Certificate management method, certificate authority, management node and Internet of Vehicles terminal
By introducing vehicle terminal certificates and vehicle certificates into the Internet of Vehicles system and using blockchain technology for verification and recording, the problem of cumbersome application process and incommunication of information in the Internet of Vehicles is solved, and efficient and secure certificate configuration and information interoperability are achieved.
Patent Information
- Application Number
- CN201911065460.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-11-04
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2039-11-04
AI Technical Summary
The application process for digital certificates in the Internet of Vehicles is cumbersome, inefficient and low security, and information is not communicated due to multiple regulatory departments.
Introduce the Internet of Vehicles terminal certificate and vehicle certificate, and verify and record through the blockchain digital certificate management node. The Internet of Vehicles terminal uses the vehicle certificate to apply for a security message certificate from the certificate authorization center.
It simplifies the verification process of CA institutions, improves the efficiency of certificate configuration, solves the problem of information non-interoperability, and enhances the security and credibility of Internet of Vehicles terminals.
Smart Images

Figure CN112784310B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a certificate management method, a certificate authority, a management node and a vehicle networking terminal. Background Art
[0002] The Internet of Vehicles is a network system based on the intra-vehicle network, inter-vehicle network and in-vehicle mobile Internet. It carries out wireless communication and data exchange and sharing between vehicles (V2V), vehicles and roadside facilities (V2I), vehicles and pedestrians (V2P) and vehicles and networks (V2N) in accordance with the agreed communication protocols and data interaction. Through real-time perception and coordination between people, vehicles, roads and networks, it can realize the integration of intelligent traffic management, intelligent dynamic information services and intelligent vehicle control, provide users with various services such as road safety, traffic efficiency improvement and infotainment, and meet people's needs for traffic information consumption.
[0003] The Internet of Vehicles terminals and roadside units exchange information over short distances through direct links to meet the needs of Internet of Vehicles services such as improving traffic efficiency, road traffic safety, and automated driving. In order to achieve secure communication between Internet of Vehicles terminals and between Internet of Vehicles terminals and roadside units, Internet of Vehicles terminals and roadside units need to be configured with digital certificates to achieve identity authentication of both parties and secure protection of transmitted data.
[0004] In order to protect the privacy of Internet of Vehicles users and prevent attackers from tracking specific vehicles by tracking digital certificates, Internet of Vehicles terminals generally have multiple certificates, including registration certificates, security message certificates, etc., of which registration certificates are used to apply for security message certificates. When protecting communications between Internet of Vehicles terminals and with roadside units, Internet of Vehicles terminals will use security message certificates, which have a short validity period and do not reflect any information about the Internet of Vehicles terminals.
[0005] There are currently two ways to apply for a vehicle registration certificate. One is to pre-install a default certificate in the device and use the default certificate to apply for a registration certificate. The other is for the vehicle factory to provide vehicle information to a registration CA (Certificate Authority), which then issues a certificate to the vehicle based on the information.
[0006] For the first application method, the Internet of Vehicles device applies for the device's digital certificate from the registration CA agency. The registration CA agency is responsible for the authentication of the Internet of Vehicles device, verifies whether the Internet of Vehicles device is legal, and then issues a registration certificate for the legal device. However, how to manage the preset default certificates is still difficult to solve. If issued by the equipment manufacturer itself, the security and credibility are low. If issued by a designated CA agency, the application and configuration efficiency is low, and it is difficult to select a unique CA agency.
[0007] For the second application method, the vehicle factory provides the registered CA agency with the vehicle information it produces, and writes information including the device ID into the device during the vehicle production process; when the vehicle initiates the registration process with the registered CA agency, the registered CA agency will issue the registration certificate to the vehicle after confirming that the vehicle identity information is correct; the vehicle uses the registration certificate to apply for or update the security message certificate. The problem with this technical solution is how the registered CA agency determines the legitimacy of the vehicle network equipment. To solve this problem, there needs to be an authoritative party to provide equipment information, and the registered CA agency queries the authoritative party for equipment information. In actual applications, the information of Internet of Vehicles equipment involves equipment manufacturers, sellers, and multiple management departments. Therefore, there are multiple authoritative parties and multiple registered CA agencies. There are great difficulties in the intercommunication and transmission of information data and trust between these authoritative parties and registered CA agencies, resulting in the need for Internet of Vehicles equipment to apply for certificates from multiple CA agencies.
[0008] In addition, no matter which of the above methods is used, the vehicle terminal or vehicle factory needs to submit a certificate application to the CA organization, and wait for the CA organization to verify and issue the certificate before the vehicle terminal or vehicle factory can obtain the certificate from the CA organization. Since each vehicle terminal uses a different certificate, the factory needs to install and configure the corresponding certificate file for each terminal device or vehicle separately, which requires adjusting the factory assembly line and working closely with the assembly line, but the cost of adjusting the assembly line is very high; otherwise, if the configuration is performed on each device, the efficiency is extremely low. Summary of the invention
[0009] The purpose of the embodiments of the present invention is to provide a certificate management method, a certificate authority, a management node and a vehicle networking terminal to solve the problems of complicated application process, low efficiency and low security of vehicle networking digital certificates in related technologies.
[0010] In order to solve the above problems, an embodiment of the present invention provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to a certificate authority center, and includes:
[0011] Receive a security message certificate application request sent by a connected vehicle terminal, the security message certificate application request including: identity information of the vehicle where the connected vehicle terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the connected vehicle terminal is located;
[0012] Obtaining a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0013] The signature of the security message certificate application request is verified using the public key corresponding to the vehicle certificate, and a security message certificate is issued to the Internet of Vehicles terminal upon successful verification.
[0014] Wherein, obtaining the vehicle certificate of the vehicle from the blockchain digital certificate management node according to the identity information of the vehicle includes:
[0015] Sending a vehicle certificate query request to a blockchain digital certificate management node, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0016] Receive the valid vehicle certificate of the vehicle sent by the blockchain digital certificate management node.
