Certificate Processing Method, Device, Equipment, and Storage Medium
By handling long-term and short-term certificates according to the working status of the on-board unit, the shortcomings of OBU equipment certificate management are solved, and the full life cycle management and safe use of certificates are realized.
Patent Information
- Application Number
- CN202210389389.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-13
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-04-13
AI Technical Summary
The prior art cannot effectively manage certificates in the life cycle of OBU equipment, and cannot guarantee the effective use and management of certificates.
According to the working status of the vehicle unit, long-term certificates and short-term certificates are processed accordingly, including application, download, update, alarm and cancellation operations.
It realizes the full life cycle management of OBU equipment certificates, improves the automatic processing efficiency of certificates, ensures the safety of the on-board unit, and improves the user's experience of the vehicle.
Smart Images

Figure CN114745695B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of wireless communication technologies, and in particular, to a method, apparatus, device, and storage medium for certificate processing. Background Art
[0002] In vehicle communication, the OBU (On board Unit) technology is often used for communication between vehicles or between a vehicle and the cloud, so as to implement intelligent transportation functions such as automatic highway toll collection and road warning.
[0003] Currently, when using the OBU for communication, it needs to load relevant license certificates itself. Through certificate licensing, the OBU can perform various permitted functions.
[0004] In the prior art, according to the prompt information of the certificate management center, the OBU generates a message certificate application request, and the authentication center generates a message certificate for the OBU. This method is only used for the case of applying for a message certificate before the OBU is used, and cannot cover the comprehensive processing of certificates during the life cycle of the OBU, nor can it ensure the effective use and management of certificates. Summary of the Invention
[0005] The embodiments of the present application provide a method, apparatus, device, and storage medium for certificate processing to implement the processing of OBU device certificates.
[0006] In a first aspect, the embodiments of the present application provide a method for certificate processing, which is executed by an on-board unit. A long-term certificate and a short-term certificate are set in the on-board unit. The method includes:
[0007] Determine the working state of the on-board unit; wherein, the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorized state;
[0008] Process the long-term certificate and / or the short-term certificate according to the working state.
[0009] In a second aspect, the embodiments of the present application further provide a certificate processing apparatus, which is executed by an on-board unit. A long-term certificate and a short-term certificate are set in the on-board unit. The apparatus includes:
[0010] A working state determination module, configured to determine the working state of the on-board unit; wherein, the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorized state;
[0011] A certificate processing module, configured to process the long-term certificate and / or the short-term certificate according to the working state.
[0012] In a third aspect, the embodiments of the present application further provide an on-board unit, including:
[0013] One or more processors;
[0014] A memory for storing one or more programs;
[0015] When the one or more programs are executed by the one or more processors, the one or more processors implement a certificate processing method provided in the embodiment of the first aspect of the present application.
[0016] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, characterized in that when the program is executed by a processor, it implements a certificate processing method provided in the embodiment of the first aspect of the present application.
[0017] In a fifth aspect, an embodiment of the present application further provides a vehicle, and the vehicle is provided with an on-vehicle unit as described in the embodiment of the third aspect of the present application.
[0018] The technical solution of the embodiment of the present application processes long-term certificates and / or short-term certificates according to the working state of the on-vehicle unit. Different working states correspond to different processing methods, which can comprehensively process certificates during the entire life cycle of the on-vehicle unit, improve the automatic processing efficiency of long-term certificates and short-term certificates of the on-vehicle unit, ensure the use safety of the on-vehicle unit, and improve the user's experience of using the vehicle. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] Figure 1 is a flowchart of a certificate processing method provided in Embodiment 1 of the present application;
[0020] Figure 2 is a flowchart of a certificate processing method provided in Embodiment 2 of the present application;
[0021] Figure 3 is a flowchart of a certificate processing method provided in Embodiment 3 of the present application;
[0022] Figure 4 is a structural diagram of a certificate processing device provided in Embodiment 4 of the present application;
[0023] Figure 5 is a structural diagram of an on-vehicle unit provided in Embodiment 5 of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, rather than limiting the present application. In addition, it should be noted that for the convenience of description, only parts related to the present application are shown in the drawings rather than all the structures.
[0025] Embodiment 1
[0026] Figure 1 It is a flowchart of a certificate processing method provided in the first embodiment of the present application. The embodiments of the present application are applicable to the processing of on-vehicle unit certificates. This method can be executed by a certificate processing device, which can be implemented by software and / or hardware and is specifically configured in the on-vehicle unit. Among them, a long-term certificate and a short-term certificate are set in the on-vehicle unit.
