above.
[0048] A vehicle includes a service execution unit for performing the first aspect and / or various possible implementations of the first aspect.
[0049] A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the methods of the first and / or second aspects described above.
[0050] A computer program product includes a computer program that, when executed by a processor, implements the methods of the first and / or second aspects described above.
[0051] The beneficial effects of this invention are as follows: After a user inputs a remote service login operation on a mobile device, the mobile cloud platform issues a service certificate to the mobile device and synchronizes it to the service execution unit in the vehicle. This allows the service execution unit to send a first synchronization result indicating successful synchronization of the service certificate to the mobile device. After the user inputs a remote service function operation, the mobile device signs the remote instruction obtained based on the user's remote service login account and sends the signed remote instruction to the service execution unit through the service components and the service cloud platform in sequence. The service execution unit can only execute the corresponding vehicle operation after verifying the signed remote instruction. Thus, the remote services of the mobile cloud platform and the mobile device are decoupled from the original services, and the service certificate is used to ensure the information security of remote instruction transmission, thereby improving the security of remote vehicle operation. Attached Figure Description
[0052] Figure 1 This is an application scenario diagram provided by an embodiment of the present invention;
[0053] Figure 2 Flowchart of a remote control method provided in an embodiment of the present invention Figure 1 ;
[0054] Figure 3 Flowchart of a remote control method provided in an embodiment of the present invention Figure 2 ;
[0055] Figure 4 Flowchart of a remote control method provided in an embodiment of the present invention Figure 3 ;
[0056] Figure 5 This is an architecture diagram of a remote command transmission method provided in an embodiment of the present invention;
[0057] Figure 6 A schematic diagram of a remote business certificate synchronization process provided in an embodiment of the present invention. Figure 1 ;
[0058] Figure 7 A schematic diagram of a remote business certificate synchronization process provided in an embodiment of the present invention. Figure 2 ;
[0059] Figure 8This is a schematic diagram of a remote service instruction transmission process provided in an embodiment of the present invention;
[0060] Figure 9 A schematic diagram of the structure of a remote control device provided in an embodiment of the present invention. Figure 1 ;
[0061] Figure 10 A schematic diagram of the structure of a remote control device provided in an embodiment of the present invention. Figure 2 ;
[0062] Figure 11 This is a schematic diagram of the structure of a business execution unit provided in an embodiment of the present invention;
[0063] Figure 12 This is a schematic diagram of the structure of a mobile terminal provided in an embodiment of the present invention. Detailed Implementation
[0064] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.
[0065] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this invention are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.
[0066] Figure 1 This is an application scenario diagram provided by an embodiment of the present invention, such as... Figure 1As shown, remote services in multi-terminal vehicle control scenarios typically involve the vehicle, mobile, and mobile cloud platforms. Specifically, when executing third-party remote services, the process is completed by third-party business components deployed on the mobile device, the third-party business cloud platform, the Original Equipment Manufacturer (OEM) cloud platform, and the third-party business execution unit on the vehicle. Due to emerging security issues, the third-party business components and cloud platform on the mobile device do not conduct two-way identity authentication and business information exchange with the OEM cloud platform. Furthermore, the OEM cloud platform cannot participate in the transmission and execution of third-party services. The end-to-end business security between the mobile device and the vehicle cannot be guaranteed at the vehicle level, increasing the information security risks during remote command transmission. Traditional remote service solutions are no longer applicable to remote service scenarios involving third-party roles.
[0067] In view of this, embodiments of the present invention propose a remote control method that can improve the information security of remote command transmission, improve end-to-end business security, and ensure the safety of remote vehicle operation in multi-terminal control scenarios.
[0068] The technical solution of the present invention will now be described in detail through specific embodiments. It should be noted that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments.
[0069] Figure 2 Flowchart of a remote control method provided in an embodiment of the present invention Figure 1 ,like Figure 2 As shown, the method includes:
[0070] 201. The business execution unit receives the business certificate sent by the mobile terminal and generates the first synchronization result of the business certificate; wherein, the business certificate is obtained from the mobile terminal cloud platform based on the user's remote business login account after the user inputs the remote business login operation; the first synchronization result indicates that the business certificate is successfully synchronized.
[0071] For example, in a scenario of multi-terminal remote vehicle control, this embodiment may include a business execution unit in the vehicle, a mobile terminal, and a mobile cloud platform such as an Original Equipment Manufacturer (OEM) cloud platform. In this case, the mobile terminal is an OEM mobile terminal, which integrates business components. The execution entity in this embodiment can be the business execution unit in the vehicle. The user can input a remote business login operation into the mobile terminal's display interface. After responding to the remote business login operation, the mobile terminal can obtain the remote business login account corresponding to the remote business login operation from the mobile cloud platform and obtain the business certificate corresponding to the remote business login account. This business certificate is a digital certificate used to ensure data transmission security and authentication; only entities holding valid business certificates can access protected resources. The business component applies for a business certificate from the mobile terminal and sends the business certificate to the business execution unit through the business cloud platform. The business execution unit receives the business certificate and automatically generates a first synchronization result for the business certificate, indicating successful synchronization, and the user can then perform remote vehicle control processing. The business certificate is applied for and managed by the mobile application (App or APP), and is bound to the user's remote business login account. It is unique to ensure the secure transmission of the business certificate.
[0072] 202. The business execution unit sends the first synchronization result to the mobile terminal; wherein, the first synchronization result is used to sign the remote instruction; the remote instruction is generated based on the remote business function operation input by the user.
[0073] For example, the business execution unit sends the generated first synchronization result to the mobile terminal. After receiving the first synchronization result, the mobile terminal stores it in the third-party business component deployed on the mobile terminal. Once the business certificate synchronization is complete, the mobile terminal can display the remote business function page, allowing the user to input remote business function operations, such as clicking a function button corresponding to a specific remote business function on the page. The mobile terminal then determines whether to enter the remote business operation interface. If the mobile terminal determines to have entered the remote business operation interface, the mobile terminal business component responds to the user's input remote business function operation by generating a remote instruction corresponding to that operation. The mobile terminal then signs the generated remote instruction. Specifically, it uses a hash function (such as SHA-256) to perform a hash operation on the instruction, generating a fixed-length hash value as a digital signature. This digital signature and the remote instruction are packaged together to generate a signed remote instruction, which is returned to the business component. The business component then sends the signed remote instruction to the business execution unit via the business cloud platform.
[0074] 203. The business execution unit receives the signed remote instruction sent by the mobile terminal through the business component via the business cloud platform; and performs verification processing on the signed remote instruction to obtain the first verification result of the signed remote instruction.
[0075] For example, the mobile terminal sends the signed remote instruction to the business component, which then transmits it to the business cloud platform. The business cloud platform then transmits the signed remote instruction to the business execution unit. The business execution unit receives the signed remote instruction from the mobile terminal and verifies it using a preset verification method. Specifically, the signed remote instruction includes a digital signature (e.g., a hash value) and the remote instruction itself. The digital signature is compared with a preset digital signature corresponding to the remote business function operation stored locally. If the digital signature matches the preset digital signature, the signed remote instruction passes verification; otherwise, it fails verification, resulting in the first verification result. This ensures end-to-end business protection in remote business scenarios involving third-party services, where the signed remote instruction is transmitted through the links between the business component, business cloud platform, and business execution unit, and verified by the business execution unit.
