Vehicle communication method, terminal, vehicle, and computer-readable storage medium

By generating and verifying certificates in vehicle communication and negotiating the generation of session keys, data security issues in vehicle communication are solved, and the security and reliability of vehicle communication are achieved.

CN115334101BActive Publication Date: 2025-06-10NIO TECH ANHUI CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210863656.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-22
Publication Date
2025-06-10
Estimated Expiration
2042-07-22

AI Technical Summary

Technical Problem

With the development of intelligent connected vehicles, more and more data generated by vehicles is related to user privacy. Data leakage may affect user privacy, property and even life safety. The existing technology is difficult to effectively solve data security problems in vehicle communications.

Method used

The vehicle terminal private key and public key are generated through the vehicle terminal, and the authentication center distributes the vehicle terminal certificate to the mobile terminal. The vehicle terminal receives the mobile terminal certificate, presents the signature information of the mobile terminal certificate, generates test information through private key signature and certificate encryption, and negotiates to generate a session key to achieve encrypted communication.

Benefits of technology

The reliability of the certificate between the vehicle and the mobile terminal is verified, and encrypted communication is implemented based on the reliable certificate, ensuring the security of vehicle communication and is suitable for real-time screen transmission and other services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115334101B_ABST
    Figure CN115334101B_ABST
Patent Text Reader

Abstract

The present application relates to a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium. The method includes: generating, by a vehicle end, a corresponding vehicle-end private key and a vehicle-end public key, and distributing, via an authentication center, a vehicle-end certificate based on the vehicle-end public key to a mobile end; receiving, by the vehicle end, the mobile-end certificate distributed via the authentication center; presenting, by the vehicle end, a graphical code of first signature information about the mobile-end certificate, the graphical code being used for the mobile end to read and verify the first signature information with the mobile-end public key; signing, by the vehicle end, test data with the vehicle-end private key and encrypting the signed information with the mobile-end certificate to generate test information, and sending the test information to the mobile end; and negotiating, by the vehicle end, a session key with the mobile end based on the vehicle-end private key, the vehicle-end public key, the mobile-end public key, and the mobile-end private key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of vehicle privacy protection. Specifically, it relates to a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium. Background Art

[0002] With the development of intelligent connected vehicles, communication security has increasingly attracted the attention of users. In the intelligent electric vehicle industry, a very important security area is data security, which is behind user privacy, property, and even life safety. With the increasing intelligence and networking of vehicles, intelligent vehicles generate more and more data, and many of these data are related to user privacy. If these data are leaked, it will have a significant impact on the user's privacy, property, and even life safety. With the introduction of the Data Security Law and the Personal Information Protection Law, user privacy protection has become a compliance requirement.

[0003] In view of this, an improved communication mechanism needs to be proposed. Summary of the Invention

[0004] Embodiments of this application provide a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium for improving the security of vehicle communication.

[0005] According to one aspect of this application, a vehicle communication method is provided. The method includes: generating, by a vehicle end, a corresponding vehicle-end private key and a vehicle-end public key, and distributing, via an authentication center, a vehicle-end certificate based on the vehicle-end public key to a mobile end; receiving, by the vehicle end, a mobile-end certificate distributed by the authentication center, where the mobile-end certificate is generated based on a mobile-end public key, and the mobile-end public key and its corresponding mobile-end private key are generated by the mobile end; presenting, by the vehicle end, a graphical code of first signature information about the mobile-end certificate, where the graphical code is for the mobile end to read and verify the first signature information through the mobile-end public key; signing, by the vehicle end, test data with the vehicle-end private key and encrypting the signed information with the mobile-end certificate to generate test information, and sending the test information to the mobile end, where the test information is decrypted by the mobile end with the mobile-end private key and the second signature information in the decrypted data is verified based on the vehicle-end certificate; and negotiating, by the vehicle end, a session key with the mobile end based on the vehicle-end private key, the vehicle-end public key, the mobile-end public key, and the mobile-end private key.

[0006] In some embodiments of this application, optionally, the graphical code is a QR code.

