Vehicle communication method, terminal, vehicle, and computer-readable storage medium

By using seed keys and session keys in vehicle communication, the problem of difficult security of intelligent connected vehicles is solved, and the security and reliability of data transmission are achieved.

CN115334102BActive Publication Date: 2025-06-17NIO TECH ANHUI CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210864541.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-22
Publication Date
2025-06-17
Estimated Expiration
2042-07-22

AI Technical Summary

Technical Problem

In the field of intelligent connected vehicles, the data security generated by vehicles is difficult to ensure, especially in the data transmission process related to user privacy, there is a risk of leakage, affecting the user's privacy, property and life safety.

Method used

The seed key is generated by the vehicle end and the graphical code is presented. The mobile end decrypts the seed key through the password password. Both ends generate session keys through the key generation algorithm to encrypt and transmit the session content to ensure the security of the data during the transmission process.

Benefits of technology

It realizes data security during vehicle communication, ensures that even if it is intercepted in the middle, information will not be leaked, and ensures user privacy and data transmission reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115334102B_ABST
    Figure CN115334102B_ABST
Patent Text Reader

Abstract

The present application relates to a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium. The method includes the following steps performed by the vehicle side: generating a seed key and presenting a graphical code regarding the seed key, wherein the information carried in the graphical code is encrypted by a password, and the graphical code is used for being read by a mobile terminal communicating with the vehicle side; generating a session key through a key generation algorithm according to the seed key and session information formed by the vehicle side according to a preset rule; encrypting session content by using the session key to generate encrypted session content; and sending the encrypted session content and the session information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle privacy protection, and more particularly, to a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium. Background Art

[0002] With the development of intelligent connected vehicles, communication security has increasingly attracted the attention of users. In the intelligent electric vehicle industry, an extremely important area of security is data security, which underlies user privacy, property, and even life safety. As vehicles become more intelligent and connected, the amount of data generated by intelligent vehicles is increasing, and a lot of this data is related to user privacy. If this data is leaked, it will have a significant impact on user privacy, property, and even life safety. With the introduction of the Data Security Law and the Personal Information Protection Law, user privacy protection has become a compliance requirement. In scenarios such as the guard mode and vehicle calendar synchronization, the vehicle networking privacy protection solution with end-to-end encryption in the offline scenario based on the authentication center system can not only protect user privacy but also meet compliance requirements.

[0003] In view of this, there is a need to propose an improved vehicle communication solution. Summary of the Invention

[0004] Embodiments of the present application provide a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium for improving the security of vehicle communication.

[0005] According to one aspect of the present application, a vehicle communication method is provided. The method includes the following steps performed by the vehicle end: generating a seed key and presenting a graphical code regarding the seed key, where the information carried in the graphical code is encrypted by a password and is for the mobile terminal communicating with the vehicle end to read; generating a session key through a key generation algorithm according to the seed key and session information formed by the vehicle end according to a preset rule; encrypting session content using the session key to generate encrypted session content; and sending the encrypted session content and the session information.

[0006] In some embodiments of the present application, optionally, the graphical code is a QR code.

[0007] In some embodiments of the present application, optionally, the information carried in the graphical code further includes the vehicle identification code of the vehicle end.

[0008] In some embodiments of the present application, optionally, the session information includes at least one of the following: a timestamp, a random number.

[0009] In some embodiments of the present application, optionally, the session content includes at least one of the following: a video pushed to the mobile terminal, calendar synchronization data.

[0010] In some embodiments of the present application, optionally, the method further includes: receiving second encrypted session content and second session information from the mobile terminal, where the second session information is formed by the mobile terminal according to a preset rule; generating a second session key through a key generation algorithm based on the seed key and the second session information; and decrypting the second encrypted session content with the second session key to obtain second session content.

[0011] According to another aspect of the present application, a vehicle communication method is provided. The method includes the following steps performed by a mobile terminal: reading a graphical code presented by a vehicle terminal communicating with the mobile terminal; decrypting the information carried in the graphical code with a password to obtain a seed key; receiving encrypted session content and session information from the vehicle terminal, where the session information is formed by the vehicle terminal according to a preset rule; generating a session key through a key generation algorithm based on the seed key and the session information; and decrypting the encrypted session content with the session key to obtain session content.

[0012] In some embodiments of the present application, optionally, the method further includes: generating a second session key through a key generation algorithm based on the seed key and second session information formed according to a preset rule; encrypting second session content with the second session key to generate second encrypted session content; and sending the second encrypted session content and the second session information.