[0076] 204. If the business execution unit determines that the first verification result indicates that the remote instruction after signing has been successfully verified, it shall execute the vehicle operation corresponding to the remote instruction after signing.
[0077] For example, if the business execution unit determines that the remote instruction after signing has been successfully verified, it determines that the remote instruction comes from the mobile terminal or has been allowed to be executed by the mobile terminal. Then, it can convert the remote instruction into a vehicle control instruction inside the vehicle and send the vehicle control instruction to the corresponding actuator in the vehicle, so that the actuator can perform the corresponding vehicle operation, thereby securely realizing the remote business function of the vehicle in the multi-terminal vehicle control scenario.
[0078] This embodiment provides a remote control method. In a remote service scenario implemented with the participation of a third party, after the user enters a remote service login operation on a mobile terminal, the mobile cloud platform issues a service certificate to the mobile terminal based on the user's remote service login account. This certificate is then synchronized to the service execution unit in the vehicle via the service component and the service cloud platform link. The service execution unit then sends the first synchronization result of the service certificate to the service component in the mobile terminal. The mobile terminal signs the remote command generated by the service component. The signed remote command is transmitted through the link between the service component, the service cloud platform, and the service execution unit. Furthermore, by decoupling the remote service implemented with the participation of a third party from the original remote service (implemented by the OEM), and using a service certificate to ensure the information security of the remote command transmission, when the link between the third-party service component, the service cloud platform, and the service execution unit fails or one of the units is compromised, attackers cannot obtain the private key to use the remote service for abnormal vehicle control, nor will it affect the execution of other services, thereby improving the security of remote vehicle operation.
[0079] Figure 3 Flowchart of a remote control method provided in an embodiment of the present invention Figure 2 ,like Figure 3 As shown, this method is applied to mobile devices; the method includes:
[0080] 301. In response to the user's input of a remote business login operation, the mobile terminal obtains the business certificate corresponding to the remote business login operation from the mobile cloud platform based on the user's remote business login account.
[0081] For example, the scope of remote services (i.e., remote vehicle control services) is first defined. These services involve users controlling the vehicle on the OEM's mobile terminal. The actual command transmission and function implementation are handled by third-party business components integrated into the mobile terminal and the business execution unit on the vehicle side. The mobile terminal's business components display a vehicle control interface to the user. Based on this interface, the user can input remote service login operations (such as entering a user account and clicking the login button). Upon responding to this login operation, the mobile terminal retrieves the business certificate corresponding to the user's remote service login account from the mobile cloud platform. Specifically, upon responding to the login operation, the mobile terminal generates an operation signal corresponding to the remote service login account and sends it to the mobile cloud platform. The mobile cloud platform then retrieves the corresponding business certificate from a preset certificate store and sends it to the mobile terminal.
[0082] 302. The mobile terminal sends the business certificate to the vehicle's business execution unit; wherein, the business certificate is used to generate the first synchronization result of the business certificate; the first synchronization result indicates that the business certificate synchronization is successful.
[0083] For example, the business component sends the business certificate it applied for from the mobile terminal to the business execution unit of the vehicle, so that after receiving the business certificate, the business execution unit completes the business certificate synchronization process and generates the first synchronization result of the business certificate to indicate that the business certificate synchronization is successful.
[0084] 303. The business execution unit receives the business certificate sent by the mobile terminal and generates the first synchronization result of the business certificate; wherein, the business certificate is obtained from the mobile terminal cloud platform based on the remote business login operation input by the user; the first synchronization result indicates that the business certificate is successfully synchronized.
[0085] For example, this step can be referred to as step 201, which will not be repeated here.
[0086] 304. The business execution unit sends the first synchronization result to the mobile terminal; wherein, the first synchronization result is used to sign the remote instruction; the remote instruction is generated based on the remote business function operation input by the user.
[0087] For example, this step can be referred to as step 202, which will not be repeated here.
[0088] 305. The mobile terminal receives the first synchronization result sent by the business execution unit.
[0089] For example, the mobile device receives a first synchronization result sent by the business execution unit and sends the first synchronization result to the business component inside the mobile device. The business component receives and stores the first synchronization result.
[0090] 306. The mobile terminal responds to the remote business function operation input by the user and generates a remote instruction; based on the business certificate, the remote instruction is signed to obtain the signed remote instruction.
[0091] For example, after the mobile terminal's business component receives the first synchronization result indicating successful synchronization of the business certificate, it controls the mobile terminal's display interface to show a function page, allowing the user to input remote business function operations through this page, such as clicking a function button corresponding to a specific remote business function on the function page. In response to the user's input of the remote business function operation, the mobile terminal's business component generates a remote instruction corresponding to that operation and sends the remote instruction to the mobile terminal. The mobile terminal then signs the generated remote instruction. Specifically, based on a hash algorithm, it performs a hash calculation on the business certificate and the generated remote instruction to obtain a hash string of the remote instruction as a digital signature. This digital signature and the remote instruction are then packaged to generate a signed remote instruction, which the mobile terminal returns to the business component.
[0092] 307. The mobile terminal, based on the business component, sends the signed remote instruction to the business execution unit through the business cloud platform; wherein, the signed remote instruction is used to obtain the first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
[0093] For example, based on the mobile terminal's business component, the signed remote instruction is forwarded to the business cloud platform via the mobile terminal's data forwarding function. The business cloud platform then sends the signed remote instruction to the vehicle terminal via its data forwarding function, and finally forwards it to the business execution unit. Upon receiving the signed remote instruction, the business execution unit verifies it, for example, checking whether the digital signature format conforms to a preset format or length, obtaining a first verification result to determine if the verification was successful. If the business execution unit determines that the verification was successful, for example, that the digital signature format conforms to a preset format or length, then the business execution unit determines that the signed remote instruction is a remote instruction issued by the mobile terminal or a remote instruction allowed by the mobile terminal. The business execution unit then controls the corresponding actuator in the vehicle to execute the remote business function operation corresponding to the signed remote instruction. The preset format and preset length are determined by the user according to actual needs and are not limited here.
[0094] 308. The business execution unit receives the signed remote instruction sent by the mobile terminal through the business component via the business cloud platform; and performs verification processing on the signed remote instruction to obtain the first verification result of the signed remote instruction.
[0095] For example, this step can be referred to as step 203, which will not be repeated here.
[0096] 309. If the business execution unit determines that the first verification result indicates that the remote instruction after signing has been successfully verified, it shall execute the vehicle operation corresponding to the remote instruction after signing.
[0097] For example, this step can be referred to as step 204, which will not be repeated here.
[0098] In this embodiment, based on the above embodiments, the business certificate issued by the OEM cloud platform is synchronized to the execution business unit on the mobile terminal and the vehicle terminal. The business instructions of the business component must be signed by the mobile terminal before they can be sent. They are then forwarded to the execution business unit via the business cloud platform and the vehicle terminal. The execution business unit can only execute the remote instructions after the signature is verified using the public key. This satisfies the information security protection in the complex remote business scenario involving the OEM mobile terminal, business components, business cloud platform, and vehicle terminal business execution unit, and ensures the security of end-to-end remote control business.
[0099] Figure 4 Flowchart of a remote control method provided in an embodiment of the present invention Figure 3 ,like Figure 4 As shown, the method includes:
[0100] 401. The mobile terminal responds to the user's input of a remote service login operation, determines the user's remote service permissions based on the user's remote service login account, and generates a certificate signing request based on the user's remote service permissions.
