A certificate authorization processing method based on Internet of Vehicles and related equipment
By adding network device interfaces to the cellular Internet of Vehicle Certificate Authorization Management System, the authorization certificate management of V2X devices is solved, and the problem that legal departments cannot control certificate authorization is improved, and the security of the system and user privacy protection are improved.
Patent Information
- Application Number
- CN202010622188.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-06-30
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2040-09-11
AI Technical Summary
In the existing cellular Internet of Vehicle Certificate Authorization Management System, V2X devices cannot be effectively controlled by legal departments when applying for authorization certificates, and there are risks that cannot be controlled.
By adding an interface between the first network device and the second network device, the second network device is used to control the interactive behavior of the application and update of the authorization certificate of the V2X device, and prevent illegal operations without authorization.
The legal department of V2X equipment controls certificate authorization, protects user privacy, and prevents V2X equipment from being illegally tracked.
Smart Images

Figure CN114095919B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of Internet of Vehicles, and in particular to a certificate authorization processing method based on Internet of Vehicles and related equipment. Background Art
[0002] At present, in the basic workflow of the Certificate Authority (CA) management system for cellular vehicle wireless communication technology (C-V2X, Cellular-Vehicle to everything) (referred to as cellular vehicle networking), V2X devices further apply for authorization certificates based on the registration certificates obtained in the initial stage. After obtaining the registration certificate, the V2X device can interact with the authorization certificate registration authority or other third-party applications with the registration certificate to obtain authorized digital certificates or carry out various third-party applications. These applications are not controlled by the legal departments of the V2X devices, and risks cannot be controlled once they occur. Summary of the invention
[0003] In order to solve the existing technical problems, an embodiment of the present invention provides a certificate authorization processing method based on the Internet of Vehicles and related equipment.
[0004] To achieve the above object, the technical solution of the embodiment of the present invention is implemented as follows:
[0005] In a first aspect, an embodiment of the present invention provides a certificate authorization processing method based on an Internet of Vehicles, the method comprising:
[0006] The first network device receives a first message from the V2X device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier;
[0007] Sending a second message to a second network device; the second message includes the temporary identifier; the second message is used to apply for review authorization for the service request;
[0008] A second response message sent by the second network device is obtained, where the second response message is used to indicate whether the audit authorization is successful.
[0009] In the above solution, the first message also includes user identity information.
[0010] In the above solution, the user identity information is encrypted based on the fifth key.
[0011] In the above solution, the first message is encrypted and / or integrity protected based on the first key and the second key;
[0012] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key;
[0013] Correspondingly, the first network device performs integrity protection verification and / or decryption on the first message based on the second key and the first key, and applies for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0014] In the above solution, the first message is encrypted and / or integrity protected based on the first key;
[0015] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key;
[0016] Correspondingly, the first network device performs integrity protection verification and / or decryption on the first message based on the first key, and applies for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0017] In the above solution, when the second response message indicates that the authorization review is successful, the second response message also includes a third key; the method further includes:
[0018] Based on the third key, identity authentication is performed between the first network device and the V2X device.
[0019] In the above scheme, when the second response message indicates that the authorization review is successful, the second response message also includes a fourth key; the method also includes: based on the fourth key, establishing a secure transmission channel between the first network device and the V2X device.
[0020] In the above scheme, the method also includes: the first network device sends a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on the first key and the second key, or the first response message is encrypted and / or integrity protected based on the first key; the first response message includes authorization certificate related information.
[0021] In the above scheme, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes the download time of the application certificate;
[0022] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
[0023] In the above solution, the sending a first response message to the V2X device includes:
[0024] The first network device directly sends a first response message to the V2X device; or,
[0025] The first network device sends a first response message to the V2X device after forwarding.
[0026] In the above solution, the first network device receives a first message from the V2X device, including:
[0027] The first network device receives a first message directly sent by the V2X device; or,
[0028] The first network device receives a forwarded first message from the V2X device.
[0029] In a second aspect, an embodiment of the present invention further provides a certificate authorization processing method based on the Internet of Vehicles, the method comprising:
[0030] The second network device receives a second message sent by the first network device; the second message includes a temporary identifier; the second message is used to apply for review and authorization for the service request; the service request is sent by the V2X device to the first network device;
[0031] Performing authorization verification based on the temporary identifier;
[0032] A second response message is sent to the first network device, where the second response message is used to indicate whether the authorization review is successful.
[0033] In the above solution, the second message also includes user identity information.
[0034] In the above solution, the user identity information is encrypted based on the fifth key;
[0035] The performing authorization verification based on the temporary identifier includes:
[0036] A fifth key is generated based on the temporary identifier, the user identity information is decrypted using the fifth key, and an authorization check is performed.
[0037] In the above solution, the generating the fifth key based on the temporary identifier includes:
[0038] A shared symmetric key corresponding to the V2X device is obtained based on the temporary identifier, and at least the fifth key is generated based on the shared symmetric key.
[0039] In the above solution, the method further comprises: generating at least a first key and a second key based on the shared symmetric key;
[0040] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
[0041] In the above solution, the method further comprises: generating at least a first key based on the shared symmetric key;
[0042] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
[0043] In the above solution, the method further includes: generating a third key based on the shared symmetric key, the third key being used for identity authentication between the first network device and the V2X device;
[0044] When the second response message indicates that the authorization review is successful, the second response message also includes the third key.
[0045] In the above solution, the method further includes: generating a fourth key based on the shared symmetric key, the fourth key being used to establish a secure transmission channel between the first network device and the V2X device;
[0046] When the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
[0047] In a third aspect, an embodiment of the present invention further provides a certificate authorization processing method based on the Internet of Vehicles, the method comprising:
[0048] The V2X device sends a first message to the first network device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier.
[0049] In the above solution, the first message also includes user identity information.
[0050] In the above solution, the user identity information is encrypted based on a fifth key; and the fifth key is generated based on a shared symmetric key.
[0051] In the above solution, before the V2X device sends the first message to the first network device, the method further includes:
[0052] The V2X device generates at least a first key and a second key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
[0053] In the above solution, before the V2X device sends the first message to the first network device, the method further includes:
[0054] The V2X device generates at least a first key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key.
[0055] In the above solution, the method further includes: the V2X device generates a third key based on the shared symmetric key, and based on the third key, the V2X device performs identity authentication with the first network device.
[0056] In the above solution, the method further includes: the V2X device generates a fourth key based on the shared symmetric key, and based on the fourth key, establishes a secure transmission channel between the V2X device and the first network device.
[0057] In the above solution, the method further includes: the V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; the first response message includes authorization certificate related information;
[0058] The first response message is integrity checked and / or decrypted based on the second key and the first key, and the authorization certificate related information is obtained based on the first response message that has passed the integrity check and / or decryption.
[0059] In the above solution, the method further includes: the V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on a first key; the first response message includes information related to the authorization certificate;
[0060] The first response message is integrity checked and / or decrypted based on the first key, and the authorization certificate related information is obtained based on the first response message that has passed the integrity check and / or decryption.
[0061] In the above scheme, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate; or, the authorization certificate related information includes a download time of the application certificate; the method further includes: the V2X device downloading the application certificate according to the download time;
[0062] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes a download time of the pseudonym certificate; the method further includes: the V2X device downloading the pseudonym certificate according to the download time.
[0063] In the above solution, the V2X device receives the first response message sent by the first network device, including:
[0064] The V2X device receives a first response message directly sent by the first network device; or,
[0065] The V2X device receives the forwarded first response message from the first network device.
[0066] In the above solution, the V2X device sends the first message to the first network device, including:
[0067] The V2X device directly sends the first message to the first network device; or,
[0068] The V2X device sends the first message to the first network device after forwarding.
[0069] In a fourth aspect, an embodiment of the present invention further provides a network device, wherein the network device is a first network device, and the network device comprises: a first communication unit and a second communication unit; wherein,
[0070] The first communication unit is used to receive a first message from a V2X device; the first message is used to indicate a service request related to an authorization certificate; the first message includes a temporary identifier;
[0071] The second communication unit is used to send a second message to a second network device; the second message includes the temporary identifier; the second message is used to apply for an audit authorization for the service request; and is also used to obtain a second response message sent by the second network device, the second response message is used to indicate whether the audit authorization is successful.
[0072] In the above solution, the first message also includes user identity information.
[0073] In the above solution, the user identity information is encrypted based on the fifth key.
[0074] In the above solution, the first message is encrypted and / or integrity protected based on the first key and the second key;
[0075] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key;
[0076] The network device also includes a first processing unit, which is used to perform integrity protection verification and / or decryption on the first message based on the second key and the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0077] In the above solution, the first message is encrypted and / or integrity protected based on the first key;
[0078] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key;
[0079] The network device also includes a first processing unit, which is used to perform integrity protection verification and / or decryption on the first message based on the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0080] In the above solution, when the second response message indicates that the authorization review is successful, the second response message also includes a third key;
[0081] The network device also includes a first processing unit, configured to perform identity authentication with the V2X device based on the third key.
[0082] In the above solution, when the second response message indicates that the authorization review is successful, the second response message also includes a fourth key;
[0083] The network device also includes a first processing unit, configured to establish a secure transmission channel with the V2X device based on the fourth key.
[0084] In the above scheme, the first communication unit is also used to send a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on the first key and the second key, or the first response message is encrypted and / or integrity protected based on the first key; the first response message includes information related to the authorization certificate.
