Vehicle Internet of Things Information Encryption Method, Device and Vehicle Internet of Things System

By using true random number encryption and secure key distribution technology in the Internet of Vehicles system, the problems of easy breaking of dynamic passwords and low data transmission security in Internet of Vehicles information interaction are solved, and the security of data transmission and difficulty of deciphering are improved.

CN115174083BActive Publication Date: 2025-05-27CHONGQING LIANXIN INTELLIGENT TECH RES INST CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210794868.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-07
Publication Date
2025-05-27
Estimated Expiration
2042-07-07

AI Technical Summary

Technical Problem

In the prior art, the communication key update method adopted by Internet of Vehicles information interaction leads to high correlation between dynamic passwords, easy deciphering dynamic passwords, and low security of data transmission.

Method used

By obtaining the data to be encrypted, the confidentiality level is judged according to the preset rules, and the encryption level is obtained; based on the encryption level and the data to be encrypted, the target true random number is generated and the encrypted data is encrypted; the target true random number is distributed by charging, QKD or PQC encryption keys, the encrypted information is decrypted, and the original data is restored.

Benefits of technology

Using true random number encryption increases the difficulty of deciphering, and through a secure key distribution mechanism, the security of data transmission is improved, solving the problems of easy breaking of dynamic passwords and low data transmission security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115174083B_ABST
    Figure CN115174083B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data security technology, and provides a vehicle networking information encryption method, device and vehicle networking system, which are applied to the vehicle networking system. The vehicle networking information encryption method includes: obtaining data to be encrypted, judging the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level; obtaining a target true random number based on the encryption level and the data to be encrypted; encrypting the data to be encrypted with the target true random number to obtain encrypted information; distributing the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted. Compared with the prior art, the vehicle networking information encryption method, device and vehicle networking system provided by the present invention realize the secure distribution of keys and improve the security of data transmission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and more particularly, to a vehicle networking information encryption method, apparatus, and vehicle networking system. Background Art

[0002] With the development of vehicle networking, it has been possible to remotely control a vehicle to unlock, start ventilation, and view images around the vehicle using a mobile phone. It is also possible to complete operations such as upgrading the in-vehicle infotainment (IVI) firmware and updating the map package through over-the-air (OTA) technology. Autonomous driving technology can even enable a vehicle to automatically assist in steering, accelerating, and braking according to road conditions. With the advent of the quantum computer era, the RSA system based on the factorization problem, the ElGamal system based on the discrete logarithm problem, and the ECC system based on the elliptic discrete logarithm problem will all become insecure. However, these algorithms are the foundation of all current Internet security and are widely used.

[0003] With the rapid development of vehicle networking, the accompanying information security issues have become key issues that must be addressed in the development of intelligent connected vehicles. Cryptography, as the core technology and basic support for ensuring vehicle networking security, plays an irreplaceable role in aspects such as vehicle networking data encryption and authentication.

[0004] In the prior art, the communication key update adopted in vehicle networking information interaction is a method of encrypting an old key to obtain a new key, and performing an operation with a continuously updated synchronization code based on the initial key to update and replace the dynamic key. The dynamic keys have a large correlation, making it easy to break the dynamic password and resulting in low data transmission security. Summary of the Invention

[0005] The purpose of the present invention is to provide a vehicle networking information encryption method, apparatus, and vehicle networking system to improve the problems in the prior art that the dynamic passwords have a large correlation, are easy to break, and the data transmission security is low.

[0006] To achieve the above purpose, the technical solutions adopted in the embodiments of the present invention are as follows:

[0007] In a first aspect, an embodiment of the present invention provides a vehicle networking information encryption method applied to a vehicle networking system. The vehicle networking information encryption method includes: obtaining data to be encrypted, judging the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level; obtaining a target true random number based on the encryption level and the data to be encrypted; encrypting the data to be encrypted with the target true random number to obtain encrypted information; distributing the target true random number by means of charging, quantum key distribution (QKD), or post-quantum cryptography (PQC) encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0008] Second aspect, an embodiment of the present invention provides a vehicle networking information encryption device, which is applied to a vehicle networking system. The vehicle networking information encryption device includes: an encryption level judgment module, configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, and obtain an encryption level; a true random number acquisition module, configured to obtain a target true random number according to the encryption level and the data to be encrypted; an encryption module, configured to encrypt the data to be encrypted with the target true random number to obtain encrypted information; a distribution module, configured to distribute the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0009] Third aspect, an embodiment of the present invention provides a vehicle networking system. The vehicle networking system includes an in-vehicle terminal, and the in-vehicle terminal includes a random number generator, a secure memory, and a controller. The random number generator is electrically connected to the secure memory, and the secure memory is electrically connected to the controller; the random number generator is configured to generate a true random number and transmit it to the secure memory for storage; the controller is configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, obtain an encryption level, obtain a target true random number according to the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0010] Fourth aspect, an embodiment of the present invention provides a vehicle networking system. The vehicle networking system includes an in-vehicle terminal and a random number injector. The in-vehicle terminal is electrically connected to the random number injector; the random number injector is configured to generate a true random number and send it to the in-vehicle terminal; the in-vehicle terminal is configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, obtain an encryption level, obtain a target true random number according to the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0011] Fifth aspect, an embodiment of the present invention provides a vehicle networking system, which includes an in-vehicle terminal, a cloud platform, and a true random number injector. The in-vehicle terminal is communicatively connected to the cloud platform, and the true random number injector is connected to the cloud platform. The true random number injector is configured to generate true random numbers and send them to the in-vehicle terminal through the cloud platform. The in-vehicle terminal is configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level, obtain a target true random number based on the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of injection, QKD, or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0012] Compared with the prior art, the embodiment of the present invention has the following beneficial effects:

