A system communication encryption and decryption method
By using system communication encryption and decryption methods in transportation tools, the encrypted communication connection between the system host and the slave device is ensured, and the problem of unstable equipment use in the prior art is solved, and the stable and consistent operation of the equipment is achieved.
Patent Information
- Application Number
- CN202210865843.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-22
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2042-07-22
AI Technical Summary
In existing transportation vehicles, the control of components of host equipment and slave equipment cannot be achieved by one machine, resulting in unstable use of the overall system of the equipment and serious abuse and mixed use of various components.
The system communication encryption and decryption method is adopted, and power is supplied through the battery module. The system host and slave device conduct specific encryption and decryption communication connections, and communicate with the cloud platform system to generate and combine session keys, perform key matching and verification to ensure point-to-point communication.
Effectively prevent the abuse and mixing of slave equipment, ensure the integrity, consistency and stability of the system, and ensure that the equipment can operate normally when started.
Smart Images

Figure CN115242385B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicles, and in particular relates to a method for encrypting and decrypting system communications of vehicles. Background Art
[0002] In current vehicles such as power-assisted bicycles, electric motorcycles, and scooters, the component management and control of the host device and the slave device cannot be achieved in one system for one device. The abuse and mixing of various components cause instability in the use of the overall device system. Summary of the invention
[0003] Purpose of the invention: In order to overcome the deficiencies in the prior art, the present invention provides a system communication encryption and decryption method that can prevent the abuse of various components and ensure the stability of the overall system of the equipment.
[0004] Technical solution: To achieve the above purpose, the technical solution of the present invention is as follows:
[0005] A system communication encryption and decryption method, characterized in that it includes:
[0006] The system host and each slave device in the vehicle are powered by the battery module;
[0007] The system host communicates with each slave device in a specific encryption and decryption manner, and connects the system host to the cloud platform system;
[0008] Each slave device encrypts specific information and reports registration information to the system host;
[0009] The system host generates and combines the HS+random number session key each time it is powered on. The system host obtains the production internal information data of each slave device from the cloud platform system;
[0010] The system host decrypts and matches the acquired internal production information data with the registration information reported by each slave device;
[0011] The system host sends the session key and startup command to each slave device and starts the system. Each slave device decrypts the sent information.
[0012] After the system host successfully shakes hands with each slave device, each slave device enters the working mode. If the system host fails to shake hands with any slave device, the whole vehicle system fails to start;
[0013] From successful communication to system host shutdown, all communication instructions and messages are encrypted and decrypted using session keys and specific methods;
[0014] Furthermore, the encryption and decryption method between the system host and each slave device includes three keys: root key, registration key and session key:
[0015] Root key: 16 bytes, used to encrypt and decrypt registration keys;
[0016] Registration key: 8 bytes, used to encrypt and decrypt session keys; the registration key is randomly generated each time the machine is turned on. After decryption, the system host compares the first four bytes of the ID number to determine whether the slave device is legal. If the slave device is legal, the system host encrypts the session key with the registration key and sends it point-to-point to the slave device;
[0017] Session key: 8 bytes, used to encrypt and decrypt communication data; the session key is randomly generated each time the machine is turned on. After decryption, the slave device compares the first two specific characters to determine whether the system host is legal. If the system host is legal, the slave device retains this session key, and all communications before shutdown will use this key and respond to the system host point-to-point;
[0018] Further, the system host combines the session key of this time, the slave device combines the registration key of this time and shakes hands and verifies the registration information;
[0019] The system host combines the session keys to include:
[0020] The system host generates an independent root ID and root key; generates a 6-byte random number;
[0021] Combined into the session key "HS+random number";
[0022] The slave device combination registration key includes:
[0023] The slave device generates an independent root ID and root key;
[0024] Generate a 6-byte random number;
[0025] Combined into the registration key "ID + random number";
[0026] Encrypt the registration key with the root key;
[0027] Packaging registration information;
[0028] The handshake and verification of registration information includes:
[0029] The system host obtains the slave device key and decrypts the ID in the packaged registration information;
[0030] Check whether the ID of the slave device in the registration information is correct;
[0031] Encrypt the system host session key using the slave device registration key;
[0032] Use the registration key to decrypt the information containing "HS" and save the session key;
[0033] Reply "READY";
[0034] The system host decrypts "READY" using the session key;
[0035] The system host encrypts "START" with the session key;
[0036] The slave device decrypts "START" through the session key and enters normal working state to realize information exchange.