[0085] In the above scheme, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes the download time of the application certificate;
[0086] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
[0087] In the above solution, the first communication unit is used to send the first response message directly to the V2X device; or send the first response message to the V2X device through forwarding.
[0088] In the above solution, the first communication unit is used to receive a first message directly sent by the V2X device; or to receive a forwarded first message from the V2X device.
[0089] In a fifth aspect, an embodiment of the present invention further provides a network device, the network device is a second network device, and the network device includes: a fourth communication unit and a second processing unit; wherein,
[0090] The fourth communication unit is used to receive a second message sent by the first network device; the second message includes a temporary identifier; the second message is used to apply for review and authorization for the service request; the service request is sent by the V2X device to the first network device;
[0091] The second processing unit is configured to perform authorization verification based on the temporary identifier;
[0092] The fourth communication unit is further used to send a second response message to the first network device, where the second response message is used to indicate whether the authorization review is successful.
[0093] In the above solution, the second message also includes user identity information.
[0094] In the above solution, the user identity information is encrypted based on the fifth key;
[0095] The second processing unit is used to generate a fifth key based on the temporary identifier, decrypt the user identity information using the fifth key, and perform authorization verification.
[0096] In the above solution, the second processing unit is used to obtain the shared symmetric key corresponding to the V2X device based on the temporary identifier, and generate at least the fifth key based on the shared symmetric key.
[0097] In the above solution, the second processing unit is further used to generate at least a first key and a second key based on the shared symmetric key;
[0098] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
[0099] In the above solution, the second processing unit is further used to generate at least a first key based on the shared symmetric key;
[0100] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
[0101] In the above solution, the second processing unit is further used to generate a third key based on the shared symmetric key, and the third key is used for identity authentication between the first network device and the V2X device;
[0102] When the second response message indicates that the authorization review is successful, the second response message also includes the third key.
[0103] In the above solution, the second processing unit is further used to generate a fourth key based on the shared symmetric key, and the fourth key is used to establish a secure transmission channel between the first network device and the V2X device;
[0104] When the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
[0105] In a sixth aspect, an embodiment of the present invention further provides a V2X device, wherein the V2X device comprises a fifth communication unit, configured to send a first message to a first network device; the first message is used to represent a service request related to an authorization certificate; and the first message includes a temporary identifier.
[0106] In the above solution, the first message also includes user identity information.
[0107] In the above solution, the user identity information is encrypted based on a fifth key; and the fifth key is generated based on a shared symmetric key.
[0108] In the above scheme, the V2X device also includes a third processing unit, which is used to generate at least a first key and a second key based on a shared symmetric key before the fifth communication unit sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
[0109] In the above scheme, the V2X device also includes a third processing unit, which is used to generate at least a first key based on a shared symmetric key before the fifth communication unit sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key.
[0110] In the above solution, the V2X device also includes a third processing unit, which is used to generate a third key based on the shared symmetric key, and perform identity authentication with the first network device based on the third key.
[0111] In the above solution, the V2X device also includes a third processing unit, which is used to generate a fourth key based on the shared symmetric key, and establish a secure transmission channel with the first network device based on the fourth key.
[0112] In the above solution, the V2X device further includes a third processing unit;
[0113] The fifth communication unit is further used to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; the first response message includes authorization certificate related information;
[0114] The third processing unit is used to perform integrity protection verification and / or decryption on the first response message based on the second key and the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection verification and / or decryption.
[0115] In the above solution, the V2X device further includes a third processing unit;
[0116] The fifth communication unit is further used to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key; the first response message includes authorization certificate related information;
[0117] The third processing unit is used to perform integrity protection verification and / or decryption on the first response message based on the first key, and obtain the authorization certificate related information based on the first response message that passes the integrity protection verification and / or decryption.
[0118] In the above scheme, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate; the third processing unit is further used to download the application certificate according to the download time;
[0119] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes a download time of the pseudonym certificate; and the third processing unit is further configured to download the pseudonym certificate according to the download time.
[0120] In the above solution, the fifth communication unit is used to receive the first response message directly sent by the first network device; or to receive the first response message forwarded from the first network device.
[0121] In the above scheme, the fifth communication unit is used to send the first message directly to the first network device; or, send the first message to the first network device after forwarding.
[0122] In the seventh aspect, an embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect, the second aspect or the third aspect of the embodiment of the present invention.
[0123] In an eighth aspect, an embodiment of the present invention further provides a network device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method described in the first or second aspect of the embodiment of the present invention are implemented.
[0124] In a ninth aspect, an embodiment of the present invention further provides a V2X device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of the method described in the third aspect of the embodiment of the present invention are implemented.
[0125] The certificate authorization processing method based on the Internet of Vehicles and related equipment provided by the embodiment of the present invention include: a first network device receives a first message from a V2X device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier; a second message is sent to a second network device; the second message includes the temporary identifier; the second message is used to apply for an audit authorization for the service request; and a second response message is obtained from the second network device, the second response message being used to indicate whether the audit authorization is successful. The technical solution of the embodiment of the present invention is adopted, by adding an interface between the first network device and the second network device, and by implementing an authorization audit of the V2X device application for the service request through the second network device, the control of the certificate authorization by the legal department of the V2X device is realized. BRIEF DESCRIPTION OF THE DRAWINGS
[0126] Figure 1 It is a schematic diagram of the architecture of the Internet of Vehicles certificate management system in the relevant technical solution;
[0127] Figure 2 A schematic diagram of a system architecture for an application of a certificate authorization processing method based on Internet of Vehicles according to an embodiment of the present invention;
[0128] Figure 3 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 1 ;
[0129] Figure 4 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 2 ;
[0130] Figure 5 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 3 ;
[0131] Figure 6 A schematic diagram of an interactive process of a certificate authorization processing method based on Internet of Vehicles according to an embodiment of the present invention;
[0132] Figure 7 The structure diagram of the network device according to the embodiment of the present invention is shown in FIG. Figure 1 ;
[0133] Figure 8 The structure diagram of the network device according to the embodiment of the present invention is shown in FIG. Figure 2 ;
[0134] Fig. 9 Schematic diagram of the composition structure of a V2X device according to an embodiment of the present invention;
[0135] Fig.10 The figure is a schematic diagram of the hardware structure of the communication device according to the embodiment of the present invention. DETAILED DESCRIPTION
[0136] The present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0137] In order to achieve secure authentication and secure communication between V2X devices such as on-board units (OBU) and road-side units (RSU), the C-V2X system has explicitly adopted a public key infrastructure (PKI) mechanism based on public key certificates to ensure the security of direct communication between V2X devices, such as vehicle-to-vehicle (V2V) / vehicle-to-infrastructure (V2I) / vehicle-to-pedestrians (V2P). The PKI-based CA management system manages various types of digital certificates such as registration and authorization used on V2X devices such as OBU and RSU, and completes operations such as certificate issuance, downloading, and revocation in accordance with the process. At present, examples of CA management system architectures that are generally recognized by the industry include: Figure 1 According to the different specific technologies used in the implementation, the Authentication & Authorization Authority (AAA) system can have three different implementation modes: Device Configuration Manager (DCM), General Bootstrapping Architecture (GBA), and OAuth.
[0138] Reference Figure 1 The system architecture shown in the figure can include the following basic workflows of the CA management system:
[0139] 1. In the initial stage, OBU, RSU and other V2X devices, as the certificate application subject, apply for a registration certificate from the Enrolment Certificate Authority (ECA) through the AAA system. After AAA successfully authenticates the V2X device, ECA issues a registration certificate to the V2X device. After that, the V2X device is ready to apply to the authorized certificate authority to obtain an authorization certificate for various applications.
[0140] 2. The V2X device uses the registration certificate to apply for authorization of relevant application functions from the authorized certificate registration authority (including the Pseudonym Certificate Registration Authority (PRA) and / or the Application Certificate Registration Authority (ARA)).
[0141] 3. The Authorized Certificate Registration Authority (PRA and / or ARA) checks the registration certificate of the V2X device, verifies the identity of the V2X device, and further applies for the relevant authorization certificate from the authorized certificate issuing authority (including the Pseudonym Certificate Authority (PCA) or the Application Certificate Authority (ACA)) according to the scope of authority given in the registration certificate, and issues it to the V2X device. The authorization certificate describes the applications, functions and security operations that the device can carry out.
[0142] 4. V2X devices use authorization certificates and their corresponding public and private keys to sign, verify signatures, or encrypt and decrypt messages to ensure the security of V2X message transmission.
[0143] From the above process, it can be seen that the application for the above authorization certificate is carried out independently between the V2X device and the authorization certificate authority. The process of remote download, update and data interaction of the V2X device is completely unknown to the legal management department of the V2X device (such as automobile manufacturers, transportation infrastructure management departments, industry regulatory agencies, etc.) and is not controlled by the management department. This will cause the problem that the V2X device cannot be tracked and managed after deployment.
[0144] Based on this, the following embodiments of the present invention are proposed.
[0145] Figure 2 Schematic diagram of the system architecture of the certificate authorization processing method based on the Internet of Vehicles according to an embodiment of the present invention; Figure 2As shown, in the embodiment of the present invention, an interface is added between AAA and the authorization certificate registration authority (such as PRA / ARA) to control the interactive behaviors of the authorization certificate application, update and other operations of the V2X device to prevent unauthorized illegal operations. At the same time, the interface is used to extract the privacy information related to the user identity of the V2X device, so that the authorization certificate registration authority cannot obtain the real identity and pseudonym identity information of the V2X device at the same time, thereby preventing the security risk of the user vehicle corresponding to the V2X device being illegally tracked by the authorization certificate registration authority and protecting user privacy.
