Data transmission method and data processing device

By performing signature processing in the computing unit and communication unit of the V2X communication system, the problem that the equipment in the existing V2X communication system does not reach the ASIL-B level is solved, which improves the reliability and security of V2X information and reduces costs.

CN115226060BActive Publication Date: 2025-05-23YINWANG INTELLIGENT TECHNOLOGIES CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110412576.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-04-16
Publication Date
2025-05-23
Estimated Expiration
2041-04-16

AI Technical Summary

Technical Problem

In the existing V2X communication system, the equipment does not reach the ASIL-B level, resulting in the V2X information being unable to serve as an effective and reliable input to the autonomous driving system or auxiliary system during transmission, affecting the safety of vehicle motion decisions and control.

Method used

By performing a first signature process on the V2X information of the application layer in the computing unit and performing a second signature process on the V2X information that has passed the first signature process in the communication unit, the functional security and network security of the V2X information during transmission are ensured.

Benefits of technology

While trying not to transform and upgrade existing equipment hardware, the reliability of V2X information is improved, thereby improving the safety of vehicle motion decisions and control, reducing the requirements for equipment functional safety levels, and reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115226060B_ABST
    Figure CN115226060B_ABST
Patent Text Reader

Abstract

The present application relates to a data transmission method and a data processing device, the method comprising: in the data processing device at the transmitting end: the operation unit performs a first signature process on the first V2X information of the application layer to obtain the second V2X information including the first V2X information and the first signature; the communication unit performs a second signature process on the second V2X information to obtain the third V2X information including the second V2X information and the second signature; then, the communication unit sends the third V2X information; in the data processing device at the receiving end: the communication unit receives the third V2X information and verifies its second signature; if the second signature verification is successful, the operation unit verifies the first signature; if the first signature verification is successful, the operation unit performs information processing on the first V2X information. The data transmission method and data processing device provided by the present application can improve the reliability of V2X information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a data transmission method and a data processing device. Background Art

[0002] With the development of society, people's demand for vehicles is increasing year by year. While vehicles provide people with convenient travel, they also bring problems such as traffic congestion and frequent traffic accidents. Based on this, the vehicle-to-everything (V2X) technology came into being. Vehicles can obtain road traffic information, safety warning information, etc. in a timely manner through vehicle-to-vehicle (V2V) communication or vehicle-to-roadside infrastructure (V2I) communication, thereby improving traffic efficiency and reducing traffic safety risks to a certain extent.

[0003] With the development of Internet of Vehicles technology, vehicles are gradually developing from supporting low levels of autonomous driving to high levels of autonomous driving, and the application of Internet of Vehicles technology is also gradually developing from basic safety warning applications and traffic efficiency applications to collaborative control and other directions. Safety warning applications and traffic efficiency applications in vehicles do not participate in the vehicle's motion decision-making and control. Therefore, the required safety level requirements are quality management (QM) that is not related to safety management. Collaborative control applications involve vehicle motion decision-making and control, so they need to have higher reliability and functional safety level requirements, such as reaching Automotive Safety Integration Level (ASIL) B or above (such as C or D).

[0004] At present, in the V2X communication system, neither the roadside equipment nor the vehicle-mounted equipment has reached ASIL B (i.e. ASIL-B). After the V2X information is transmitted in the above roadside equipment or vehicle-mounted equipment, it cannot become an effective and reliable input for vehicle motion decision-making and control in the Auto Driving System (ADS) or Auto Driving Assistance System (ADAS). Summary of the invention

[0005] In view of this, a data transmission method and a data processing device are proposed, which improve the reliability of V2X information and thus improve the safety of vehicle motion decision-making and control without modifying and upgrading the existing equipment hardware as much as possible.

[0006] In a first aspect, an embodiment of the present application provides a data transmission method, which is applied to a data processing device, wherein the data processing device includes a computing unit and a communication unit, and the method includes: the computing unit performs a first signature processing on a first vehicle network V2X information of an application layer to obtain second V2X information, wherein the second V2X information includes the first V2X information and a first signature; the computing unit sends the second V2X information to the communication unit; the communication unit performs a second signature processing on the second V2X information to obtain a third V2X information, wherein the third V2X information includes the second V2X information and a second signature; and the communication unit sends the third V2X information.

[0007] In the embodiment of the present application, the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional safety of the V2X information of the application layer can be guaranteed, there is no functional safety requirement for the communication unit, and the functional safety level requirements for the transmission channel between the computing unit and the communication unit are reduced; then, the communication unit performs the second signature processing on the V2X information that has been processed by the first signature, so that the security of the V2X information of the application layer during the network transmission process is guaranteed. Therefore, the embodiment of the present application can improve the reliability of V2X information without modifying and upgrading the hardware of existing equipment as much as possible, thereby improving the security of vehicle motion decision-making and control.

[0008] According to the first aspect, in a first possible implementation of the data transmission method, the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0009] This helps to timely discover whether there is message corruption or message insertion in the first V2X information, thus providing a guarantee for functional safety.

[0010] According to the first aspect, or the first possible implementation of the first aspect, in a second possible implementation of the data transmission method, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0011] In this way, the reliability of V2X information provided by the vehicle to other devices in the V2X network can be improved.

[0012] According to the first aspect, or the first possible implementation manner of the first aspect, in a third possible implementation manner of the data transmission method, the data processing device is a roadside equipment, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0013] In this way, the reliability of V2X information provided by roadside equipment to vehicles can be improved, which in turn helps to improve the safety of vehicle motion decision-making and control.

[0014] According to the first aspect, or any possible implementation manner of the first aspect above, in a fourth possible implementation manner of the data transmission method, the operation unit sending the second V2X information to the communication unit includes: the operation unit sending the second V2X information to the communication unit via Ethernet.

[0015] In this way, the transmission of V2X information between the operation unit and the communication unit through Ethernet can improve transmission efficiency, simplify information structure and reduce costs.

[0016] In a second aspect, an embodiment of the present application provides a data transmission method, which is applied to a data processing device, wherein the data processing device includes a computing unit and a communication unit, and the method includes: the computing unit performs a first signature processing on a first vehicle network V2X information of an application layer to obtain second V2X information, wherein the second V2X information includes the first V2X information and a first signature; the computing unit sends the second V2X information to the communication unit through a secure channel between the computing unit and the communication unit; and the communication unit sends the second V2X information.

[0017] In the embodiment of the present application, by transmitting the second V2X information in the secure channel between the operation unit and the communication unit, the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the functional requirements for the first communication unit and reducing the cost of the first communication unit.

[0018] According to the second aspect, in a first possible implementation of the data transmission method, the first signature processing includes: a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0019] According to the second aspect, or the first possible implementation of the second aspect, in a second possible implementation of the data transmission method, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0020] According to the second aspect, or the first possible implementation of the second aspect, in a third possible implementation of the data transmission method, the data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0021] In a third aspect, an embodiment of the present application provides a data transmission method, which is applied to a data processing device, wherein the data processing device includes a computing unit and a communication unit, and the method includes: the communication unit receives third vehicle network V2X information, the third V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature of the application layer; the communication unit verifies the second signature; if the second signature verification is successful, the communication unit sends the second V2X information to the computing unit; the computing unit verifies the first signature; if the first signature verification is successful, the computing unit processes the first V2X information.

[0022] In the embodiment of the present application, the second communication unit can directly forward the received V2X information to the second operation unit through the secure channel, and the second operation unit performs signature verification. In this way, on the one hand, the V2X information that has not been verified by signature can be concentrated in the second operation unit to prevent the V2X information that has not been verified by signature from causing adverse effects on other components in the vehicle. On the other hand, the functional requirements for the second communication unit can be reduced, thereby reducing the cost of the second communication unit. At the same time, the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety.

[0023] According to the third aspect, in a first possible implementation of the data transmission method, the communication unit verifies the second signature, including: the communication unit extracts the second V2X information to obtain a first summary; the communication unit decrypts the second signature to obtain a second summary; when the first summary and the second summary are the same, the communication unit determines that the second signature verification is successful.

[0024] According to the third aspect, or the first possible implementation manner of the third aspect, in the second possible implementation manner of the data transmission method, the verification of the first signature by the operation unit includes: the operation unit performs information excerpt verification on the first signature, or performs cyclic redundancy CRC verification, or performs digital signature verification, wherein the digital signature verification includes digital signature verification based on the root certificate issued by the national certification authority platform, or digital signature verification based on the root certificate of the automobile enterprise self-inspection certification authority platform, or digital signature verification based on the root certificate issued by the ecological alliance certification authority platform.