[0013] An information encryption method, device, and vehicle networking system provided by an embodiment of the present invention obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level; obtain a target true random number based on the encryption level and the data to be encrypted; encrypt the data to be encrypted with the target true random number to obtain encrypted information; and distribute the target true random number by means of injection, QKD, or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted. Using true random numbers for encryption increases the difficulty of deciphering. At the same time, using injection, QKD, or PQC encryption key for key distribution realizes secure key distribution and improves data transmission security.

[0014] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following specific preferred embodiments are given, and in conjunction with the accompanying drawings, the detailed description is as follows. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without creative efforts.

[0016] Figure 1 Shows a first block diagram of the vehicle networking system provided by an embodiment of the present invention;

[0017] Figure 2 Shows a second block diagram of the vehicle networking system provided by an embodiment of the present invention;

[0018] Figure 3 Shows a schematic diagram of a third - party box of the vehicle - to - everything (V2X) system provided by an embodiment of the present invention;

[0019] Figure 4 Shows a flowchart of a vehicle - to - everything information encryption method provided by an embodiment of the present invention;

[0020] Figure 5 Is Figure 4 The first sub - step flowchart of step S2 shown;

[0021] Figure 6 Is Figure 5 The sub - step flowchart of step S23 shown;

[0022] Figure 7 Is Figure 4 The second sub - step flowchart of step S2 shown;

[0023] Figure 8 Is Figure 4 The third sub - step flowchart of step S2 shown;

[0024] Figure 9 Shows a schematic diagram of the structure of a vehicle - to - everything information encryption device provided by an embodiment of the present invention.

[0025] Reference numerals: 10 - vehicle terminal; 20 - cloud platform; 30 - electronic device; 40 - car key; 100 - vehicle - to - everything information encryption device; 110 - encryption level judgment module; 120 - true random number acquisition module; 130 - encryption module; 140 - distribution module. Detailed implementation manners

[0026] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. The components of the embodiments of the present invention described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the detailed description of the embodiments of the present invention provided in the drawings below is not intended to limit the scope of the present invention claimed, but only represents the selected embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0027] It should be noted that: similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present invention, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0028] The following will describe in detail some embodiments of the present application with reference to the accompanying drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0029] The vehicle networking information encryption method provided by the embodiments of the present invention is applied to a vehicle networking system. Please refer to Figure 1 , Figure 1 , which shows a block diagram of the vehicle networking system provided by the embodiments of the present invention. The vehicle networking system includes an in-vehicle terminal 10, a cloud platform 20, an electronic device 30, and a vehicle key 40. The cloud platform 20, the electronic device 30, and the vehicle key 40 are all communicatively connected to the in-vehicle terminal 10 to realize information interaction between the cloud platform 20 and the in-vehicle terminal 10, information interaction between the electronic device 30 and the in-vehicle terminal 10, and information interaction between the vehicle key 40 and the in-vehicle terminal 10.

[0030] An in-vehicle terminal 10 is installed in the vehicle, and the in-vehicle terminal 10 is connected to other devices in the vehicle. As an implementation manner, the in-vehicle terminal 10 may include a random number generator, a secure storage device, and a controller. The random number generator and the secure memory are electrically connected, and the secure memory is electrically connected to the controller. The random number generator is used to generate true random numbers and transmit them to the secure memory for storage. The secure memory is used to transmit true random numbers to the controller. The controller is used to execute a program to implement the vehicle networking information encryption method after receiving an execution instruction.

[0031] The secure memory may include a high-speed random access memory (RAM: Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. The secure memory may be, but is not limited to, a random access memory (Random Access Memory, RAM), a read-only memory (Read Only Memory, ROM), a programmable read-only memory (Programmable Read-Only Memory, PROM), an erasable programmable read-only memory (Erasable Programmable Read-Only Memory, EPROM), an electrically erasable programmable read-only memory (Electric Erasable Programmable Read-Only Memory, EEPROM), etc.