[0017] Wherein, the vehicle certificate is used to identify the identity information of the vehicle;
[0018] or,
[0019] The vehicle certificate is also used to bind the identity information of the Internet of Vehicles terminal with the identity information of the vehicle.
[0020] The embodiment of the present invention also provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to a blockchain digital certificate management node, including:
[0021] Receiving a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0022] The vehicle certificate of the vehicle is fed back to the certificate authority according to the identity information of the vehicle.
[0023] Before receiving the vehicle certificate query request sent by the certificate authority, the method further includes:
[0024] Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate;
[0025] Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification;
[0026] Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate;
[0027] The second certificate issuance request is verified, and upon successful verification, the vehicle certificate is recorded in the blockchain.
[0028] The Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0029] Wherein, the vehicle certificate is used to identify the identity information of the vehicle;
[0030] or,
[0031] The vehicle certificate is also used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0032] The verifying the second certificate issuance request includes:
[0033] Verifying the validity of the Internet of Vehicles terminal certificate;
[0034] Verifying the signature of the second certificate issuance request using the public key corresponding to the Internet of Vehicles terminal certificate;
[0035] The correspondence between the identity information of the Internet of Vehicles terminal indicated by the vehicle certificate and the identity information of the vehicle is verified.
[0036] The embodiment of the present invention further provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to an Internet of Vehicles terminal and includes:
[0037] Sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0038] Receive a security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0039] Wherein, the method further comprises:
[0040] Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate;
[0041] Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a vehicle certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate;
[0042] Among them, the Internet of Vehicles terminal certificate and the vehicle certificate are recorded in the blockchain.
[0043] Wherein, the method further comprises:
[0044] The Internet of Vehicles terminal certificate is generated according to the identity information of the Internet of Vehicles terminal and the public-private key pair of the Internet of Vehicles terminal; wherein the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0045] Wherein, the method further comprises:
[0046] Generate the vehicle certificate according to the identity information of the vehicle, the identity information of the Internet of Vehicles terminal and the public and private key pair of the vehicle;
[0047] The vehicle certificate is used to identify the identity information of the vehicle; and / or the vehicle certificate is used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0048] The embodiment of the present invention further provides a management device for a digital certificate of an Internet of Vehicles, which is applied to a certificate authority center, including:
[0049] A first receiving module is used to receive a security message certificate application request sent by a vehicle networking terminal, wherein the security message certificate application request includes: identity information of the vehicle where the vehicle networking terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the vehicle networking terminal is located;
[0050] An acquisition module, used to acquire a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0051] The issuing module is used to verify the signature of the security message certificate application request using the public key corresponding to the vehicle certificate, and issue a security message certificate to the Internet of Vehicles terminal after successful verification.
[0052] An embodiment of the present invention further provides a certificate authority, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and the processor is used to perform the following operations:
[0053] Receive a security message certificate application request sent by a connected vehicle terminal, the security message certificate application request including: identity information of the vehicle where the connected vehicle terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the connected vehicle terminal is located;
[0054] Obtaining a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0055] The signature of the security message certificate application request is verified using the public key corresponding to the vehicle certificate, and a security message certificate is issued to the Internet of Vehicles terminal upon successful verification.
[0056] The embodiment of the present invention further provides a management device for a digital certificate of an Internet of Vehicles, which is applied to a blockchain digital certificate management node, including:
[0057] A second receiving module is used to receive a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0058] A feedback module is used to feedback the vehicle certificate of the vehicle to the certificate authority according to the identity information of the vehicle.
[0059] An embodiment of the present invention further provides a blockchain digital certificate management node, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and the processor is used to perform the following operations:
[0060] Receiving a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0061] The vehicle certificate of the vehicle is fed back to the certificate authority according to the identity information of the vehicle.
[0062] The embodiment of the present invention further provides a management device for an Internet of Vehicles digital certificate, which is applied to an Internet of Vehicles terminal and includes:
[0063] A first sending module is used to send a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0064] The third receiving module is used to receive the security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0065] An embodiment of the present invention further provides a vehicle networking terminal, including a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, and the processor is used to perform the following operations:
[0066] Sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0067] Receive a security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0068] An embodiment of the present invention also provides a communication device, including a memory, a processor, and a program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned method for managing digital certificates of Internet of Vehicles when executing the program.
[0069] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the method for managing digital certificates for an Internet of Vehicles as described above.
[0070] The above technical solution of the present invention has at least the following beneficial effects:
[0071] In the certificate management method, certificate authority center, management node and Internet of Vehicles terminal of the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority center, and the certificate authority center verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-intercommunication due to the existence of multiple regulatory departments in the Internet of Vehicles. BRIEF DESCRIPTION OF THE DRAWINGS
[0072] Figure 1 A flowchart showing the steps of a method for managing a digital certificate of an Internet of Vehicles provided by an embodiment of the present invention;
[0073] Figure 2 A second flowchart showing the method for managing a digital certificate for an Internet of Vehicles provided by an embodiment of the present invention;
[0074] Figure 3 A flowchart showing the steps of the method for managing a digital certificate of an Internet of Vehicles provided by an embodiment of the present invention;
[0075] Figure 4 It shows the process of issuing the Internet of Vehicles terminal certificate in the method for managing the Internet of Vehicles digital certificate provided by the embodiment of the present invention;
[0076] Figure 5 The vehicle certificate issuing process in the vehicle networking digital certificate management method provided by the embodiment of the present invention is shown;
[0077] Figure 6 It shows the process of applying for a security message certificate in the method for managing a digital certificate for an Internet of Vehicles provided by an embodiment of the present invention;
[0078] Figure 7 One of the structural schematic diagrams showing the device for managing digital certificates of Internet of Vehicles provided by an embodiment of the present invention;
[0079] Figure 8 A schematic diagram showing the structure of a certificate authority provided by an embodiment of the present invention;
[0080] Fig. 9 A second structural diagram showing a device for managing a digital certificate for an Internet of Vehicles provided by an embodiment of the present invention;
[0081] Fig.10 A schematic diagram showing the structure of a blockchain digital certificate management node provided by an embodiment of the present invention;
[0082] Fig.11 A third structural diagram showing a device for managing a digital certificate for an Internet of Vehicles provided by an embodiment of the present invention;
[0083] Fig.12 A schematic diagram showing the structure of a vehicle networking terminal provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0084] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0085] like Figure 1 As shown, an embodiment of the present invention provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to a certificate authority CA, including:
[0086] Step 11, receiving a security message certificate application request sent by a vehicle networking terminal, wherein the security message certificate application request includes: identity information of the vehicle where the vehicle networking terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the vehicle networking terminal is located;
[0087] Step 12, obtaining a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0088] Step 13: Use the public key corresponding to the vehicle certificate to verify the signature of the security message certificate application request, and issue a security message certificate to the Internet of Vehicles terminal after successful verification.