[0025] According to the third aspect, or the first possible implementation manner or the second possible implementation manner of the third aspect, in a third possible implementation manner of the data transmission method, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0026] According to the third aspect, or the first possible implementation manner or the second possible implementation manner of the third aspect, in a fourth possible implementation manner of the data transmission method, the data processing device is a roadside equipment, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0027] According to the third aspect, or any possible implementation manner of the third aspect above, in a fifth possible implementation manner of the data transmission method, when the second signature verification is successful, the communication unit sends the second V2X information to the operation unit, including: when the second signature verification is successful, the communication unit sends the second V2X information to the operation unit via Ethernet.

[0028] In a fourth aspect, an embodiment of the present application provides a data transmission method, which is applied to a data processing device, wherein the data processing device includes a computing unit and a communication unit, and the method includes: the communication unit receives second vehicle network V2X information, wherein the second V2X information includes first V2X information and a first signature of an application layer; the communication unit sends the second V2X information to the computing unit through a secure channel between the communication unit and the computing unit; the computing unit verifies the first signature; and when the first signature verification is successful, the computing unit processes the first V2X information.

[0029] In the embodiment of the present application, the communication unit sends the second V2X information to the operation unit through the secure channel, so that the unverified V2X information can go through the dedicated channel, reducing the impact on other components in the data processing device; the operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety.

[0030] According to the fourth aspect, in a first possible implementation of the data transmission method, the first signature verifies the first signature including: the operation unit verifies the first signature based on the digital signature of the root certificate issued by the national certification authority platform, or based on the digital signature of the root certificate of the automobile enterprise self-inspection certification authority platform, or based on the digital signature of the root certificate issued by the ecological alliance certification authority platform.

[0031] According to the fourth aspect, or the first possible implementation of the fourth aspect, in a second possible implementation of the data transmission method, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0032] According to the fourth aspect, or the first possible implementation of the fourth aspect, in a third possible implementation of the data transmission method, the data processing device is a roadside equipment, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0033] In a fifth aspect, an embodiment of the present application provides a data processing device, the data processing device comprising a computing unit and a communication unit, the computing unit comprising a first signature module and a first sending module, the communication unit comprising a second signature module and a second sending module;

[0034] The first signature module is used to perform a first signature processing on the first vehicle network V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;

[0035] The first sending module is configured to send the second V2X information obtained by the first signature module to the second signature module;

[0036] The second signature module is configured to perform a second signature processing on the second V2X information sent by the first sending module to obtain third V2X information, where the third V2X information includes the second V2X information and the second signature;

[0037] The second sending module is used to send the third V2X information obtained by the second signature module.

[0038] According to the fifth aspect, in a first possible implementation method of the data processing device, the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0039] According to the fifth aspect, or the first possible implementation of the fifth aspect, in a second possible implementation of the data processing device, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0040] According to the fifth aspect, or the first possible implementation of the fifth aspect, in a third possible implementation of the data processing device, the data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0041] According to the fifth aspect, or any possible implementation of the fifth aspect, in a fifth possible implementation of the data processing device, the first sending module is further used to send the second V2X information to the second signature module via Ethernet.

[0042] In a sixth aspect, an embodiment of the present application provides a data processing device, the data processing device comprising a computing unit and a communication unit, the computing unit and the communication unit are connected via a secure channel, the computing unit comprises a first signature module and a first sending module, and the communication unit comprises a second sending module;

[0043] The first signature module is used to perform a first signature processing on the first vehicle network V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;

[0044] The first sending module is configured to send the second V2X information to the second sending module through the secure channel;

[0045] The second sending module is used to send the second V2X information.

[0046] According to the sixth aspect, in a first possible implementation method of the data processing device, the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0047] According to the sixth aspect, or the first possible implementation of the sixth aspect, in a second possible implementation of the data processing device, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0048] According to the sixth aspect, or the first possible implementation of the sixth aspect, in a third possible implementation of the data processing device, the data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0049] In a seventh aspect, an embodiment of the present application provides a data processing device, the data processing device comprising a computing unit and a communication unit, the communication unit comprising a receiving module, a first signature verification module and a sending module, the computing unit comprising a second signature verification module and a processing module;

[0050] The receiving module is used to receive third vehicle network V2X information, where the third vehicle network V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature of an application layer;

[0051] The first signature verification module is used to verify the second signature in the third V2X information received by the receiving module;

[0052] The sending module is configured to send the second V2X information to the second signature verification module when the first signature verification module successfully verifies the second signature;

[0053] The second signature verification module is used to verify the first signature in the second V2X information sent by the sending module;

[0054] The processing module is configured to process the first V2X information when the second signature verification module successfully verifies the first signature.

[0055] According to the seventh aspect, in a first possible implementation manner of the data processing device, the first signature verification module is further used to:

[0056] performing information abstraction processing on the second V2X information to obtain a first summary;

[0057] Decrypting the second signature to obtain a second summary;

[0058] When the first digest and the second digest are identical, it is determined that the second signature verification succeeds.

[0059] According to the seventh aspect, or the first possible implementation manner of the seventh aspect, in a second possible implementation manner of the data processing device, the second signature verification module is further used to:

[0060] The first signature is subjected to information excerpt verification, cyclic redundancy CRC verification, or digital signature verification, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, digital signature verification based on a root certificate issued by a car manufacturer's self-inspection certification authority platform, or digital signature verification based on a root certificate issued by an ecological alliance certification authority platform.

[0061] According to the seventh aspect, or the first possible implementation manner or the second possible implementation manner of the seventh aspect, in a third possible implementation manner of the data processing device, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0062] According to the seventh aspect, or the first possible implementation manner or the second possible implementation manner of the seventh aspect, in a fourth possible implementation manner of the data processing device, the data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0063] According to the seventh aspect, or any possible implementation manner of the seventh aspect, in a fifth possible implementation manner of the data processing device, the sending module is further used to: when the first signature verification module successfully verifies the second signature, send the second V2X information to the second signature verification module via Ethernet.

[0064] In an eighth aspect, an embodiment of the present application provides a data processing device, the data processing device comprising a communication unit and a computing unit, the communication unit and the computing unit being connected via a secure channel, the communication unit comprising a receiving module and a sending module, the computing unit comprising a signature verification module and a processing module;

[0065] The receiving module is used to receive second vehicle network V2X information, where the second V2X information includes first V2X information and a first signature of an application layer;

[0066] The sending module is configured to send the second V2X information received by the receiving module to the signature verification module through the secure channel;

[0067] The signature verification module is used to verify the first signature in the second V2X information sent by the sending module;

[0068] The processing module is configured to process the first V2X information if the signature verification module successfully verifies the first signature.

[0069] According to the eighth aspect, in a first possible implementation manner of the data processing device, the signature verification module is further used to:

[0070] The first signature is verified by digital signature based on the root certificate issued by the national certification authority platform, or by digital signature based on the root certificate of the automobile enterprise self-inspection certification authority platform, or by digital signature based on the root certificate issued by the ecological alliance certification authority platform.

[0071] According to the eighth aspect, or the first possible implementation of the eighth aspect, in a second possible implementation of the data processing device, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0072] According to the eighth aspect, or the first possible implementation of the eighth aspect, in a third possible implementation of the data processing device, the data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0073] In the ninth aspect, an embodiment of the present application provides a data processing device, which can execute the data transmission method of the first aspect or one or more of the multiple possible implementations of the first aspect, or execute the data transmission method of the second aspect or one or more of the multiple possible implementations of the second aspect, or execute the data transmission method of the third aspect or one or more of the multiple possible implementations of the third aspect, or execute the data transmission method of the fourth aspect or one or more of the multiple possible implementations of the fourth aspect.

[0074] In the tenth aspect, an embodiment of the present application provides a computer program product, comprising a computer-readable code, or a computer-readable storage medium carrying a computer-readable code, which, when executed by a processor, implements the second aspect or one or more of the multiple possible implementations of the second aspect, or executes the third aspect or one or more of the multiple possible implementations of the third aspect, or executes the fourth aspect or one or more of the multiple possible implementations of the fourth aspect.

[0075] These and other aspects of the present application will become more apparent from the following description of the embodiment(s). BRIEF DESCRIPTION OF THE DRAWINGS

[0076] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate exemplary embodiments, features, and aspects of the present application and, together with the description, serve to explain the principles of the present application.