[0037] Furthermore, when the battery module and the system component do not successfully handshake, the battery module is in a low-power supply mode.
[0038] Furthermore, when any slave device fails to handshake with the system host, the battery module is in a low-power supply mode.
[0039] Furthermore, the system host at least includes an external mobile communication module or a short-range wireless transmission module for communication with the cloud platform system.
[0040] Furthermore, the slave device at least includes a meter, Bluetooth, a sensor, and a battery BMS.
[0041] Furthermore, the production internal information data contained in the cloud platform system includes serial number, batch number, hardware version, firmware version, component root ID, and component root key.
[0042] Furthermore, the system host and each slave device may have the same or different root IDs and root keys.
[0043] Furthermore, when the system host issues a shutdown command, the system host and each slave device shut down and clear the session key in the current working process at the same time.
[0044] Beneficial effect: The present invention establishes a communication connection between the system host device and each slave device through a specific encryption and decryption method, thereby identifying whether the slave device is in a matched state with the system host, ensuring point-to-point communication between the system host and each slave device, preventing abuse and mixing of each slave device, and ensuring the integrity, consistency and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Attached Figure 1 It is a schematic diagram of the overall process of the present invention;
[0046] Attached Figure 2 It is a schematic diagram of the overall flow of the system of the present invention. DETAILED DESCRIPTION
[0047] The present invention will be further described below in conjunction with the accompanying drawings.
[0048] As attached Figure 1 and attached Figure 2 As shown, a system communication encryption and decryption method, which is applied to an automobile system as an example, includes:
[0049] The system host and each slave device in the vehicle are powered by the battery module;
[0050] The system host communicates with each slave device in a specific encryption and decryption manner, and connects the system host to the cloud platform system;
[0051] Each slave device encrypts specific information and reports registration information to the system host;
[0052] Each time the system host is turned on, it generates a random number - Token and combines it into a session key. The system host obtains the production internal information data of each slave device from the cloud platform system;
[0053] The system host decrypts and matches the acquired internal production information data with the registration information reported by each slave device;
[0054] The system host sends the session key and startup command to each slave device and starts the system. Each slave device decrypts the sent information.
[0055] After the system host successfully shakes hands with each slave device, each slave device enters the working mode. If the system host fails to shake hands with any slave device, the whole vehicle system fails to start;
[0056] From successful communication to system host shutdown, all communication instructions and messages are encrypted and decrypted using this key and a specific method.
[0057] The encryption and decryption methods of the system host and each slave device include three keys: root key, registration key and session key:
[0058] Root key: 16 bytes, used to encrypt and decrypt registration keys;
[0059] Registration key: 8 bytes, used to encrypt and decrypt session keys; the registration key is randomly generated each time the machine is turned on. After decryption, the system host determines whether the slave device is legal by comparing the first four bytes of the ID number. If the slave device is legal, the system host uses the registration key to encrypt the session key and sends it point-to-point to the slave device; the slave device refers to each slave device.
[0060] Session key: 8 bytes, used to encrypt and decrypt communication data; the session key is randomly generated each time the machine is turned on. After decryption, the slave device compares the first two specific characters to determine whether the system host is legal. The specific characters in this embodiment are "HS", which are preset as needed. If the system host is legal, the slave device retains this session key, and all communications before shutdown will use this key, and point-to-point reply "READY" to the system host. This encryption and decryption method has a variable key length, a variable encrypted data length, and a fast operation speed, which is suitable for single-chip microcomputers.
[0061] Including the system host combining the session key, the slave device combining the registration key and handshake and verifying the registration information;
[0062] The system host group and the session key include:
[0063] The system host generates an independent root ID and root key; generates a 6-byte random number;
[0064] Combined into the session key "HS+random number";
[0065] The slave device combination registration key includes:
[0066] The slave device generates an independent root ID and root key;
[0067] Generate a 6-byte random number;
[0068] Combined into session key "ID + random number";
[0069] Encrypt the registration key with the root key;
[0070] Packaging registration information;
[0071] The handshake and verification of registration information includes:
[0072] The system host obtains the slave device key and decrypts the ID in the packaged registration information;
[0073] Check whether the ID of the slave device in the registration information is correct;
[0074] Encrypt the system host session key using the slave device registration key;
[0075] Use the registration key to decrypt the information containing "HS" and save the session key;
[0076] Reply "READY";
[0077] The system host decrypts "READY" using the session key;
[0078] The system host encrypts "START" with the session key;
[0079] The slave device decrypts "START" through the session key and enters normal working state to realize information exchange.