[0089] In the embodiment of the present invention, when the Internet of Vehicles terminal communicates securely with other vehicles or roadside facilities, it is necessary to apply for a secure message certificate from a certificate authority CA.
[0090] The Internet of Vehicles terminal sends a request for a secure message certificate to the CA, which includes the vehicle's identity information and signs the request using the private key corresponding to the vehicle certificate. After receiving the request, the CA queries the blockchain digital certificate management node for the vehicle certificate (and verifies the validity of the vehicle certificate) and verifies the correctness of the signature in the secure message certificate request. After successful verification, the secure message certificate is issued to the Internet of Vehicles terminal.
[0091] As an optional embodiment, step 12 includes:
[0092] Sending a vehicle certificate query request to a blockchain digital certificate management node, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0093] Receive the valid vehicle certificate of the vehicle sent by the blockchain digital certificate management node.
[0094] Optionally, the vehicle certificate is used to identify the identity information of the vehicle;
[0095] or,
[0096] The vehicle certificate is also used to bind the identity information of the Internet of Vehicles terminal with the identity information of the vehicle.
[0097] In the embodiment of the present invention, the Internet of Vehicles terminal certificate and vehicle certificate are introduced. The Internet of Vehicles terminal certificate is used to identify the terminal identity. The vehicle certificate is jointly generated by the Internet of Vehicles terminal based on the Internet of Vehicles terminal certificate and vehicle information. The Internet of Vehicles terminal can be bound to a specific vehicle, and the two certificates can be used to identify the terminal information and vehicle information respectively. For example, Internet of Vehicles terminal manufacturers can use terminal certificates to authenticate the terminal, thereby providing services such as remote security upgrades of equipment. In the traditional way, the Internet of Vehicles terminal certificate and the vehicle certificate are not distinguished, and only the registration certificate is used to identify the vehicle identity, and the terminal identity cannot be identified separately.
[0098] The application method of the secure message certificate simplifies the verification process of the CA agency. The CA agency only needs to verify whether the identity information of the vehicle in the secure message certificate application request is consistent with the information in the vehicle certificate, and to ensure the validity of the vehicle certificate by querying the blockchain system. There is no need to query the vehicle information from the corresponding management agency, nor to verify other identification certificates and other materials related to the vehicle. This solves the problem of information non-intercommunication due to the existence of multiple regulatory departments in the Internet of Vehicles.
[0099] like Figure 2 As shown, an embodiment of the present invention also provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to a blockchain digital certificate management node, including:
[0100] Step 21, receiving a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0101] Step 22: Feedback the vehicle certificate of the vehicle to the certificate authority based on the identity information of the vehicle.
[0102] In the embodiment of the present invention, the blockchain digital certificate management node records the valid vehicle certificate, and the Internet of Vehicles terminal sends a security message certificate application request to the CA, which includes the identity information of the vehicle, and signs the request using the private key corresponding to the vehicle certificate; after receiving the security message certificate application request, the CA queries the blockchain digital certificate management node for the vehicle certificate (and verifies the validity of the vehicle certificate), and verifies the correctness of the signature in the security message certificate application request. After successful verification, the security message certificate is issued to the Internet of Vehicles terminal.
[0103] Furthermore, before step 21, the method further includes:
[0104] Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate;
[0105] Verify the first certificate issuance request, and after successful verification, record the Internet of Vehicles terminal certificate to the blockchain; for example, the verification node that verifies the first certificate issuance request is a terminal manufacturer node;
[0106] Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate;
[0107] The second certificate issuance request is verified, and after successful verification, the vehicle certificate is recorded in the blockchain. For example, the verification nodes for verifying the second certificate issuance request are the vehicle factory node and the vehicle management department node; the vehicle factory node can verify the correspondence between the vehicle identification and the identification of the Internet of Vehicles terminal, and the vehicle management department node can verify the correspondence between the vehicle identification and the license plate number.
[0108] Optionally, the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0109] The vehicle certificate is used to identify the identity information of the vehicle;
[0110] Alternatively, the vehicle certificate is also used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0111] In the embodiment of the present invention, the Internet of Vehicles terminal certificate and vehicle certificate are introduced. The Internet of Vehicles terminal certificate is used to identify the terminal identity. The vehicle certificate is jointly generated by the Internet of Vehicles terminal based on the Internet of Vehicles terminal certificate and vehicle information. The Internet of Vehicles terminal can be bound to a specific vehicle, and the two certificates can be used to identify the terminal information and vehicle information respectively. For example, Internet of Vehicles terminal manufacturers can use terminal certificates to authenticate the terminal, thereby providing services such as remote security upgrades of equipment. In the traditional way, the Internet of Vehicles terminal certificate and the vehicle certificate are not distinguished, and only the registration certificate is used to identify the vehicle identity, and the terminal identity cannot be identified separately.
[0112] Optionally, the verifying the second certificate issuance request includes:
[0113] Verifying the validity of the Internet of Vehicles terminal certificate;
[0114] Verifying the signature of the second certificate issuance request using the public key corresponding to the Internet of Vehicles terminal certificate;
[0115] The correspondence between the identity information of the Internet of Vehicles terminal indicated by the vehicle certificate and the identity information of the vehicle is verified.