[0077] Figure 1 A schematic diagram of the architecture of a V2X communication system provided in an embodiment of the present application is shown;

[0078] Figure 2 A schematic diagram showing the transmission process of V2X information in a V2I scenario;

[0079] Figure 3a A schematic diagram showing the architecture of a data transmission system provided in an embodiment of the present application is shown;

[0080] Figure 3b A schematic diagram showing the structure of an electronic device provided in an embodiment of the present application is shown;

[0081] Figure 3c An interactive schematic diagram showing a data transmission method provided by an embodiment of the present application;

[0082] Figure 3d An interactive schematic diagram showing a data transmission method provided by an embodiment of the present application;

[0083] Figure 4a A schematic diagram of the architecture of a data transmission system in a V2I scenario provided in an embodiment of the present application is shown;

[0084] Figure 4b A schematic diagram of the architecture of a data transmission system in a V2I scenario provided in an embodiment of the present application is shown;

[0085] Figure 4c A schematic diagram showing the architecture of a data transmission system in a V2V scenario provided in an embodiment of the present application;

[0086] Figure 4dA schematic diagram showing the architecture of a data transmission system in a V2V scenario provided in an embodiment of the present application;

[0087] Figure 5 A schematic diagram showing the structure of a data processing device provided in an embodiment of the present application is shown;

[0088] Figure 6 A schematic diagram showing the structure of a data processing device provided in an embodiment of the present application is shown;

[0089] Figure 7 A schematic diagram showing the structure of a data processing device provided in an embodiment of the present application is shown;

[0090] Figure 8 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0091] Various exemplary embodiments, features and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the accompanying drawings represent elements with the same or similar functions. Although various aspects of the embodiments are shown in the accompanying drawings, the drawings are not necessarily drawn to scale unless otherwise specified.

[0092] The word “exemplary” is used exclusively herein to mean “serving as an example, example, or illustration.” Any embodiment described herein as “exemplary” is not necessarily to be construed as preferred or advantageous over other embodiments.

[0093] In addition, in order to better illustrate the present application, numerous specific details are given in the following specific embodiments. It should be understood by those skilled in the art that the present application can also be implemented without certain specific details. In some examples, methods, means, components and circuits well known to those skilled in the art are not described in detail in order to highlight the subject matter of the present application.

[0094] Vehicle to Everything (V2X) communication refers to the communication between vehicles and anything in the outside world. Figure 1 FIG. 1 is a schematic diagram showing the architecture of a V2X communication system provided in an embodiment of the present application. Figure 1 As shown in Figure 1, V2X communication includes vehicle-to-vehicle communication (V2V), vehicle-to-pedestrian communication (V2P), and vehicle-to-infrastructure communication (V2I). In a V2X communication system, devices can communicate directly with each other. For example, Figure 1As shown, vehicles can communicate directly with each other, and vehicles can communicate directly with roadside units (RSU). In implementation, devices in the V2X system can communicate directly based on communication protocols such as Dedicated Short Range Communication (DSRC) and Long Term Evolution-Vehicle (LTE-V). The embodiments of the present application do not limit the communication protocols between devices in the V2X communication system. In the V2X communication system, the equipment involved on the road side includes signal machines, V2X servers, roadside units, etc., and the equipment involved on the vehicle side includes vehicle-mounted communication units, gateways (GateWay, GW), vehicle-mounted computing platforms and controllers, etc. In one example, the vehicle-mounted communication unit may include a telematics BOX (TBox), the vehicle-mounted computing platform may include a mobile data center (MDC), and the controller may include a vehicle control unit (VCU).

[0095] Functional safety is to reduce the hazards caused by the failure of electronic and electrical systems to an acceptable range, and its main purpose is to protect personal safety. Reliability is the ability of electronic and electrical systems to work without failure, and its main purpose is to avoid failures and ensure availability. Therefore, reliability is the "foundation" and functional safety is the "superstructure". The data transmission method provided in the embodiment of the present application involves the functional safety issues of the V2X communication system, that is, to improve the reliability of the V2X information input into the automatic driving system (Auto Driving System, ADS) or the automatic driving assistance system (Auto Driving Assistance System, ADAS), thereby improving the safety of vehicle motion decision-making and control.

[0096] The data transmission method provided in the embodiment of the present application can be applied to V2I scenarios or V2V scenarios. For example, in a V2I scenario, when a vehicle is traveling on a city road, the roadside equipment sends the traffic light information to the vehicle using V2X information, and the on-board computing platform in the vehicle can fuse the traffic light information provided by the roadside equipment and the information sensed by the in-vehicle sensor, thereby helping the vehicle to perform correct operations. At this time, the data transmission method provided in the embodiment of the present application can be used to transmit traffic light information, improve the reliability of traffic light information, and thereby improve the safety of vehicle motion decision-making and control. In a V2V scenario, the leading vehicle will use V2X information to send decision information such as acceleration, braking, changing lanes or maintaining the status quo to the following vehicle, and periodically send blind spot detection system (Blind Spot Monitoring, BSM) information and computer-aided manufacturing (Computer Aided Drafting, CAM) information. The on-board computing platform in the following vehicle can integrate the decision information, BSM information, CAM information and the information sensed by the in-vehicle sensors, so as to help the following vehicle perform correct operations and avoid vehicle scratches and collisions due to failure to see the rear vehicle when merging with the front vehicle. At this time, the data transmission method provided in the embodiment of the present application can be used to transmit decision information, BSM information and CAM information, improve the reliability of decision information, BSM information and CAM information, and thus improve the safety of vehicle motion decision and control. Figure 2 , the transmission process of V2X information in the V2I scenario is taken as an example to illustrate. The transmission process of V2X information in the V2V scenario can refer to the transmission process of V2X information in the V2I scenario, which will not be repeated here.

[0097] Figure 2 Figure 2 shows a schematic diagram of the transmission process of V2X information in a V2I scenario. Figure 2As shown in the figure, in the V2I scenario, the traffic signal control system transmits the traffic light information to the signal machine through the traffic dedicated network. The signal machine can control the display of the traffic light according to the received traffic light information, and send the received traffic light information to the roadside unit. The V2X server can send some traffic control information and road condition information to the roadside unit. The traffic light information, traffic control information and road condition information here will be transmitted in the V2X communication system later, and the security of this information needs to be guaranteed. The roadside unit is responsible for broadcasting the received V2X information such as traffic light information, traffic control information and road condition information to the vehicle. The on-board communication unit in the vehicle can send the received V2X information such as traffic light information, traffic control information and road condition information to the on-board computing platform through the gateway. The on-board computing platform fuses the data obtained by sensors such as radars and cameras (such as radar signals, images, etc.) with the received V2X information such as traffic light information, traffic control information and road condition information to obtain fused information. Then, the on-board computing platform can send the fused information to the controller so that the controller can make motion decisions and control the vehicle based on the fused information. In one example, the traffic light information received by the on-board computing platform is a red light, and the camera also captures a red light. The on-board computing platform can obtain the fused information as a red light. After the on-board computing platform sends the fused information to the controller, the controller generates a brake command based on the red light, and then controls the vehicle to brake automatically. In another example, the traffic control information received by the on-board computing platform is that the maximum speed limit on the construction section is 40km / h, and the speed limit sign captured by the camera is also a maximum speed limit of 40km / h. The high-precision map shows that the vehicle enters the construction section after 100 meters. The on-board computing platform can obtain the fused information that the speed is less than 40km / h. After the on-board computing platform sends the fused information to the controller, the controller determines whether it is necessary to control the deceleration based on the speed being less than 40km / h, and automatically decelerates if it is necessary to control the vehicle to decelerate.

[0098] Reference Figure 2It can be seen that the equipment involved in the transmission of V2X information such as traffic light information, traffic control information and road condition information includes roadside signal machines (or V2X servers) and roadside units, as well as vehicle-mounted communication units, gateways and vehicle-mounted computing platforms on the vehicle side. The transmission paths involved in the transmission of V2X information such as traffic light information, traffic control information and road condition information include: signal machines (or V2X servers) to roadside units, roadside units to vehicle-mounted communication units, vehicle-mounted communication units to gateways, and gateways to vehicle-mounted computing platforms. In related technologies, in order to ensure that the V2X information received by the vehicle-mounted computing platform is consistent with the V2X information provided by the signal machine (or V2X server) (that is, the V2X information received by the vehicle-mounted computing platform reaches the functional safety level of ASIL-B), the software and hardware development of all equipment involved in the V2X information transmission process needs to be designed, developed and verified in accordance with the ISO26262 system and reach the functional safety level of ASIL-B. However, requiring roadside equipment (such as traffic lights, V2X servers, and roadside units, etc.) to reach the functional safety level of ASIL-B will significantly increase the cost of roadside equipment, and the existing roadside equipment cannot meet the requirements of the functional safety level, and the feasibility is low. At the same time, requiring the vehicle-side onboard communication units and gateways to reach the functional safety level of ASIL-B will increase vehicle costs, which is not conducive to the development of ADS or ADAS.