[0032] The controller may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the vehicle networking information encryption method can be completed by the integrated logic circuit of the hardware in the processor or the instructions in the form of software. The above-mentioned controller may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0033] In other embodiments of the present invention, please refer to Figure 2 , Figure 2 which shows a second block diagram of the vehicle networking system provided by the embodiment of the present invention. The vehicle networking system may further include an in-vehicle terminal 10 and a true random number injector. The in-vehicle terminal 10 and the true random number injector are electrically connected. The true random number injector is used to generate true random numbers and send them to the in-vehicle terminal 10. The in-vehicle terminal 10 is used to execute a program to implement the vehicle networking information encryption method after receiving an execution instruction.

[0034] In other embodiments of the present invention, please refer to Figure 3 , Figure 3 which shows a third block diagram of the vehicle networking system provided by the embodiment of the present invention. The vehicle networking system may further include an in-vehicle terminal 10, a cloud platform 20, and a true random number injector. The in-vehicle terminal 10 and the cloud platform 20 are communicatively connected. The true random number injector and the cloud platform 20 are connected. Specifically, the true random number injector may be electrically connected or communicatively connected to the cloud platform 20. The true random number injector is used to generate true random numbers and send them to the in-vehicle terminal 10 through the cloud platform 20. The in-vehicle terminal 10 is used to execute a program to implement the vehicle networking information encryption method after receiving an execution instruction. It should be noted that the in-vehicle terminal 10 may also obtain true random numbers through other devices or methods.

[0035] An electronic device 30. The electronic device 30 may be, but is not limited to, a smart phone, a tablet computer, a personal computer, an in-vehicle computer, a personal digital assistant (PDA), etc.

[0036] It should be understood that Figures 1 to 3The structure shown is only a schematic diagram of the structural application of the vehicle networking system. The vehicle networking system may also include more or fewer components than those shown in the figure, or have a configuration different from that shown in the figure. Each component shown in the figure may be implemented by hardware, software, or a combination thereof.

[0037] The vehicle networking information encryption method provided by the present invention is applied to information interaction in the vehicle networking system. Specifically, the vehicle networking information encryption method can be used for information interaction between the cloud platform 20 and the vehicle-mounted terminal 10, can also be used for information interaction between the electronic device 30 and the vehicle-mounted terminal 10, and can also be used for information interaction between the vehicle key 40 and the vehicle-mounted terminal 10. It should be noted that the vehicle networking information encryption method can be applied to one pair, two pairs, or three pairs of information interactions at the same time, and there is no limitation in the embodiments of the present invention.

[0038] Based on the above vehicle networking system, when information is sent from the vehicle-mounted terminal 10 to the cloud platform 20, the vehicle-mounted terminal 10 executes the vehicle networking information encryption method and decrypts it on the cloud platform 20; when information is sent from the cloud platform 20 to the vehicle-mounted terminal 10, the cloud platform 20 executes the vehicle networking information encryption method and decrypts it on the vehicle-mounted terminal 10; when information is sent from the vehicle-mounted terminal 10 to the electronic device 30, the vehicle-mounted terminal 10 executes the vehicle networking information encryption method and decrypts it on the electronic device 30; when information is sent from the electronic device 30 to the vehicle-mounted terminal 10, the electronic device 30 executes the vehicle networking information encryption method and decrypts it on the vehicle-mounted terminal 10; when information is sent from the vehicle-mounted terminal 10 to the vehicle key 40, the vehicle-mounted terminal 10 executes the vehicle networking information encryption method and decrypts it on the vehicle key 40; when information is sent from the vehicle key 40 to the vehicle-mounted terminal 10, the vehicle key 40 executes the vehicle networking information encryption method and decrypts it on the vehicle-mounted terminal 10.

[0039] First Embodiment

[0040] Taking the information interaction between the vehicle-mounted terminal 10 and the cloud platform 20 and the information being sent from the vehicle-mounted terminal 10 to the cloud platform 20 as an example, a possible implementation manner of the vehicle networking information encryption method is given below. Please refer to Figure 4 , Figure 4 shows a flowchart of the vehicle networking information encryption method provided by the embodiment of the present invention. The vehicle networking information encryption method includes the following steps:

[0041] S1, obtain the data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, and obtain the encryption level.

[0042] In the embodiments of the present invention, the data to be encrypted may be the data to be transmitted in information interaction. For example, when transmitting from the vehicle terminal 10 to the cloud platform 20, the data to be encrypted may be the data representing the current state of the vehicle, including at least one of radar data, position data, vehicle bus data, and vehicle driving data. Specifically, the radar data may be vehicle-mounted radar data, the position data may be the real-time GPS latitude and longitude coordinate values, the vehicle bus data may be, but is not limited to, seat cushion heating instructions, engine start instructions, lock switch instructions, current fuel quantity, current power, etc., and the vehicle driving data may be, but is not limited to, lateral acceleration, longitudinal acceleration, lateral speed, longitudinal speed, steering wheel angle, engine speed, etc. Of course, the vehicle data may also be other data related to the vehicle, such as sensor data, etc., which are not limited in the embodiments of the present invention. When transmitting from the cloud platform 20 to the vehicle terminal 10, the data to be encrypted may be the control instructions generated by the cloud platform 20, such as window opening, acceleration, deceleration, etc.