[0146] The embodiment of the present invention provides a certificate authorization processing method based on the Internet of Vehicles, which is applied to a first network device, which may be the aforementioned Figure 2 The authorized certificate registration authority in, exemplarily, the first network device may be, for example, a PRA and / or an ARA. Figure 3 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 1 ;like Figure 3 As shown, the method includes:
[0147] Step 101: A first network device receives a first message from a V2X device; the first message is used to indicate a service request related to an authorization certificate; the first message includes a temporary identifier;
[0148] Step 102: Send a second message to a second network device; the second message includes the temporary identifier; the second message is used to apply for review authorization for the service request;
[0149] Step 103: Obtain a second response message sent by the second network device, where the second response message is used to indicate whether the audit authorization is successful.
[0150] In this embodiment, based on the above Figure 2 In the system architecture shown, the first network device may be an authorization certificate registration authority, and the authorization certificate registration authority may be, for example, a PRA and / or an ARA. Correspondingly, the second network device may be an authentication authority (AAA). According to different application scenarios, the AAA system may be implemented in a variety of ways, such as a DCM service system, a GBA authentication and authorization system, or an OAuth authorization service system. In some examples, the first network device may be a DCM service system, a GBA authentication and authorization system, or an OAuth authorization service system. In the following embodiments, the first network device may be a GBA authentication and authorization system as an example for illustration.
[0151] In this embodiment, the first message may be an authorization certificate application request or an authorization certificate update request from the V2X device. In some examples, the V2X device may issue an authorization certificate application request when it does not have an authorization certificate. In other examples, the V2X device may issue an authorization certificate update request when its own authorization certificate is invalid or expired.
[0152] In some optional embodiments, the first message includes a temporary identifier; the temporary identifier is an identifier corresponding to the V2X device. It can be understood that the temporary identifier can be used to identify the V2X device.
[0153] In some optional embodiments, the first message also includes user identity information. In one example, the user identity information may be unencrypted user identity information; in another example, the user identity information is encrypted based on a fifth key. The fifth key used to encrypt the user identity information is generated by the V2X device.
[0154] In one example, the user identity information may also be referred to as user privacy information, or privacy information related to the user identity, etc. Exemplarily, the user identity information may include: information such as vehicle and / or device identification numbers related to the user identity, a previously obtained registration certificate (such as the registration certificate obtained in the aforementioned step 1), etc. In another example, the user identity information may also include device description information related to the device and / or vehicle.
[0155] Referring to the basic workflow of the aforementioned CA management system, it can be seen that the V2X device needs to send relevant information containing user identity privacy (such as registration certificates) to PRA and / or ARA for identity and authority scope review and verification, and this information contains the real identity information of the V2X device. In the case where the pseudonym certificate is not encrypted, PRA can simultaneously obtain the user identity information and pseudonym certificate information of the V2X device, which will enable PRA to associate the real identity of the V2X device with the pseudonym identity information, thereby tracking the V2X device.
[0156] However, the present application can encrypt and protect the user identity information through the fifth key. The first network device (such as PRA) cannot obtain the decrypted user identity information. The user identity information can only be known at the second network device. The user's real identity and pseudonymous identity are separated at the first network device (such as PRA), thereby protecting the user's privacy and achieving tracking and control.
[0157] In some optional embodiments of the present invention, the first network device receives a first message from a V2X device, including: the first network device receives a first message directly sent by the V2X device; or the first network device receives a forwarded first message from the V2X device.
[0158] In this embodiment, refer to Figure 2 In the example shown, taking the first network device as the authorized certificate registration authority and the second network device as the certification authority as an example, the first network device can obtain the first message directly sent by the certificate application subject (such as OBU and / or RSU) as the V2X device, or the first network device can also obtain the first message sent by the certificate application subject (such as OBU and / or RSU) as the V2X device and forwarded by the second network device through the interface between the first network device and the second network device.
[0159] In this embodiment, the first network device sends a second message to the second network device, and the second message includes the temporary identifier, or the second message includes the temporary identifier and user identity information. Wherein, based on the foregoing, the user identity information included in the second message can be unencrypted user identity information, or can be user identity information encrypted based on the fifth key. It can be understood that the second message also includes relevant information for applying for authorization review of the service request, so as to perform authorization review on the content carried in the second message through the second network device. Furthermore, the first network device obtains a second response message sent by the second network device; when the authorization review of the second network device is successful, the obtained second response message is used to indicate that the review authorization is successful; when the authorization review of the second network device is unsuccessful, the obtained second response message is used to indicate that the review authorization failed.
[0160] In some optional embodiments of the present invention, the first message is encrypted and / or integrity protected based on a first key and a second key; when the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key; accordingly, the first network device performs integrity protection verification and / or decryption on the first message based on the second key and the first key, and applies for an authorization certificate based on the first message that has passed the integrity protection verification and / or decryption.
[0161] In one example of the present invention, the V2X device may use the first key and the second key to encrypt and integrity protect the first message respectively during the process of generating the first message; in another example of the present invention, the V2X device may use the first key and the second key to encrypt or integrity protect the first message during the process of generating the first message.
[0162] In some optional embodiments of the present invention, the first message is encrypted and / or integrity protected based on a first key; when the second response message indicates that the authorization review is successful, the second response message includes at least the first key; accordingly, the first network device performs integrity protection verification and / or decryption on the first message based on the first key, and applies for an authorization certificate based on the first message that has passed the integrity protection verification and / or decryption.
[0163] In one example of the present invention, the V2X device may use the first key to encrypt and integrity protect the first message during the process of generating the first message; in another example of the present invention, the V2X device may use the first key to encrypt or integrity protect the first message during the process of generating the first message.
[0164] Moreover, in the present embodiment, the user identity information is encrypted for protection (specifically, the user identity information is encrypted using the fifth key). After the first network device obtains the first message, it is unable to decrypt and obtain the user identity information carried in the first message. The user identity information can only be obtained at the second network device. The separation of the user's real identity and pseudonymous identity is achieved at the first network device, thereby protecting the user's privacy and achieving authorization control.
[0165] In some optional embodiments of the present invention, when the second response message indicates that the authorization review is successful, the second response message also includes a third key; the method also includes: based on the third key, performing identity authentication between the first network device and the V2X device.
[0166] Exemplarily, a message for identity authentication may be transmitted between the first network device and the V2X device, and the message may be encrypted using a third key, so that the first network device and the V2X device may decrypt the message using the third key, thereby performing identity authentication.
[0167] In some optional embodiments of the present invention, when the second response message indicates that the authorization review is successful, the second response message also includes a fourth key; the method also includes: based on the fourth key, establishing a secure transmission channel between the first network device and the V2X device.
[0168] Exemplarily, a message for establishing a secure transmission channel can be transmitted between the first network device and the V2X device, and the message is encrypted by a fourth key so that the first network device and the V2X device can decrypt the message by the fourth key, thereby establishing a secure transmission channel.
[0169] In some optional embodiments of the present invention, the method also includes: the first network device sends a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on the first key and the second key, or the first response message is encrypted and / or integrity protected based on the first key; the first response message includes information related to the authorization certificate.
[0170] In this embodiment, refer to Figure 2 In the system architecture example shown, when the first network device is an authorization certificate registration authority, the first network device can apply for relevant application function authorization through an authorization certificate issuing authority (such as PCA / ACA), obtain authorization certificate related information, and send the authorization certificate related information to the V2X device through a first response message.
[0171] In one example, the first response message may be encrypted and integrity protected based on the first key and the second key, respectively; in another example, the first response message may be encrypted or integrity protected based on the first key and the second key.
[0172] Exemplarily, in the case where the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes the download time of the application certificate; in the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
[0173] It can be understood that in the scenario of application certificate application, in one embodiment, the first network device can obtain the issued application certificate from the authorized certificate issuing agency (specifically, it can be ACA), and send the obtained application certificate to the V2X device through a first response message; in another embodiment, the first network device can inform the V2X device of the download time of the application certificate through the first response message; within this time range, the first network device can obtain the issued application certificate from the authorized certificate issuing agency (specifically, it can be ACA) and store it, and when the V2X device determines that the download time has arrived, it sends an application certificate download request message to the first network device; the first network device sends an application certificate download response message to the V2X device, and sends the application certificate to the V2X device through the application certificate download response message. It can be understood that after the first network device determines that it has passed the review and authorization of the second network device, it can send the download time of the application certificate to the V2X device through the first response message; and after the first network device obtains the application certificate issued by the authorized certificate issuing agency (specifically, it can be ACA), when the download time of the application certificate arrives, the V2X device initiates the download of the application certificate according to the download time of the application certificate.
[0174] On the other hand, the application for a pseudonym certificate is similar to the second implementation of the application certificate described above, and will not be described in detail here.
[0175] In some optional embodiments of the present invention, sending the first response message to the V2X device includes: the first network device directly sending the first response message to the V2X device; or, the first network device sending the first response message to the V2X device via forwarding.