[0116] In the embodiment of the present invention, the blockchain digital certificate management node verifies the second certificate issuance request. After the verification is passed, the blockchain digital certificate management system records the vehicle certificate to be issued into the blockchain. The verification content includes the validity of the Internet of Vehicles terminal certificate, the correctness of the request signature, and the correctness of the vehicle and Internet of Vehicles terminal information.
[0117] like Figure 3 As shown, an embodiment of the present invention further provides a method for managing a digital certificate of an Internet of Vehicles, which is applied to an Internet of Vehicles terminal and includes:
[0118] Step 31, sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0119] Step 32: Receive a security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0120] In the embodiment of the present invention, when the Internet of Vehicles terminal communicates securely with other vehicles or roadside facilities, it is necessary to apply for a secure message certificate from a certificate authority CA.
[0121] The Internet of Vehicles terminal sends a request for a secure message certificate to the CA, which includes the vehicle's identity information and signs the request using the private key corresponding to the vehicle certificate. After receiving the request, the CA queries the blockchain digital certificate management node for the vehicle certificate (and verifies the validity of the vehicle certificate) and verifies the correctness of the signature in the secure message certificate request. After successful verification, the secure message certificate is issued to the Internet of Vehicles terminal.
[0122] As an optional embodiment, the method further includes:
[0123] Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate;
[0124] Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a vehicle certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate;
[0125] Among them, the Internet of Vehicles terminal certificate and the vehicle certificate are recorded in the blockchain.
[0126] Furthermore, the method further comprises:
[0127] The Internet of Vehicles terminal certificate is generated according to the identity information of the Internet of Vehicles terminal and the public-private key pair of the Internet of Vehicles terminal; wherein the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0128] During the production process of the Internet of Vehicles terminal (such as On Board Unit), the Internet of Vehicles terminal generates a public-private key pair, and uses the public-private key pair and the identity information of the Internet of Vehicles terminal to generate an Internet of Vehicles terminal certificate; the identity information of the Internet of Vehicles terminal is such as the OBU device identification number, or the OBU device identification number after a transformation (such as a hash transformation).
[0129] In this method, the Internet of Vehicles terminal generates the Internet of Vehicles terminal certificate by itself, and then publishes the Internet of Vehicles terminal certificate to the blockchain digital certificate management system. If the traditional method is adopted, the terminal needs to submit the certificate application materials to the CA organization, and the CA organization will issue the certificate after review. Then the terminal or terminal manufacturer obtains the certificate from the CA organization, and finally configures the certificate to the terminal. The process is long and it is difficult to achieve batch filling. Therefore, this application proposal method is simpler than the traditional method and can be mass-produced in the Internet of Vehicles terminal production line.
[0130] Furthermore, the method further comprises:
[0131] Generate the vehicle certificate according to the identity information of the vehicle, the identity information of the Internet of Vehicles terminal and the public and private key pair of the vehicle;
[0132] The vehicle certificate is used to identify the identity information of the vehicle; and / or the vehicle certificate is used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0133] After the IoV terminal is installed in the vehicle, it generates a vehicle certificate and publishes it to the blockchain through a certificate publishing request. The vehicle certificate is used to identify the vehicle and can also be called a registration certificate. The vehicle certificate can bind the IoV terminal identity to the vehicle information.
[0134] The issuance process of the vehicle certificate is similar to that of the Internet of Vehicles terminal certificate. In the embodiment of the present invention, the Internet of Vehicles terminal generates the vehicle certificate by itself, and then publishes the vehicle certificate and related information to the blockchain digital certificate management system. If the traditional method is adopted, the terminal needs to submit the certificate application materials to the CA organization, and the CA organization will issue the vehicle certificate after review. After that, the terminal or the car factory obtains the certificate from the CA organization, and finally configures the certificate to the Internet of Vehicles terminal. The process is long and it is difficult to achieve batch filling. Therefore, the proposed application method is simpler than the traditional method and can be mass-produced on the vehicle production line.
[0135] In summary, in the embodiment of the present invention, during the application process of the Internet of Vehicles terminal certificate and vehicle certificate, the Internet of Vehicles terminal certificate is generated by the equipment manufacturer itself, and then the equipment manufacturer publishes the certificate to the blockchain digital certificate management system. Therefore, the certificate can be generated and filled and configured simultaneously on the production line. In the traditional way, the Internet of Vehicles terminal certificate needs to be applied to the CA organization. After the CA organization approves and issues it, the equipment manufacturer needs to obtain the certificate from the CA organization before performing the filling and configuration operation. Compared with the traditional method, the embodiment of the present invention can greatly improve the efficiency of certificate configuration.
[0136] In order to more clearly describe the method for managing a digital certificate of an Internet of Vehicles provided by an embodiment of the present invention, an example is described below:
[0137] 1. Release of the Internet of Vehicles Terminal Certificate, which is used to identify the Internet of Vehicles Terminal; Figure 4 As shown, specifically including:
[0138] 1. The Internet of Vehicles terminal generates a public-private key pair, and uses the public-private key pair and the identity information of the Internet of Vehicles terminal to generate an Internet of Vehicles terminal certificate;
[0139] 2. The Internet of Vehicles terminal sends the Internet of Vehicles terminal certificate to the blockchain through the first certificate issuance request;
[0140] 3. The verification node in the blockchain digital certificate management system verifies the above-mentioned Internet of Vehicles terminal certificate;
[0141] 4. After verification, the blockchain digital certificate management system will record the above-mentioned Internet of Vehicles terminal certificate to be issued into the blockchain.
[0142] Second, the vehicle certificate is issued. The vehicle certificate is used to identify the vehicle and can also be called a registration certificate. This certificate can bind the identity of the Internet of Vehicles terminal with the vehicle information; Figure 5 As shown, specifically including:
[0143] 1. The Internet of Vehicles terminal generates a public-private key pair, and uses the public-private key pair and the vehicle and Internet of Vehicles terminal information to generate a vehicle certificate, where the vehicle and Internet of Vehicles terminal information includes the license plate number, frame number, OBU equipment identification number, etc., or the information after transformation (such as hash value) of this information.