[0043] The encryption levels may be multiple encryption levels divided according to the confidentiality importance of the data to be encrypted. For example, three, four, five, or even more. Taking the encryption levels including three encryption levels as an example for illustration. The encryption levels include the first encryption level, the second encryption level, and the third encryption level. Obtain the data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, and obtain the encryption level. It can be understood that the preset radar data is the third encryption level, the position data, vehicle bus data, and sensor data are the second encryption level, and the vehicle driving data is the first encryption level. In other embodiments of the present invention, the preset rule may also be that as long as the data to be encrypted contains vehicle driving data, it is determined as the first encryption level. When the data to be encrypted only contains radar data, it is determined as the third encryption level, and in other cases, it is determined as the second encryption level. The preset rule can be various as long as it is reasonable, and will not be elaborated one by one in the embodiments of the present invention.

[0044] S2. Obtain a target true random number according to the encryption level and the data to be encrypted;

[0045] In the embodiments of the present invention, the true random number may be a random number generated from a physical process rather than a computer program, and is obtained from microscopic phenomena of statistical random "noise" signals, such as thermal noise, the photoelectric effect involving a beam splitter, and other quantum phenomena. The true random number can be obtained by pre-storing in a storage medium or generated by a random number generator. The target true random number represents a true random number that matches the encryption level and data length of the data to be encrypted.

[0046] The vehicle networking system includes a secure memory, which is disposed in the vehicle terminal 10 and electrically connected to the controller of the vehicle terminal 10. A plurality of true random numbers and the corresponding reuse times of each true random number are stored in the secure memory.

[0047] Please refer to Figure 5 , step S2 may further include the following sub-steps:

[0048] Sub-step S21, calculate the data length of the data to be encrypted to obtain the first data length.

[0049] In an embodiment of the present invention, the first data length represents the data length of the data to be encrypted.

[0050] Sub-step S22, determine the target multiplexing times from multiple multiplexing times according to the encryption level.

[0051] In an embodiment of the present invention, the multiplexing times represents the number of times the corresponding true random number can be reused. The multiplexing times being 0 means that the true random number is used only once and the number of repeated uses is 0. For example, now there are true random numbers A, B, C, D, E, F, G, and H. The multiplexing times corresponding to true random number A is 2, the multiplexing times corresponding to true random number B is 3, the multiplexing times corresponding to true random number C is 0, the multiplexing times corresponding to true random number D is 5, the multiplexing times corresponding to true random number E is 1, the multiplexing times corresponding to true random number F is 0, the multiplexing times corresponding to true random number G is 2, and the multiplexing times corresponding to true random number H is 4. Counting the true random numbers with multiplexing times of 0 are C and F, the true random number with multiplexing times of 1 is E, the true random numbers with multiplexing times of 2 are A and G, the true random number with multiplexing times of 3 is B, and the true random number with multiplexing times of 5 is D.

[0052] The multiplexing times corresponding to the preset first encryption level is 0, the multiplexing times corresponding to the second encryption level is 1 to 4, and the multiplexing times corresponding to the third encryption level is 5. In an embodiment of the present invention, the earlier the encryption level, the higher the corresponding confidentiality importance. The first encryption level > the second encryption level > the third encryption level. In other embodiments of the present invention, it can also be set conversely, which is not limited herein. The step of determining the target multiplexing times from multiple multiplexing times according to the encryption level can be understood as that when the encryption level is the first encryption level, the target multiplexing times is 0; when the encryption level is the second encryption level, the target multiplexing times is 1 to 4; when the encryption level is the third encryption level, the target multiplexing times is 5. As long as the preset encryption level and its corresponding multiplexing times are reasonable, the embodiments of the present invention do not make specific limitations.

[0053] In other embodiments of the present invention, the execution of sub-step S21 and sub-step S22 can be swapped in order or executed simultaneously, which is not limited in the embodiments of the present invention.

[0054] Sub-step S23, determine the target true random number from multiple true random numbers according to the target multiplexing times and the first data length.

[0055] In an embodiment of the present invention, the step of determining a target true random number from a plurality of true random numbers according to a target reuse count and a first data length can be understood as obtaining at least one true random number corresponding to the target reuse count, calculating the data lengths of the at least one true random number to obtain at least one second data length, comparing the at least one second data length with the first data length, and using the true random number corresponding to the second data length being greater than or equal to the first data length as the target true random number.