[0099] The data transmission method provided in the embodiment of the present application improves the reliability of V2X information while minimizing the need to modify or upgrade the hardware of existing equipment, thereby improving the security of vehicle motion decision-making and control.

[0100] Figure 3a The schematic diagram of the architecture of the data transmission system provided by the embodiment of the present application is shown. Figure 3a As shown, the data transmission system includes a first operation unit 11, a first communication unit 12, a second communication unit 13 and a second operation unit 14. In the embodiment of the present application, the V2X information that needs to ensure reliability is referred to as the first V2X information. Figure 3a The first operation unit 11 shown is used to represent a device that provides first V2X information, and the first V2X information comes from the application layer of the first operation unit 11. The second operation unit 14 is used to represent a device that uses the first V2X information. Ensuring the reliability of the first V2X information is essentially to make the first V2X information provided by the first operation unit 11 consistent with the first V2X information that reaches the second operation unit 14 and is used by the second operation unit 14. The first communication unit 12 is used to send the V2X information from the first operation unit 11, and the second communication unit 13 is used to receive the V2X information from the first communication unit 12 and send the V2X information to the second operation unit 14.

[0101] like Figure 3aAs shown, the first computing unit 11 and the first communication unit 12 belong to the data processing device at the sending end, and the second computing unit 14 and the second communication unit 13 belong to the data processing device at the receiving end.

[0102] In the embodiments of the present application, Figure 3a The first computing unit 11 and the second computing unit 14 are designed, developed, verified and meet the functional safety level of ASIL-B according to ISO26262 system. Figure 3a The first communication unit 12 and the second communication unit 13 shown in the figure have no functional safety requirements for other devices involved in the first V2X information transmission process. In this way, the functional safety level requirements for devices in the V2X communication system are effectively reduced, and existing devices can be compatible as much as possible to reduce costs.

[0103] As mentioned above, the data transmission method provided in the embodiment of the present application can be applied to the V2I scenario or the V2V scenario. In the V2I scenario, the roadside device can provide the first V2X information to the vehicle-mounted device. Figure 3a The data processing device at the sending end is the roadside device, the data output device at the receiving end is the vehicle-mounted device, the first computing unit 11 can be a signal machine or a V2X server, the first communication unit 12 can be a roadside unit, the second communication unit 13 can be a telematics processor, and the second computing unit 14 can be a mobile data center. Of course, in the V2I scenario, the vehicle-mounted device can also provide the first V2X information to the roadside device. Figure 3a The first computing unit 11 shown in the figure can be a mobile data center, the first communication unit 12 can be a telematics processor, the second communication unit 13 can be a roadside unit, and the second computing unit 14 can be a signal machine or a V2X server. In the V2V scenario, vehicles can provide each other with first V2X information. Figure 3a The first computing unit 11 shown may be a mobile data center of vehicle A, the first communication unit 12 may be a telematics processor of vehicle A, the second communication unit 13 may be a telematics processor of vehicle B, and the second computing unit 14 may be a mobile data center of vehicle B.

[0104] It should be noted that the "first" and "second" in the first operation unit and the second operation unit involved in the embodiment of the present application are only used to distinguish different operation units. The first operation unit represents the operation unit in the data processing device of the sending end, and the second operation unit represents the operation unit in the data processing device of the receiving end, and both are operation units. It can be understood that in one scenario, an operation unit can be used as the first operation unit in the sending end, and in another scenario, the same operation unit can be used as the second operation unit in the receiving end. The "first" and "second" in the first communication unit and the second communication unit involved in the embodiment of the present application are only used to distinguish different communication units. The first communication unit represents the communication unit in the data processing device of the sending end, and the second communication unit represents the communication unit in the data processing device of the receiving end, and both are communication units. A communication unit can be used as the first communication unit in the sending end in one scenario, and can be used as the second communication unit in the receiving end in another scenario. In the embodiment of the present application, there is no restriction on whether the operation unit and the communication unit are the sending end or the receiving end.

[0105] The first computing unit, the first communication unit, the second communication unit, and the second computing unit involved in the embodiments of the present application can be deployed in an electronic device with communication functions (wireless communication functions and / or wired communication functions). Figure 3b A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown.

[0106] like Figure 3b As shown, the electronic device may include at least one processor 301, a memory 302, an input / output device 303, and a bus 304. Figure 3b A detailed introduction to the various components of electronic equipment:

[0107] The processor 301 is the control center of the electronic device, which can be a processor or a general term for multiple processing elements. For example, the processor 301 is a central processing unit (CPU), or an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more microprocessors (Digital Signal Processor, DSP), or one or more field programmable gate arrays (Field Programmable Gate Array, FPGA).

[0108] The processor 301 can execute various functions of the electronic device by running or executing the software program stored in the memory 302, and calling the data stored in the memory 302. In the embodiment of the present application, the processor can be used to perform a first signature process on the first V2X information, perform a second signature process on the second V2X information, verify the first signature, or verify the second signature.

[0109] In a specific implementation, as an embodiment, the processor 301 may include one or more CPUs, such as CPU 0 and CPU 1 shown in the figure.

[0110] In a specific implementation, as an embodiment, the electronic device may include multiple processors, such as Figure 3b 301 and processor 305 are shown in FIG. Each of these processors may be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0111] The memory 302 may be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 302 may exist independently and be connected to the processor 301 via the bus 304. The memory 302 may also be integrated with the processor 301. In an embodiment of the present application, the memory may be used to store the first V2X information, the second V2X information, or the third V2X information, or a private key, a public key, etc.

[0112] The input / output device 303 is used to communicate with other devices or communication networks. For example, it is used to communicate with communication networks such as Ethernet, Radio Access Network (RAN), and Wireless Local Area Networks (WLAN). The input / output device 303 may include all or part of the baseband processor, and may also selectively include a Radio Frequency (RF) processor. The RF processor is used to transmit and receive RF signals, and the baseband processor is used to process the baseband signals converted from RF signals or the baseband signals to be converted into RF signals.

[0113] In a specific implementation, as an embodiment, the input / output device 303 may include a transmitter and a receiver. Among them, the transmitter is used to send signals to other devices or communication networks, and the receiver is used to receive signals sent by other devices or communication networks. The transmitter and the receiver may exist independently or be integrated together. In the embodiments of the present application, the input / output device may be used to transmit and receive: first V2X information, second V2X information, or third V2X information.

[0114] The bus 304 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 3b only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0115] Figure 3b The device structure shown in the figure does not limit the electronic device, and it may include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.

[0116] Next, the V2X information involved in the embodiments of the present application will be described.

[0117] The first V2X information may represent V2X information whose reliability needs to be guaranteed. The first V2X information is provided by the application layer of the first operation unit for use by the second operation unit. The first V2X information departs from the first operation unit via the first communication unit and the second communication unit to the second operation unit. The first V2X information includes traffic light information provided by a traffic light, traffic control information provided by a V2X server, road condition information provided by a V2X server, or decision information, BSM information, and CAM information provided by an on-board computing platform. The embodiments of the present application do not limit the content of the first V2X information.

[0118] The second V2X information may represent the V2X information obtained after the first V2X information is processed with the first signature. The second V2X information includes the first V2X information and the first signature. When the first operation unit sends the first V2X information, the first V2X information needs to pass through the application layer, transport layer, network layer, access layer and physical layer of the first operation unit in sequence. In an embodiment of the present application, a first signature processing function is added to the application layer of the first operation unit. After the first operation unit can obtain the first V2X information from its application layer, it can perform the first signature processing on the first V2X information to obtain the second V2X information. The first signature processing includes but is not limited to one or more of information excerpt (for example, using a hash function to calculate the information excerpt), cyclic redundancy check (CRC) check and digital signature. These processing methods can ensure that when the protected data (i.e., the first V2X information) changes, the opposite end can detect it, prevent message corruption and message insertion, etc., and thus ensure end-to-end functional safety. Among them, the digital signature includes the digital signature based on the root certificate issued by the national certification body platform, or the digital signature based on the root certificate of the automobile enterprise self-inspection certification body platform, or the digital signature based on the root certificate issued by the ecological alliance certification body platform.