[0027] Refer to Figure 1 The certificate processing method shown specifically includes the following steps:
[0028] S110. Determine the working state of the on-vehicle unit; where the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorization state.
[0029] Among them, the on-vehicle unit OBU (On board Unit) is a hardware device used for communication between vehicles and the cloud, and between vehicles, and is widely used in current various vehicles. The corresponding working states of the on-vehicle unit are different in different life cycle stages of the vehicle. When the vehicle is just assembled and leaves the factory, all electronic devices in the vehicle need to be initialized, including the on-vehicle unit. Therefore, the working state of the on-vehicle unit corresponding to the vehicle when it leaves the factory is the initial state. It can be understood that the on-vehicle unit in the initial state can perform preset initialization operations on its own functions. During the vehicle sales stage, the hardware functions of the vehicle need to be able to be used normally. At this time, the corresponding working state of the on-vehicle unit is the activation state. It is conceivable that the on-vehicle unit after activating the usage certificate can be allowed to be used normally. During the user usage stage after the vehicle is sold, when there are problems with the usage certificate of the on-vehicle unit-related functions resulting in the on-vehicle unit being unable to work properly, the corresponding working state of the on-vehicle unit is the abnormal state. During the vehicle scrapping stage, the usage certificates of the on-vehicle unit-related functions need to be unbound and cancelled for the vehicle. At this time, the corresponding working state of the on-vehicle unit is the authorization state for each certificate.
[0030] Specifically, to determine the currently corresponding working state of the on-vehicle unit, it can be judged according to different life cycle stages of the vehicle where the on-vehicle unit is located.
[0031] S120. Process the long-term certificate and / or short-term certificate according to the working state.
[0032] Among them, the long-term certificate can be a usage certificate for in-vehicle unit related functions that requires long-term and stable provision of function licenses and does not need to be updated frequently, such as an X.509 certificate or a V2X registration certificate. Both are long-term certificates and provide long-term and stable communication functions for the in-vehicle unit. The short-term certificate can be a usage certificate for in-vehicle unit related functions that provides function licenses in the short term or needs to be updated frequently, such as a V2X pseudonym certificate, which is only used for message protection and is updated once every one to two weeks on average.
[0033] Specifically, according to the working state of the in-vehicle unit, corresponding processing can be performed on the long-term certificate and / or the short-term certificate. Among them, the processing of the long-term certificate and / or the short-term certificate can include but is not limited to application, download, update, alarm, cancellation, etc.
[0034] In an alternative embodiment, if the working state includes an authorized state, then the processing of the long-term certificate and / or the short-term certificate according to the working state may include: removing the long-term certificate and the short-term certificate from the certificate cancellation list according to the unauthorized situation of the long-term certificate and the short-term certificate.
[0035] Among them, the authorized state can be the state of the authorized or unauthorized situation of the long-term certificate and / or the short-term certificate in the in-vehicle unit. It can be understood that if both the long-term certificate and / or the short-term certificate in the in-vehicle unit are in an authorized situation, there is no need to perform other processing on the long-term certificate and / or the short-term certificate, and the corresponding functions of the in-vehicle unit can be used normally. The unauthorized situation can include but is not limited to non-application, non-download, expiration, and cancellation, etc. Corresponding processing is performed according to the specific unauthorized situation of the long-term certificate and the short-term certificate. When the long-term certificate and / or the short-term certificate has expired, in order to reduce the storage occupied by the expired certificates in the certificate cancellation list, the expired long-term certificate and / or the short-term certificate are removed from the certificate cancellation list.
[0036] In the above embodiment, by removing the expired long-term certificate and / or the short-term certificate from the certificate cancellation list, the excessive growth of the certificate cancellation list can be effectively prevented. At the same time, by automatically detecting the expiration of each certificate and performing automatic deletion, the certificate cancellation list can be dynamically cleared, saving storage resources for the certificate cancellation list.
[0037] In an alternative embodiment, if the working state includes an initial state, then the processing of the long-term certificate according to the working state may include: downloading the long-term certificate according to the initial state of the in-vehicle unit.
[0038] Among them, when the in-vehicle unit is in the initial state, it is necessary to initialize the long-term certificate that the in-vehicle unit needs to use. The initialization process includes the application and download of the long-term certificate.