[0176] Based on the above embodiment, the embodiment of the present invention further provides a certificate authorization processing method based on the Internet of Vehicles, which is applied to a second network device, and the second network device can be the above Figure 2 Authentication and authorization system in, exemplarily, the second network device may be, for example, a GBA authentication and authorization system. Figure 4 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 2 ;like Figure 4 As shown, the method includes:
[0177] Step 201: The second network device receives a second message sent by the first network device; the second message includes a temporary identifier; the second message is used to apply for review and authorization for a service request; the service request is sent by the V2X device to the first network device;
[0178] Step 202: Performing authorization verification based on the temporary identifier;
[0179] Step 203: Send a second response message to the first network device, where the second response message is used to indicate whether the authorization review is successful.
[0180] In this embodiment, the second message includes a temporary identifier; the temporary identifier is an identifier corresponding to the V2X device. It can be understood that the temporary identifier can be used to identify the V2X device.
[0181] In some optional embodiments of the present invention, the second message further includes user identity information. In one example, the user identity information may be unencrypted user identity information; in another example, the user identity information is encrypted based on a fifth key.
[0182] In some optional embodiments of the present invention, the authorization check based on the temporary identifier includes: generating a fifth key based on the temporary identifier, decrypting the user identity information using the fifth key, and performing an authorization check.
[0183] In some optional embodiments of the present invention, generating the fifth key based on the temporary identifier includes: obtaining a shared symmetric key corresponding to the V2X device based on the temporary identifier, and generating at least the fifth key based on the shared symmetric key.
[0184] It can be understood that the second network device obtains the shared symmetric key corresponding to the V2X device in advance before executing the method of this embodiment. In some optional embodiments, when AAA is implemented in GBA mode, AAA (i.e., the second network device) or the GBA authentication and authorization system can be connected to the bootstrapping service function (BSF) or the home subscriber server (HSS) to obtain or generate a shared symmetric key from the operator network.
[0185] In some examples, when AAA is implemented in GBA mode, the temporary identifier can be a business temporary identifier (B-TID) in the GBA mode. After executing the GBA processing flow, the second network device can obtain and store the mapping relationship between the temporary identifier of the V2X device and the shared symmetric key; after obtaining the second message, the mapping relationship can be searched based on the temporary identifier carried in the second message to obtain the shared symmetric key corresponding to the temporary identifier of the V2X device. Further, at least a fifth key is generated based on the shared symmetric key. Exemplarily, at least a fifth key can be generated based on the shared symmetric key and a key derivation function (KDF).
[0186] Exemplarily, the second network device pre-stores security context information corresponding to the temporary identifier of the V2X device, and the security context information may include information such as the shared symmetric key of the V2X device and the real identifier of the V2X device; it can be understood that the above security context information includes a mapping relationship between the temporary identifier of the V2X device and the shared symmetric key.
[0187] It should be noted that the second network device may obtain the shared symmetric key and the temporary identifier during the initialization process. The shared symmetric key and the temporary identifier may be implemented online or offline (ie, pre-configured).
[0188] In this embodiment, the second network device generates at least a fifth key based on the shared symmetric key, decrypts the user identity information using the fifth key, and performs review and authorization on the user's service operation request based on the decrypted user identity information to determine whether to allow the application for the authorization certificate (including the pseudonym certificate and / or the application certificate) to be issued to the V2X device; if the review and authorization pass, the second network device sends a second response message to the first network device indicating that the authorization review is successful; if the review and authorization fail, the second network device sends a second response message to the first network device indicating that the authorization review failed.
[0189] In some optional embodiments of the present invention, the method further includes: generating at least a first key and a second key based on the shared symmetric key; when the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
[0190] In this embodiment, in addition to generating the fifth key based on the shared symmetric key, the second network device can also generate the first key and the second key based on the shared symmetric key. When the authorization is successfully reviewed, the first key and the second key are sent to the first network device via a second response message, so that the first network device can perform integrity protection verification and / or decryption on the first message based on the second key and the first key.
[0191] In some optional embodiments of the present invention, the method further includes: the method further includes: generating at least a first key based on the shared symmetric key; when the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
[0192] In this embodiment, in addition to generating the fifth key based on the shared symmetric key, the second network device can also generate the first key based on the shared symmetric key. When the authorization is successfully reviewed, the first key is sent to the first network device via a second response message, so that the first network device can perform integrity protection verification and / or decryption on the first message based on the first key.
[0193] In some optional embodiments of the present invention, the method further includes: generating a third key based on the shared symmetric key, the third key being used for identity authentication between the first network device and the V2X device; when the second response message indicates that the authorization review is successful, the second response message also includes the third key.
[0194] In some optional embodiments of the present invention, the method further includes: generating a fourth key based on the shared symmetric key, the fourth key being used to establish a secure transmission channel between the first network device and the V2X device; when the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
[0195] Based on the foregoing embodiments, an embodiment of the present invention further provides a certificate authorization processing method based on the Internet of Vehicles, which is applied to a V2X device, and the V2X device may be, for example, an OBU, an RSU or other device. Figure 5 The process diagram of the certificate authorization processing method based on the Internet of Vehicles embodiment of the present invention is as follows Figure 3 ;like Figure 5 As shown, the method includes:
[0196] Step 301: The V2X device sends a first message to a first network device; the first message is used to indicate a service request related to an authorization certificate; the first message includes a temporary identifier.
[0197] In some optional embodiments, the first message includes a temporary identifier; the temporary identifier is an identifier corresponding to the V2X device. It can be understood that the temporary identifier can be used to identify the V2X device.
[0198] In some optional embodiments, the first message also includes user identity information. In one example, the user identity information may be unencrypted user identity information; in another example, the user identity information is encrypted based on a fifth key. The fifth key used to encrypt the user identity information is generated by the V2X device based on a shared symmetric key.
[0199] In one example, the user identity information may also be referred to as user privacy information, or privacy information related to the user identity, etc. Exemplarily, the user identity information may include: information such as vehicle and / or device identification numbers related to the user identity, a previously obtained registration certificate (such as the registration certificate obtained in the aforementioned step 1), etc. In another example, the user identity information may also include device description information related to the device and / or vehicle.
[0200] In some optional embodiments of the present invention, before the V2X device sends a first message to the first network device, the method further includes: the V2X device generates at least a first key and a second key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
[0201] In some optional embodiments of the present invention, before the V2X device sends the first message to the first network device, the method further includes: the V2X device generates at least a first key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key.
[0202] The above two embodiments are for the scenario where the first message includes only a temporary identifier, or the first message includes a temporary identifier and user identity information (the user identity information is not encrypted). In this case, the first message can be encrypted and / or integrity protected based on the first key and the second key; or it can be encrypted and / or integrity protected only based on the first key.
[0203] In some optional embodiments of the present invention, before the V2X device sends a first message to the first network device, the method further includes: the V2X device generates at least a first key, a second key and a fifth key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key and the second key; and the user identity information is encrypted based on the first key.
[0204] In some optional embodiments of the present invention, before the V2X device sends the first message to the first network device, the method further includes: the V2X device generates at least a first key and a fifth key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key; and the user identity information is encrypted based on the first key.
[0205] The above two embodiments are for the scenario where the first message includes a temporary identifier and user identity information, and the user identity information is encrypted based on the fifth key. The first message can be encrypted and / or integrity protected based on the first key and the second key; or it can be encrypted and / or integrity protected only based on the first key.
[0206] It can be understood that before the V2X device executes the method of this embodiment, that is, in the initialization phase, the V2X device can obtain a shared symmetric key and a temporary identifier. In some optional examples, the V2X device can interact with the first network device (such as an AAA or GBA authentication and authorization system) in an online manner to obtain a temporary identifier; or the V2X device can also obtain a temporary identifier in an offline manner (such as a pre-configured manner).
[0207] Further, the V2X device may generate a first key, or a first key and a second key, or a first key and a fifth key, or a first key, a second key and a fifth key based on a shared symmetric key, may encrypt user identity information based on the fifth key, and encrypt and / or integrity protect the first message based on the first key and the second key, or encrypt and / or integrity protect the first message based on the first key. The encrypted user identity information is in the first message, while the temporary identifier is outside the first message, so that after the first message is sent to the first network device and then sent by the first network device to the second network device, the second network device can directly obtain the temporary identifier carried by the first message.
[0208] In some optional embodiments of the present invention, the V2X device sends the first message to the first network device, including: the V2X device directly sends the first message to the first network device; or, the V2X device sends the first message to the first network device after forwarding.
[0209] In this embodiment, refer to Figure 2 In the example shown, taking the first network device as the authorized certificate registration authority and the second network device as the certification authority as an example, the certificate application subject (such as OBU and / or RSU) as the V2X device can directly send the first message to the first network device, or the certificate application subject (such as OBU and / or RSU) as the V2X device can also first send the first message to the second network device, and then the second network device forwards the first message to the second network device through the interface between the second network device and the second network device.
[0210] In some optional embodiments of the present invention, the method may further include:
[0211] Step 302a: The V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; the first response message includes information related to the authorization certificate;
[0212] Step 303a: Perform integrity protection verification and / or decryption on the first response message based on the second key and the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection verification and / or decryption.
[0213] Similar to the above steps, the method may further include:
[0214] Step 302b: The V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on a first key; the first response message includes information related to the authorization certificate;
[0215] Step 303b: Perform integrity protection check and / or decryption on the first response message based on the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection check and / or decryption.