[0119] The third V2X information may represent the V2X information obtained after performing the second signature processing on the second V2X information. The third V2X information includes the second V2X information and the second signature. That is to say, the third V2X information includes the first V2X information, the first signature and the second signature, wherein the first V2X information and the first signature constitute the second V2X information. In an embodiment of the present application, the second V2X information reaches the physical layer of the first communication unit from the physical layer of the first operation unit, and then passes through the access layer, network layer and transport layer of the first communication unit in turn to reach the application layer of the first pass unit. In an embodiment of the present application, a second signature processing function is added to the application layer of the first communication unit. After the first communication unit obtains the second V2X information from its application layer, it performs the second signature processing on the second V2X information to obtain the third V2X information. Afterwards, the third V2X information is sent out through the application layer, transport layer, network layer, access layer and physical layer of the first communication unit. In this way, when the protected data (i.e., the first V2X information) is transmitted together with the second signature in the V2X network (i.e., between the first communication unit and the second communication unit), it is possible to verify whether the protected data (the first V2X information) is denied or forged during transmission in the network, thereby ensuring the security of network transmission. In a possible implementation, the second signature processing may include digital signature, adding tokens, etc.

[0120] In the embodiment of the present application, the first communication unit and the second communication unit may transmit the second V2X information obtained through the first signature process, or may transmit the third V2X information obtained through the first signature process and the second signature process.

[0121] Combine the following Figure 3c The process of transmitting the third V2X information between the first communication unit and the second communication unit is described. Figure 3c The interactive schematic diagram of the data transmission method provided in the embodiment of the present application is shown. The method can be applied to Figure 3a The data transmission system shown in FIG. Figure 3c As shown, the method may include:

[0122] Step S401: The first computing unit obtains first V2X information of the application layer.

[0123] Step S402: The first operation unit performs a first signature process on the first V2X information to obtain second V2X information including the first V2X information and the first signature.

[0124] Step S403: The first computing unit sends the second V2X information to the first communication unit.

[0125] Step S404: The first communication unit receives the second V2X information sent by the first computing unit.

[0126] Step S405: The first communication unit performs a second signature process on the second V2X information to obtain third V2X information including the second V2X information and the second signature.

[0127] Step S406: The first communication unit broadcasts third V2X information.

[0128] At the transmitting end, the first operation unit performs a first signature process on the first V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety; the first communication unit performs a second signature process on the second V2X information, which can prevent message repudiation and message forgery, and provide protection for network security. In implementation, the application layer of the first operation unit obtains the first V2X information, and performs a first signature process on the first V2X information to obtain the second V2X information. The first operation unit sends the second V2X information to the first communication unit via Ethernet or other physical buses. After the application layer of the first communication unit obtains the second V2X information, it performs a second signature process on the second V2X information to obtain the third V2X information, and then passes it through the transport layer, network layer, access layer, physical layer, and finally passes it to other devices (such as the second communication unit) through the V2X network (such as DSRC or LTE-V).

[0129] Step S407: The second communication unit receives the third V2X information sent by the first communication unit.

[0130] Step S408: The second communication unit verifies the second signature in the third V2X information.

[0131] In a possible implementation, step S408 may include: the second communication unit extracts the second V2X information in the third V2X information to obtain a first summary; the second communication unit decrypts the second signature in the third V2X information to obtain a second summary; when the first summary and the second summary are the same, the second communication unit determines that the second signature verification succeeds; when the first summary and the second summary are different, the second communication unit determines that the second signature verification fails.

[0132] When the first digest and the second digest are the same, it indicates that the source of the third V2X information is reliable and the content of the second V2X information in the third V2X information has not been tampered with, so the second communication unit can determine that the second signature verification is successful.

[0133] It should be noted that the second communication unit may also verify the second signature in other ways agreed upon with the first communication unit, and this application does not impose any limitation on this.

[0134] Step S409: When the second signature verification succeeds, the second communication unit sends the second V2X information in the third V2X information to the second computing unit.

[0135] Step S410: The second operation unit receives the second V2X information sent by the second communication unit.

[0136] Step S411: The second operation unit verifies the first signature in the second V2X information.

[0137] Step S412: When the first signature verification succeeds, the second operation unit processes the first V2X information.

[0138] In a possible implementation, the second computing unit may process the first V2X information to obtain fusion information, and the second computing unit may send the fusion information to the controller so that the controller can make motion decisions and controls based on the fusion information.

[0139] At the receiving end, the second communication unit verifies the second signature in the third V2X information, which can prevent message repudiation and message forgery during network transmission, and provide protection for network security; the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety. In implementation, the third V2X information passes through the V2X network, physical layer, access layer, network layer, and transport layer to reach the application layer of the second communication unit. The application layer of the second communication unit verifies the second signature in the third V2X information. If the second signature in the third V2X information fails to be verified, the second communication unit does not forward the second V2X information in the third V2X information. If the second signature in the third V2X information is successfully verified, the second communication unit forwards the second V2X information in the third V2X message through the transport layer, network layer, access layer, and physical layer. The second V2X information passes through the physical layer, access layer, network layer, and transport layer to reach the application layer of the second operation unit. The application layer of the second operation unit verifies the first signature in the second V2X information. If the first signature verification in the second V2X information fails, it indicates that the first V2X information has been changed and is incomplete. In order to ensure functional safety, the second operation unit cannot use the first V2X information for subsequent processing. If only the first signature verification of the second V2X information succeeds, it indicates that the first V2X information has not been changed and is complete, and the second operation unit can perform subsequent processing based on the first V2X information.

[0140] In the embodiment of the present application, the functional safety level requirement of the link ASIL-B is decomposed into: QM requirements for the transmission channel and ASIL-B requirements for information processing. The first communication unit and the second communication unit have no functional safety requirements. The first operation unit and the second operation unit are designed, developed, verified and meet the functional safety of ASIL-B in accordance with the ISO26262 system, thereby reducing the functional safety level requirement of the transmission channel. In the embodiment of the present application, the functional safety (i.e. integrity) of the V2X information is ensured by performing the first signature processing and the first signature verification in the first operation unit and the second operation unit; the network security of the V2X information is ensured by performing the second signature processing and the second signature verification in the first communication unit and the second communication unit. Therefore, the embodiment of the present application can improve the reliability of the V2X information without modifying and upgrading the existing equipment hardware as much as possible, thereby improving the safety of vehicle motion decision-making and control.

[0141] Figure 4a The schematic diagram of the architecture of the data transmission system in the V2I scenario provided by the embodiment of the present application is shown. Figure 4a As shown in FIG. 1 , the data transmission system includes a signal machine, a roadside unit, a vehicle communication unit, a gateway and a vehicle computing platform. The signal machine corresponds to Figure 3a The first computing unit 11 shown, the roadside unit corresponds to Figure 3a The first communication unit 12 shown, the vehicle communication unit corresponds to Figure 3a The second communication unit 13 shown, the vehicle computing platform corresponds to Figure 3a The second computing unit 14 is shown. Figure 3c The method shown can be applied to Figure 4a The data transmission system shown.

[0142] like Figure 4a As shown, at the transmitting end: the application layer of the signal machine obtains information such as traffic light signals, and uses the obtained information as the first V2X information. The application layer of the signal machine performs a first signature process on the first V2X information to obtain a second V2X information including the first V2X information and the first signature. The second V2X information is transmitted layer by layer (including the transport layer, network layer, access layer, and physical layer) in the signal machine, and finally reaches the physical layer of the roadside unit through Ethernet or other buses. After that, the second V2X information is transmitted layer by layer (including the physical layer, access layer, network layer, and transport layer) in the roadside unit to reach the application layer of the roadside unit. The application layer of the roadside unit performs a second signature process on the second V2X information to obtain a third V2X information including the second V2X information and the second signature. The third V2X information is transmitted layer by layer in the roadside unit, and finally sent to the vehicle communication unit through the V2X network (such as DSEC or LTE-V).

[0143] like Figure 4a As shown, at the receiving end: the third V2X information is transmitted layer by layer in the vehicle communication unit to reach the application side of the vehicle communication unit. Then, the application layer verifies the second signature of the third V2X information. In the case where the second signature in the third V2X information is successfully verified, the vehicle communication unit transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the vehicle computing platform through the gateway. The application layer of the vehicle computing platform receives the second V2X information after layer by layer transmission, and then the application layer of the vehicle computing platform verifies the first signature in the second V2X information. In the case where the first signature in the second V2X information is successfully verified, the vehicle computing platform performs subsequent processing based on the first V2X information in the second V2X information.

[0144] Figure 4b The schematic diagram of the architecture of the data transmission system in the V2I scenario provided by the embodiment of the present application is shown. Figure 4b As shown in FIG. 1 , the data transmission system includes an on-board computing platform, a gateway, an on-board communication unit, a roadside unit, and a V2X server. The on-board computing platform corresponds to Figure 3a The first computing unit 11 shown in the figure corresponds to the vehicle communication unit Figure 3a The first communication unit 12 shown, the roadside unit corresponds to Figure 3a The second communication unit 13 shown, the V2X server corresponds to Figure 3a The second computing unit 14 is shown. Figure 3c The method shown can be applied to Figure 4b The data transmission system shown.