[0007] In some embodiments of the present application, optionally, the vehicle certificate based on the vehicle public key distributed to the mobile device includes: the mobile device determines the ID of the vehicle certificate through the vehicle identification code of the vehicle, and obtains the vehicle certificate accordingly, where the vehicle identification code is bound to the ID of the corresponding vehicle certificate and the ID of the mobile device certificate.

[0008] In some embodiments of the present application, optionally, the vehicle receives the mobile device certificate distributed by the certification center, including: the vehicle determines the ID of the mobile device certificate through the vehicle identification code, and obtains the mobile device certificate accordingly.

[0009] In some embodiments of the present application, optionally, the method further includes: encrypting the session content using the session key to generate encrypted session content; and sending the encrypted session content to the mobile device.

[0010] In some embodiments of the present application, optionally, the method further includes: the mobile device decrypts the encrypted session content using the session key to generate the session content.

[0011] In some embodiments of the present application, optionally, the method is used to transmit a real-time video from the vehicle to the mobile device.

[0012] In some embodiments of the present application, optionally, the vehicle negotiates with the mobile device to generate the session key through the DH algorithm based on the vehicle private key, the vehicle public key, the mobile device public key, and the mobile device private key.

[0013] According to another aspect of the present application, a vehicle communication terminal is provided. The terminal includes: a key management, encryption and decryption module configured to generate a corresponding vehicle private key and a vehicle public key; an authentication center client module configured to generate a vehicle certificate based on the vehicle public key and distribute it to the mobile terminal via the authentication center, and receive the mobile terminal certificate based on the mobile terminal public key distributed via the authentication center, wherein the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal; and a verification module configured to present a graphical code of first signature information about the mobile terminal certificate, the graphical code being used for the mobile terminal to read and verify the first signature information through the mobile terminal public key; wherein the verification module is further configured to sign test data through the vehicle private key and encrypt the signed information through the mobile terminal certificate to generate test information, and send the test information to the mobile terminal, wherein the test information is decrypted by the mobile terminal through the mobile terminal private key, and the second signature information in the decrypted data is verified through the vehicle certificate; and the key management, encryption and decryption module is further configured to negotiate and generate a session key with the mobile terminal based on the vehicle private key, the vehicle public key, the mobile terminal public key and the mobile terminal private key.

[0014] In some embodiments of the present application, optionally, the graphical code is a QR code.

[0015] In some embodiments of the present application, optionally, the authentication center client module is configured to determine the ID of the vehicle certificate through the vehicle identification code of the vehicle, and obtain the vehicle certificate thereby, wherein the vehicle identification code is bound to the ID of the corresponding vehicle certificate and the ID of the mobile terminal certificate.

[0016] In some embodiments of the present application, optionally, the key management, encryption and decryption module is further configured to: encrypt the session content with the session key to generate encrypted session content; and send the encrypted session content to the mobile terminal.

[0017] According to another aspect of the present application, a vehicle communication terminal is provided. The terminal includes: a memory configured to store instructions; and a processor configured to execute the instructions to perform any one of the vehicle communication methods described above.

[0018] According to another aspect of the present application, a vehicle is provided. The vehicle includes any one of the vehicle communication terminals described above.

[0019] According to another aspect of the present application, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and characterized in that when the instructions are executed by a processor, the processor is caused to execute any one of the vehicle communication methods described above.

[0020] The vehicle communication method, terminal, vehicle, and computer-readable storage medium according to some embodiments of the present application can verify the reliability of the certificates exchanged between the vehicle side and the mobile side, and can perform encrypted communication based on the reliable certificates, so as to implement services such as real-time transmission of images between the vehicle side and the mobile side. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] From the following detailed description in conjunction with the accompanying drawings, the above and other objects and advantages of the present application will become more fully apparent, wherein the same or similar elements are denoted by the same reference numerals.