[0080] When the battery module fails to shake hands with the system components, the battery module is in low-power supply mode, that is, the system cannot enter the running state and is still in a non-working state. Moreover, when any slave device fails to shake hands with the system host, the battery module is in low-power supply mode, thereby preventing incompatible slave devices from entering the original system, preventing the abuse and mixing of slave devices, and ensuring the integrity, consistency and stability of the system.
[0081] The system host at least includes an external mobile communication module or a short-range wireless transmission module for communication connection with the cloud platform system.
[0082] The slave device at least includes a meter, a Bluetooth, a sensor, and a battery BMS.
[0083] The production internal information data contained in the cloud platform system includes serial number, batch number, hardware version, firmware version, component root ID, and component root key.
[0084] The system host and each slave device have the same or different root ID and root key.
[0085] When the system host sends a shutdown command, the system host and each slave device shut down and clear the session key during this working process at the same time.
[0086] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A system communication encryption and decryption method, applied to a whole vehicle system, wherein the whole vehicle system includes a battery module, a system host, various slave devices and a cloud platform system; The battery module supplies power to the system host and slave devices in the vehicle; After the system is turned on, the system communication encryption and decryption operation is performed, and the system communication encryption and decryption operation includes the system host combining the current session key, the slave device combining the current registration key and handshaking and verifying the registration information; The system host combines the session key to include: The system host randomly generates a 6-byte random number, and the 6-byte random number is combined with "HS" to obtain the session key "HS+random number"; The session key is 8 bytes and is used to encrypt and decrypt communication data; The slave device combines the registration key for this time, including: the slave device generates a root ID and a root key of the slave device; wherein the root key of the slave device is 16 bytes; the slave device randomly generates a 6-byte random number, combines the root ID of the slave device and the randomly generated 6-byte random number, and obtains a registration key "ID+random number" of the slave device, wherein the registration key is 8 bytes, and the registration key is used to encrypt and decrypt the session key; the slave device uses its own root key to encrypt the registration key to obtain packaged registration information; the slave device sends the registration information to the system host; The handshake and verification of registration information includes the legitimacy verification of the slave device, the legitimacy verification of the system host and the handshake success process; The legitimacy verification of the slave device includes: the system host is connected to the cloud platform system in communication, the system host obtains the internal production information data of each slave device from the cloud platform system, and the internal production information data includes the root ID of each slave device and the root key of each slave device; the system host obtains the registration information of the slave device, decrypts the registration information by the root key of the slave device, and obtains the root ID and registration key of the slave device; checks whether the root ID of the slave device is consistent with the root ID obtained from the cloud platform system, and if so, the slave device is legal; The host device legitimacy verification includes: when the slave device is legitimate, the system host uses the slave device's registration key to encrypt the session key, and sends the encrypted session key to the slave device in a point-to-point manner; the slave device uses its own registration key to decrypt, obtain the session key, and determine whether the system host's session key contains "HS", if so, the system host is determined to be legitimate; The successful handshake process includes: when the system host is legal, the slave device saves the session key; and the slave device uses the session key to encrypt "READY" and sends it to the system host; after the system host uses the session key to decrypt the "READY" sent by the slave device, it uses the session key to encrypt "START" and sends it to the slave device; after the slave device uses the session key to decrypt "START", the system communication encryption and decryption operation is completed, and before shutting down, all communications between the system host and each slave device will be encrypted and decrypted using the session key, and each slave device will respond to the system host point-to-point, enter a normal working state, and realize information interaction.
2. A system communication encryption and decryption method according to claim 1, characterized in that: When any slave device fails to successfully handshake with the system host, the battery module is in low-power supply mode.
3. A system communication encryption and decryption method according to claim 1, characterized in that: The system host at least includes an external mobile communication module or a short-range wireless transmission module for communication connection with the cloud platform system.
4. A system communication encryption and decryption method according to claim 1, characterized in that: The slave device at least includes a meter, a Bluetooth, a sensor, and a battery BMS.
5. A system communication encryption and decryption method according to claim 1, characterized in that: The production internal information data contained in the cloud platform system also includes serial number, batch number, hardware version and firmware version.
6. A system communication encryption and decryption method according to claim 1, characterized in that: When the system host sends a shutdown command, the system host and each slave device shut down and clear the session key during this working process at the same time.
Citation Information
Patent Citations
Cloud-based secure instant messaging method and system
CN106411715A
Secure communication system and method of main control chip and encryption chip
CN108234132A