[0216] The difference between the above two implementations is that in the first implementation, the first response message is encrypted and / or integrity protected based on the first key and the second key; therefore, the second network device performs integrity protection verification and / or decryption on the first response message based on the second key and the first key, and only the information related to the authorization certificate can be obtained based on the first response message that passes the integrity protection verification and / or decryption. In the second implementation, the first response message is encrypted and / or integrity protected only based on the first key, so the second network device performs integrity protection verification and / or decryption on the first response message based on the first key, and obtains the information related to the authorization certificate based on the first response message that passes the integrity protection verification and / or decryption.
[0217] In some optional embodiments of the present invention, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate; or, the authorization certificate related information includes the download time of the application certificate; the method further includes: the V2X device downloads the application certificate according to the download time; when the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate; the method further includes: the V2X device downloads the pseudonym certificate according to the download time.
[0218] In this embodiment, in the scenario of application certificate application, in one embodiment, the first network device can obtain the application certificate issued from the authorized certificate issuing authority (specifically, ACA), and send the obtained application certificate to the V2X device through a first response message; in another embodiment, the first network device can inform the V2X device of the download time of the application certificate through the first response message; within this time range, the first network device can obtain the application certificate issued from the authorized certificate issuing authority (specifically, ACA) and store it, and when the V2X device determines that the download time has arrived, it sends an application certificate download request message to the first network device; the first network device sends an application certificate download response message to the V2X device, and sends the application certificate to the V2X device through the application certificate download response message. It can be understood that after the first network device determines that it has passed the review and authorization of the second network device, it can send the download time of the application certificate to the V2X device through the first response message; and after the first network device obtains the application certificate issued from the authorized certificate issuing authority (specifically, ACA), when the download time of the application certificate arrives, the V2X device initiates the download of the application certificate according to the download time of the application certificate.
[0219] On the other hand, the application for a pseudonym certificate is similar to the second implementation of the application certificate described above, and will not be described in detail here.
[0220] In some optional embodiments of the present invention, the V2X device receives a first response message sent by the first network device, including: the V2X device receives a first response message directly sent by the first network device; or the V2X device receives a forwarded first response message from the first network device.
[0221] In some optional embodiments of the present invention, the method further includes: the V2X device generates a third key based on the shared symmetric key, and based on the third key, the V2X device performs identity authentication with the first network device.
[0222] Exemplarily, a message for identity authentication may be transmitted between the V2X device and the first network device, and the message may be encrypted using a third key, so that the V2X device and the first network device may decrypt the message using the third key, thereby performing identity authentication.
[0223] In some optional embodiments of the present invention, the method further includes: the V2X device generates a fourth key based on the shared symmetric key, and based on the fourth key, establishes a secure transmission channel between the V2X device and the first network device.
[0224] Exemplarily, a message for establishing a secure transmission channel can be transmitted between the V2X device and the first network device, and the message is encrypted by a fourth key so that the V2X device and the first network device can decrypt the message by the fourth key, thereby establishing a secure transmission channel.
[0225] By adopting the technical solution of the embodiment of the present invention, on the one hand, by encrypting and protecting the user identity information, the first network device cannot obtain the decrypted user identity information, and the user identity information can only be known at the second network device. The real identity of the user and the pseudonym identity are separated at the first network device, the user privacy is protected, and authorization management and control are achieved; on the other hand, by adding an interface between the first network device and the second network device, and implementing authorization review of the V2X device application for service requests through the second network device, the control of certificate authorization by the legal department of the V2X device is achieved.
[0226] The following describes in detail a certificate authorization processing method based on the Internet of Vehicles according to an embodiment of the present invention with reference to a specific example.
[0227] Figure 6 FIG. 1 is a schematic diagram of an interactive process of a certificate authorization processing method based on the Internet of Vehicles according to an embodiment of the present invention; Figure 6 As shown, the method includes:
[0228] Step 401: Key preparation process. When applying for an authorization certificate, the V2X device generates a session key based on the shared symmetric key K. The session key includes the first key K in the above embodiment. 1 , the second key K 2 , the third key K 3 , the fourth key K 4 and the fifth key K 5 It can be understood that the above five keys can also be called the first session key K 1 , the second session key K 2 , the third session key K 3 , the fourth session key K 4 and the fifth session key K 5 .
[0229] Step 402: Preparation for authorization certificate application. The V2X device generates a cryptographic public-private key pair for the authorization certificate locally, constructs an authorization certificate application request message, and signs the authorization certificate application request message using the private key of the obtained registration certificate.
[0230] Step 403: Authorization certificate application request message security protection. The V2X device uses the first session key K 1 and the first session key K 2The authorization certificate application request is encrypted and integrity protected respectively. The V2X device can use the fifth session key K 5 The user identity information is encrypted and protected; in one example, the user identity information may include at least one of the following information: information such as vehicle and / or device identification number related to the user identity, registration certificate, etc. This example can be applied to the application for a pseudonym certificate; in another example, the user identity information may also include device description information related to the device and / or vehicle; this example can be applied to the application for an application certificate.
[0231] Step 404: The V2X device sends an authorization certificate application request message (i.e., the first message in the above embodiment) to the PRA / ARA. The authorization certificate application request message may include a temporary identifier T-ID and user identity information; wherein the user identity information may be obtained using the fifth key K 5 The message can be forwarded by AAA to PRA / ARA as shown in step 404a and step 404b in the figure; in other embodiments, the authorization certificate application request message can also be sent directly to PRA / ARA by the V2X device without being forwarded by AAA.
[0232] It can be understood that if a pseudonym certificate is applied for, the V2X device sends an authorization certificate application request message to the PRA; if an application certificate is applied for, the V2X device sends an authorization certificate application request message to the ARA.
[0233] Step 405: PRA / ARA sends an authorization and user information request message (i.e., the second message in the aforementioned embodiment) to AAA to apply for an operation authorization license. The authorization and user information request message may include a temporary identifier T-ID of the V2X device and user identity information.
[0234] Step 406: Authorization verification. AAA searches locally for the security context information of the V2X device based on the temporary identifier T-ID in the authorization and user information request message (for example, the security context message may include the real identifier of the V2X device, the shared symmetric key K, and other user information, etc.), and derives a session key based on the shared symmetric key K. The session key includes the first key K in the aforementioned embodiment. 1 , the second key K 2 , the third key K 3 , the fourth key K 4 and the fifth key K 5 AAA uses the fifth key K 5Decrypt the encrypted user identity information. Based on the decrypted user identity information, AAA checks the authorization and user information request messages sent by PRA / ARA, and reviews and authorizes the user's service operation request to determine whether the requested authorization certificate (the authorization certificate may include a pseudonym certificate / application certificate) is allowed to be issued to the V2X device.
[0235] Step 407: If the authorization review is passed, AAA sends an authorization and user information response message (i.e., the second response message in the above embodiment) to PRA / ARA. The second response message may include user information and the first key K 1 , the second key K 2 , the third key K 3 and the fourth key K 4 .
[0236] Optionally, AAA generates a session key based on the shared symmetric key K and determines the key lifetime corresponding to each session key; accordingly, the second response message may include the first key K 1 , the second key K 2 , the third key K 3 and the fourth key K 4 , and the key lifetime corresponding to each key.
[0237] Step 408: Authorization certificate application message verification. PRA / ARA uses the second key K 2 and the first key K 1 The authorization certificate application request message (ie, the first message in the aforementioned embodiment) is integrity-protected and decrypted.
[0238] Steps 409a to 409b: PRA / ARA returns an authorization certificate application response message (i.e., an example of the first response message in the above embodiment) to the V2X device, wherein the authorization certificate application response includes the download time of the pseudonym certificate / application certificate to notify the V2X device of the download time of the pseudonym certificate / application certificate. The authorization certificate application response message may use the first key K 1 and the second key K 2 The authorization certificate application response message may be forwarded by AAA to the V2X device as shown in the figure. In other embodiments, the authorization certificate application response message may not be forwarded by AAA but may be sent directly to the V2X device by PRA / ARA.
[0239] It should be noted that if this step is for the application of the application certificate, that is, the download time of the application certificate is returned to the V2X device through the authorization certificate application response message, then step 413a and step 413b will not be executed subsequently.
[0240] Step 410: PRA / ARA sends an authorization certificate application request to PCA / ACA.
[0241] Step 411: PCA / ACA issues relevant authorization certificates (including pseudonym certificates / application certificates).
[0242] Step 412: PCA / ACA sends an authorization certificate request response to PRA / ARA. In the case of applying for a pseudonym certificate, PRA compresses and stores the received pseudonym certificate and waits for the V2X device to download it according to the download time indicated in steps 409a to 409b.
[0243] Steps 413a to 413b: In the case of applying for an application certificate, the ARA sends an authorization certificate application response message (i.e., another example of the first response message in the above embodiment) to the V2X device, wherein the authorization certificate application response message includes the application certificate. The authorization certificate application response message may use the first key K 1 and the second key K 2 The authorization certificate application response message may be forwarded by AAA to the V2X device as shown in the figure. In other embodiments, the authorization certificate application response message may not be forwarded by AAA but may be sent directly to the V2X device by ARA.
[0244] It should be noted that if the ARA sends an authorization certificate application response message to the V2X device through this step, the aforementioned steps 409a to 409b are not performed.
[0245] After the V2X device receives the authorization certificate application response message, it 2 and the first key K 1 Perform integrity protection verification and decryption on the authorization certificate application response message, and securely store the content of the decrypted message.