[0056] Please refer to Figure 6 , Figure 6 For Figure 5 the flowchart of the sub-steps of step S23 shown, step S23 includes the following sub-steps:

[0057] Sub-step S231: Obtain at least one true random number corresponding to the target reuse count.

[0058] In an embodiment of the present invention, the step of obtaining at least one true random number corresponding to the target reuse count can be understood as, for example, when the target reuse count is 0, the corresponding true random numbers are C and F; when the target reuse count is 1 to 4, the corresponding true random numbers are E, A, G, and B; and when the target reuse count is 5, the corresponding true random number is D.

[0059] Sub-step S232: Calculate the data lengths of the at least one true random number to obtain at least one second data length.

[0060] In an embodiment of the present invention, the second data length represents the data length of the true random number corresponding to the target reuse count. Taking the target reuse count of 0 as an example, calculate the data length of the true random number C to obtain the second data length corresponding to the true random number C, and calculate the data length corresponding to the true random number F to obtain the second data length corresponding to the true random number F.

[0061] Sub-step S233: Compare the at least one second data length with the first data length, and use the true random number corresponding to the second data length being greater than or equal to the first data length as the target true random number.

[0062] In an embodiment of the present invention, compare the second data length corresponding to the true random number C with the first data length. If the second data length corresponding to the true random number C is greater than or equal to the first data length, then use the true random number C as the target true random number. Compare the second data length corresponding to the true random number F with the first data length. If the second data length corresponding to the true random number F is greater than or equal to the first data length, then use the true random number F as the target true random number. It should be noted that if multiple target true random numbers that meet the conditions are obtained simultaneously, any one of them can be selected.

[0063] It should be noted that each time a true random number participates in encryption as the target true random number, its corresponding reuse count is decreased by one. If the reuse count corresponding to the true random number is already 0, after participating in encryption as the target true random number, the reuse count becomes -1 and it can no longer be used. The true random number with a reuse count of -1 can be deleted to optimize the storage space.

[0064] By screening the target true random numbers whose length is greater than or equal to the data to be encrypted to encrypt the data to be encrypted, the security performance of the data to be encrypted is improved. At the same time, by pre-judging the confidentiality level and importance of the data to be encrypted to set the reuse count of the true random number as the session key, the amount of key usage can be reduced.

[0065] The vehicle networking system includes a secure memory, in which multiple true random numbers and the corresponding reuse counts of each true random number are stored. The reuse count represents the number of times the corresponding true random number has been reused.

[0066] Please refer to Figure 7 , step S2 may further include the following sub-steps:

[0067] Sub-step S24, calculate the data length of the data to be encrypted to obtain a third data length.

[0068] In the embodiment of the present invention, the third data length represents the data length of the data to be encrypted.

[0069] Sub-step S25, obtain the true random number with a data length of the third data length to obtain the to-be-determined true random number.

[0070] In the embodiment of the present invention, the to-be-determined true random number represents the true random number with a data length of the third data length. For example, if the third data length is 300 bit, the step of obtaining the true random number with a data length of the third data length to obtain the to-be-determined true random number can be understood as obtaining a true random number with a data length of 300 bit from the secure memory as the to-be-determined true random number. If there is no true random number with this data length in the secure memory, it can be generated in the random number generator, and the corresponding reuse count of this true random number is set to 0.

[0071] Sub-step S26, obtain the target true random number based on the to-be-determined true random number, the corresponding reuse count of the to-be-determined true random number, and the encryption level.

[0072] In the embodiment of the present invention, the step of obtaining the target true random number based on the to-be-determined true random number, the corresponding reuse count of the to-be-determined true random number, and the encryption level can be understood as follows: First, equally divide the to-be-determined true random number according to the encryption level, and then take out the part corresponding to the reuse count as the target true random number.

[0073] For example, when the true random number to be determined has a data length of 300 bits, the encryption level is the third encryption level, and the corresponding number of times of reuse of the true random number to be determined is 1, the true random number to be determined is equally divided into three parts to obtain three sub-true random numbers with a data length of 100 bits. The preset number of times of reuse is 0, corresponding to the first sub-true random number among them, the number of times of reuse is 1, corresponding to the second sub-true random number among them, and the number of times of reuse is 2, corresponding to the third sub-true random number among them. The second sub-true random number among them is retrieved as the target true random number.

[0074] It should be noted that each time a part of the true random number to be determined is used as the target true random number to participate in encryption once, the corresponding number of times of reuse is incremented by one. If the number of times of reuse corresponding to the true random number to be determined is equal to the encryption level - 1, it cannot be used anymore, and the true random number to be determined can be deleted to optimize the storage space.

[0075] Please refer to Figure 8 , step S2 may further include the following sub-steps:

[0076] Sub-step S27, calculate the data length of the data to be encrypted to obtain a fourth data length.

[0077] In the embodiment of the present invention, the fourth data length represents the data length of the data to be encrypted.