[0039] Optionally, downloading the long-term certificate according to the initial state of the in-vehicle unit may include: applying for and downloading the first type of certificate according to the initialization conditions of the in-vehicle unit, and generating a key; applying for and downloading the second type of registration certificate based on the first type of certificate and the key.
[0040] Among them, the initialization conditions of the in-vehicle unit are the initialization states of the in-vehicle unit before use. For example, when the in-vehicle unit is powered on at the factory, in this initialization state, the first type of certificate is first applied for and downloaded. Among them, the first type of certificate may be a long-term certificate that guarantees the remote communication (secure connection between the vehicle and the remote cloud), such as an X.509 certificate. At the same time, the in-vehicle unit will generate the key of the certificate, such as a pair of public and private keys. Based on the application and download of the first type of certificate, the second type of certificate is applied for and downloaded through the key of the first type of certificate. Among them, the second type of certificate may be a long-term certificate for short-range communication (secure connection between vehicles), such as a V2X registration certificate.
[0041] Exemplarily, after the X.509 certificate registration is completed, the X.509 certificate and the key are used to apply for the V2X registration certificate. The X.509 certificate is used to establish a two-way identity connection with the cloud and establish a secure channel. The X.509 certificate serves as the identity credential for applying for the V2X registration certificate.
[0042] In the above embodiments, based on the first type of certificate, the second type of certificate is applied for and downloaded through the key of the first type of certificate. A secure connection is established with the cloud based on remote communication, providing security guarantee for the application and download of the second type of certificate. At the same time, the first type of certificate and the second type of certificate share a set of keys, saving the key management resources.
[0043] The technical solution of the embodiment of the present application processes the long-term certificate and / or short-term certificate according to the working state of the in-vehicle unit. Different working states correspond to different processing methods, which can comprehensively process the certificates in the whole life cycle of the in-vehicle unit, improve the automatic processing efficiency of the long-term certificate and short-term certificate of the in-vehicle unit, ensure the use safety of the in-vehicle unit, and improve the user's use experience of the vehicle.
[0044] Embodiment 2
[0045] Figure 2 This is a flowchart of a certificate processing method provided by the second embodiment of the present application. The second embodiment of the present application further refines the certificate processing operations in the activated state on the basis of the technical solutions of the foregoing embodiments to ensure the comprehensive processing of long-term certificates and short-term certificates in the whole life cycle of the in-vehicle unit.
[0046] Refer to Figure 2 As shown in a certificate processing method, it specifically includes the following steps:
[0047] S210. Determine the working state of the on-vehicle unit; wherein, the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorized state.
[0048] S220. Control the update of the short-term certificate according to the activation situation of the on-vehicle unit and the certificate state of the long-term certificate.
[0049] Wherein, the activation situation of the on-vehicle unit may be the situation where the on-vehicle unit is activated when the vehicle is sold. The certificate state may include a certificate valid state (the certificate is legal and within the validity period), a certificate not yet in effect state (the current time has not reached the start time of the certificate validity period), a certificate expired state (the current time has reached the end time of the certificate validity period), a certificate abnormal warning state (a state where the certificate is warned due to abnormal behavior of the vehicle, but cancellation has not been executed), and a certificate cancellation state (the certificate is revoked due to situations such as key leakage, equipment scrapping, or serious vehicle anomalies).
[0050] Specifically, if the working state includes an activation state, when the on-vehicle unit is activated, the short-term certificate needs to be updated according to the certificate state of the long-term certificate. For example, the on-vehicle unit checks whether the long-term certificate exists, whether it matches the vehicle and the device, whether it is in the certificate valid state, and whether it is damaged, etc. After the check is correct, relying on the permission of the long-term certificate for remote communication, the on-vehicle unit downloads the short-term certificate through the cloud and replaces the previous version, so as to achieve the purpose of update. It can be understood that since the validity period of the short-term certificate is short, the on-vehicle unit can automatically update the short-term certificate according to the validity period before each expiration.
[0051] In an alternative embodiment, the controlling the update of the short-term certificate according to the activation situation of the on-vehicle unit and the certificate state of the long-term certificate may include: if the on-vehicle unit is in an activated state and the long-term certificate is in a certificate valid state, then control the update of the short-term certificate.
[0052] If the long-term certificate is in a certificate valid state, the long-term certificate can enable the on-vehicle unit to establish a secure and stable connection with the cloud for the on-vehicle unit to download and update the short-term certificate.