[0246] The above process is the authorization certificate application process, and the above process can also be applied to the authorization certificate update process. In the case where the above process is applied to the authorization certificate update process, the names of some messages in the above process should be adaptively modified, for example, step 402 is authorization certificate update preparation; steps 404a to 404b are authorization certificate update request messages; step 408 is authorization certificate update message verification; steps 413a to 413b are authorization certificate update response messages; step 410 is authorization certificate update request message; step 412 is authorization certificate update response message.
[0247] It should be noted that, optionally, the naming of steps 405 to 406 in the above process is based on the naming of the message corresponding to the application for the pseudonym certificate; if it is an application for an application certificate, step 405 may be: ARA sends a certificate issuance authorization request message to AAA (i.e., the second message in the above embodiment); correspondingly, step 407 may be: if the authorization review is passed, AAA sends a certificate issuance authorization response message to ARA (i.e., the second response message in the above embodiment), and the second response message may include user information and the first key K 1 , the second key K 2 , the third key K 3 and the fourth key K 4 .
[0248] It can be understood that the above-mentioned authorization certificate application request message and authorization certificate update request message can both be used as the first message in the above-mentioned embodiment of the present invention; the above-mentioned authorization certificate application response message and authorization certificate update response message can both be used as the first response message in the above-mentioned embodiment of the present invention.
[0249] Optionally, based on the above method, the following steps may also be included:
[0250] Step 414: Based on the third key K 3 , PRA / ARA and V2X devices can perform two-way identity authentication.
[0251] Step 415: Based on the fourth key K 4 , a secure transmission channel can be established between PRA / ARA and V2X devices, such as Transport Layer Security (TLS), Internet Protocol Security (IPSec) security channel, application layer security channel, etc., for end-to-end secure data transmission.
[0252] In this embodiment, during the initialization phase, V2X devices such as OBU and RSU can interact with AAA offline or online to obtain a temporary identification T-ID (Temporary ID), negotiate a shared symmetric key or exchange digital certificates, and establish a security association. At the same time, the V2X device applies to the registration certificate authority through AAA to obtain a registration certificate or a service token. It can be understood that in other examples, similar processes can be used based on the service token, which will not be repeated here.
[0253] In some optional embodiments, when AAA is implemented using GBA, in the scenario of applying for a pseudonym certificate:
[0254] If the V2X device does not have a valid GBA shared session key (i.e., the shared session key in the aforementioned embodiment), the V2X device accesses the GBA authentication and authorization system through the cellular network and initiates an authentication and authorization request. The GBA authentication and authorization system preferentially adopts the GBA_U method, and returns an authentication and authorization response to the V2X device after success. The BSF in the GBA authentication and authorization system is responsible for authenticating the V2X device and providing the GBA key to the NAF, and the NAF is responsible for generating multiple GBA shared session keys for use by the PRA.
[0255] For the above step 404, the V2X device sends a protected pseudonym certificate application request message to the pseudonym certificate authority PRA through the GBA authentication and authorization system, which includes the encrypted user identity information. The pseudonym certificate application request message can be carried by a Hyper Text Transfer Protocol (HTTP) message, and the HTTP message can carry B-TID and PRA server domain name information.
[0256] Among them, the GBA authentication and authorization system can forward the pseudonym certificate application request to the PRA based on the PRA server domain name information.
[0257] An embodiment of the present invention further provides a network device, which is the first network device in the aforementioned embodiment. Figure 7 The structure diagram of the network device according to the embodiment of the present invention is shown in FIG. Figure 1 ;like Figure 7 As shown, the network device includes: a first communication unit 51 and a second communication unit 52; wherein,
[0258] The first communication unit 51 is used to receive a first message from the V2X device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier;
[0259] The second communication unit 52 is used to send a second message to the second network device; the second message includes the temporary identifier; the second message is used to apply for audit authorization for the service request; and is also used to obtain a second response message sent by the second network device, and the second response message is used to indicate whether the audit authorization is successful.
[0260] In some optional embodiments of the present invention, the first message also includes user identity information.
[0261] In some optional embodiments of the present invention, the user identity information is encrypted based on a fifth key.
[0262] In some optional embodiments of the present invention, the first message is encrypted and / or integrity protected based on the first key and the second key;
[0263] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key;
[0264] The network device also includes a first processing unit 53, which is used to perform integrity protection verification and / or decryption on the first message based on the second key and the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0265] In some optional embodiments of the present invention, the first message is encrypted and / or integrity protected based on a first key; when the second response message indicates that the authorization review is successful, the second response message includes at least the first key;
[0266] The first processing unit 53 is configured to perform integrity protection verification and / or decryption on the first message based on the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
[0267] In some optional embodiments of the present invention, when the second response message indicates that the authorization review is successful, the second response message also includes a third key;
[0268] The network device also includes a first processing unit 53, configured to perform identity authentication with the V2X device based on the third key.
[0269] In some optional embodiments of the present invention, when the second response message indicates that the authorization review is successful, the second response message also includes a fourth key;
[0270] The network device also includes a first processing unit 53, configured to establish a secure transmission channel with the V2X device based on the fifth key.
[0271] In some optional embodiments of the present invention, the first communication unit 51 is further used to send a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on the first key and the second key, or the first response message is encrypted and / or integrity protected based on the first key; the first response message includes information related to the authorization certificate.
[0272] In some optional embodiments of the present invention, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate;
[0273] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
[0274] In some optional embodiments of the present invention, the first communication unit 51 is configured to directly send a first response message to the V2X device; or, send the first response message to the V2X device via forwarding.
[0275] In some optional embodiments of the present invention, the first communication unit 51 is configured to receive a first message directly sent by the V2X device; or receive a forwarded first message from the V2X device.
[0276] In the embodiment of the present invention, the first processing unit 53 in the network device can be implemented by a central processing unit (CPU), a digital signal processor (DSP), a microcontroller unit (MCU) or a programmable gate array (FPGA) in the network device in actual applications; the first communication unit 51, the second communication unit 52 and the third communication unit in the network device can be implemented by a communication module (including: a basic communication kit, an operating system, a communication module, a standardized interface and protocol, etc.) and a transceiver antenna in actual applications.
[0277] An embodiment of the present invention further provides a network device, which is the second network device in the aforementioned embodiment. Figure 8 The structure diagram of the network device according to the embodiment of the present invention is shown in FIG. Figure 2 ;like Figure 8 As shown, the network device includes: a fourth communication unit 61 and a second processing unit 62; wherein,
[0278] The fourth communication unit 61 is used to receive a second message sent by the first network device; the second message includes a temporary identifier; the second message is used to apply for review and authorization for the service request; the service request is sent by the V2X device to the first network device;
[0279] The second processing unit 62 is used to perform authorization verification based on the temporary identifier;
[0280] The fourth communication unit 61 is further used to send a second response message to the first network device, where the second response message is used to indicate whether the authorization review is successful.
[0281] In some optional embodiments of the present invention, the second message also includes user identity information.
[0282] In some optional embodiments of the present invention, the user identity information is encrypted based on a fifth key;
[0283] The second processing unit 62 is configured to generate a fifth key based on the temporary identifier, decrypt the user identity information using the fifth key, and perform authorization verification.
[0284] In some optional embodiments of the present invention, the second processing unit 62 is configured to obtain a shared symmetric key corresponding to the V2X device based on the temporary identifier, and generate at least the fifth key based on the shared symmetric key.
[0285] In some optional embodiments of the present invention, the second processing unit 62 is further configured to generate at least a first key and a second key based on the shared symmetric key;
[0286] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
[0287] The second processing unit 62 is further configured to generate at least a first key based on the shared symmetric key;
[0288] When the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
[0289] In some optional embodiments of the present invention, the second processing unit 62 is further configured to generate a third key based on the shared symmetric key, wherein the third key is used for identity authentication between the first network device and the V2X device;
[0290] When the second response message indicates that the authorization review is successful, the second response message also includes the third key.
[0291] In some optional embodiments of the present invention, the second processing unit 62 is further configured to generate a fourth key based on the shared symmetric key, wherein the fourth key is used to establish a secure transmission channel between the first network device and the V2X device;
[0292] When the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
[0293] In an embodiment of the present invention, the second processing unit 62 in the network device can be implemented by the CPU, DSP, MCU or FPGA in the network device in actual applications; the fourth communication unit 61 in the network device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.
[0294] An embodiment of the present invention further provides a V2X device, Fig. 9 Schematic diagram of the composition structure of the V2X device according to an embodiment of the present invention. Fig. 9 As shown, the V2X device includes a fifth communication unit 71, which is used to send a first message to a first network device; the first message is used to indicate a service request related to an authorization certificate; and the first message includes a temporary identifier.
[0295] In some optional embodiments of the present invention, the first message also includes user identity information.
[0296] In some optional embodiments of the present invention, the user identity information is encrypted based on a fifth key; and the fifth key is generated based on a shared symmetric key.
[0297] In some optional embodiments of the present invention, the V2X device also includes a third processing unit 72, which is used to generate at least a first key and a second key based on a shared symmetric key before the fifth communication unit 71 sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
[0298] In some optional embodiments of the present invention, the third processing unit 72 is used to generate at least a first key based on a shared symmetric key before the fifth communication unit sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key.
[0299] In some optional embodiments of the present invention, the third processing unit 72 is configured to generate a third key based on the shared symmetric key, and perform identity authentication with the first network device based on the third key.