[0101] For example, Figure 5 This is an architecture diagram of a remote command transmission method provided in an embodiment of the present invention, as shown below. Figure 5 As shown, the architecture includes an OEM cloud platform (i.e., a mobile cloud platform, similar to...) Figure 5 OEM cloud), OEM mobile applications (Application, or App for short), business components, business cloud platform (same as OEM cloud), Figure 5The system comprises a business cloud platform, an in-vehicle terminal, and a business execution ECU (i.e., a business execution unit). The OEM cloud platform receives business certificate application requests and issues business certificates. The OEM's mobile app provides the corresponding business function entry point; the mobile app applies for and stores business certificates from the OEM cloud platform and has business certificate synchronization and business instruction signing interfaces. Business components are typically software development kits (SDKs) integrated within the mobile app, acting as the actual sender of remote business instructions, responsible for requesting business certificate synchronization and business instruction signing from the mobile app. The business cloud platform handles data forwarding between the business components and the in-vehicle business execution ECU. The in-vehicle terminal enables remote communication with the outside of the vehicle, providing a channel for communication between key in-vehicle components and the cloud platform. The business execution ECU stores business certificates and verifies business instructions; upon successful verification, it executes the business instructions. The business components, business cloud platform, and business execution ECU are strongly correlated. Communication between the OEM cloud platform and the mobile app is generally achieved through Hypertext Transfer Protocol Secure (HTTPS). Communication between the mobile device and business components is generally achieved through an Application Programming Interface (API). Communication between business components and the business cloud platform is generally achieved through HTTPS. Communication between the business cloud and the in-vehicle terminal is generally achieved through HTTPS. In-vehicle communication between the in-vehicle terminal and the business execution ECU can be achieved through Controller Area Network (CAN) or in-vehicle Ethernet. Remote services are implemented by the user controlling the vehicle from the OEM's mobile device. The actual command transmission and function implementation are handled by the business components integrated in the mobile device, the business cloud platform, and the in-vehicle business execution ECU, typically provided based on vehicle configuration or user subscription. Figure 6 A schematic diagram of a remote business certificate synchronization process provided in an embodiment of the present invention. Figure 1 ,like Figure 6 As shown, the user logs into the vehicle control interface on the mobile device and enters a remote service login operation, such as entering a user account and password to log in. The mobile device responds to the user's remote service login operation. At this time, the mobile device determines the remote service permissions corresponding to the remote service login account based on the remote service login account entered by the user. If the remote service permission indicates that the user has remote vehicle control permissions, a Certificate Signing Request (CSR) is generated, which contains at least a public-private key pair and the vehicle's unique identification information, to request a business certificate from the OEM cloud platform.
[0102] In one example, step 401 includes: the mobile terminal determines the user's business certificate storage information based on the user's remote business permissions; if the determination of the user's business certificate storage information indicates that the user has not stored a business certificate or the business certificate stored by the user has expired, then a certificate signing request is generated.
[0103] Specifically, such as Figure 6 As shown, when a user logs into the vehicle control interface on the mobile device, the mobile device needs to check whether it has saved the business certificate. Based on the user account entered by the user, the mobile device determines the remote business permissions pre-corresponding to that user account. If the remote business permissions are confirmed, indicating that the user has remote vehicle control authority, the mobile device obtains the business certificate information pre-corresponding to that user account. If the business certificate information indicates that the user has not saved a business certificate or that the user's saved business certificate has expired, a CSR file containing at least a public-private key pair and the vehicle's unique identification information is generated to request a business certificate from the OEM cloud platform. If the business certificate information indicates that the business certificate is valid, the business certificate synchronization process begins. By binding with the user account, when the user has remote business permissions, the mobile device needs to apply for a dedicated business certificate for signing business instructions. After synchronizing the business certificate, the vehicle needs to verify the business instructions to ensure that the instructions originate from the mobile device or have been allowed to be executed by the mobile device, thus meeting the information security protection requirements in complex remote business scenarios involving the OEM mobile device, business components, business cloud platform, and vehicle business execution unit.
[0104] 402. The mobile terminal sends a certificate signing request to the mobile cloud platform; the certificate signing request includes a public-private key pair and vehicle identification information; the certificate signing request is used to request the acquisition of a business certificate.
[0105] For example, combined Figure 6 The mobile device sends the generated certificate signing request to the mobile cloud platform to request a business certificate from the OEM cloud platform. The mobile cloud platform receives the certificate signing request from the mobile device and identifies the vehicle's identification information based on the public / private key pair in the received certificate signing request. Specifically, it identifies the business certificate with a preset mapping relationship to the vehicle's identification information from the preset certificate library and sends the business certificate back to the mobile device.
[0106] 403. The mobile terminal receives the business certificate sent by the mobile cloud platform; and performs verification processing on the business certificate according to the pre-stored root certificate to obtain the third verification result of the business certificate.
[0107] The root certificate is already pre-configured in the basic business logic.
[0108] For example, combined Figure 6The mobile device receives the business certificate sent by the mobile cloud platform and obtains the pre-stored root certificate. It then verifies the business certificate, specifically determining whether the effective date in the business certificate falls within the validity period recorded in the root certificate. If the effective date is within the validity period, the business certificate verification is successful; otherwise, it fails, resulting in a third verification result for further processing. The triggering mechanism for mobile device business certificate detection can be tailored to the specific business scenario, and it is recommended to perform this every time a user logs into the mobile device. Before executing remote control services, the mobile terminal needs to check whether it has the corresponding business certificate. If not, it generates a CSR file containing at least a public-private key pair and the vehicle's unique identification information and applies to the OEM cloud platform. The OEM cloud platform issues a business certificate to the mobile terminal, and the mobile terminal saves the business certificate after verifying it using the existing root certificate. The business certificate is used to ensure the information security of command transmission. The business certificate is managed by the OEM mobile terminal. When the link between the third-party business component, the business cloud platform, and the business execution unit fails or a unit is compromised, attackers cannot obtain the private key to use the service for abnormal vehicle control, and it will not affect the execution of other services, thus improving the security of remote control.
[0109] 404. If the mobile terminal determines that the third verification result indicates that the business certificate verification is successful, then the business certificate is saved.
[0110] For example, combined Figure 6 If the mobile device confirms that the obtained business certificate has been successfully verified, it will store the business certificate for subsequent processing.
[0111] In one example, after step 403, the process further includes: if the mobile terminal determines that the third verification result of the business certificate indicates that the business certificate verification has failed, it generates a business certificate verification failure log and determines the user's cumulative number of verification failures; if it determines that the user's cumulative number of verification failures is less than a preset number, it regenerates the certificate signing request. If the mobile terminal determines that the user's cumulative number of verification failures is greater than or equal to the preset number, it stops the user from continuing to request to obtain the business certificate; in response to the user's remote service entry operation on the vehicle control interface, it executes the function exception handling method.