[0145] like Figure 4b As shown, at the sending end: the application layer of the on-board computing platform obtains decision information and other information, and uses the obtained information as the first V2X information. The application layer of the on-board computing platform performs a first signature process on the first V2X information to obtain a second V2X information including the first V2X information and the first signature. The second V2X information is transmitted layer by layer in the on-board computing platform, and finally forwarded to the physical layer of the on-board communication unit through the gateway. Afterwards, the second V2X information is transmitted layer by layer in the on-board communication unit to the application layer of the on-board communication unit. Then, the application layer of the on-board communication unit performs a second signature process on the second V2X information to obtain a third V2X information including the second V2X information and the second signature. The third V2X information is transmitted layer by layer in the on-board communication unit, and finally sent to the roadside unit through the V2X network (such as DSEC or LTE-V).

[0146] like Figure 4bAs shown, at the receiving end: the third V2X information is received in the roadside unit through layer-by-layer transmission and reaches the application layer of the roadside unit. Then, the application layer of the roadside unit verifies the second signature in the third V2X information. In the case where the second signature in the third V2X information is successfully verified, the roadside unit transmits the second V2X information in the third V2X information to the V2X server through Ethernet or other buses after layer-by-layer transmission. The application layer of the V2X server receives the second V2X information through layer-by-layer transmission, and then the application layer of the V2X server verifies the first signature in the second V2X information. In the case where the first signature in the second V2X information is successfully verified, the V2X server performs subsequent processing based on the first V2X information in the second V2X information.

[0147] Figure 4c The schematic diagram of the architecture of the data transmission system in the V2V scenario provided by the embodiment of the present application is shown. Figure 4c As shown, the data transmission system includes an on-board computing platform of vehicle A, a gateway of vehicle A, an on-board communication unit of vehicle A, and an on-board communication unit of vehicle B, a gateway of vehicle B, and an on-board computing platform of vehicle B. The on-board computing platform of vehicle A corresponds to Figure 3a The first computing unit 11 shown in FIG. 1 corresponds to the vehicle communication unit of vehicle A. Figure 3a The first communication unit 12 shown, the vehicle-mounted communication unit of vehicle B corresponds to Figure 3a The second communication unit 13 shown, the vehicle-mounted computing platform of vehicle B corresponds to Figure 3a The second computing unit 14 is shown. Figure 3c The method shown can be applied to Figure 4c The data transmission system shown.

[0148] like Figure 4c As shown, at the sending end: the application layer of the vehicle-mounted computing platform of vehicle A obtains decision information and other information, and uses the obtained information as the first V2X information. The application layer of the vehicle-mounted computing platform of vehicle A performs a first signature process on the first V2X information to obtain a second V2X information including the first V2X information and the first signature. The vehicle-mounted computing platform of vehicle A transmits the second V2X information layer by layer, and finally forwards the second V2X information to the vehicle-mounted communication unit of vehicle A through the gateway. The application layer of the vehicle-mounted communication unit of vehicle A receives the second V2X information after layer by layer transmission. Then, the application layer of the vehicle-mounted communication unit of vehicle A performs a second signature process on the second V2X information to obtain a third V2X information including the second V2X information and the second signature. The vehicle-mounted communication unit of vehicle A transmits the third V2X information layer by layer, and finally sends the third V2X information to the vehicle-mounted communication unit of vehicle B through the V2X network (such as DSEC or LTE-V).

[0149] like Figure 4cAs shown, at the receiving end: the application layer of the on-board communication unit of vehicle B receives the third V2X information through layer-by-layer transmission. Then, the application layer of the on-board communication unit of vehicle B verifies the second signature in the third V2X information. In the case where the second signature in the third V2X information is successfully verified, the on-board communication unit of vehicle B transmits layer by layer, and finally forwards the second V2X information in the third V2X information to the on-board computing platform of vehicle B through the gateway. The application layer of the on-board computing platform of vehicle B receives the second V2X information through layer by layer transmission, and then the application layer of the on-board computing platform of vehicle B verifies the first signature in the second V2X information. In the case where the first signature in the second V2X information is successfully verified, the on-board computing platform of vehicle B performs subsequent processing based on the first V2X information in the second V2X information.

[0150] Combine the following Figure 3d The process of transmitting the second V2X information obtained through the first signature processing between the first communication unit and the second communication unit is described. Figure 3d The interactive schematic diagram of the data transmission method provided in the embodiment of the present application is shown. The method can be applied to Figure 3a The data transmission system shown in FIG. Figure 3d As shown, the method may include:

[0151] Step S501: The first computing unit obtains first V2X information of the application layer.

[0152] Step S502: The first operation unit performs a first signature process on the first V2X information to obtain second V2X information including the first V2X information and the first signature.

[0153] In a possible implementation, the first operation unit can perform the first signature processing on the first V2X information by performing the digital signature processing on the first V2X information. In implementation, the root certificate of the national certification authority (CA) platform can be used for digital signature processing, thereby realizing the interconnection and interoperability between vehicles produced by different car companies; the root certificate of the car company's self-check CA platform can be used for digital signature processing, thereby realizing the interconnection and interoperability between vehicles produced by the same car company; the root certificate issued by the ecological alliance CA platform can also be used for digital signature processing, thereby realizing the interconnection and interoperability between vehicles produced by car companies under the same ecological alliance.

[0154] Step S503: The first computing unit sends the second V2X information to the first communication unit through the secure channel between the first computing unit and the first communication unit.

[0155] In an embodiment of the present application, a secure channel can be established between the first operation unit and the first communication unit. In one example, the first operation unit and the first communication unit generate a session key through link session key negotiation, and use the session key to encrypt transmission data, thereby achieving the establishment of a secure channel. In another example, the first operation unit and the first communication unit are respectively configured with secure communication modules, and encryption and decryption of transmission data are achieved through the secure communication modules at both ends, thereby achieving the establishment of a secure channel. The embodiment of the present application does not limit the method of establishing a secure channel, does not limit the encryption and decryption method used in the secure channel, and does not limit the key used in the secure channel.

[0156] Step S504: The first communication unit receives second V2X information through a secure channel between the first communication unit and the first computing unit.

[0157] Step S505: The first communication unit broadcasts second V2X information.

[0158] The V2X information received by the first communication unit through the secure channel is the V2X information processed by the first signature. At this time, the first communication unit does not need to perform the second signature processing on the received V2X information, and can also ensure the functional safety of the application layer V2X information. The first communication unit directly broadcasts the second V2X information, which can reduce the functional requirements of the first communication unit, thereby reducing the cost of the first communication unit.

[0159] Step S506: The second communication unit receives the second V2X information sent by the first communication unit.

[0160] Step S507: The second communication unit sends the second V2X information to the second computing unit through the secure channel between the second communication unit and the second computing unit.

[0161] In the embodiment of the present application, a secure channel can be established between the second communication unit and the second computing unit. The manner of establishing a secure channel between the second communication unit and the second computing unit can refer to the manner of establishing a secure channel between the first computing unit and the first communication unit, which will not be repeated here.

[0162] When a secure channel is established between the second communication unit and the second computing unit, the second communication unit can forward the received V2X information directly to the second computing unit through the secure channel, and the second computing unit will perform signature verification. This can, on the one hand, concentrate the V2X information that has not been signature verified in the second computing unit to prevent the V2X information that has not been signature verified from causing adverse effects on other components in the vehicle. On the other hand, it can reduce the functional requirements for the second communication unit, thereby reducing the cost of the second communication unit.

[0163] Step S508: The second computing unit receives second V2X information through a secure channel with the second communication unit.

[0164] Step S509: The second operation unit verifies the first signature in the second V2X information.

[0165] Step S510: When the first signature verification succeeds, the second operation unit performs information processing on the first V2X information in the second V2X information.

[0166] In a possible implementation, the second computing unit may process the first V2X information to obtain fusion information, and the second computing unit may send the fusion information to the controller so that the controller can make motion decisions and controls based on the fusion information.

[0167] At the receiving end, the second communication unit sends the second V2X information to the second operation unit through a secure channel, so that the unverified V2X information can go through a dedicated channel, reducing the impact on other components in the data processing device; the second operation unit verifies the first signature in the second V2X information to prevent problems such as message corruption and message insertion, thereby providing protection for functional safety.