[0300] In some optional embodiments of the present invention, the third processing unit 72 is configured to generate a fourth key based on the shared symmetric key, and establish a secure transmission channel with the first network device based on the fourth key.
[0301] In some optional embodiments of the present invention, the fifth communication unit 71 is further used to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; the first response message includes authorization certificate related information;
[0302] The third processing unit 72 is further configured to perform integrity protection verification and / or decryption on the first response message based on the second key and the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection verification and / or decryption.
[0303] In some optional embodiments of the present invention, the fifth communication unit 71 is further used to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key; the first response message includes authorization certificate related information;
[0304] The third processing unit 72 is configured to perform integrity protection verification and / or decryption on the first response message based on the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection verification and / or decryption.
[0305] In some optional embodiments of the present invention, when the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate; the third processing unit 72 is further used to download the application certificate according to the download time;
[0306] In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate; the third processing unit 72 is further used to download the pseudonym certificate according to the download time.
[0307] In some optional embodiments of the present invention, the fifth communication unit 71 is configured to receive a first response message directly sent by the first network device; or receive a forwarded first response message from the first network device.
[0308] In some optional embodiments of the present invention, the fifth communication unit 71 is used to send the first message directly to the first network device; or, send the first message to the first network device through forwarding.
[0309] In the embodiment of the present invention, the third processing unit 72 in the V2X device can be implemented by the CPU, DSP, MCU or FPGA in the V2X device in actual applications; the fifth communication unit 71 in the network device can be implemented by a communication module (including: basic communication kit, operating system, communication module, standardized interface and protocol, etc.) and a transceiver antenna in actual applications.
[0310] It should be noted that: the information reminder device provided in the above embodiment only uses the division of the above program modules as an example when performing information reminder. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the information reminder device provided in the above embodiment and the information reminder method embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.
[0311] An embodiment of the present invention also provides a communication device, which may be the first network device, the second network device or the V2X device in the aforementioned embodiment. Fig.10 FIG. 1 is a schematic diagram of the hardware structure of a communication device according to an embodiment of the present invention. Fig.10 As shown, the communication device may include a memory 82, a processor 81, and a computer program stored in the memory 82 and executable on the processor 81. When the processor 81 executes the program, the steps of the certificate authorization processing method based on the Internet of Vehicles applied to the aforementioned first network device, second network device or V2X device in an embodiment of the present invention are implemented.
[0312] It is understood that the communication device may also include one or more network interfaces 83. Optionally, the components in the communication device are coupled together via a bus system 84. It is understood that the bus system 84 is used to achieve connection and communication between these components. In addition to the data bus, the bus system 84 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Fig.10 Various buses are labeled as bus system 84 .
[0313] It can be understood that the memory 82 can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disk, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory 82 described in the embodiments of the present invention is intended to include, but is not limited to, these and any other suitable types of memory.
[0314] The method disclosed in the above embodiment of the present invention can be applied to the processor 81, or implemented by the processor 81. The processor 81 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit in the processor 81 or the instruction in the form of software. The above processor 81 can be a general-purpose processor, a DSP, or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 81 can implement or execute the methods, steps and logic block diagrams disclosed in the embodiment of the present invention. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present invention, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium, which is located in the memory 82. The processor 81 reads the information in the memory 82 and completes the steps of the above method in combination with its hardware.
[0315] In an exemplary embodiment, the communication device may be implemented by one or more application specific integrated circuits (ASIC), DSP, programmable logic device (PLD), complex programmable logic device (CPLD), FPGA, general purpose processor, controller, MCU, microprocessor, or other electronic components to execute the aforementioned method.
[0316] In an exemplary embodiment, the present invention also provides a computer-readable storage medium, such as a memory 82 including a computer program, and the computer program can be executed by a processor 81 of a communication device to complete the steps of the aforementioned method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disk, or CD-ROM; or it can be various devices including one or any combination of the above memories.
[0317] The computer-readable storage medium provided by an embodiment of the present invention stores a computer program thereon, and is characterized in that when the program is executed by a processor, the steps of the certificate authorization processing method based on the Internet of Vehicles applied to the aforementioned first network device, second network device or V2X device in the embodiment of the present invention are implemented.
[0318] The methods disclosed in several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0319] The features disclosed in several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0320] The features disclosed in several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0321] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.
[0322] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0323] In addition, all functional units in the embodiments of the present invention may be integrated into one processing unit, or each unit may be separately used as a unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.
[0324] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium, which, when executed, executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, disks or optical disks.
[0325] Alternatively, if the above-mentioned integrated unit of the present invention is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention can be essentially or partly reflected in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0326] The above is only a specific embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present invention, which should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope of the claims.
Claims
1. A certificate authorization processing method based on Internet of Vehicles, characterized in that: The method comprises: The first network device receives a first message from the V2X device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier and user identity information encrypted based on a fifth key; Sending a second message to a second network device; the second message includes the temporary identifier and the user identity information encrypted based on the fifth key; the second message is used to apply for review authorization for the service request; Obtain a second response message sent by the second network device, where the second response message is used to indicate whether the audit authorization is successful; wherein the audit authorization is performed by the second network device obtaining a shared symmetric key corresponding to the V2X device based on the temporary identifier, generating at least a fifth key based on the shared symmetric key, decrypting the user identity information using the fifth key, and performing authorization verification based on the decrypted user identity information.
2. The method according to claim 1, characterized in that The first message is encrypted and / or integrity protected based on the first key and the second key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key; Correspondingly, the first network device performs integrity protection verification and / or decryption on the first message based on the second key and the first key, and applies for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
3. The method according to claim 1, characterized in that The first message is encrypted and / or integrity protected based on a first key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key; Correspondingly, the first network device performs integrity protection verification and / or decryption on the first message based on the first key, and applies for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
4. The method according to any one of claims 1 to 3, characterized in that: When the second response message indicates that the authorization review is successful, the second response message also includes a third key; and the method further includes: Based on the third key, identity authentication is performed between the first network device and the V2X device.
5. The method according to any one of claims 1 to 3, characterized in that: When the second response message indicates that the authorization review is successful, the second response message also includes a fourth key; and the method further includes: Based on the fourth key, a secure transmission channel is established between the first network device and the V2X device.
6. The method according to claim 1, characterized in that The method further comprises: The first network device sends a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on a first key and a second key, or the first response message is encrypted and / or integrity protected based on the first key; the first response message includes information related to the authorization certificate.
7. The method according to claim 6, characterized in that In the case where the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate; In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
8. The method according to claim 6, characterized in that The sending a first response message to the V2X device includes: The first network device directly sends a first response message to the V2X device; or, The first network device sends a first response message to the V2X device after forwarding.
9. The method according to claim 1, characterized in that: The first network device receives a first message from a V2X device, including: The first network device receives a first message directly sent by the V2X device; or, The first network device receives a forwarded first message from the V2X device.
10. A certificate authorization processing method based on Internet of Vehicles, characterized in that: The method comprises: The second network device receives a second message sent by the first network device; the second message includes a temporary identifier and user identity information encrypted based on a fifth key; the second message is used to apply for review and authorization of a service request related to the authorization certificate; the service request is sent by the V2X device to the first network device; Performing authorization verification based on the temporary identifier; Sending a second response message to the first network device, where the second response message is used to indicate whether the authorization review is successful; The authorization verification based on the temporary identifier includes: The method further comprises: obtaining a shared symmetric key corresponding to the V2X device based on the temporary identifier, generating at least a fifth key based on the shared symmetric key, decrypting the user identity information using the fifth key, and performing authorization verification according to the decrypted user identity information.
11. The method according to claim 10, characterized in that The method further comprises: generating at least a first key and a second key based on the shared symmetric key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
12. The method according to claim 10, characterized in that The method further comprises: generating at least a first key based on the shared symmetric key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
13. The method according to claim 10, characterized in that The method further comprises: Generate a third key based on the shared symmetric key, where the third key is used for identity authentication between the first network device and the V2X device; When the second response message indicates that the authorization review is successful, the second response message also includes the third key.
14. The method according to claim 10, characterized in that The method further comprises: generating a fourth key based on the shared symmetric key, where the fourth key is used to establish a secure transmission channel between the first network device and the V2X device; When the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
15. A certificate authorization processing method based on Internet of Vehicles, characterized in that: The method comprises: The V2X device sends a first message to the first network device, so that the first network device sends a second message for applying for review authorization for a service request to the second network device; the first message is used to represent a service request related to the authorization certificate; the first message and the second message include a temporary identifier and user identity information encrypted based on a fifth key; the temporary identifier is used by the second network device to obtain a shared symmetric key corresponding to the V2X device, generate at least a fifth key based on the shared symmetric key, and use the fifth key to decrypt the user identity information, so that the second network device can perform authorization verification according to the decrypted user identity information.
16. The method according to claim 15, characterized in that The fifth key is generated based on the shared symmetric key.
17. The method according to claim 15, characterized in that Before the V2X device sends the first message to the first network device, the method further includes: The V2X device generates at least a first key and a second key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
18. The method according to claim 15, characterized in that Before the V2X device sends the first message to the first network device, the method further includes: The V2X device generates at least a first key based on a shared symmetric key; wherein the first message is encrypted and / or integrity protected based on the first key.
19. The method according to any one of claims 15 to 18, characterized in that The method further comprises: The V2X device generates a third key based on the shared symmetric key, and performs identity authentication between the V2X device and the first network device based on the third key.