[0022] Figure 1 Shows a vehicle communication method according to an embodiment of the present application;

[0023] Figure 2 Shows a vehicle communication terminal according to an embodiment of the present application;

[0024] Figure 3 Shows a vehicle communication terminal according to an embodiment of the present application;

[0025] Figure 4 Shows a mobile terminal according to an embodiment of the present application;

[0026] Figure 5 Shows a vehicle communication system according to an embodiment of the present application and its working principle. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] For the sake of simplicity and illustrative purposes, the principles of the present application are mainly described herein with reference to its exemplary embodiments. However, those skilled in the art will readily recognize that the same principles can be equivalently applied to all types of vehicle communication methods, terminals, vehicles, and computer-readable storage media, and these same or similar principles can be implemented therein, and any such variations do not depart from the true spirit and scope of the present application.

[0028] According to one aspect of the present application, a vehicle communication method is provided. As Figure 1As shown, the vehicle communication method 10 (hereinafter referred to as method 10) includes the following steps: In step S102, the vehicle terminal generates a corresponding vehicle terminal private key and a vehicle terminal public key, and distributes the vehicle terminal certificate based on the vehicle terminal public key to the mobile terminal via the certification center; In step S104, the vehicle terminal receives the mobile terminal certificate distributed by the certification center; In step S106, the vehicle terminal presents a graphical code of the first signature information regarding the mobile terminal certificate; In step S108, the vehicle terminal signs the test data with the vehicle terminal private key and encrypts the signed information with the mobile terminal certificate to generate test information, and sends the test information to the mobile terminal; And in step S110, the vehicle terminal negotiates with the mobile terminal to generate a session key based on the vehicle terminal private key, the vehicle terminal public key, the mobile terminal public key, and the mobile terminal private key, for example, through the DH (Diffie Hellman) algorithm. Through the above steps of method 10, it is possible to verify the certificates of the peer received by the vehicle terminal and the mobile terminal, and avoid the certificates being tampered with midway. The verified certificates can be further used to generate a session key, thus ensuring the reliability of the communication between the vehicle terminal and the mobile terminal. The specific working principle of the above steps of method 10 will be described in detail below.

[0029] To clearly illustrate the working principle of method 10, the following will be described in conjunction with Figure 5 the vehicle communication system shown. As Figure 5 shown, the vehicle communication system includes a vehicle terminal, a mobile terminal, a certification center (PKI / CA, public key infrastructure / certificate authority), a telematics service provider (TSP, telematics service provider), etc. The following operations will be performed among the above entities, and the serial numbers of the following operations correspond to the serial numbers in the figure:

[0030] ① Certificate issuance. Figure 5 The shown solution can be an end-to-end encryption solution for real-time scenario vehicle networking privacy protection. Before establishing a real-time session, the two ends of the session (the vehicle terminal and the mobile terminal) need to generate end-side certificates. The preferred solution is for each end to generate a pair of public keys and private keys, specifically including a mobile terminal public key and a mobile terminal private key pair, and a vehicle terminal public key and a vehicle terminal private key pair. Then, the two ends respectively request the PKI / CA system to issue certificates for the opposite end side.

[0031] ② Certificate request (as shown in the figure, specifically obtaining the mobile terminal certificate and obtaining the vehicle terminal certificate respectively). Before establishing a real-time session, the session request end (the vehicle terminal or the mobile terminal) obtains the session receiving end (the mobile terminal or the vehicle terminal) certificate through the PKI / CA system. At the same time, the request end locally can manage the received certificate through the certificate management module.

[0032] ③ QR code scanning for verification. After the vehicle terminal and the mobile terminal have installed the certificates of each other, the mobile terminal needs to scan the QR code to verify the certificate installed on the vehicle terminal (the vehicle terminal can display the signature of the mobile terminal certificate installed locally, and the mobile terminal compares whether the signature information is the same by scanning the QR code). If the verification is successful, the vehicle terminal can generate random information, sign the random information with the vehicle terminal private key, and then encrypt the signed information with the mobile terminal certificate and send it to the mobile terminal. The mobile terminal can decrypt the data with the local mobile terminal private key and verify the signature information with the vehicle terminal certificate installed locally, thereby preventing a man-in-the-middle from tampering with the certificate.