[0053] The technical solution of the embodiment of the present application updates the short-term certificate according to the activation situation of the on-vehicle unit and the certificate state of the long-term certificate after determining the working state of the on-vehicle unit. The advantage of this is that it can update the short-term certificate on the basis of ensuring the validity of the long-term certificate, improving the security and stability of the short-term certificate during the update process.
[0054] In an alternative embodiment, if the working state includes an abnormal state, then the processing of the long-term certificate according to the working state may include: processing the long-term certificate according to the abnormal state information of the on-vehicle unit.
[0055] Among them, the abnormal state of the on-vehicle unit may be a state where the on-vehicle unit cannot work properly. For example, the on-vehicle unit cannot connect to the cloud, or the on-vehicle unit broadcasts error information, etc. Therefore, the long-term certificate of the on-vehicle unit is processed accordingly according to the reason why the on-vehicle unit cannot work properly. Among them, the corresponding processing may be alarm or cancellation, etc.
[0056] Optionally, the processing of the long-term certificate according to the abnormal state information of the on-vehicle unit may include: if the occurrence frequency of the abnormal state information meets a preset frequency range, alarm and / or cancel the long-term certificate.
[0057] Among them, the abnormal state information may be the error information broadcast by the on-vehicle unit, and the risk levels of different abnormal state information are different.
[0058] Specifically, different abnormal state information can be classified, and different frequency ranges are preset for different levels of abnormal state information. For example, the on-vehicle unit actively sends abnormal state information and cannot be recognized and filtered by other vehicles, resulting in a serious traffic accident. Such abnormal state information can be defined as a serious level. If the abnormal state information of the serious level is detected once, the long-term certificate of the on-vehicle unit can be cancelled to prevent the broadcast of error information again.
[0059] For another example, due to software or hardware abnormalities of the vehicle, the abnormal state information sent is inconsistent with the actual information or the messages before and after are incoherent, etc., but can be recognized and filtered by other vehicles, and the possibility of causing a traffic accident is low. Such abnormal state information can be defined as a relatively serious level. If such abnormal state information is detected less than 10 times, no processing needs to be done to the long-term certificate of the on-vehicle unit. However, if such abnormal state information occurs between 10 and 50 times, an alarm for abnormal certificate of the on-vehicle unit should be given; if such abnormal state information is detected more than 50 times, the long-term certificate of the on-vehicle unit should be cancelled.
[0060] If the abnormal state information of the vehicle cannot cause vehicle judgment errors and trigger traffic accidents through correctness consistency checks, etc., then such abnormal state information can be defined as a lighter level. If such abnormal state information is detected less than 10 times, no processing needs to be done; if it is detected between 10 and 100 times, an alarm for abnormal certificate of the on-vehicle unit can be given; if it is detected more than 100 times, the long-term certificate of the on-vehicle unit is cancelled.
[0061] If the abnormal status information of a vehicle can be completely filtered by other vehicles, this abnormal status information can be classified as a light level. If this abnormal status information is detected less than 50 times, it can be left unprocessed; if this abnormal status information is detected more than 50 times or more than 100 times, an abnormal warning for the in-vehicle unit certificate can be issued.
[0062] In the above embodiments, according to the abnormal status information of the in-vehicle unit, the long-term certificate is processed, and different treatments can be performed on the long-term certificate according to the occurrence of different abnormal status information. Moreover, grading is carried out according to the severity of the abnormal status information, and grading processing is carried out on the abnormal status according to the occurrence frequency, which refines the processing method, optimizes the processing process, and thus improves the processing effect.
[0063] Embodiment III
[0064] Based on the above embodiments, an exemplary embodiment is provided in this application. Taking the entire life cycle of the in-vehicle unit as an example, this embodiment of the application includes the initial stage of the production line, the sales activation stage, the operation and use stage, and the vehicle scrapping stage.
[0065] In the initial stage of the production line, an OBU certificate initialization command is sent through a diagnostic device. After receiving the diagnostic command, the OBU executes certificate initialization. The OBU generates a pair of public and private keys, first applies for an X.509 certificate, and uses the vehicle identification number and the OBU identification number as the unique identifier of the certificate to bind the vehicle, the OBU, and the X.509 certificate. After completing the X.509 certificate application, the OBU securely stores this certificate, which can be used for remote secure connection between the vehicle and the cloud. The OBU uses the X.509 certificate to apply for a V2X registration certificate, uses the X.509 certificate to establish a two-way identity connection with the cloud, and establishes a secure channel, with the X.509 certificate as the identity credential for applying for the V2X registration certificate. After completing the X.509 certificate and V2X registration certificate applications, the production line certificate initialization is completed.