[0144] 2. The Internet of Vehicles terminal sends a second certificate issuance request to the blockchain digital certificate management system. The request includes the vehicle certificate to be issued, the Internet of Vehicles terminal certificate, and the signature of the request using the private key corresponding to the Internet of Vehicles terminal certificate.
[0145] 3. The verification node in the blockchain digital certificate management system verifies the validity of the Internet of Vehicles terminal certificate; all verification nodes can verify the validity of the Internet of Vehicles terminal certificate by querying the certificate status in the blockchain;
[0146] 4. The verification node in the blockchain digital certificate management system verifies the correctness of the signature;
[0147] 5. The verification node in the blockchain digital certificate management system verifies the correctness of the vehicle and Internet of Vehicles terminal information; the correctness of the vehicle and Internet of Vehicles terminal information is verified by the second verification node (such as the vehicle factory node) and the third verification node (such as the vehicle management department node), where the second verification node can verify the correspondence between the frame number and the OBU equipment identification number, and the third verification node can verify the correspondence between the frame number and the license plate number.
[0148] 6. After verification, the blockchain digital certificate management system will record the above-mentioned vehicle certificate to be issued into the blockchain.
[0149] 3. Application for secure message certificate; Figure 6 As shown, specifically including:
[0150] 1. The Internet of Vehicles terminal sends a security message certificate application request to the CA, which includes the vehicle's identity information and signs the request using the private key corresponding to the vehicle certificate.
[0151] 2. After receiving the security message certificate application request, the CA agency queries the blockchain digital certificate system for the validity of the vehicle certificate;
[0152] 3. The CA verifies the correctness of the signature in the security message certificate application request.
[0153] 4. After successful verification, a security message certificate is issued to the Internet of Vehicles terminal;
[0154] 5. The CA sends the signed security message certificate to the Internet of Vehicles terminal through the certificate request response.
[0155] In summary, the method for managing digital certificates for the Internet of Vehicles provided by the embodiment of the present invention solves the problem of information non-intercommunication caused by the existence of multiple regulatory departments in the Internet of Vehicles. By introducing multiple verification nodes, different verification nodes are responsible for verifying the information belonging to the corresponding regulatory departments, thereby realizing unified application of certificates and improving the efficiency of application and configuration of vehicle network certificates; further establishing a trust relationship between multiple participants in the Internet of Vehicles, avoiding mutual trust issues between multiple CA institutions; avoiding duplicate construction of CA institutions and saving costs.
[0156] like Figure 7 As shown, an embodiment of the present invention further provides a management device for a digital certificate of an Internet of Vehicles, which is applied to a certificate authority center, including:
[0157] The first receiving module 71 is used to receive a security message certificate application request sent by a vehicle networking terminal, wherein the security message certificate application request includes: identity information of the vehicle where the vehicle networking terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the vehicle networking terminal is located;
[0158] An acquisition module 72, configured to acquire a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0159] The issuing module 73 is used to verify the signature of the security message certificate application request using the public key corresponding to the vehicle certificate, and issue a security message certificate to the Internet of Vehicles terminal after successful verification.
[0160] Optionally, in the above embodiment of the present invention, the acquisition module includes:
[0161] The first submodule is used to send a vehicle certificate query request to the blockchain digital certificate management node, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0162] The second submodule is used to receive the valid vehicle certificate of the vehicle sent by the blockchain digital certificate management node.
[0163] Optionally, in the above embodiment of the present invention, the vehicle certificate is used to identify the identity information of the vehicle;
[0164] or,
[0165] The vehicle certificate is also used to bind the identity information of the Internet of Vehicles terminal with the identity information of the vehicle.
[0166] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0167] It should be noted that the management device for the Internet of Vehicles digital certificate provided in the embodiment of the present invention is a device capable of executing the above-mentioned management method for the Internet of Vehicles digital certificate. All embodiments of the above-mentioned management method for the Internet of Vehicles digital certificate are applicable to the device and can achieve the same or similar beneficial effects.
[0168] like Figure 8 As shown, an embodiment of the present invention further provides a certificate authority, including a processor 800 and a transceiver 810, wherein the transceiver 810 receives and sends data under the control of the processor 800, and the processor 800 is used to perform the following operations:
[0169] Receive a security message certificate application request sent by a connected vehicle terminal, the security message certificate application request including: identity information of the vehicle where the connected vehicle terminal is located, and a signature of the security message certificate application request using a private key corresponding to a vehicle certificate of the vehicle where the connected vehicle terminal is located;
[0170] Obtaining a vehicle certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle;
[0171] The signature of the security message certificate application request is verified using the public key corresponding to the vehicle certificate, and a security message certificate is issued to the Internet of Vehicles terminal upon successful verification.
[0172] Optionally, in the above embodiment of the present invention, the processor 800 is further configured to perform the following operations:
[0173] Sending a vehicle certificate query request to a blockchain digital certificate management node, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0174] Receive the valid vehicle certificate of the vehicle sent by the blockchain digital certificate management node.
[0175] Optionally, in the above embodiment of the present invention, the vehicle certificate is used to identify the identity information of the vehicle;
[0176] or,
[0177] The vehicle certificate is also used to bind the identity information of the Internet of Vehicles terminal with the identity information of the vehicle.
[0178] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0179] It should be noted that the certificate authority provided in the embodiment of the present invention is a certificate authority that can execute the above-mentioned method for managing digital certificates for the Internet of Vehicles. All embodiments of the above-mentioned method for managing digital certificates for the Internet of Vehicles are applicable to the certificate authority and can achieve the same or similar beneficial effects.
[0180] An embodiment of the present invention also provides a communication device, which is a certificate authority, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the various processes in the embodiment of the method for managing digital certificates for the Internet of Vehicles as described above are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be described here.
[0181] The embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, each process in the embodiment of the method for managing a digital certificate of a connected vehicle network as described above is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0182] like Fig. 9 As shown, an embodiment of the present invention further provides a management device for a digital certificate of an Internet of Vehicles, which is applied to a blockchain digital certificate management node, including:
[0183] The second receiving module 91 is used to receive a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0184] The feedback module 92 is used to feedback the vehicle certificate of the vehicle to the certificate authority according to the identity information of the vehicle.