[0078] Sub-step S28, calculate a fifth data length according to the fourth data length and the encryption level.

[0079] In the embodiment of the present invention, the fifth data length = the fourth data length / the encryption level. For example, if the fourth data length is 300 bits and the encryption level is the third encryption level, then the fifth data length is 300 bits / 3 = 100 bits.

[0080] Sub-step S29, obtain a true random number with a data length of the fifth data length as the target true random number.

[0081] In the embodiment of the present invention, the step of obtaining a true random number with a data length of the fifth data length as the target true random number can be understood as obtaining a true random number with a data length of the fifth data length as the target true random number from the secure memory, or generating a true random number with a data length of the fifth data length as the target true random number from a random number injector.

[0082] S3, encrypt the data to be encrypted with the target true random number to obtain encrypted information.

[0083] In an embodiment of the present invention, the step of encrypting the data to be encrypted with a target true random number to obtain encrypted information is to use the target true random number as a session key in combination with an encryption algorithm to encrypt the data to be encrypted to obtain encrypted information, and send the encrypted information to the cloud platform 20. The encryption algorithm can be, but is not limited to, the XOR high-speed encryption operation.

[0084] It should be noted that if the data length of the target true random number is less than the data length of the data to be encrypted, the target true random number needs to be copied equally according to the encryption level to generate a session key with a data length greater than or equal to the data to be encrypted. Combining the above example, the encryption level is the third encryption level, the data length of the data to be encrypted is 300 bit, and the data length of the target true random number is 100 bit. Then, the true random number needs to be replicated three times itself first and then used as the session key to participate in the encryption. The block encryption method can be Electronic Code Book (ECB), Cipher-block chaining (CBC), Propagating cipher-block chaining (PCBC), Cipher feedback (CFB), Output feedback (OFB), Counter mode (CTR), etc.

[0085] S4. Use the method of injecting, QKD or PQC to encrypt the key to distribute the target true random number, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0086] In an embodiment of the present invention, in an embodiment of the present invention, injection can be by means of an external storage medium, such as a hard disk, a USB flash drive, an optical disc, etc.

[0087] The distribution process of QKD is as follows:

[0088] The A end randomly selects a polarization basis;

[0089] The A end modulates a single-photon signal according to the polarization basis;

[0090] The polarization basis randomly selected by the B end is used for reception;

[0091] The key bit converted by the B end according to the measurement of the single-photon polarization state can be seen that when the two ends select the same polarization basis, the correct key bit can be measured, and when the two ends select different polarization bases, an incorrect key bit will be measured;

[0092] The B end sends its basis selection to the A end through a public channel;

[0093] The A - end sends a subset of the correctly selected bases to the B - end through the public channel;

[0094] The A - end and the B - end select a section of the keys corresponding to the same base selection and make them public. If there are differences in the emerging sequence, it indicates that someone is eavesdropping, and then this communication is invalidated. If there are no differences, the un - publicized part of the keys corresponding to the same base selection is used as the final key bits;

[0095] The key bits negotiated by the cloud platform 20 through QKD can be stored in the memory, and the vehicle - mounted terminal 10 can obtain the key from the nearest QKD terminal.

[0096] The process of PQC encryption key is as follows:

[0097] In the case where the identity authentication has been carried out between the sender and the receiver, the receiving end obtains the public - private key pair through the PQC algorithm and sends the public key to the sending end;

[0098] The sending end encrypts the session key (i.e., the target true random number) to be transmitted with the public key through the PQC algorithm and sends the encrypted session key to the receiving end.

[0099] The receiving end receives the encrypted session key and decrypts the encrypted session key with the private key through the PQC algorithm to obtain the session key.

[0100] In the embodiments of the present invention, the step of distributing the target true random number by using the method of filling, QKD or PQC encryption key to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted can be understood as distributing the target true random number to the cloud platform 20 by using any one of the methods of filling with an external storage medium, QKD, or PQC encryption key, so that the cloud platform 20 decrypts the encrypted information according to the received target true random number combined with the corresponding decryption operation to restore the original data to be encrypted.

[0101] Compared with the prior art, the embodiments of the present invention have the following advantages:

[0102] First, by screening the target true random numbers whose length is greater than or equal to the data to be encrypted to encrypt the data to be encrypted, the deciphering difficulty is increased and the security performance of the data to be encrypted is improved;

[0103] Second, by pre - judging the confidentiality level and importance degree of the data to be encrypted to set the reuse times of the true random numbers used as the session key, the key usage amount can be reduced;

[0104] Third, using filling, QKD or PQC encryption key to perform key distribution realizes secure key distribution and improves the security of data transmission.

[0105] Second Embodiment

[0106] Please refer to Figure 9 , Figure 9 , which shows a block diagram of the vehicle networking information encryption device provided by an embodiment of the present invention. The vehicle networking information encryption device 100 includes an encryption level determination module 110, a true random number acquisition module 120, an encryption module 130, and a distribution module 140.