[0112] Specifically, in combination Figure 6If the mobile device determines that the obtained business certificate verification has failed, it generates and stores a business certificate verification failure log to record the verification process and help technical personnel investigate the cause of the failure. Simultaneously, the mobile device will reapply for the business certificate. At this time, a preset monitor tracks the cumulative number of business certificate verification failures recorded from the moment the user initiates remote business login until the current moment; this is the user's cumulative verification failure count. The mobile device compares this cumulative failure count with a preset number (e.g., 3 times). If the cumulative failure count is less than the preset number, a new certificate signing request is generated to reapply for the business certificate from the OEM cloud platform. If the cumulative failure count is greater than or equal to the preset number, the mobile device stops requesting the business certificate while the user is logged in, thus preventing remote vehicle control. At this point, the mobile device displays the vehicle control interface, and the user clicks the remote business entry point on the interface. Based on the mobile device's business components, after responding to the user's remote business entry operation on the vehicle control interface, a function error message is displayed, and function error handling is performed. The preset number of attempts can be set by the user according to the actual situation, and there is no limit here.
[0113] 405. The mobile terminal sends the business certificate to the vehicle's business execution unit; wherein, the business certificate is used to generate the first synchronization result of the business certificate; the first synchronization result indicates that the business certificate synchronization is successful.
[0114] For example, this step can be referred to as step 302, which will not be repeated here.
[0115] Specifically, Figure 7 A schematic diagram of a remote business certificate synchronization process provided in an embodiment of the present invention. Figure 2 ,like Figure 7As shown, after the mobile terminal completes the business certificate detection or application, a remote business entry button on the vehicle control interface can be displayed, allowing users to click the button to attempt to enter the function page. When a user needs to use the function, they click the business entry. At this time, the mobile terminal's business component can obtain the synchronization information of the business certificate corresponding to the remote business entry operation, query its own saved business certificate synchronization result, and if it is determined that the business certificate is not synchronized, the business component needs to request the business certificate from the mobile terminal. The mobile terminal sends the business certificate to the business component, and the business component sends the business certificate to the business cloud platform. The business cloud platform sends the received business certificate to the vehicle terminal, and based on the vehicle terminal's pass-through function, sends the received business certificate to the business execution unit. After receiving the business certificate, the business execution unit performs certificate synchronization processing, generates a synchronization success result, and forwards it to the business component via the vehicle terminal and the business cloud platform, feeding back the first synchronization success result. The business component then saves the business certificate synchronization result as "synchronized". The mobile terminal's business component queries its own saved business certificate synchronization result. If it determines that the business certificate is synchronized, subsequent functions will start normally. After querying the synchronization results of the business certificate stored within itself, if it is determined that the synchronization information of the business certificate is "synchronized", the business component can display the business interface through the mobile terminal's display interface, allowing users to use the remote vehicle control function normally.
[0116] 406. The business execution unit receives the business certificate sent by the mobile terminal through the vehicle terminal.
[0117] For example, combined Figure 7 The business execution unit receives the business certificate sent by the mobile terminal's business component through the business cloud platform via the data forwarding function of the vehicle terminal.
[0118] 407. The business execution unit performs verification processing on the business certificate and obtains the second verification result of the business certificate.
[0119] For example, combined Figure 7 The business execution unit verifies the business certificate according to a preset verification algorithm. Specifically, it identifies the certificate authority recorded in the business certificate. If the certificate authority recorded in the business certificate is determined to be a certificate authority recorded in the preset database, the business certificate verification is considered successful. If the certificate authority recorded in the business certificate is determined not to be a certificate authority recorded in the preset database, the business certificate verification is considered to have failed, thus obtaining a second verification result for the business certificate. The preset database is a pre-stored database.
[0120] In one example, step 407 includes: the business execution unit performs verification processing on the business certificate based on the pre-stored root certificate to obtain a second verification result of the business certificate.
[0121] The root certificate mentioned here is already pre-configured in the basic business.
[0122] Specifically, in combination Figure 7 The business execution unit can invoke a pre-stored root certificate, which may be pre-issued to the business execution unit by the OEM cloud platform in other basic services. The business execution unit uses the root certificate to verify the received business certificate. Specifically, it can determine whether the certificate authority in the root certificate is consistent with the certificate authority in the received business certificate, and whether the date recorded in the business certificate is within the validity period recorded in the root certificate. If the certificate authority in the root certificate is consistent with the certificate authority in the received business certificate, and the date recorded in the business certificate is within the validity period recorded in the root certificate, then the business certificate verification is successful; otherwise, the business certificate verification fails.
[0123] 408. If the business execution unit determines that the second verification result indicates that the business certificate verification is successful, it saves the business certificate and generates the first synchronization result of the business certificate.
[0124] For example, combined Figure 7 If the business execution unit determines that the received business certificate has been successfully verified, it saves the business certificate and generates the first synchronization result of the business certificate to indicate that the business certificate has been successfully synchronized.
[0125] In one possible implementation, step 408 further includes: if the business execution unit determines that the second verification result indicates that the business certificate verification has failed, it generates a first verification log of the business certificate and generates a second synchronization result of the business certificate; wherein the second synchronization result includes business certificate synchronization failure; the second synchronization result is sent to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the second synchronization result to the mobile terminal; the second synchronization result is used to re-execute the business certificate synchronization process.
[0126] Specifically, in combination Figure 7If the business execution unit determines that the received business certificate verification has failed, it indicates that the business certificate has been tampered with or is otherwise abnormal during storage or transmission. In this case, a first verification log for the business certificate can be generated to record the verification process of the failed certificate, allowing technical personnel to investigate the cause of the failure. Simultaneously, if the business execution unit determines that the received business certificate verification has failed, it generates a second synchronization result indicating that the synchronization of the business certificate has failed, and sends this second synchronization result to the business cloud platform via the vehicle terminal. Based on the data forwarding function of the business cloud platform, the second synchronization result is sent to the mobile terminal, causing the mobile terminal to re-execute the business certificate synchronization process. That is, referring to the aforementioned process, the mobile terminal re-sends the business certificate to the business execution unit for verification. If the verification is successful, the business certificate is saved, and a synchronization success result is reported, which is then forwarded to the business component via the vehicle terminal and the business cloud platform. The business component saves the business certificate synchronization result as "synchronized".
[0127] In one possible implementation, step 406 further includes: if the business execution unit determines that the business certificate has expired, it generates a business certificate synchronization request; and sends the business certificate synchronization request to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the business certificate synchronization request to the mobile terminal; and the business certificate synchronization request is used to re-execute the business certificate synchronization process.
[0128] Specifically, in combination Figure 7 During the business certificate synchronization process, the business execution ECU will continuously monitor its own business certificate for expiration. For example, if it detects that the date on its business certificate is not within the preset validity period, it determines that its business certificate is invalid. When the business execution ECU detects that its own business certificate is invalid, it needs to update the business certificate. At this time, it initiates a business certificate synchronization request. That is, the business execution ECU generates a business certificate synchronization request and forwards it to the business component on the mobile terminal via the vehicle terminal and the business cloud platform. The business component receives the business certificate synchronization request, obtains the corresponding saved business certificate based on the request, and sends the business certificate to the business cloud platform, which is then forwarded to the business execution ECU via the vehicle terminal. The business execution ECU can then repeat the business certificate verification and synchronization process according to the aforementioned steps. The preset validity period can be automatically updated according to a preset cycle, which is determined by the user based on actual needs and is not limited here. Furthermore, the business certificate is issued by the OEM cloud platform and stored only on the mobile device and the business execution ECU. The mobile device and the business execution ECU need to use the existing root certificate (issued by the OEM cloud platform) to verify the legality of the business certificate. The business certificate is dedicated to this type of remote business that relies on third-party development components and will not affect other remote businesses.
[0129] 409. The business execution unit sends the first synchronization result to the mobile terminal; wherein, the first synchronization result is used to sign the remote instruction; the remote instruction is generated based on the remote business function operation input by the user.