20. The method according to any one of claims 15 to 18, characterized in that The method further comprises: The V2X device generates a fourth key based on the shared symmetric key, and establishes a secure transmission channel between the V2X device and the first network device based on the fourth key.
21. The method according to claim 15, characterized in that The method further comprises: The V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; the first response message includes authorization certificate related information; The first response message is integrity checked and / or decrypted based on the second key and the first key, and the authorization certificate related information is obtained based on the first response message that has passed the integrity check and / or decryption.
22. The method according to claim 15, characterized in that The method further comprises: The V2X device receives a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on a first key; the first response message includes authorization certificate related information; The first response message is integrity checked and / or decrypted based on the first key, and the authorization certificate related information is obtained based on the first response message that has passed the integrity check and / or decryption.
23. The method according to claim 21 or 22, characterized in that In the case where the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate; Alternatively, the authorization certificate related information includes the download time of the application certificate; The method further includes: the V2X device downloading the application certificate according to the download time; In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes a download time of the pseudonym certificate; the method further includes: the V2X device downloading the pseudonym certificate according to the download time.
24. The method according to claim 21 or 22, characterized in that The V2X device receives a first response message sent by the first network device, including: The V2X device receives a first response message directly sent by the first network device; or, The V2X device receives the forwarded first response message from the first network device.
25. The method according to claim 15, characterized in that The V2X device sending the first message to the first network device includes: The V2X device directly sends the first message to the first network device; or, The V2X device sends the first message to the first network device after forwarding.
26. A network device, the network device being a first network device, characterized in that: The network device comprises: a first communication unit and a second communication unit; wherein, The first communication unit is used to receive a first message from the V2X device; the first message is used to indicate a service request related to the authorization certificate; the first message includes a temporary identifier and user identity information encrypted based on a fifth key; The second communication unit is used to send a second message to a second network device; the second message includes the temporary identifier and the user identity information encrypted based on the fifth key; the second message is used to apply for an audit authorization for the service request; and is also used to obtain a second response message sent by the second network device, the second response message is used to indicate whether the audit authorization is successful; wherein the audit authorization is obtained by the second network device based on the temporary identifier. The shared symmetric key corresponding to the V2X device is obtained, at least a fifth key is generated based on the shared symmetric key, the user identity information is decrypted using the fifth key, and authorization verification is performed based on the decrypted user identity information.
27. The network device according to claim 26, characterized in that: The first message is encrypted and / or integrity protected based on the first key and the second key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key; The network device also includes a first processing unit, which is used to perform integrity protection verification and / or decryption on the first message based on the second key and the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
28. The network device according to claim 26, characterized in that: The first message is encrypted and / or integrity protected based on a first key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key; The network device also includes a first processing unit, which is used to perform integrity protection verification and / or decryption on the first message based on the first key, and apply for an authorization certificate based on the first message that passes the integrity protection verification and / or decryption.
29. The network device according to any one of claims 26 to 28, characterized in that: When the second response message indicates that the authorization review is successful, the second response message also includes a third key; The network device also includes a first processing unit, configured to perform identity authentication with the V2X device based on the third key.
30. The network device according to any one of claims 26 to 28, characterized in that: When the second response message indicates that the authorization review is successful, the second response message also includes a fourth key; The network device also includes a first processing unit, configured to establish a secure transmission channel with the V2X device based on the fifth key.
31. The network device according to claim 26, characterized in that: The first communication unit is further configured to send a first response message to the V2X device; the first response message is encrypted and / or integrity protected based on the first key and the second key, or the first response message is encrypted and / or integrity protected based on the first key; The first response message includes information related to the authorization certificate.
32. The network device according to claim 31, characterized in that: In the case where the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate; In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes the download time of the pseudonym certificate.
33. The network device according to claim 31, characterized in that The first communication unit is configured to directly send a first response message to the V2X device; or send the first response message to the V2X device via forwarding.
34. The network device according to claim 27, characterized in that: The first communication unit is configured to receive a first message directly sent by the V2X device; or receive a forwarded first message from the V2X device.
35. A network device, the network device being a second network device, characterized in that: The network device comprises: a fourth communication unit and a second processing unit; wherein, The fourth communication unit is used to receive a second message sent by the first network device; the second message includes a temporary identifier and user identity information encrypted based on a fifth key; the second message is used to apply for review and authorization of a service request related to the authorization certificate; the service request is sent by the V2X device to the first network device; The second processing unit is configured to perform authorization verification based on the temporary identifier; The fourth communication unit is further used to send a second response message to the first network device, where the second response message is used to indicate whether the authorization review is successful; Among them, the second processing unit is used to obtain the shared symmetric key corresponding to the V2X device based on the temporary identifier, generate at least a fifth key based on the shared symmetric key, use the fifth key to decrypt the user identity information, and perform authorization verification according to the decrypted user identity information.
36. The network device according to claim 35, characterized in that The second processing unit is further configured to generate at least a first key and a second key based on the shared symmetric key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key and the second key.
37. The network device according to claim 35, characterized in that: The second processing unit is further configured to generate at least a first key based on the shared symmetric key; When the second response message indicates that the authorization review is successful, the second response message includes at least the first key.
38. The network device according to claim 35, characterized in that: The second processing unit is further configured to generate a third key based on the shared symmetric key, wherein the third key is used for identity authentication between the first network device and the V2X device; When the second response message indicates that the authorization review is successful, the second response message also includes the third key.
39. The network device according to claim 35, characterized in that: The second processing unit is further configured to generate a fourth key based on the shared symmetric key, wherein the fourth key is used to establish a secure transmission channel between the first network device and the V2X device; When the second response message indicates that the authorization review is successful, the second response message also includes the fourth key.
40. A V2X device, characterized in that: The V2X device includes a fifth communication unit, configured to send a first message to a first network device, so that the first network device sends a second message for applying for review authorization for a service request to a second network device; the first message is used to indicate a service request related to an authorization certificate; the first message and the second message include a temporary identifier and user identity information encrypted based on a fifth key; The temporary identifier is used by the second network device to obtain the shared symmetric key corresponding to the V2X device, generate at least a fifth key based on the shared symmetric key, and use the fifth key to decrypt the user identity information, so that the second network device can perform authorization verification according to the decrypted user identity information.
41. The V2X device according to claim 40, characterized in that: The fifth key is generated based on the shared symmetric key.
42. The V2X device according to claim 40, characterized in that: The V2X device also includes a third processing unit, which is used to generate at least a first key and a second key based on a shared symmetric key before the fifth communication unit sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key and the second key.
43. The V2X device according to claim 40, characterized in that: The V2X device also includes a third processing unit, which is used to generate at least a first key based on a shared symmetric key before the fifth communication unit sends a first message to the first network device; wherein the first message is encrypted and / or integrity protected based on the first key.
44. The V2X device according to any one of claims 40 to 43, characterized in that: The V2X device also includes a third processing unit, configured to generate a third key based on the shared symmetric key, and perform identity authentication with the first network device based on the third key.
45. The V2X device according to any one of claims 40 to 43, characterized in that: The V2X device also includes a third processing unit, configured to generate a fourth key based on the shared symmetric key, and establish a secure transmission channel with the first network device based on the fourth key.
46. The V2X device according to claim 40, characterized in that: The V2X device further includes a third processing unit; The fifth communication unit is further configured to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key and the second key; The first response message includes authorization certificate related information; The third processing unit is used to perform integrity protection verification and / or decryption on the first response message based on the second key and the first key, and obtain the authorization certificate related information based on the first response message that has passed the integrity protection verification and / or decryption.
47. The V2X device according to claim 40, characterized in that: The V2X device further includes a third processing unit; The fifth communication unit is further used to receive a first response message sent by the first network device; the first response message is encrypted and / or integrity protected based on the first key; the first response message includes authorization certificate related information; The third processing unit is used to perform integrity protection verification and / or decryption on the first response message based on the first key, and obtain the authorization certificate related information based on the first response message that passes the integrity protection verification and / or decryption.
48. The V2X device according to claim 46 or 47, characterized in that: In the case where the first message is used to apply for an application certificate, the authorization certificate related information includes the application certificate, or the authorization certificate related information includes a download time of the application certificate; The third processing unit is further configured to download the application certificate according to the download time; In the case where the first message is used to apply for a pseudonym certificate, the authorization certificate related information includes a download time of the pseudonym certificate; and the third processing unit is further configured to download the pseudonym certificate according to the download time.
49. The V2X device according to claim 46 or 47, characterized in that: The fifth communication unit is configured to receive a first response message directly sent by the first network device; or to receive a forwarded first response message from the first network device.
50. The V2X device according to claim 40, characterized in that: The fifth communication unit is used to send the first message directly to the first network device; or to send the first message to the first network device through forwarding.
51. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, it implements the steps of the method described in any one of claims 1 to 9; or, when the program is executed by a processor, it implements the steps of the method described in any one of claims 10 to 14; or, when the program is executed by a processor, it implements the steps of the method described in any one of claims 15 to 25.
52. A network device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method described in any one of claims 1 to 9 are implemented; or, when the processor executes the program, the steps of the method described in any one of claims 10 to 14 are implemented.
53. A V2X device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the method according to any one of claims 15 to 25 are implemented.
Citation Information
Patent Citations
Method and device for managing enrollment certificate in security credential management system
CN111224781A
Vehicle-to-everything (V2X) service access
US20200029268A1