[0107] The encryption level determination module 110 is configured to obtain the data to be encrypted, determine the confidentiality level of the data to be encrypted according to a preset rule, and obtain the encryption level.

[0108] It can be understood that the encryption level determination module 110 can execute the above step S1.

[0109] The true random number acquisition module 120 is configured to obtain a target true random number according to the encryption level and the data to be encrypted.

[0110] It can be understood that the true random number acquisition module 120 can execute the above step S2.

[0111] In the embodiment of the present invention, the vehicle networking system includes a secure memory, in which a plurality of true random numbers and the corresponding reuse times of each true random number are stored. The true random number acquisition module 120 is specifically configured to: calculate the data length of the data to be encrypted to obtain a first data length; determine a target reuse time from a plurality of reuse times according to the encryption level; and determine a target true random number from a plurality of true random numbers according to the target reuse time and the first data length.

[0112] When the true random number acquisition module 120 executes the step of determining a target true random number from a plurality of true random numbers according to the target reuse time and the first data length, it is specifically configured to: obtain at least one true random number corresponding to the target reuse time; calculate the data length of at least one true random number to obtain at least one second data length; compare at least one second data length with the first data length, and use the true random number corresponding to the second data length being greater than or equal to the first data length as the target true random number.

[0113] In other embodiments of the present invention, the vehicle networking system includes a secure memory, in which a plurality of true random numbers and the corresponding reused times of each true random number are stored. The true random number acquisition module 120 may also be specifically configured to: calculate the data length of the data to be encrypted to obtain a third data length; obtain the true random number with the data length of the third data length to obtain the true random number to be determined; and obtain the target true random number according to the true random number to be determined, the corresponding reused time of the true random number to be determined, and the encryption level.

[0114] In other embodiments of the present invention, the true random number acquisition module 120 may specifically be configured to: calculate the data length of the data to be encrypted to obtain a fourth data length; calculate a fifth data length according to the fourth data length and the encryption level; and obtain a true random number with a data length of the fifth data length as the target true random number.

[0115] The encryption module 130 is configured to encrypt the data to be encrypted with the target true random number to obtain encrypted information;

[0116] It can be understood that the encryption module 130 may execute the above step S3.

[0117] The distribution module 140 is configured to distribute the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted.

[0118] It can be understood that the distribution module 140 may execute the above step S4.

[0119] In summary, the embodiments of the present invention provide a vehicle networking information encryption method, apparatus and vehicle networking system. The vehicle networking information encryption method includes: acquiring data to be encrypted, judging the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level; obtaining a target true random number according to the encryption level and the data to be encrypted; encrypting the data to be encrypted with the target true random number to obtain encrypted information; and distributing the target true random number by means of key injection, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted. Compared with the prior art, the vehicle networking information encryption method, apparatus and vehicle networking system provided by the embodiments of the present invention have the following advantages: First, by screening a target true random number with a length greater than or equal to the data to be encrypted to encrypt the data to be encrypted, the deciphering difficulty is increased, and the security performance of the data to be encrypted is improved; Second, the reuse times of the true random number used as the session key are set by pre-judging the confidentiality level and importance degree of the data to be encrypted, which can reduce the key usage amount; Third, key injection, QKD or PQC encryption key is used for key distribution, realizing secure key distribution and improving data transmission security.

[0120] In several embodiments provided in this application, it should be understood that the disclosed device can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the block diagrams in the drawings show the possible architectures, functions, and operations of the device and computer program products according to multiple embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the drawings. For example, two consecutive blocks can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or actions, or can be implemented by a combination of dedicated hardware and computer instructions.

[0121] In addition, each functional module in various embodiments of the present invention can be integrated together to form an independent part, or each module can exist alone, or two or more modules can be integrated to form an independent part.

[0122] If the described functions are implemented in the form of software functional modules and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs, etc., which can store program codes. It should be noted that the term "including", "comprising", or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article, or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such a process, method, article, or device. Without further limitations, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article, or device including the said element.

[0123] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.

Claims

1. A method for encrypting vehicle networking information, characterized in that, applied to a vehicle networking system, the method for encrypting vehicle networking information includes: Obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, and obtain an encryption level; Based on the encryption level and the data to be encrypted, obtain a target true random number; Encrypt the data to be encrypted with the target true random number to obtain encrypted information; Use the method of injecting, QKD or PQC to encrypt the key to distribute the target true random number, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted; Wherein, the vehicle networking system includes a secure memory, and the secure memory stores a plurality of true random numbers and the corresponding reuse times of each true random number. The step of obtaining a target true random number based on the encryption level and the data to be encrypted includes: Calculate the data length of the data to be encrypted to obtain a first data length; Determine a target reuse time from a plurality of reuse times according to the encryption level; Based on the target reuse time and the first data length, determine a target true random number from a plurality of true random numbers.