[0066] In the sales activation stage, since the valid period of the pseudonym certificate is one week or two weeks, it is necessary to download and update it relatively frequently. Since there is a certain period from production to formal sales, if the pseudonym certificate application and download are directly carried out during the production line initialization, it will cause excessive waste of traffic consumption, certificate system burden, and cost.
[0067] In the sales stage, the salesperson uses the diagnostic device to send an OBU device status detection instruction to detect whether the device certificate initialization is completed, and the OBU feeds back the certificate status of its X509 certificate, V2X certificate, etc. (including whether the long-term certificate exists, whether it matches the vehicle and the device, whether it is valid, whether it is damaged, etc.).
[0068] After the OBU completes the device certificate initialization through the diagnostic device, the diagnostic device sends a V2X pseudonym certificate application diagnostic command. The OBU receives the pseudonym certificate application diagnostic command, uses the X.509 certificate to establish a two-way identity connection with the cloud, establishes a secure channel, and applies for a pseudonym certificate using the V2X registration certificate. After the complete pseudonym certificate application, the OBU follows the pseudonym certificate download address and periodically updates the pseudonym certificate.
[0069] In the operation and use stage, after the OBU starts with the whole vehicle, it performs a certificate check on the long-term certificates X.509 certificate, V2X registration certificate, and pseudonym certificate, and the certificates can be used only after the certificate check is completed.
[0070] Figure 3 It is a flowchart of a certificate processing method provided in Embodiment 3 of the present application. As Figure 3 shown, the certificate check process is as follows:
[0071] S301. Determine whether the X.509 certificate and the V2X registration certificate exist. If so, execute S302; otherwise, execute S305.
[0072] S302. Determine whether the vehicle identification number, OBU identification number match the respective long-term certificates. If so, execute S303; otherwise, execute S305.
[0073] S303. Determine the legality and public-private key matching of the X.509 and V2X registration certificates. If so, execute S304; otherwise, execute S305.
[0074] S304. Determine whether the long-term certificates X.509 and V2X registration certificates are valid. If so, execute S306; otherwise, execute S305.
[0075] S305. Display on the in-vehicle unit that the owner's certificate is damaged or expired, and there may be situations such as illegal intrusion or component replacement, and it is necessary to go to the after-sales for inspection and repair.
[0076] S306. Determine whether the long-term certificate reaches one month before the expiration date. If so, execute S308; otherwise, execute S307.
[0077] S307. Determine whether the pseudonym certificate has expired. If so, execute S301; otherwise, end the certificate check process.
[0078] S308. The OBU automatically accesses the public key infrastructure system, submits the original certificate as a voucher, and performs long-term certificate update.
[0079] S309. The public key infrastructure system cancels the original certificate and reissues the long-term certificate.
[0080] S310. Check whether a pseudonym certificate needs to be reapplied. If so, execute S311; otherwise, execute S312.
[0081] S311. Access the certificate management system to make a request for applying a pseudonym certificate.
[0082] S312. Access the certificate management system to download a pseudonym certificate.
[0083] During the use of the certificate, after the OBU receives the message broadcast by other vehicles and detects the message, if it detects that there is an abnormality in the vehicle sending the message, it reports the abnormal situation to the cloud. The cloud analyzes according to the reported abnormal vehicle behavior, and performs relevant management operations on the certificates of the abnormal vehicle according to the abnormal vehicle behavior level and the number of reports. According to the number of occurrences corresponding to the abnormal vehicle behavior level, warning or cancellation operations are performed on the long-term certificate.
[0084] After the OBU is powered on, it accesses the cloud to inquire about the current version of the certificate warning list, and judges whether the OBU needs to update the certificate warning list or the certificate revocation list through the version number; after the OBU receives the message from other OBUs, it first queries the certificate warning list and the certificate cancellation list. If the certificate is in a warning state or a cancellation state, it reminds the abnormal vehicle through human-computer interaction.
[0085] In the vehicle scrapping stage, corresponding processing is performed on various certificates of the OBU of the scrapped vehicle:
[0086] Detect whether the OBU is available. If the OBU is available, the detection device sends a certificate cancellation command, and the OBU connects to the certificate management system to send a certificate cancellation request. After receiving the cancellation request, the certificate management system verifies the identity of the OBU and executes the certificate cancellation.