[0130] For example, this step can be referred to as step 202, which will not be repeated here.
[0131] 410. The mobile terminal receives the first synchronization result sent by the business execution unit.
[0132] For example, this step can be referred to as step 305, which will not be repeated here.
[0133] Specifically, in combination Figure 7 When the business execution ECU detects that its own business certificate has expired during the business certificate synchronization process, i.e., the business execution ECU detects a business certificate update requirement, it needs to initiate a business certificate synchronization request. The business execution ECU forwards the generated business certificate synchronization request to the business component on the mobile terminal via the vehicle terminal and the business cloud platform. The business component receives the business certificate synchronization request, obtains the corresponding saved business certificate based on the request, and sends the business certificate to the business cloud platform, which is then forwarded to the business execution ECU via the vehicle terminal. The business execution ECU can then repeat the business certificate synchronization process according to the aforementioned steps.
[0134] 411. The mobile terminal, based on the business component, saves the first synchronization result of the business certificate and displays the business interface.
[0135] For example, after receiving the synchronization result of a successful business certificate synchronization, the business component in the mobile terminal saves the first synchronization result of the business certificate and updates the synchronization information of the business certificate to "synchronized". Simultaneously, the business component can display the business interface through the mobile terminal's display interface, allowing users to use the remote vehicle control function normally. This is combined with... Figure 6 , Figure 7 Certificate application and synchronization are performed asynchronously. After a user logs into the mobile app, regardless of whether the user clicks on a business entry point to launch the corresponding function, the mobile app can first ensure the validity of its own business certificate and respond to the business component's business certificate acquisition request at any time. The validity of the business certificate in the business execution ECU is jointly maintained by the business component and the business execution ECU. Only after the remote business certificate synchronization process is successfully completed can the business interface be made available for user operation. If the execution fails, functional exception handling will be implemented, and the exception handling method can be designed by the user according to actual business needs.
[0136] One example also includes: receiving a second synchronization result of the business certificate sent by the business execution unit through the business cloud platform; wherein the second synchronization result is generated based on the second verification result of the business certificate, indicating that the business certificate verification failed; the second synchronization result indicates that the business certificate synchronization failed; determining the user's cumulative number of synchronization failures based on the business component; if it is determined that the user's cumulative number of synchronization failures is greater than or equal to a preset number, then stopping the user from continuing to request synchronization of the business certificate; and updating the synchronization information of the business certificate. If it is determined that the user's cumulative number of verification failures is less than the preset number, then sending the business certificate to the business execution unit through the business cloud platform.
[0137] Specifically, in combination Figure 7 If the business execution unit determines that the received business certificate verification has failed, it indicates that the business certificate has been tampered with or is otherwise abnormal during storage or transmission. In this case, the business execution unit generates a second synchronization result indicating the failure and sends this result to the business cloud platform via the vehicle terminal. Based on the data forwarding function of the business cloud platform, the second synchronization result is sent to the mobile terminal. The mobile terminal receives the second synchronization result of the business certificate sent by the business execution unit. The mobile terminal then re-executes the business certificate synchronization process, i.e., it obtains the cumulative number of business certificate synchronization failures under the current user login state from the preset monitor through the business component. If the business component determines that the cumulative number of synchronization failures is greater than or equal to a preset number (e.g., 3 times), it stops the user from continuing to request business certificate synchronization and updates the synchronization information of the business certificate to "not synchronized," while simultaneously handling the functional anomaly. If the business component determines that the user's cumulative verification failure count is less than the preset number, it can refer to the aforementioned process and resend the business certificate to the business execution unit for verification. If the verification is successful, the business certificate is saved, and a synchronization success result is fed back, which is then forwarded to the business component via the vehicle terminal and the business cloud platform. The business component saves the business certificate synchronization result as "synchronized". The specific methods and preset number of exception handling steps are designed by the user according to actual needs and are not limited here.
[0138] 412. The mobile terminal, based on business components, responds to remote business function operations performed by the user on the business interface and generates remote instructions corresponding to the remote business function operations.
[0139] For example, Figure 8 This is a schematic diagram of a remote service instruction transmission process provided in an embodiment of the present invention, as shown below. Figure 8As shown, based on the business component, after the certificate application and synchronization process is completed, the business interface is displayed. Subsequent user operations are handled by the business component. That is, users can input remote business function operations through the business interface, such as clicking a function button for a remote business function (e.g., parking assist). The business component responds to the user's remote business function operation on the business interface and generates the corresponding remote command (i.e., business command). For example, if the user clicks the "Parking Assist" function button on the business interface, the business component generates the corresponding remote command for "Parking Assist".
[0140] 413. The mobile terminal signs the remote instruction using the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; wherein, the business execution unit is used to verify the signed remote instruction using the public key in the public-private key pair corresponding to the business certificate.
[0141] For example, such as Figure 8 As shown, the business component first sends the business instruction to the mobile terminal. The mobile terminal retrieves the public-private key pair corresponding to the business certificate from the local database and uses the private key from the public-private key pair to sign the generated remote instruction. Specifically, it calls a preset hash algorithm to hash the private key and the remote instruction, obtaining a hash value as a digital signature. This digital signature and the remote instruction are then packaged to obtain the signed business instruction, which is returned to the business component. When verifying the signed remote instruction, the business execution unit uses the public-private key pair corresponding to the business certificate pre-received from the OEM cloud platform and verifies the received signed remote instruction based on the public key. The private key of the business certificate is stored only on the mobile terminal. This prevents attackers from obtaining the private key from the external transmission link of the business instruction and from using this type of remote service to perform abnormal operations on the vehicle.
[0142] 414. The mobile terminal, based on the business component, sends the signed remote instruction to the business execution unit through the business cloud platform; wherein, the signed remote instruction is used to obtain the first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
[0143] For example, this step can be referred to as step 307, which will not be repeated here.
[0144] Specifically, such as Figure 8As shown, when the business execution unit verifies the signed remote command, if the verification fails, it generates an execution failure result corresponding to the signed remote command and sends this result to the mobile terminal via the business cloud platform. The mobile terminal receives the execution failure result from the business execution unit through the business cloud platform. The business component then displays a function error message and performs error handling. The error handling method can be designed according to the actual business requirements and is not limited here. Furthermore, since the business certificate and private key are entirely managed by the OEM mobile terminal and are actually bound to the user account based on business permissions, they do not depend on the vehicle terminal and have the characteristics of being updatable and customizable according to business needs.
[0145] 415. The business execution unit receives the signed remote instruction sent by the mobile terminal through the business component via the business cloud platform; and verifies the signed remote instruction based on the public key in the public-private key pair of the business certificate to obtain the first verification result.
[0146] For example, such as Figure 8 As shown, the business execution unit receives the signed remote instruction sent by the mobile terminal through the business component via the business cloud platform, and obtains the public key of the pre-synchronized business certificate from the local storage space. It uses this public key to verify the received signed remote instruction. Specifically, it decrypts the digital signature in the signed remote instruction to obtain decrypted data. Simultaneously, it uses a specified hash algorithm (such as SHA-256) to hash the data portion (excluding the signature itself) of the synchronized business certificate to obtain a hash value. This hash value is compared with the decrypted data. If the hash value matches the decrypted data, the signed remote instruction is verified successfully, meaning it has not been tampered with. If the hash value does not match the decrypted data, the signed remote instruction verification fails, meaning it has been tampered with or leaked. This results in the first verification result of the signed remote instruction, which is then used to execute the vehicle operation corresponding to the signed remote instruction. By decoupling remote services involving third-party business components, business cloud platforms, and business execution ECUs from existing services, and using dedicated business certificates to ensure information security for command transmission, the private key is managed by the OEM's mobile terminal. When the link between the third-party business component, business cloud platform, and business execution unit fails or a unit is compromised, attackers cannot obtain the private key to use the service for abnormal vehicle control, nor will it affect the execution of other services.