[0168] In the embodiment of the present application, the functional safety level requirements of the link ASIL-B are decomposed into: QM requirements for the transmission channel and ASIL-B requirements for information processing. The first communication unit and the second communication unit have no functional safety requirements. The first operation unit and the second operation unit are designed, developed, verified and meet the functional safety of ASIL-B according to the ISO26262 system, thereby reducing the functional safety level requirements of the transmission channel. By performing the first signature processing in the first operation unit and transmitting the second V2X information in the secure channel, both the functional safety (i.e., integrity) of the V2X information and the network security of the V2X information are guaranteed. Therefore, the embodiment of the present application can improve the reliability of the V2X information without upgrading the existing equipment hardware as much as possible, thereby improving the safety of vehicle motion decision-making and control. At the same time, the embodiment of the present application simplifies the information transmission process between the first operation unit and the first communication unit and the information transmission process between the second communication unit and the second operation unit, reduces the functional requirements of the first communication unit and the second communication unit, and thus reduces the cost of the first communication unit and the second communication unit.

[0169] Figure 4d The schematic diagram of the architecture of the data transmission system in the V2V scenario provided by the embodiment of the present application is shown. Figure 4dAs shown, the data transmission system includes the vehicle-mounted computing platform of vehicle A, the gateway of vehicle A, the vehicle-mounted communication unit of vehicle A, and the vehicle-mounted communication unit of vehicle B, the gateway of vehicle B and the vehicle-mounted computing platform of vehicle B. Among them, the vehicle-mounted computing platform of vehicle A corresponds to Figure 3a The first computing unit 11 shown in FIG. 1 corresponds to the vehicle communication unit of vehicle A. Figure 3a The first communication unit 12 shown, the vehicle-mounted communication unit of vehicle B corresponds to Figure 3a The second communication unit 13 shown, the vehicle-mounted computing platform of vehicle B corresponds to Figure 3a The second computing unit 14 is shown. Figure 3d The method shown can be applied to Figure 4d The data transmission system shown.

[0170] like Figure 4d As shown, at the sending end: a secure channel is established between the vehicle-mounted computing platform of vehicle A and the vehicle-mounted communication unit of vehicle A. The application layer of the vehicle-mounted computing platform of vehicle A obtains the first V2X information, and performs a first signature process on the first V2X information to obtain V2X information including the first V2X information and the first signature. The vehicle-mounted computing platform of vehicle A transmits the second V2X information to the vehicle-mounted communication unit of vehicle A through the pre-established secure channel. The vehicle-mounted communication unit of vehicle A broadcasts the second V2X information through the V2X network.

[0171] like Figure 4d As shown, at the receiving end: a secure channel is established between the vehicle-mounted computing platform of vehicle B and the vehicle-mounted communication unit of vehicle B. After the vehicle-mounted communication unit of vehicle B receives the second V2X information, it sends the second V2X information to the vehicle-mounted computing platform of vehicle B through the pre-established secure channel. The application layer of the vehicle-mounted computing platform of vehicle B verifies the first signature in the second V2X information. If the first signature verification is successful, the vehicle-mounted computing platform of vehicle B can perform subsequent processing based on the first V2X information in the second V2X information.

[0172] Figure 5 The schematic diagram of the structure of the data processing device provided in the embodiment of the present application is shown. The device can be used to execute Figure 3c As shown in the method. Figure 5 As shown, the data processing device 50 may include: a computing unit 51 and a communication unit 52 , wherein the computing unit 51 includes a first signature module 511 and a first sending module 512 , and the communication unit 52 includes a second signature module 521 and a second sending module 522 .

[0173] The first signature module 511 is configured to perform a first signature process on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;

[0174] The first sending module 512 is configured to send the second V2X information obtained by the first signature module 511 to the second signature module;

[0175] The second signature module 521 is configured to perform a second signature process on the second V2X information sent by the first sending module 512 to obtain third V2X information, where the third V2X information includes the second V2X information and the second signature;

[0176] The second sending module 522 is used to send the third V2X information obtained by the second signing module 521.

[0177] In the embodiment of the present application, the computing unit performs the first signature processing on the V2X information of the application layer, so that when the computing unit meets the functional safety level requirements, the functional safety of the V2X information of the application layer can be guaranteed, there is no functional safety requirement for the communication unit, and the functional safety level requirements for the transmission channel between the computing unit and the communication unit are reduced; then, the communication unit performs the second signature processing on the V2X information that has been processed by the first signature, so that the security of the V2X information of the application layer during the network transmission process is guaranteed. Therefore, the embodiment of the present application can improve the reliability of V2X information without modifying and upgrading the hardware of existing equipment as much as possible, thereby improving the security of vehicle motion decision-making and control.

[0178] In one possible implementation, the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0179] In a possible implementation, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0180] In a possible implementation, the data processing device is a roadside device, the computing unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0181] In a possible implementation manner, the first sending module is further used to: send the second V2X information to the second signature module via Ethernet.

[0182] Figure 6 The schematic diagram of the structure of the data processing device provided in the embodiment of the present application is shown. The device can be used to execute Figure 3dAs shown in the method. Figure 6 As shown, the data processing device 60 includes a computing unit 61 and a communication unit 62, wherein the computing unit 61 is connected to the communication unit 62 via a secure channel 63, the computing unit 61 includes a first signature module 611 and a first sending module 612, and the communication unit 62 includes a second sending module 621.

[0183] The first signature module 611 is configured to perform a first signature process on the first V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature;

[0184] The first sending module 612 is configured to send the second V2X information to the second sending module 621 through the secure channel 63;

[0185] The second sending module 621 is used to send the second V2X information.

[0186] In the embodiment of the present application, by transmitting the second V2X information in the secure channel between the operation unit and the communication unit, the signature processing process of the second V2X information by the communication unit can be omitted, thereby reducing the functional requirements for the first communication unit and reducing the cost of the first communication unit.

[0187] In one possible implementation, the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car company's self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform.

[0188] In a possible implementation, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0189] In a possible implementation, the data processing device is a roadside device, the computing unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0190] Figure 7 The schematic diagram of the structure of the data processing device provided in the embodiment of the present application is shown. The device can be used to execute Figure 3c As shown in the method. Figure 7 As shown, the data processing device 70 includes a communication unit 71 and a computing unit 72 . The communication unit 71 includes a receiving module 711 , a first signature verification module 712 , and a sending module 713 . The computing unit 72 includes a second signature verification module 721 and a processing module 722 .

[0191] The receiving module 711 is used to receive third V2X information, where the third vehicle networking V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature of an application layer;

[0192] The first signature verification module 712 is used to verify the second signature in the third V2X information received by the receiving module 711;

[0193] The sending module 713 is configured to send the second V2X information to the second signature verification module 721 when the first signature verification module 712 successfully verifies the second signature;

[0194] The second signature verification module 721 is used to verify the first signature in the second V2X information sent by the sending module 713;

[0195] The processing module 722 is configured to process the first V2X information when the second signature verification module 721 successfully verifies the first signature.

[0196] In the embodiment of the present application, the second communication unit can directly forward the received V2X information to the second operation unit through the secure channel, and the second operation unit performs signature verification. In this way, on the one hand, the V2X information that has not been verified by signature can be concentrated in the second operation unit to prevent the V2X information that has not been verified by signature from causing adverse effects on other components in the vehicle. On the other hand, the functional requirements for the second communication unit can be reduced, thereby reducing the cost of the second communication unit. At the same time, the second operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety.

[0197] In a possible implementation manner, the first signature verification module is further configured to:

[0198] performing information abstraction processing on the second V2X information to obtain a first summary;

[0199] Decrypting the second signature to obtain a second summary;

[0200] When the first digest and the second digest are identical, it is determined that the second signature verification succeeds.

[0201] In a possible implementation manner, the second signature verification module is further configured to:

[0202] The first signature is subjected to information excerpt verification, cyclic redundancy CRC verification, or digital signature verification, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, digital signature verification based on a root certificate issued by a car manufacturer's self-inspection certification authority platform, or digital signature verification based on a root certificate issued by an ecological alliance certification authority platform.

[0203] In a possible implementation, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0204] In a possible implementation, the data processing device is a roadside device, the computing unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0205] In a possible implementation manner, the sending module is further used to: when the first signature verification module successfully verifies the second signature, send the second V2X information to the second signature verification module via Ethernet.

[0206] Figure 8 The schematic diagram of the structure of the data processing device provided in the embodiment of the present application is shown. The device can be used to execute Figure 3d As shown in the method. Figure 8 As shown, the data processing device 80 includes a communication unit 81 and a computing unit 82, the communication unit 81 and the computing unit 82 are connected via a secure channel 83, the communication unit 81 includes a receiving module 811 and a sending module 812, and the computing unit 82 includes a signature verification module 821 and a processing module 822;

[0207] The receiving module 811 is configured to receive second V2X information, where the second V2X information includes first V2X information and a first signature of an application layer;

[0208] The sending module 812 is configured to send the second V2X information received by the receiving module 811 to the signature verification module 821 through the secure channel 83;

[0209] The signature verification module 821 is used to verify the first signature in the second V2X information sent by the sending module 812;

[0210] The processing module 822 is configured to process the first V2X information when the signature verification module 821 successfully verifies the first signature.