2. The method according to claim 1, characterized in that, The step of determining a target true random number from a plurality of true random numbers based on the target reuse time and the first data length includes: Obtain at least one true random number corresponding to the target reuse time; Calculate the data length of the at least one true random number to obtain at least one second data length; Compare the at least one second data length with the first data length, and use the true random number corresponding to the second data length greater than or equal to the first data length as the target true random number.

3. The method as claimed in claim 1, characterized in that, The vehicle networking system includes a secure memory, and the secure memory stores a plurality of true random numbers and the corresponding reused times of each true random number. The step of obtaining a target true random number based on the encryption level and the data to be encrypted includes: Calculate the data length of the data to be encrypted to obtain a third data length; Obtain a true random number with the data length of the third data length to obtain a true random number to be determined; Based on the true random number to be determined, the corresponding reused times of the true random number to be determined and the encryption level, obtain a target true random number.

4. The method as claimed in claim 1, characterized in that, The step of obtaining a target true random number based on the encryption level and the data to be encrypted includes: Calculate the data length of the data to be encrypted to obtain a fourth data length; Based on the fourth data length and the encryption level, calculate a fifth data length; Obtain a true random number with the data length of the fifth data length as the target true random number.

5. A vehicle networking information encryption device, characterized in that, applied to a vehicle networking system, the vehicle networking information encryption device includes: An encryption level judgment module, configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule, and obtain an encryption level; A true random number acquisition module, configured to obtain a target true random number according to the encryption level and the data to be encrypted; An encryption module, configured to encrypt the data to be encrypted with the target true random number to obtain encrypted information; A distribution module, configured to distribute the target true random number by means of filling, QKD or PQC encrypted key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted; Wherein, the vehicle networking system includes a secure memory, and a plurality of true random numbers and the corresponding reuse times of each true random number are stored in the secure memory. The true random number acquisition module is specifically configured to: Calculate the data length of the data to be encrypted to obtain a first data length; Determine a target reuse time from a plurality of reuse times according to the encryption level; Determine a target true random number from a plurality of true random numbers according to the target reuse time and the first data length.

6. A vehicle networking system Characterized in that The vehicle networking system includes an in-vehicle terminal, and the in-vehicle terminal includes a random number generator, a secure memory and a controller. The random number generator is electrically connected to the secure memory, and the secure memory is electrically connected to the controller; The random number generator is configured to generate a true random number and transmit it to the secure memory for storage; The controller is configured to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level, obtain a target true random number according to the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of filling, QKD or PQC encrypted key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted; Wherein, obtaining a target true random number according to the encryption level and the data to be encrypted includes: Calculate the data length of the data to be encrypted to obtain a first data length; Determine a target reuse time from a plurality of reuse times according to the encryption level; Determine a target true random number from a plurality of true random numbers according to the target reuse time and the first data length.

7. A vehicle networking system Characterized in that The vehicle networking system includes an in-vehicle terminal and a random number filling machine, and the in-vehicle terminal is electrically connected to the random number filling machine; The random number filling machine is configured to generate a true random number and send it to the in-vehicle terminal; The in-vehicle terminal is used to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level, obtain a target true random number based on the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of charging, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted; Wherein, the obtaining of the target true random number based on the encryption level and the data to be encrypted includes: Calculating the data length of the data to be encrypted to obtain a first data length; Determining a target multiplexing number from multiple multiplexing numbers according to the encryption level; Determining a target true random number from multiple true random numbers based on the target multiplexing number and the first data length.

8. A vehicle networking system Characterized in that The vehicle networking system includes an in-vehicle terminal, a cloud platform and a random number charger, the in-vehicle terminal is communicatively connected to the cloud platform, and the random number charger is connected to the cloud platform; The random number charger is used to generate a true random number and send it to the in-vehicle terminal through the cloud platform; The in-vehicle terminal is used to obtain data to be encrypted, judge the confidentiality level of the data to be encrypted according to a preset rule to obtain an encryption level, obtain a target true random number based on the encryption level and the data to be encrypted, encrypt the data to be encrypted with the target true random number to obtain encrypted information, and distribute the target true random number by means of charging, QKD or PQC encryption key, so as to decrypt the encrypted information according to the target true random number to obtain the original data to be encrypted; Wherein, the obtaining of the target true random number based on the encryption level and the data to be encrypted includes: Calculating the data length of the data to be encrypted to obtain a first data length; Determining a target multiplexing number from multiple multiplexing numbers according to the encryption level; Determining a target true random number from multiple true random numbers based on the target multiplexing number and the first data length.

Citation Information

Patent Citations

  • Encryption equipment with bluetooth function based on quantum true random number

    CN108601008A

  • Quantum encryption communication method based on multi-party security computing

    CN114257314A