[0087] Since the vehicle identification code and the OBU identification code are uniquely bound to the certificate, all certificates of the vehicle and the OBU are cancelled through the certificate management system, and the certificate activities during the vehicle life cycle end.
[0088] After the certificate is cancelled, a corresponding certificate cancellation list will be issued. As the number of certificate cancellations for scrapped vehicles increases, the certificate cancellation list becomes larger and larger. To reduce the growth of the certificate cancellation list, when the certificate reaches its validity period and the certificate has expired and is unavailable, the certificate is removed from the certificate cancellation list.
[0089] Embodiment 4
[0090] Figure 4 It is a structural diagram of a certificate processing device provided in Embodiment 4 of the present application. The embodiments of the present application are applicable to the processing of in-vehicle unit certificates. The device can be implemented in software and / or hardware and can be configured in the in-vehicle unit. As Figure 4As shown, the certificate processing device 400 may include: a working state determination module 410 and a certificate processing module 420, where
[0091] The working state determination module 410 is configured to determine the working state of the on-vehicle unit; where the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorization state;
[0092] The certificate processing module 420 is configured to process the long-term certificate and / or short-term certificate according to the working state.
[0093] The technical solution of the embodiment of the present application processes the long-term certificate and / or short-term certificate according to the working state of the on-vehicle unit. Different working states correspond to different processing methods, which can comprehensively process the certificates in the entire life cycle of the on-vehicle unit, improve the automatic processing efficiency of the long-term certificate and short-term certificate of the on-vehicle unit, ensure the use safety of the on-vehicle unit, and improve the user's use experience of the vehicle.
[0094] In an alternative embodiment, if the working state includes an activation state, the certificate processing module 420 may include:
[0095] The short-term certificate update unit is configured to control the update of the short-term certificate according to the activation situation of the on-vehicle unit and the certificate status of the long-term certificate.
[0096] In an alternative embodiment, the short-term certificate update module may include:
[0097] The short-term certificate update subunit is configured to control the update of the short-term certificate if the on-vehicle unit is in an activated state and the long-term certificate is in a valid certificate state.
[0098] In an alternative embodiment, if the working state includes an abnormal state, the certificate processing module 420 may include:
[0099] The abnormal state processing unit is configured to process the long-term certificate according to the abnormal state information of the on-vehicle unit.
[0100] In an alternative embodiment, the abnormal state processing unit may include:
[0101] The alarm cancellation subunit is configured to perform alarm and / or cancellation processing on the long-term certificate if the occurrence frequency of the abnormal state information meets the preset frequency range.
[0102] In an alternative embodiment, if the working state includes an authorization state, the certificate processing module 420 may include:
[0103] A deregistration removal unit is configured to remove long-term certificates and short-term certificates from the certificate revocation list according to the unauthorized situations of the long-term certificates and the short-term certificates.
[0104] In an alternative embodiment, if the working state includes an initial state, the certificate processing module 420 may include:
[0105] A long-term certificate download unit is configured to download long-term certificates according to the initial state of the on-vehicle unit.
[0106] In an alternative embodiment, the long-term certificate download unit may include:
[0107] A first type of certificate download subunit is configured to apply for and download a first type of certificate according to the initialization conditions of the on-vehicle unit, and generate a key;
[0108] A second type of certificate download subunit is configured to apply for and download a second type of registration certificate based on the first type of certificate and the key.
[0109] The certificate processing device provided by the embodiments of the present application can execute the certificate processing method provided by any embodiment of the present application, and has the corresponding functional modules and beneficial effects for executing each certificate processing method.
[0110] Embodiment 5
[0111] Figure 5 It is a structural diagram of an on-vehicle unit provided by Embodiment 5 of the present application. Figure 5 It shows a block diagram of an exemplary on-vehicle unit 512 suitable for implementing the embodiments of the present application. Figure 5 The shown on-vehicle unit 512 is only an example, and should not impose any limitation on the functions and usage scope of the embodiments of the present application.
[0112] As Figure 5 shown, the on-vehicle unit 512 is presented in the form of a general-purpose computing device. The components of the on-vehicle unit 512 may include, but are not limited to: one or more processors or processing units 516, a system memory 528, and a bus 518 connecting different system components (including the system memory 528 and the processing unit 516).