[0185] Optionally, in the above embodiment of the present invention, the device further includes:
[0186] The first module is configured to receive a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate;
[0187] The second module is used to verify the first certificate issuance request, and after successful verification, record the Internet of Vehicles terminal certificate into the blockchain;
[0188] The third module is used to receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate;
[0189] The fourth module is used to verify the second certificate issuance request, and after successful verification, record the vehicle certificate to the blockchain.
[0190] Optionally, in the above embodiment of the present invention, the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0191] Optionally, in the above embodiment of the present invention, the vehicle certificate is used to identify the identity information of the vehicle;
[0192] or,
[0193] The vehicle certificate is also used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0194] Optionally, in the above embodiment of the present invention, the fourth module includes:
[0195] The third submodule is used to verify the validity of the Internet of Vehicles terminal certificate;
[0196] A fourth submodule, configured to verify the signature of the second certificate issuance request using the public key corresponding to the Internet of Vehicles terminal certificate;
[0197] The fifth submodule is used to verify the correspondence between the identity information of the Internet of Vehicles terminal indicated by the vehicle certificate and the identity information of the vehicle.
[0198] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0199] It should be noted that the management device for the Internet of Vehicles digital certificate provided in the embodiment of the present invention is a device capable of executing the above-mentioned management method for the Internet of Vehicles digital certificate. All embodiments of the above-mentioned management method for the Internet of Vehicles digital certificate are applicable to the device and can achieve the same or similar beneficial effects.
[0200] like Fig.10 As shown, an embodiment of the present invention further provides a blockchain digital certificate management node, including a processor 100 and a transceiver 110, wherein the transceiver 110 receives and sends data under the control of the processor 100, and the processor 100 is used to perform the following operations:
[0201] Receiving a vehicle certificate query request sent by a certificate authority, wherein the vehicle certificate query request includes: identity information of the vehicle;
[0202] The vehicle certificate of the vehicle is fed back to the certificate authority according to the identity information of the vehicle.
[0203] Optionally, in the above embodiment of the present invention, the processor 100 is configured to perform the following operations:
[0204] Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate;
[0205] Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification;
[0206] Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate;
[0207] The second certificate issuance request is verified, and upon successful verification, the vehicle certificate is recorded in the blockchain.
[0208] Optionally, in the above embodiment of the present invention, the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0209] Optionally, in the above embodiment of the present invention, the vehicle certificate is used to identify the identity information of the vehicle;
[0210] or,
[0211] The vehicle certificate is also used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0212] Optionally, in the above embodiment of the present invention, the processor 100 is configured to perform the following operations:
[0213] Verifying the validity of the Internet of Vehicles terminal certificate;
[0214] Verifying the signature of the second certificate issuance request using the public key corresponding to the Internet of Vehicles terminal certificate;
[0215] The correspondence between the identity information of the Internet of Vehicles terminal indicated by the vehicle certificate and the identity information of the vehicle is verified.
[0216] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0217] It should be noted that the blockchain digital certificate management node provided in the embodiment of the present invention is a node that can execute the above-mentioned method for managing the digital certificate of the Internet of Vehicles. All embodiments of the above-mentioned method for managing the digital certificate of the Internet of Vehicles are applicable to the node and can achieve the same or similar beneficial effects.
[0218] An embodiment of the present invention also provides a communication device, which is a blockchain digital certificate management node, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the various processes in the embodiment of the method for managing digital certificates of the Internet of Vehicles as described above are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be repeated here.
[0219] The embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, each process in the embodiment of the method for managing a digital certificate of a connected vehicle network as described above is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0220] like Fig.11 As shown, an embodiment of the present invention further provides a management device for an Internet of Vehicles digital certificate, which is applied to an Internet of Vehicles terminal and includes:
[0221] The first sending module 110 is used to send a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0222] The third receiving module 111 is used to receive the security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0223] Optionally, in the above embodiment of the present invention, the device further includes:
[0224] A second sending module is used to send a first certificate issuance request to the blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate;
[0225] A third sending module is used to send a second certificate issuance request to the blockchain digital certificate management node, where the second certificate issuance request includes: a vehicle networking terminal certificate, a vehicle certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate;
[0226] Among them, the Internet of Vehicles terminal certificate and the vehicle certificate are recorded in the blockchain.
[0227] Optionally, in the above embodiment of the present invention, the device further includes:
[0228] The first generation module is used to generate the Internet of Vehicles terminal certificate according to the identity information of the Internet of Vehicles terminal and the public-private key pair of the Internet of Vehicles terminal; wherein the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0229] Optionally, in the above embodiment of the present invention, the device further includes:
[0230] A second generating module, configured to generate the vehicle certificate according to the identity information of the vehicle, the identity information of the vehicle networking terminal and the public and private key pair of the vehicle;
[0231] The vehicle certificate is used to identify the identity information of the vehicle; and / or the vehicle certificate is used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0232] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0233] It should be noted that the management device for the Internet of Vehicles digital certificate provided in the embodiment of the present invention is a device capable of executing the above-mentioned management method for the Internet of Vehicles digital certificate. All embodiments of the above-mentioned management method for the Internet of Vehicles digital certificate are applicable to the device and can achieve the same or similar beneficial effects.
[0234] like Fig.12 As shown, an embodiment of the present invention further provides a vehicle networking terminal, including a processor 1200 and a transceiver 1210. The vehicle networking terminal also includes a user interface 1220. The transceiver 1210 receives and sends data under the control of the processor 1200. The processor 1200 is used to perform the following operations:
[0235] Sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the vehicle certificate of the vehicle where the Internet of Vehicles terminal is located;
[0236] Receive a security message certificate issued by the certificate authority for the Internet of Vehicles terminal.
[0237] Optionally, in the above embodiment of the present invention, the processor 1200 is configured to perform the following operations:
[0238] Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate;
[0239] Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a vehicle certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate;
[0240] Among them, the Internet of Vehicles terminal certificate and the vehicle certificate are recorded in the blockchain.