[0147] 416. If the business execution unit determines that the first verification result indicates that the remote instruction after signing has been successfully verified, it shall execute the vehicle operation corresponding to the remote instruction after signing.
[0148] For example, this step can be referred to as step 204, which will not be repeated here.
[0149] In one example, it also includes: if the business execution unit determines that the first verification result indicates that the verification of the signed remote instruction has failed, it generates a second verification log corresponding to the signed remote instruction; and generates an execution failure result corresponding to the signed remote instruction; and sends the execution failure result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the execution failure result to the mobile terminal; and the execution failure result is used for functional exception handling.
[0150] Specifically, such as Figure 8 As shown, if the business execution unit determines that the verification of the signed remote instruction fails, it generates a second verification log corresponding to the signed remote instruction. This log records the verification failure and is used by technical personnel to investigate the cause of the failure. Simultaneously, if the business execution unit determines that the verification of the signed remote instruction fails, it generates an execution failure result corresponding to the signed remote instruction and sends this result to the business cloud platform via the vehicle terminal. Based on the data transmission function of the business cloud platform, the platform sends the execution failure result to the mobile terminal. The mobile terminal's business components handle the functional anomaly; the anomaly handling method can be designed according to the actual business requirements.
[0151] In this embodiment, based on the above embodiments, a remote command transmission method based on a dedicated business certificate reduces the key requirements on the vehicle end, protects the transmission security of specific business commands, and can be decoupled from traditional remote services, thus achieving both security and business applicability. Furthermore, the implementation of this embodiment is not limited to vehicle-mounted terminals, improving business applicability and possessing significant practical application value.
[0152] Figure 9 A schematic diagram of the structure of a remote control device provided in an embodiment of the present invention. Figure 1 ,like Figure 9As shown, this device is applied to a business execution unit in a vehicle. The device includes: a receiving module 501, used to receive a business certificate sent by a mobile terminal and generate a first synchronization result for the business certificate; wherein the business certificate is obtained from the mobile terminal cloud platform based on the user's remote business login account after the user inputs a remote business login operation; the first synchronization result indicates successful synchronization of the business certificate; a sending module 502, used to send the first synchronization result to the mobile terminal; wherein the first synchronization result is used to sign a remote instruction; the remote instruction is generated based on a remote business function operation input by the user; a verification module 503, used to receive the signed remote instruction sent by the mobile terminal through a business component via the business cloud platform; and to verify the signed remote instruction to obtain a first verification result for the signed remote instruction; and an execution module 504, used to execute the vehicle operation corresponding to the signed remote instruction if it is determined that the first verification result indicates successful verification of the signed remote instruction.
[0153] Furthermore, the receiving module 501 is specifically used to: receive the service certificate sent by the mobile terminal through the vehicle terminal; perform verification processing on the service certificate to obtain a second verification result of the service certificate; if it is determined that the second verification result indicates that the service certificate verification is successful, then save the service certificate and generate a first synchronization result of the service certificate.
[0154] Furthermore, the receiving module 501 is specifically used to: perform verification processing on the business certificate based on the pre-stored root certificate, and obtain the second verification result of the business certificate.
[0155] Furthermore, the receiving module 501 is specifically configured to: if it is determined that the second verification result indicates that the business certificate verification has failed, generate a first verification log of the business certificate and generate a second synchronization result of the business certificate; wherein the second synchronization result includes business certificate synchronization failure; send the second synchronization result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the second synchronization result to the mobile terminal; the second synchronization result is used to re-execute the business certificate synchronization process.
[0156] Furthermore, the mobile terminal is used to sign the remote instruction based on the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; the verification module 503 is specifically used to: perform verification processing on the signed remote instruction based on the public key in the public-private key pair of the business certificate to obtain the first verification result.
[0157] Furthermore, the device is also used to: if it is determined that the first verification result indicates that the verification of the signed remote instruction has failed, generate a second verification log corresponding to the signed remote instruction; and generate an execution failure result corresponding to the signed remote instruction; and send the execution failure result to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the execution failure result to the mobile terminal; and the execution failure result is used for functional anomaly handling.
[0158] Furthermore, the device is also used to: generate a business certificate synchronization request if it is determined that the business certificate has expired; send the business certificate synchronization request to the business cloud platform through the vehicle terminal; wherein the business cloud platform is used to send the business certificate synchronization request to the mobile terminal; the business certificate synchronization request is used to re-execute the business certificate synchronization process.
[0159] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.
[0160] Figure 10 A schematic diagram of the structure of a remote control device provided in an embodiment of the present invention. Figure 2 ,like Figure 10 As shown, the device is applied to a mobile terminal. The device includes: a generation module 601, used to obtain a business certificate corresponding to the remote business login operation from the mobile cloud platform based on the user's remote business login account in response to a user's input remote business login operation; a first sending module 602, used to send the business certificate to the vehicle's business execution unit; wherein, the business certificate is used to generate a first synchronization result of the business certificate; the first synchronization result indicates successful synchronization of the business certificate; a receiving module 603, used to receive the first synchronization result sent by the business execution unit; a signing module 604, used to generate a remote instruction in response to a user's input remote business function operation; and sign the remote instruction according to the business certificate to obtain a signed remote instruction; a second sending module 605, used to send the signed remote instruction to the business execution unit through the business cloud platform based on the business component; wherein, the signed remote instruction is used to obtain a first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
[0161] Furthermore, the signature module 604 is specifically used for: based on the business component, saving the first synchronization result of the business certificate; and displaying the business interface; based on the business component, responding to the user's remote business function operation on the business interface, and generating a remote instruction corresponding to the remote business function operation.
[0162] Furthermore, the signature module 604 is specifically used for: receiving the second synchronization result of the business certificate sent by the business execution unit through the business cloud platform; wherein, the second synchronization result is generated based on the second verification result of the business certificate, indicating that the business certificate verification failed; the second synchronization result indicates that the business certificate synchronization failed; determining the user's cumulative number of synchronization failures based on the business component; if it is determined that the user's cumulative number of synchronization failures is greater than or equal to a preset number, then stopping the user from continuing to request synchronization of the business certificate; and updating the synchronization information of the business certificate.
[0163] Furthermore, the signature module 604 is also specifically used to: if it is determined that the user's cumulative number of verification failures is less than a preset number, then send the business certificate to the business execution unit through the business cloud platform.
[0164] Further, the generation module 601 is specifically used for: responding to a user's input of a remote business login operation, determining the user's remote business permissions based on the user's remote business login account; and generating a certificate signing request based on the user's remote business permissions; sending the certificate signing request to the mobile cloud platform; wherein, the certificate signing request includes a public-private key pair and vehicle identification information; the certificate signing request is used to request the acquisition of a business certificate; receiving the business certificate sent by the mobile cloud platform; and performing verification processing on the business certificate based on the pre-stored root certificate to obtain a third verification result of the business certificate; if the third verification result indicates that the business certificate verification is successful, then saving the business certificate.