[0211] In the embodiment of the present application, the communication unit sends the second V2X information to the operation unit through the secure channel, so that the unverified V2X information can go through the dedicated channel, reducing the impact on other components in the data processing device; the operation unit verifies the first signature in the second V2X information, which can prevent problems such as message corruption and message insertion, and provide protection for functional safety.

[0212] In a possible implementation, the signature verification module is further used to:

[0213] The first signature is verified by digital signature based on the root certificate issued by the national certification authority platform, or by digital signature based on the root certificate of the automobile enterprise self-inspection certification authority platform, or by digital signature based on the root certificate issued by the ecological alliance certification authority platform.

[0214] In a possible implementation, the data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

[0215] In a possible implementation, the data processing device is a roadside device, the computing unit includes a signal machine, and the communication unit includes a roadside unit RSU.

[0216] An embodiment of the present application provides a data processing device, comprising: a processor and a memory for storing processor-executable instructions; wherein the processor is configured to implement the above method when executing the instructions.

[0217] An embodiment of the present application provides a non-volatile computer-readable storage medium on which computer program instructions are stored. When the computer program instructions are executed by a processor, the above method is implemented.

[0218] An embodiment of the present application provides a computer program product, including a computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in a processor of an electronic device, the processor in the electronic device executes the above method.

[0219] A computer-readable storage medium may be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium may be, for example, (but not limited to) an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination thereof. More specific examples (a non-exhaustive list) of computer-readable storage media include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a protruding structure in a groove on which instructions are stored, and any suitable combination thereof.

[0220] The computer-readable program instructions or codes described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.

[0221] The computer program instructions for performing the operation of the present application may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages, such as Smalltalk, C++, etc., and conventional procedural programming languages, such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, by utilizing the state information of computer-readable program instructions to personalize an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA), the electronic circuit can execute the computer-readable program instructions to implement various aspects of the present application.

[0222] Various aspects of the present application are described herein with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer-readable program instructions.

[0223] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.

[0224] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operating steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.

[0225] The flow chart and block diagram in the accompanying drawings show the possible architecture, function and operation of the device, system, method and computer program product according to multiple embodiments of the present application. In this regard, each square frame in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of the module, program segment or instruction includes one or more executable instructions for realizing the logical function of the specification. In some alternative implementations, the functions marked in the square frame can also occur in a sequence different from that marked in the accompanying drawings. For example, two continuous square frames can actually be executed substantially in parallel, and they can also be executed in reverse order sometimes, depending on the functions involved.

[0226] It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented by hardware (such as a circuit or ASIC (Application Specific Integrated Circuit)) that performs the corresponding function or action, or can be implemented by a combination of hardware and software, such as firmware.

[0227] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art may understand and implement other variations of the disclosed embodiments by viewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "one" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0228] The embodiments of the present application have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technology in the market, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein.

Claims

1. A data transmission method, It is characterized in that The method is applied to a data processing device, the data processing device includes a computing unit and a communication unit, and the method includes: The operation unit performs a first signature processing on the first vehicle network V2X information of the application layer to obtain second V2X information, wherein the second V2X information includes the first V2X information and the first signature; the first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a vehicle enterprise self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform; The computing unit sends the second V2X information to the communication unit; The communication unit performs a second signature processing on the second V2X information to obtain third V2X information, where the third V2X information includes the second V2X information and the second signature; The communication unit sends the third V2X information.

2. The method according to claim 1, It is characterized in that The data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

3. The method according to claim 1, It is characterized in that The data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

4. A data transmission method, It is characterized in that The method is applied to a data processing device, the data processing device includes a computing unit and a communication unit, and the method includes: The communication unit receives third vehicle network V2X information, where the third V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature of an application layer; The communication unit verifies the second signature; If the second signature verification succeeds, the communication unit sends the second V2X information to the operation unit; The operation unit verifies the first signature, including: the operation unit performs information excerpt verification, cyclic redundancy CRC verification, or digital signature verification on the first signature, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or digital signature verification based on a root certificate of a vehicle enterprise self-inspection certification authority platform, or digital signature verification based on a root certificate issued by an ecological alliance certification authority platform; When the first signature verification succeeds, the operation unit performs information processing on the first V2X information.

5. The method according to claim 4, It is characterized in that The communication unit verifies the second signature, including: The communication unit performs information abstraction processing on the second V2X information to obtain a first summary; The communication unit decrypts the second signature to obtain a second summary; In a case where the first digest and the second digest are identical, the communication unit determines that verification of the second signature succeeds.

6. The method according to claim 4 or 5, It is characterized in that The data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

7. The method according to claim 4 or 5, It is characterized in that The data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

8. A data processing device, It is characterized in that The data processing device comprises a computing unit and a communication unit, the computing unit comprises a first signature module and a first sending module, and the communication unit comprises a second signature module and a second sending module; The first signature module is used to perform a first signature processing on the first vehicle network V2X information of the application layer to obtain second V2X information, where the second V2X information includes the first V2X information and the first signature; The first signature processing includes: one or more of information excerpt, cyclic redundancy CRC check and digital signature, wherein the digital signature includes a digital signature based on a root certificate issued by a national certification authority platform, or a digital signature based on a root certificate of a car enterprise self-inspection certification authority platform, or a digital signature based on a root certificate issued by an ecological alliance certification authority platform; The first sending module is configured to send the second V2X information obtained by the first signature module to the second signature module; The second signature module is configured to perform a second signature processing on the second V2X information sent by the first sending module to obtain third V2X information, where the third V2X information includes the second V2X information and the second signature; The second sending module is used to send the third V2X information obtained by the second signature module.

9. The device according to claim 8, It is characterized in that The data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

10. The device according to claim 8, It is characterized in that The data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

11. A data processing device, It is characterized in that The data processing device comprises a computing unit and a communication unit, the communication unit comprises a receiving module, a first signature verification module and a sending module, and the computing unit comprises a second signature verification module and a processing module; The receiving module is used to receive third vehicle network V2X information, where the third vehicle network V2X information includes second V2X information and a second signature, and the second V2X information includes first V2X information and a first signature of an application layer; The first signature verification module is used to verify the second signature in the third V2X information received by the receiving module; The sending module is configured to send the second V2X information to the second signature verification module when the first signature verification module successfully verifies the second signature; The second signature verification module is used to verify the first signature in the second V2X information sent by the sending module; the second signature verification module is also used to: perform information excerpt verification, or perform cyclic redundancy CRC verification, or perform digital signature verification on the first signature, wherein the digital signature verification includes digital signature verification based on a root certificate issued by a national certification authority platform, or digital signature verification based on a root certificate of a vehicle enterprise self-inspection certification authority platform, or digital signature verification based on a root certificate issued by an ecological alliance certification authority platform; The processing module is configured to process the first V2X information when the second signature verification module successfully verifies the first signature.

12. The device according to claim 11, It is characterized in that The first signature verification module is further used for: performing information abstraction processing on the second V2X information to obtain a first summary; Decrypting the second signature to obtain a second summary; When the first digest and the second digest are identical, it is determined that the second signature verification succeeds.

13. The device according to claim 11 or 12, It is characterized in that The data processing device is a vehicle-mounted device, the computing unit includes a mobile data center MDC, and the communication unit includes a telematics processor TBox.

14. The device according to claim 11 or 12, It is characterized in that The data processing device is a roadside device, the operation unit includes a signal machine, and the communication unit includes a roadside unit RSU.

15. A data processing device, It is characterized in that include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the method described in any one of claims 1 to 3, or implement the method described in any one of claims 4 to 7 when executing the instructions.

16. A computer readable storage medium having computer program instructions stored thereon, It is characterized in that When the computer program instructions are executed by a processor, the method described in any one of claims 1 to 3 is implemented, or the method described in any one of claims 4 to 7 is implemented.

17. A computer program product, comprising a computer-readable code, or a computer-readable storage medium carrying the computer-readable code, which, when the computer-readable code is executed by a processor, implements the method described in any one of claims 1 to 3, or implements the method described in any one of claims 4 to 7.

Citation Information

Patent Citations

  • Data transmission method, terminal, node device and system

    CN109845185A

  • Vehicle fleet key negotiation method, storage medium and vehicle

    CN112423262A