[0033] Through the above process, it can be determined whether the vehicle terminal and the mobile terminal have correctly received the certificates of each other. The correct certificate is the basis for subsequent other communication steps. Some examples of end-to-end encryption (E2EE) communication using the verified certificates will be described below. At this time, the data transmitted between the sending end and the receiving end (including the intermediate receiving end) is E2EE encrypted data.

[0034] ④ Real-time session. In a real-time session scenario, the session request end (vehicle terminal or mobile terminal) and the receiving end can negotiate a session key through the DH algorithm. Specifically, the two ends can generate a session key based on the public and private key information of the two ends through the DH algorithm. The process of generating a session key using the DH algorithm based on the vehicle terminal private key, vehicle terminal public key, mobile terminal public key, and mobile terminal private key can refer to the prior art and will not be elaborated herein. The session key negotiated by the two ends can be used for symmetric encryption of real-time session content, etc.

[0035] It should be noted that Figure 5 and the above description is intended to provide the reader with a sufficient but unnecessary complete solution so that the reader can thoroughly understand the basic principle of this application. However, this solution is not intended to limit other embodiments.

[0036] Return Figure 1 , different from describing the communication system as a whole, Method 10 mainly views how to execute the communication method from the perspective of the vehicle terminal. In step S102 of Method 10, the vehicle terminal generates the corresponding vehicle terminal private key and vehicle terminal public key, and the vehicle terminal certificate based on the vehicle terminal public key distributed to the mobile terminal via the certification authority. The vehicle terminal private key and vehicle terminal public key generated in step S102 will make it possible to encrypt information using the certificate in subsequent processes. In addition, in step S104 of Method 10, the vehicle terminal receives the mobile terminal certificate distributed via the certification authority. Among them, the mobile terminal certificate is generated based on the mobile terminal public key, and the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal. After steps S102 and S104, the mobile terminal and the vehicle terminal achieve the exchange of certificates, and the certificates received by both ends can be used for subsequent encrypted communication.

[0037] In some embodiments of the present application, in step S102, the mobile device can determine the ID of the vehicle-end certificate through the vehicle identification code of the vehicle end, and obtain the vehicle-end certificate based on this. Among them, the vehicle identification code is bound to the ID of the corresponding vehicle-end certificate and the ID of the mobile device certificate. In addition, in step S104, the ID of the corresponding vehicle-end certificate and the ID of the mobile device certificate can be bound through the vehicle identification code of the vehicle end, and the vehicle end can determine the ID of the mobile device certificate through the vehicle identification code and obtain the mobile device certificate based on this.

[0038] In step S106 of method 10, the vehicle end presents a graphical code of the signature information of the mobile device certificate (also referred to as the first signature information for distinction). The graphical code can be read by the mobile device, and the mobile device can verify the first signature information included in the graphical code through the mobile device public key, so as to verify the reliability of the first signature information, and further determine whether the mobile device certificate received by the vehicle end is reliable. In some examples, the graphical code can be a two-dimensional code; in other examples, the graphical code can also be other graphical encodings that can be machine-read, such as barcodes.

[0039] In step S108 of method 10, the vehicle end signs the test data through the vehicle end private key and encrypts the signed information through the mobile device certificate to generate test information, and sends the test information to the mobile device. The test information can then be received by the mobile device, and the mobile device can decrypt the test information through the mobile device private key. Subsequently, the mobile device can verify the signature information (also referred to as the second signature information for distinction) in the decrypted data based on the vehicle end certificate.

[0040] In some embodiments of the present application, the real-time session can be initiated by the vehicle end. In step S110 of method 10, the vehicle end negotiates with the mobile device to generate a session key through the DH algorithm based on the vehicle end private key, the vehicle end public key, the mobile device public key, and the mobile device private key. Specifically, both ends can generate a session key based on the public and private key information of both ends through the DH algorithm. The process of generating a session key based on the vehicle end private key, the vehicle end public key, the mobile device public key, and the mobile device private key using the DH algorithm can refer to the prior art and will not be elaborated herein.