[0241] Optionally, in the above embodiment of the present invention, the processor 1200 is configured to perform the following operations:
[0242] The Internet of Vehicles terminal certificate is generated according to the identity information of the Internet of Vehicles terminal and the public-private key pair of the Internet of Vehicles terminal; wherein the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
[0243] Optionally, in the above embodiment of the present invention, the processor 1200 is configured to perform the following operations:
[0244] Generate the vehicle certificate according to the identity information of the vehicle, the identity information of the Internet of Vehicles terminal and the public and private key pair of the vehicle;
[0245] The vehicle certificate is used to identify the identity information of the vehicle; and / or the vehicle certificate is used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
[0246] In summary, in the embodiment of the present invention, the Internet of Vehicles terminal first generates and publishes the Internet of Vehicles terminal certificate, and then generates a vehicle certificate and sends the vehicle certificate using the Internet of Vehicles terminal certificate. The vehicle certificate is verified by the blockchain digital certificate management node and then published to the blockchain; the Internet of Vehicles terminal uses the vehicle certificate to apply for a secure message certificate from the certificate authority, and the certificate authority verifies the vehicle certificate and signature and issues a secure message certificate to the Internet of Vehicles terminal; this solves the problem of information non-interoperability caused by the existence of multiple regulatory departments in the Internet of Vehicles.
[0247] It should be noted that the Internet of Vehicles terminal provided in the embodiment of the present invention is a Internet of Vehicles terminal capable of executing the above-mentioned Internet of Vehicles digital certificate management method. All embodiments of the above-mentioned Internet of Vehicles digital certificate management method are applicable to the Internet of Vehicles terminal and can achieve the same or similar beneficial effects.
[0248] An embodiment of the present invention also provides a communication device, which is a vehicle networking terminal, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the various processes in the embodiment of the vehicle networking digital certificate management method as described above are implemented, and the same technical effect can be achieved. To avoid repetition, they will not be repeated here.
[0249] The embodiment of the present invention also provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, each process in the embodiment of the method for managing a digital certificate of a connected vehicle network as described above is implemented, and the same technical effect can be achieved. To avoid repetition, it is not repeated here. The computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0250] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage and optical storage, etc.) containing computer-usable program code.
[0251] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A device that specifies functions in one or more processes and / or one or more blocks.
[0252] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable storage medium produce a paper product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0253] These computer program instructions may also be loaded onto a computer or other programmable data processing device so that the computer or other programmable device executes a series of operating steps to produce a computer-implemented process, thereby providing instructions executed on the computer or other programmable device for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1The steps for the functions specified in one or more boxes.
[0254] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for managing digital certificates for Internet of Vehicles, applied to a certificate authority, characterized in that: include: Receive a security message certificate application request sent by a connected vehicle terminal, the security message certificate application request including: identity information of the vehicle where the connected vehicle terminal is located, and a signature of the security message certificate application request using a private key corresponding to a registration certificate of the vehicle where the connected vehicle terminal is located; Obtaining the vehicle's registration certificate from a blockchain digital certificate management node based on the vehicle's identity information; Using the public key corresponding to the registration certificate to verify the signature of the security message certificate application request, and issuing a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The blockchain digital certificate management node is used to: Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
2. The method according to claim 1, characterized in that The obtaining, according to the identity information of the vehicle, a registration certificate of the vehicle from a blockchain digital certificate management node comprises: Sending a registration certificate query request to a blockchain digital certificate management node, wherein the registration certificate query request includes: identity information of the vehicle; Receive the valid registration certificate of the vehicle sent by the blockchain digital certificate management node.
3. The method according to claim 1 or 2, characterized in that: The registration certificate is used to identify the identity information of the vehicle; or, The registration certificate is also used to bind the identity information of the Internet of Vehicles terminal with the identity information of the vehicle.
4. A method for managing digital certificates of Internet of Vehicles, applied to a blockchain digital certificate management node, characterized in that: include: Receiving a vehicle registration certificate query request sent by a certificate authority, wherein the registration certificate query request includes: identity information of the vehicle; Feedback the registration certificate of the vehicle to the certificate authority based on the identity information of the vehicle; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; Before receiving the registration certificate query request sent by the certificate authority, the method further includes: Receiving a first certificate issuance request sent by a vehicle networking terminal, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
5. The method according to claim 4, characterized in that The Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
6. The method according to claim 4, characterized in that The registration certificate is used to identify the identity information of the vehicle; or, The registration certificate is also used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
7. The method according to claim 6, characterized in that The verifying the second certificate issuance request includes: Verifying the validity of the Internet of Vehicles terminal certificate; Verifying the signature of the second certificate issuance request using the public key corresponding to the Internet of Vehicles terminal certificate; The correspondence between the identity information of the Internet of Vehicles terminal indicated by the registration certificate and the identity information of the vehicle is verified.
8. A method for managing digital certificates of Internet of Vehicles, applied to Internet of Vehicles terminals, characterized in that: include: Sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the registration certificate of the vehicle where the Internet of Vehicles terminal is located; Receiving a security message certificate issued by the certificate authority for the Internet of Vehicles terminal; The certificate authority is used to obtain the registration certificate of the vehicle from the blockchain digital certificate management node according to the identity information of the vehicle; use the public key corresponding to the registration certificate to verify the signature of the security message certificate application request, and issue a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The method further comprises: Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a registration certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate; Among them, the Internet of Vehicles terminal certificate and the registration certificate are recorded in the blockchain.
9. The method according to claim 8, characterized in that The method further comprises: The Internet of Vehicles terminal certificate is generated according to the identity information of the Internet of Vehicles terminal and the public-private key pair of the Internet of Vehicles terminal; wherein the Internet of Vehicles terminal certificate is used to identify the identity information of the Internet of Vehicles terminal.
10. The method according to claim 8, characterized in that The method further comprises: Generate the registration certificate based on the identity information of the vehicle, the identity information of the Internet of Vehicles terminal, and the public and private key pair of the vehicle; The registration certificate is used to identify the identity information of the vehicle; and / or the registration certificate is used to bind the corresponding relationship between the identity information of the Internet of Vehicles terminal and the identity information of the vehicle.