[0113] The bus 518 represents one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the multiple bus structures. For example, these architectures include, but are not limited to, an Industry Standard Architecture (ISA) bus, a Micro Channel Architecture (MAC) bus, an Enhanced ISA bus, a Video Electronics Standards Association (VESA) local bus, and a Peripheral Component Interconnect (PCI) bus.
[0114] The on-vehicle unit 512 typically includes various computer system-readable media. These media can be any available media accessible to the on-vehicle unit 512, including volatile and non-volatile media, removable and non-removable media.
[0115] The system memory 528 may include computer system-readable media in the form of volatile memory, such as random access memory (RAM) 530 and / or cache memory 532. The on-vehicle unit 512 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, the storage system 534 can be used for reading and writing on non-removable, non-volatile magnetic media ( Figure 5 not shown, commonly referred to as a "hard disk drive"). Although Figure 5 not shown in, a disk drive for reading and writing on removable non-volatile disks (such as "floppy disks") and an optical disk drive for reading and writing on removable non-volatile optical disks (such as CD-ROM, DVD-ROM or other optical media) can be provided. In these cases, each drive can be connected to the bus 518 through one or more data media interfaces. The memory 528 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present application.
[0116] A program / utility 540 having a set (at least one) of program modules 542 can be stored, for example, in the memory 528. Such program modules 542 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment. The program modules 542 generally perform the functions and / or methods in the embodiments described in the present application.
[0117] The in-vehicle unit 512 can also communicate with one or more external devices 514 (such as a keyboard, a pointing device, a display 524, etc.), and can also communicate with one or more devices that enable a user to interact with the in-vehicle unit 512, and / or communicate with any device that enables the in-vehicle unit 512 to communicate with one or more other computing devices (such as a network card, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface 522. Moreover, the in-vehicle unit 512 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 520. As shown in the figure, the network adapter 520 communicates with other modules of the in-vehicle unit 512 through a bus 518. It should be understood that although not shown in the figure, other hardware and / or software modules can be used in combination with the in-vehicle unit 512, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0118] The processing unit 516 executes various functional applications and data processing by running at least one of other programs among a plurality of programs stored in the system memory 528, for example, implementing the certificate processing method provided by the embodiments of the present application.
[0119] The embodiments of the present application also provide a vehicle, which is provided with an in-vehicle unit as described in Embodiment Five of the present application. Figure 5 in the in-vehicle unit.
[0120] Embodiment Six
[0121] The embodiments of the present application also provide a computer-readable storage medium, on which a computer program (or computer-executable instructions) is stored, and when the program is executed by a processor, it is used to execute the certificate processing method provided by the embodiments of the present application: determining the working state of the in-vehicle unit; wherein the working state includes at least one of an initial state, an activation state, an abnormal state, and an authorization state; and processing the long-term certificate and / or the short-term certificate according to the working state.
[0122] The computer storage medium of the embodiments of the present application may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0123] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0124] The program code contained on the computer-readable medium may be transmitted by any appropriate medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination of the above.
[0125] The computer program code for performing the operations of the embodiments of the present application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0126] Note that the above is only a preferred embodiment of the present application and the applied technical principles. Those skilled in the art will understand that the present application is not limited to the specific embodiments described herein, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments. Without departing from the concept of the present application, more other equivalent embodiments can be included, and the scope of the present application is determined by the scope of the appended claims.
Claims
1. A method for processing certificates at different life cycle stages of a vehicle where an in-vehicle unit is located, characterized in that, it is executed by the in-vehicle unit, and a long-term certificate and a short-term certificate are set in the in-vehicle unit. The method includes: Determining the working state of the in-vehicle unit according to different life cycle stages of the vehicle where the in-vehicle unit is located; wherein, the working state includes an initial state, an activation state, an abnormal state, and an authorized state; Processing the long-term certificate and / or the short-term certificate according to the working state; Wherein, the method further includes: when all electronic devices in the vehicle are initialized at the time of vehicle factory exit, the working state of the corresponding in-vehicle unit is the initial state; when the hardware functions of the vehicle need to be used normally during the vehicle sales stage, the working state of the corresponding in-vehicle unit is the activation state; when there are problems with the usage certificates of the in-vehicle unit-related functions during the user usage stage after the vehicle is sold and the in-vehicle unit cannot work normally, the corresponding in-vehicle unit is in an abnormal state; when the usage certificates of the in-vehicle unit-related functions need to be unbound and cancelled for the vehicle during the vehicle scrapping stage, the corresponding in-vehicle unit is in the authorized state for each certificate; Wherein, the method further includes: if the working state includes the activation state, then the processing the long-term certificate and / or the short-term certificate according to the working state includes: Controlling and updating the short-term certificate according to the activation situation of the in-vehicle unit and the certificate state of the long-term certificate; Wherein, the certificate state includes a certificate valid state, a certificate not yet effective state, a certificate expired state, a certificate abnormal alarm state, and a certificate cancelled state; the controlling and updating the short-term certificate according to the activation situation of the in-vehicle unit and the certificate state of the long-term certificate includes: If the in-vehicle unit is in an activated state and the long-term certificate is in a certificate valid state, then control and update the short-term certificate.