[0041] In some embodiments of the present application, the vehicle end can encrypt the session content using a session key. Specifically, method 10 further includes the following steps: encrypting the session content using the session key to generate encrypted session content; and sending the encrypted session content to the mobile end. In addition, the mobile end can receive the encrypted session content and decrypt it. Specifically, method 10 further includes the following steps: decrypting the encrypted session content by the mobile end using the session key to generate session content. In this way, symmetric encryption and asymmetric encryption can be used simultaneously to encrypt real-time session content, thereby ensuring communication security. Among them, since the session content itself is relatively large, the session key generated by the DH algorithm can be used to perform symmetric encryption on it, and symmetric encryption makes a balance between security and efficiency.

[0042] In some embodiments of the present application, method 10 is used to transmit real-time images from the vehicle end to the mobile end. Through method 10, the session content (real-time images) can be encrypted in a relatively efficient manner, and the security of the transmitted real-time images can be guaranteed.

[0043] In some embodiments of the present application, the real-time session can be initiated by the mobile end, and the relevant process can refer to the session initiated by the vehicle end above, which will not be elaborated herein.

[0044] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 2 shown, the vehicle communication terminal 20 (hereinafter referred to as terminal 20) includes a memory 202 and a processor 204. Among them, the processor 204 can read data from the memory 202 and write data into the memory 202. The memory 202 can store instructions, and the processor 204 can execute the instructions stored in the memory 202 to perform any one of the vehicle communication methods as described above.

[0045] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 3 shown, the vehicle communication terminal 30 (hereinafter referred to as terminal 30) includes a key management and encryption / decryption module, an authentication center client module, and a verification module.

[0046] The key management and encryption / decryption module of terminal 30 is used to generate the corresponding vehicle end private key and vehicle end public key. Specifically, the key management and encryption / decryption module can provide functions such as encryption, decryption, offline session key management, real-time session key management, certificate management, and private key management.

[0047] The authentication center client module of the terminal 30 can generate a vehicle-side certificate based on the vehicle-side public key and distribute it to the mobile terminal via the authentication center, and receive the mobile terminal certificate based on the mobile terminal public key distributed by the authentication center. Among them, the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal. Specifically, the authentication center client module can provide certificate issuance and certificate download functions: Certificate issuance can be used for generating vehicle-side certificates in real-time scenarios. The vehicle-side generates a public-private key pair locally and then requests the PKI / CA system to issue a certificate; Certificate download is used for the vehicle-side to request the mobile terminal certificate from the mobile terminal in real-time scenarios.

[0048] The verification module of the terminal 30 can present a graphical code of the first signature information of the mobile terminal certificate. The graphical code is used for the mobile terminal to read and verify the first signature information through the mobile terminal public key; The verification module is also configured to sign the test data with the vehicle-side private key and encrypt the signed information with the mobile terminal certificate to generate test information, and send the test information to the mobile terminal. Among them, the test information is decrypted by the mobile terminal through the mobile terminal private key, and the second signature information in the decrypted data is verified through the vehicle-side certificate. In some embodiments of the present application, the graphical code is a QR code; In some other examples, the graphical code can also be other machine-readable graphical codes, such as barcodes.

[0049] Specifically, the verification module can provide a QR code scanning and verification function: The vehicle-side displays the signature information of the certificate of the installed mobile terminal. The mobile terminal compares whether the signatures are consistent by scanning the QR code. If they are consistent, the vehicle-side sends the encrypted signature information (the vehicle-side signs the random information with the private key and encrypts the signature information with the locally installed mobile terminal certificate) to the mobile terminal, and the mobile terminal verifies the encrypted signature information.

[0050] In addition, the key management and encryption / decryption module is also configured to negotiate and generate a session key with the mobile terminal through the DH algorithm based on the vehicle-side private key, vehicle-side public key, mobile terminal public key, and mobile terminal private key. Specifically, the key management and encryption / decryption module can negotiate with the peer based on the public-private key information of both ends through the DH algorithm to generate a session key. The process of generating a session key based on the vehicle-side private key, vehicle-side public key, mobile terminal public key, and mobile terminal private key using the DH algorithm can be referred to the prior art and will not be elaborated here.