11. A management device for digital certificates of Internet of Vehicles, applied to a certificate authority, characterized in that: include: A first receiving module is used to receive a security message certificate application request sent by a vehicle networking terminal, wherein the security message certificate application request includes: identity information of the vehicle where the vehicle networking terminal is located, and a signature of the security message certificate application request using a private key corresponding to a registration certificate of the vehicle where the vehicle networking terminal is located; An acquisition module, used to obtain the registration certificate of the vehicle from a blockchain digital certificate management node according to the identity information of the vehicle; An issuing module, used to verify the signature of the security message certificate application request using the public key corresponding to the registration certificate, and issue a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The blockchain digital certificate management node is used to: Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
12. A certificate authority, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, characterized in that: The processor is configured to perform the following operations: Receive a security message certificate application request sent by a connected vehicle terminal, the security message certificate application request including: identity information of the vehicle where the connected vehicle terminal is located, and a signature of the security message certificate application request using a private key corresponding to a registration certificate of the vehicle where the connected vehicle terminal is located; Obtaining the vehicle's registration certificate from a blockchain digital certificate management node based on the vehicle's identity information; Using the public key corresponding to the registration certificate to verify the signature of the security message certificate application request, and issuing a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The blockchain digital certificate management node is used to: Receiving a first certificate issuing request sent by the Internet of Vehicles terminal, wherein the first certificate issuing request includes: an Internet of Vehicles terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
13. A management device for digital certificates of Internet of Vehicles, applied to a blockchain digital certificate management node, characterized in that: include: A second receiving module is used to receive a vehicle registration certificate query request sent by a certificate authority, wherein the registration certificate query request includes: identity information of the vehicle; A feedback module, used for feeding back the registration certificate of the vehicle to the certificate authority according to the identity information of the vehicle; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The management device is further used for: Receiving a first certificate issuance request sent by a vehicle networking terminal, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
14. A blockchain digital certificate management node, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, characterized in that: The processor is configured to perform the following operations: Receiving a vehicle registration certificate query request sent by a certificate authority, wherein the registration certificate query request includes: identity information of the vehicle; Feedback the registration certificate of the vehicle to the certificate authority based on the identity information of the vehicle; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The management node is also used for: Receiving a first certificate issuance request sent by a vehicle networking terminal, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Verifying the first certificate issuance request, and recording the Internet of Vehicles terminal certificate to the blockchain after successful verification; Receive a second certificate issuance request sent by the Internet of Vehicles terminal, where the second certificate issuance request includes: the Internet of Vehicles terminal certificate, the registration certificate of the vehicle where the Internet of Vehicles terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the Internet of Vehicles terminal certificate; The second certificate issuance request is verified, and upon successful verification, the registration certificate is recorded in the blockchain.
15. A management device for a digital certificate of an Internet of Vehicles, applied to an Internet of Vehicles terminal, characterized in that: include: A first sending module is used to send a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to a registration certificate of the vehicle where the Internet of Vehicles terminal is located; A third receiving module is used to receive a security message certificate issued by the certificate authority for the Internet of Vehicles terminal; The certificate authority is used to obtain the registration certificate of the vehicle from the blockchain digital certificate management node according to the identity information of the vehicle; use the public key corresponding to the registration certificate to verify the signature of the security message certificate application request, and issue a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The management device is further used for: Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a registration certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate; Among them, the Internet of Vehicles terminal certificate and the registration certificate are recorded in the blockchain.
16. A vehicle networking terminal, comprising a processor and a transceiver, wherein the transceiver receives and sends data under the control of the processor, characterized in that: The processor is configured to perform the following operations: Sending a security message certificate application request to a certificate authority, wherein the security message certificate application request includes: identity information of the vehicle where the Internet of Vehicles terminal is located, and a signature of the security message certificate application request using a private key corresponding to the registration certificate of the vehicle where the Internet of Vehicles terminal is located; Receiving a security message certificate issued by the certificate authority for the Internet of Vehicles terminal; The certificate authority is used to obtain the registration certificate of the vehicle from the blockchain digital certificate management node according to the identity information of the vehicle; use the public key corresponding to the registration certificate to verify the signature of the security message certificate application request, and issue a security message certificate to the Internet of Vehicles terminal after successful verification; The registration certificate is jointly generated by the Internet of Vehicles terminal according to the Internet of Vehicles terminal certificate and vehicle information, wherein the Internet of Vehicles terminal certificate is used to identify the terminal identity; The terminal is used for: Sending a first certificate issuance request to a blockchain digital certificate management node, wherein the first certificate issuance request includes: a vehicle networking terminal certificate; Sending a second certificate issuance request to the blockchain digital certificate management node, wherein the second certificate issuance request includes: a vehicle networking terminal certificate, a registration certificate of the vehicle where the vehicle networking terminal is located, and a signature of the second certificate issuance request using a private key corresponding to the vehicle networking terminal certificate; Among them, the Internet of Vehicles terminal certificate and the registration certificate are recorded in the blockchain.
17. A communication device comprising a memory, a processor, and a program stored in the memory and executable on the processor; characterized in that: When the processor executes the program, it implements the method for managing the digital certificate of the Internet of Vehicles as described in any one of claims 1-3; or, when the processor executes the program, it implements the method for managing the digital certificate of the Internet of Vehicles as described in any one of claims 4-7; or, when the processor executes the program, it implements the method for managing the digital certificate of the Internet of Vehicles as described in any one of claims 8-10.
18. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by the processor, it implements the steps in the method for managing digital certificates for the Internet of Vehicles as described in any one of claims 1-3; or, when the program is executed by the processor, it implements the steps in the method for managing digital certificates for the Internet of Vehicles as described in any one of claims 4-7; or, when the program is executed by the processor, it implements the steps in the method for managing digital certificates for the Internet of Vehicles as described in any one of claims 8-10.
Citation Information
Patent Citations
Method for realizing authorization management of vehicle networking device, device and systems
CN103986687A
CA authentication method and device for vehicle equipment and Internet of Vehicles information management system
CN109495498A