[0165] Furthermore, the generation module 601 is specifically used to: determine the user's business certificate storage information based on the user's remote business permissions; if the determination of the user's business certificate storage information indicates that the user has not stored a business certificate or the business certificate stored by the user has expired, then generate a certificate signing request.
[0166] Furthermore, the generation module 601 is also specifically used for: if it is determined that the third verification result of the business certificate indicates that the business certificate verification has failed, then generating a verification failure log of the business certificate and determining the user's cumulative number of verification failures; if it is determined that the user's cumulative number of verification failures is less than a preset number, then regenerating the certificate signing request.
[0167] Furthermore, the generation module 601 is also specifically used to: if it is determined that the user's cumulative number of verification failures is greater than or equal to a preset number, then stop the user from continuing to request to obtain a business certificate; and in response to the user's remote business entry operation on the vehicle control interface, execute a function exception handling method.
[0168] Furthermore, the first sending module 602 is specifically used for: based on the business component, in response to the user's remote business entry operation on the vehicle control interface, determining the synchronization information of the business certificate corresponding to the remote business entry operation; if the synchronization information of the business certificate indicates that the business certificate is not synchronized, then sending the business certificate to the business cloud platform; wherein, the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal; the business certificate is used for synchronization processing.
[0169] Furthermore, the signature module 604 is specifically used to: sign the remote instruction based on the private key in the public-private key pair corresponding to the business certificate to obtain the signed remote instruction; wherein, the business execution unit is used to verify the signed remote instruction based on the public key in the public-private key pair corresponding to the business certificate.
[0170] Furthermore, the device is also configured to: receive a business certificate synchronization request sent by the business execution unit through the business cloud platform; wherein the business certificate synchronization request is generated based on the expiration of the business certificate; obtain the business certificate based on the business component; and send the business certificate to the business cloud platform; wherein the business cloud platform is configured to send the business certificate to the business execution unit through the vehicle terminal for business certificate synchronization processing.
[0171] Furthermore, the device is also used to: receive execution failure results sent by the business execution unit through the business cloud platform; wherein the execution failure result is generated when the verification of the signed remote instruction fails, based on the first verification result of the signed remote instruction; and to execute the abnormal handling method of the function according to the execution failure result.
[0172] The apparatus in this embodiment can execute the technical solutions in the above method. Its specific implementation process and technical principles are the same, and will not be repeated here.
[0173] Figure 11 This is a schematic diagram of the structure of a business execution unit provided in an embodiment of the present invention. Figure 11As shown, the service execution unit may include a memory 701 and a processor 702. The memory 701 is used to store programs. Specifically, the program may include program code, which includes computer-executable instructions. The memory 701 may include high-speed random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. The processor 702 is used to execute the computer-executable instructions stored in the memory 701 to implement the method described in the foregoing method embodiments. Optionally, the service execution unit may also include a receiver 703 and a transmitter 704. In specific implementations, if the receiver 703, transmitter 704, memory 701, and processor 702 are implemented independently, they can be interconnected via a bus to communicate with each other. The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc.
[0174] Figure 12 This is a schematic diagram of the structure of a mobile terminal provided in an embodiment of the present invention. Figure 12 As shown, the mobile terminal can be a mobile device such as a mobile phone or a watch; the mobile terminal includes a memory 801 and a processor 802. The memory 801 is used to store programs. Specifically, the program may include program code, which includes computer-executable instructions. The memory 801 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device. The processor 802 is used to execute the computer-executable instructions stored in the memory 801 to implement the methods described in the foregoing embodiments. Optionally, the mobile terminal may also include a receiver 803 and a transmitter 804. In specific implementations, if the receiver 803, transmitter 804, memory 801, and processor 802 are implemented independently, the receiver 803, transmitter 804, memory 801, and processor 802 can be interconnected via a bus to complete mutual communication. The bus can be an industry-standard architecture bus, an external device interconnection bus, or an extended industry-standard architecture bus, etc.
[0175] The present invention also provides a vehicle including a business execution unit for performing the methods described in the above embodiments.
[0176] The present invention also provides a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement the scheme described in the above embodiments.
[0177] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside within an application-specific integrated circuit (ASIC).
[0178] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the scheme described in the above embodiments.
[0179] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as magnetic disks or optical disks.
[0180] Finally, it should be noted that the above embodiments are merely preferred embodiments provided to fully illustrate the present invention, and the scope of protection of the present invention is not limited thereto. Equivalent substitutions or modifications made by those skilled in the art based on the present invention are all within the scope of protection of the present invention.
Claims
1. A remote control method, characterized in that, The method is applied to a business execution unit in a vehicle; the method includes: The system receives a business certificate sent by the mobile terminal and generates a first synchronization result for the business certificate. The business certificate is obtained from the mobile cloud platform based on the user's remote business login account after the user inputs a remote business login operation. The first synchronization result indicates that the business certificate synchronization is successful. The first synchronization result is sent to the mobile terminal; wherein the first synchronization result is used to sign the remote instruction; the remote instruction is generated based on the remote service function operation input by the user; The business cloud platform receives the signed remote instruction sent by the mobile terminal through the business component; and verifies the signed remote instruction to obtain the first verification result of the signed remote instruction. If the first verification result indicates that the remote instruction after signing has been successfully verified, then the vehicle operation corresponding to the remote instruction after signing is executed.
2. The method according to claim 1, characterized in that, The step of receiving the service certificate sent by the mobile terminal and generating the first synchronization result of the service certificate includes: The service certificate sent by the mobile terminal is received through the vehicle terminal; The business certificate is verified to obtain a second verification result for the business certificate; If the second verification result indicates that the business certificate verification is successful, then the business certificate is saved, and the first synchronization result of the business certificate is generated.
3. The method according to claim 2, characterized in that, The step of verifying the business certificate to obtain a second verification result for the business certificate includes: The business certificate is verified based on the pre-stored root certificate to obtain a second verification result for the business certificate.
4. The method according to claim 2, characterized in that, The method further includes: If it is determined that the second verification result indicates that the business certificate verification has failed, then a first verification log of the business certificate is generated, and a second synchronization result of the business certificate is generated; wherein, the second synchronization result includes business certificate synchronization failure; The second synchronization result is sent to the business cloud platform via the vehicle terminal; wherein, the business cloud platform is used to send the second synchronization result to the mobile terminal; the second synchronization result is used to re-execute the business certificate synchronization process.
5. The method according to claim 1, characterized in that, The mobile terminal is used to sign the remote instruction based on the private key in the public-private key pair corresponding to the business certificate, so as to obtain the signed remote instruction. The step of verifying the signed remote instruction to obtain a first verification result of the signed remote instruction includes: The signed remote instruction is verified based on the public key in the public-private key pair of the business certificate to obtain the first verification result.
6. The method according to claim 1, characterized in that, The method further includes: If it is determined that the first verification result indicates that the verification of the signed remote instruction has failed, then a second verification log corresponding to the signed remote instruction is generated; and an execution failure result corresponding to the signed remote instruction is generated. The execution failure result is sent to the business cloud platform via the vehicle terminal; wherein, the business cloud platform is used to send the execution failure result to the mobile terminal; the execution failure result is used for functional exception handling.