[0051] In some embodiments of the present application, the authentication center client module is configured to determine the ID of the vehicle-side certificate through the vehicle identification code of the vehicle-side, and obtain the vehicle-side certificate based on this. Among them, the vehicle identification code is bound to the ID of the corresponding vehicle-side certificate and the ID of the mobile terminal certificate.

[0052] In some embodiments of the present application, the key management and encryption / decryption module is further configured to: encrypt the session content using the session key to generate encrypted session content; and send the encrypted session content to the mobile terminal.

[0053] In some embodiments of the present application, the terminal further includes a session management module. The session management module can generate session information, which includes at least one of the following: timestamp, random number. Specifically, the session management module can provide offline session management and real-time session management. The session management module manages session information for offline sessions and real-time sessions, including information such as vehicle VIN, mobile terminal identity information, timestamp, and random number. These session information can be synchronized to both ends through a secure encryption channel. For real-time scenarios, the real-time session request end can encrypt the session key using the session receiving end certificate.

[0054] In addition, the terminal 30 may further include a hardware security module (not shown in the figure), which can be an abstraction layer of the vehicle-side underlying security hardware module HSM for providing key generation, management, and data encryption / decryption capabilities.

[0055] According to another aspect of the present application, a mobile terminal is provided. As Figure 4 shown, the mobile terminal 40 includes a key management and encryption / decryption module, an authentication center client module, and a verification module. During communication, the terminal 30 and the mobile terminal 40 are peer-to-peer ends, so each module in the mobile terminal 40 can have the same functions as the corresponding module in the terminal 30. For the sake of brevity, the functions and working principles of each module in the mobile terminal 40 will not be elaborated herein.

[0056] According to another aspect of the present application, a vehicle is provided. The vehicle includes any one of the vehicle communication terminals as described above. The layout of the vehicle in the present application is not limited (for example, wheeled vehicles, tracked vehicles, etc.), nor is the driving force of the vehicle limited (for example, motor drive, gasoline engine drive, etc.). The vehicles in the present application cover various vehicles currently known in the art and vehicles to be developed in the future.

[0057] According to another aspect of the present application, a computer-readable storage medium is provided, in which instructions are stored. When the instructions are executed by a processor, the processor is caused to execute any one of the vehicle communication methods as described above. The computer-readable medium referred to in the present application includes various types of computer storage media and can be any available medium accessible by a general or special computer. For example, the computer-readable medium can include RAM, ROM, EPROM, E 2A PROM, register, hard disk, removable disk, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage device, or any other transient or non-transitory medium that can be used to carry or store desired program code units in the form of instructions or data structures and can be accessed by a general or special purpose computer, or a general or special purpose processor. As used herein, a disk typically magnetically replicates data, while a disc optically replicates data with a laser. Combinations of the above should also be included within the scope of protection of computer-readable media. An exemplary storage medium is coupled to the processor such that the processor can read from and write to the storage medium. In an alternative, the storage medium may be integrated into the processor. The processor and the storage medium may reside in an application specific integrated circuit (ASIC). The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside in the user terminal as discrete components.

[0058] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Those skilled in the art can think of other feasible changes or substitutions based on the technical scope disclosed in the present application, and such changes or substitutions are all covered by the scope of protection of the present application. Without conflict, the embodiments of the present application and the features in the embodiments can also be combined with each other. The scope of protection of the present application shall be subject to the claims.

Claims

1. A vehicle communication method, characterized in that, the method includes: generating, by the vehicle terminal, a corresponding vehicle terminal private key and a vehicle terminal public key, and distributing, via an authentication center, a vehicle terminal certificate based on the vehicle terminal public key to the mobile terminal; receiving, by the vehicle terminal, a mobile terminal certificate distributed via the authentication center, wherein the mobile terminal certificate is generated based on a mobile terminal public key, and the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal; presenting, by the vehicle terminal, a graphical code of first signature information about the mobile terminal certificate, the graphical code being used for the mobile terminal to read and verify the first signature information with the mobile terminal public key; signing, by the vehicle terminal, test data with the vehicle terminal private key and encrypting the signed information with the mobile terminal certificate to generate test information, and sending the test information to the mobile terminal, wherein the test information is decrypted by the mobile terminal with the mobile terminal private key, and the second signature information in the decrypted data is verified based on the vehicle terminal certificate; and negotiating, by the vehicle terminal, a session key with the mobile terminal based on the vehicle terminal private key, the vehicle terminal public key, the mobile terminal public key, and the mobile terminal private key.