2. The method according to any one of claims 1, characterized in that, if the working state includes the abnormal state, then the processing the long-term certificate according to the working state includes: Processing the long-term certificate according to the abnormal state information of the in-vehicle unit.
3. The method according to claim 2, characterized in that, the processing the long-term certificate according to the abnormal state information of the in-vehicle unit includes: If the occurrence frequency of the abnormal state information meets a preset frequency range, then perform alarm and / or cancellation processing on the long-term certificate.
4. The method according to claim 1, characterized in that, if the working state includes the authorized state, then the processing the long-term certificate and / or the short-term certificate according to the working state includes: Removing the long-term certificate and the short-term certificate from the certificate cancellation list according to the unauthorized situation of the long-term certificate and the short-term certificate.
5. The method according to claim 1, characterized in that, if the working state includes the initial state, then the processing the long-term certificate according to the working state includes: Downloading the long-term certificate according to the initial state of the in-vehicle unit.
6. The method according to claim 5, wherein, the downloading of the long-term certificate according to the initial state of the in-vehicle unit includes: applying for and downloading a first type of certificate according to the initialization conditions of the in-vehicle unit, and generating a secret key; applying for and downloading a second type of registration certificate based on the first type of certificate and the secret key.
7. A certificate processing device for different life cycle stages of a vehicle where an in-vehicle unit is located, wherein, executed by the in-vehicle unit, the in-vehicle unit is provided with a long-term certificate and a short-term certificate, and the device includes: a working state determination module, configured to determine the working state of the in-vehicle unit according to different life cycle stages of the vehicle where the in-vehicle unit is located; wherein, the working state includes an initial state, an activation state, an abnormal state, and an authorization state; a certificate processing module, configured to process the long-term certificate and / or the short-term certificate according to the working state; wherein, the working state determination module is specifically configured to: when all electronic devices in the vehicle are initialized during vehicle factory production, the working state of the corresponding in-vehicle unit is the initial state; when the hardware functions of the vehicle need to be used normally during the vehicle sales stage, the working state of the corresponding in-vehicle unit is the activation state; when there are problems with the usage certificates of the in-vehicle unit related functions during the user usage stage after the vehicle is sold, resulting in the in-vehicle unit being unable to work properly, the corresponding in-vehicle unit is in an abnormal state; when the usage certificates of the in-vehicle unit related functions need to be unbound and cancelled during the vehicle scrapping stage, the corresponding in-vehicle unit is in the authorization state for each certificate; wherein, if the working state includes the activation state, the certificate processing module includes: a short-term certificate update unit, configured to control the update of the short-term certificate according to the activation situation of the in-vehicle unit and the certificate state of the long-term certificate; wherein, the certificate state includes a certificate valid state, a certificate not yet effective state, a certificate expired state, a certificate abnormal alarm state, and a certificate cancellation state; the short-term certificate update unit includes: a short-term certificate update sub-unit, configured to control the update of the short-term certificate if the in-vehicle unit is in an activated state and the long-term certificate is in a certificate valid state.
8. An in-vehicle unit, wherein, including: one or more processors; a memory, configured to store one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement a certificate processing method according to any one of claims 1-6.
9. A computer-readable storage medium, on which a computer program is stored, wherein, when the program is executed by a processor, it implements a certificate processing method according to any one of claims 1-6.
10. A vehicle, wherein, the vehicle is provided with the in-vehicle unit according to claim 8.
Citation Information
Patent Citations
Internet of Vehicles certificate management method for preventing privacy leakage
CN110958607A
Abnormal behavior detection method, device and system for Internet of Vehicles
CN111200799A
Detection method and system for connecting vehicle-mounted intelligent terminal with background server
CN113395335A