7. The method according to any one of claims 1-6, characterized in that, The method further includes: If it is determined that the business certificate has expired, a business certificate synchronization request is generated; The business certificate synchronization request is sent to the business cloud platform via the vehicle terminal; wherein, the business cloud platform is used to send the business certificate synchronization request to the mobile terminal; the business certificate synchronization request is used to re-execute the business certificate synchronization process.
8. A remote control method, characterized in that, The method is applied to a mobile device; the method includes: In response to a user's remote business login operation, the service certificate corresponding to the remote business login operation is obtained from the mobile cloud platform based on the user's remote business login account. The business certificate is sent to the vehicle's business execution unit; wherein, the business certificate is used to generate a first synchronization result of the business certificate; the first synchronization result indicates that the business certificate synchronization was successful; Receive the first synchronization result sent by the service execution unit; In response to a user's input of a remote service function operation, a remote instruction is generated; and the remote instruction is signed according to the service certificate to obtain a signed remote instruction. Based on the business component, the signed remote instruction is sent to the business execution unit through the business cloud platform; wherein, the signed remote instruction is used to obtain a first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
9. The method according to claim 8, characterized in that, The remote service function operation in response to user input generates remote instructions, including: Based on the aforementioned business component, the first synchronization result of the business certificate is saved; and the business interface is displayed. Based on the business component, in response to the user's remote business function operation on the business interface, a remote instruction corresponding to the remote business function operation is generated.
10. The method according to claim 9, characterized in that, The method further includes: The system receives a second synchronization result of the business certificate sent by the business execution unit through the business cloud platform; wherein the second synchronization result is generated based on the second verification result of the business certificate, indicating that the business certificate verification failed; the second synchronization result indicates that the business certificate synchronization failed. Based on the aforementioned business components, determine the user's cumulative number of synchronization failures; If it is determined that the user's cumulative number of synchronization failures is greater than or equal to a preset number, then the user is stopped from continuing to request synchronization of the business certificate; and the synchronization information of the business certificate is updated.
11. The method according to claim 10, characterized in that, The method further includes: If it is determined that the user's cumulative number of verification failures is less than the preset number, then the business certificate is sent to the business execution unit through the business cloud platform.
12. The method according to claim 8, characterized in that, The response to the user's remote service login operation includes obtaining the service certificate corresponding to the remote service login operation from the mobile cloud platform based on the user's remote service login account, including: In response to a user's remote service login operation, the system determines the user's remote service permissions based on the user's remote service login account and generates a certificate signing request based on the user's remote service permissions. The certificate signing request is sent to the mobile cloud platform; wherein, the certificate signing request includes a public-private key pair and vehicle identification information; the certificate signing request is used to request the acquisition of a business certificate; The system receives the business certificate sent by the mobile cloud platform and verifies the business certificate based on the pre-stored root certificate to obtain the third verification result of the business certificate. If the third verification result indicates that the business certificate verification was successful, then the business certificate is saved.
13. The method according to claim 12, characterized in that, The step of generating a certificate signing request based on the user's remote business permissions includes: Based on the user's remote business permissions, determine the user's business certificate storage information; If it is determined that the user's business certificate storage information indicates that the user has not stored a business certificate or that the business certificate stored by the user has expired, then the certificate signing request is generated.
14. The method according to claim 12, characterized in that, The method further includes: If the third verification result of the business certificate indicates that the business certificate verification has failed, a verification failure log of the business certificate is generated, and the cumulative number of verification failures of the user is determined. If it is determined that the user's cumulative number of verification failures is less than a preset number, then a new certificate signing request is generated.
15. The method according to claim 14, characterized in that, The method further includes: If it is determined that the user's cumulative number of verification failures is greater than or equal to the preset number, then the user shall be stopped from continuing to request to obtain a business certificate. In response to remote service access operations performed by the user on the vehicle control interface, an abnormal function handling method is executed.
16. The method according to claim 8, characterized in that, Sending the business certificate to the vehicle's business execution unit includes: Based on the business component, in response to the user's remote business access operation on the vehicle control interface, the synchronization information of the business certificate corresponding to the remote business access operation is determined. If it is determined that the synchronization information of the business certificate indicates that the business certificate is not synchronized, then the business certificate is sent to the business cloud platform; wherein, the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal; the business certificate is used for synchronization processing.
17. The method according to claim 8, characterized in that, The step of signing the remote instruction based on the business certificate to obtain the signed remote instruction includes: The remote instruction is signed using the private key in the public-private key pair corresponding to the business certificate to obtain a signed remote instruction; wherein, the business execution unit is used to verify the signed remote instruction using the public key in the public-private key pair corresponding to the business certificate.
18. The method according to claim 8, characterized in that, The method further includes: The system receives a business certificate synchronization request sent by the business execution unit through the business cloud platform; wherein the business certificate synchronization request is generated based on the expiration of the business certificate. Based on the business component, the business certificate is obtained; and the business certificate is sent to the business cloud platform; wherein, the business cloud platform is used to send the business certificate to the business execution unit through the vehicle terminal for business certificate synchronization processing.
19. The method according to any one of claims 8-18, characterized in that, The method further includes: The business cloud platform receives the execution failure result sent by the business execution unit; wherein, the execution failure result is generated based on the first verification result of the signed remote instruction, indicating that the verification of the signed remote instruction failed; Based on the execution failure result, the abnormal handling method of the execution function is executed.
20. A remote control device, characterized in that, The device is used in a business execution unit within a vehicle; the device includes: The receiving module is used to receive the business certificate sent by the mobile terminal and generate a first synchronization result of the business certificate; wherein, the business certificate is obtained from the mobile terminal cloud platform based on the user's remote business login account after the user inputs a remote business login operation; the first synchronization result indicates that the business certificate is successfully synchronized; A sending module is used to send the first synchronization result to the mobile terminal; wherein the first synchronization result is used to sign the remote instruction; the remote instruction is generated based on the remote service function operation input by the user; The verification module is used to receive the signed remote instruction sent by the mobile terminal through the business component via the business cloud platform; and to perform verification processing on the signed remote instruction to obtain the first verification result of the signed remote instruction. The execution module is configured to execute the vehicle operation corresponding to the signed remote instruction if it is determined that the first verification result indicates that the verification of the signed remote instruction is successful.
21. A remote control device, characterized in that, The device is used in a mobile device; the device includes: The generation module is used to respond to the remote business login operation input by the user and obtain the business certificate corresponding to the remote business login operation from the mobile cloud platform according to the user's remote business login account. A first sending module is used to send the business certificate to the vehicle's business execution unit; wherein, the business certificate is used to generate a first synchronization result of the business certificate; the first synchronization result indicates that the business certificate synchronization was successful; The receiving module is used to receive the first synchronization result sent by the service execution unit; The signature module is used to generate remote instructions in response to remote business function operations input by the user; and to sign the remote instructions according to the business certificate to obtain the signed remote instructions. The second sending module is used to send the signed remote instruction to the business execution unit through the business cloud platform based on the business component; wherein, the signed remote instruction is used to obtain a first verification result of the signed remote instruction; the first verification result is used to execute the remote business function operation corresponding to the signed remote instruction when the verification of the signed remote instruction is successful.
22. A business execution unit, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1-7.
23. A mobile terminal, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 8-19.
24. A vehicle, characterized in that, The vehicle includes a business execution unit; the business execution unit is used to perform the method as described in any one of claims 1-7.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1-19.
26. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-19.