2. The method according to claim 1, wherein, the graphical code is a QR code.

3. The method according to claim 1, wherein, the vehicle terminal certificate distributed to the mobile terminal based on the vehicle terminal public key includes: the mobile terminal determines the ID of the vehicle terminal certificate through the vehicle identification code of the vehicle terminal and obtains the vehicle terminal certificate thereby, wherein the vehicle identification code is bound to the ID of the corresponding vehicle terminal certificate and the ID of the mobile terminal certificate.

4. The method according to claim 3, wherein, receiving, by the vehicle terminal, a mobile terminal certificate distributed via the authentication center includes: the vehicle terminal determines the ID of the mobile terminal certificate through the vehicle identification code and obtains the mobile terminal certificate thereby.

5. The method according to claim 1, further includes: encrypting session content with the session key to generate encrypted session content; and sending the encrypted session content to the mobile terminal.

6. The method according to claim 5, further includes: decrypting, by the mobile terminal, the encrypted session content with the session key to generate the session content.

7. The method according to claim 1, wherein, the method is used to transmit a real-time video from the vehicle terminal to the mobile terminal.

8. The method according to claim 1, wherein, the vehicle terminal negotiates with the mobile terminal to generate the session key based on the vehicle terminal private key, the vehicle terminal public key, the mobile terminal public key, and the mobile terminal private key through the DH algorithm.

9. A vehicle communication terminal, characterized in that, the terminal includes: a key management and encryption / decryption module configured to generate a corresponding vehicle terminal private key and a vehicle terminal public key; The authentication center client module is configured to generate a vehicle-end certificate based on the vehicle-end public key and distribute it to the mobile end via the authentication center, and receive the mobile-end certificate based on the mobile-end public key distributed via the authentication center, wherein the mobile-end public key and its corresponding mobile-end private key are generated by the mobile end; and The verification module is configured to present a graphical code of the first signature information about the mobile-end certificate, and the graphical code is used for the mobile end to read and verify the first signature information through the mobile-end public key; wherein The verification module is further configured to sign the test data through the vehicle-end private key and encrypt the signed information through the mobile-end certificate to generate test information, and send the test information to the mobile end, wherein the test information is decrypted by the mobile end through the mobile-end private key, and the second signature information in the decrypted data is verified through the vehicle-end certificate; and The key management, encryption and decryption module is further configured to negotiate with the mobile end to generate a session key based on the vehicle-end private key, the vehicle-end public key, the mobile-end public key and the mobile-end private key.

10. The terminal according to claim 9, wherein The graphical code is a QR code.

11. The terminal according to claim 9, wherein The authentication center client module is configured to determine the ID of the vehicle-end certificate through the vehicle identification number of the vehicle end, and obtain the vehicle-end certificate thereby, wherein the vehicle identification number is bound to the ID of the corresponding vehicle-end certificate and the ID of the mobile-end certificate.

12. The terminal according to claim 9, wherein The key management, encryption and decryption module is further configured to: encrypt the session content with the session key to generate encrypted session content; and Send the encrypted session content to the mobile end.

13. A vehicle communication terminal, characterized in that The terminal includes: A memory configured to store instructions; and A processor configured to execute the instructions to cause the execution of the method according to any one of claims 1-8.

14. A computer-readable storage medium storing instructions therein, characterized in that When the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1-8.

15. A vehicle, characterized in that The vehicle includes the vehicle communication terminal according to any one of claims 9-13.

Citation Information

Patent Citations

  • Data processing method, vehicle-mounted equipment and electronic equipment

    CN108055236A

  • SE chip-based implementation method of electronic driving license, computer device and computer readable storage medium

    CN109495276A