[0013] According to another aspect of the present application, a vehicle communication terminal is provided. The terminal includes: a key management, encryption and decryption module configured to generate a seed key; a verification module configured to present a graphical code regarding the seed key, where the information carried in the graphical code is encrypted with a password for the mobile terminal communicating with the vehicle terminal to read; and a session management module configured to form session information according to a preset rule; where the key management, encryption and decryption module is further configured to generate a session key through a key generation algorithm based on the seed key and the session information, and encrypt session content with the session key to generate encrypted session content, and send the encrypted session content and the session information.

[0014] In some embodiments of the present application, optionally, the graphical code is a two-dimensional code.

[0015] In some embodiments of the present application, optionally, the information carried in the graphical code further includes the vehicle identification code of the vehicle terminal.

[0016] In some embodiments of the present application, optionally, the session information includes at least one of the following: a timestamp, a random number.

[0017] In some embodiments of the present application, optionally, the session content includes at least one of the following: a video pushed to the mobile terminal, and calendar synchronization data.

[0018] In some embodiments of the present application, optionally, the key management, encryption and decryption module is further configured to: receive a second encrypted session content and second session information from the mobile terminal, where the second session information is formed by the mobile terminal according to a preset rule; generate a second session key through a key generation algorithm according to the seed key and the second session information; and decrypt the second encrypted session content through the second session key to obtain a second session content.

[0019] According to another aspect of the present application, there is provided a mobile terminal for vehicle communication. The mobile terminal includes: an authentication module configured to read a graphical code presented by a vehicle terminal communicating with the mobile terminal; a key management, encryption and decryption module configured to decrypt the information carried in the graphical code through a password to obtain a seed key; and a session management module configured to receive an encrypted session content and session information from the vehicle terminal; where the key management, encryption and decryption module is further configured to generate a session key through a key generation algorithm according to the seed key and the session information, and decrypt the encrypted session content through the session key to obtain a session content.

[0020] In some embodiments of the present application, optionally, the key management, encryption and decryption module is further configured to: generate a second session key through a key generation algorithm according to the seed key and second session information formed according to a preset rule; encrypt a second session content through the second session key to generate a second encrypted session content; and send the second encrypted session content and the second session information.

[0021] According to another aspect of the present application, there is provided a vehicle communication terminal. The terminal includes: a memory configured to store instructions; and a processor configured to execute the instructions such that any one of the vehicle communication methods described above is performed.

[0022] According to another aspect of the present application, there is provided a vehicle. The vehicle includes any one of the vehicle communication terminals described above.

[0023] According to another aspect of the present application, there is provided a computer-readable storage medium storing instructions, characterized in that when the instructions are executed by a processor, the processor is caused to execute any one of the vehicle communication methods described above.

[0024] A vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium according to some embodiments of the present application can establish a reliable communication link between the vehicle end and the mobile end, thereby ensuring the security of the signals transmitted between the two. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] From the following detailed description in conjunction with the accompanying drawings, the above and other objects and advantages of the present application will become more fully apparent, wherein the same or similar elements are denoted by the same reference numerals.

[0026] Figure 1 Shows a vehicle communication method according to an embodiment of the present application;

[0027] Figure 2 Shows a vehicle communication method according to an embodiment of the present application;

[0028] Figure 3 Shows a vehicle communication terminal according to an embodiment of the present application;

[0029] Figure 4 Shows a vehicle communication terminal according to an embodiment of the present application;

[0030] Figure 5 Shows a mobile end according to an embodiment of the present application;

[0031] Figure 6 Shows a vehicle communication system according to an embodiment of the present application and its working principle. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0032] For the sake of brevity and illustrative purposes, the principles of the present application are mainly described herein with reference to its exemplary embodiments. However, those skilled in the art will readily recognize that the same principles can be equivalently applied to all types of vehicle communication methods, terminals, vehicles, and computer-readable storage media, and these same or similar principles can be implemented therein, and any such variations do not depart from the true spirit and scope of the present application.

[0033] According to one aspect of the present application, a vehicle communication method is provided. As Figure 1As shown, the vehicle communication method 10 (hereinafter referred to as method 10) includes the following steps performed by the vehicle terminal: generating a seed key in step S102 and presenting a graphical code regarding the seed key; generating a session key through a key generation algorithm according to the seed key and session information formed according to a preset rule in step S104; encrypting the session content with the session key to generate encrypted session content in step S106; and sending the encrypted session content and session information in step S108. Through the above steps of method 10, the seed key can be synchronized between the vehicle terminal and the mobile terminal, and the seed key decrypted with a password can ensure that information will not be leaked even if it is intercepted midway. The seed key synchronized between the two ends can be used for subsequent encrypted communication, thus ensuring the reliability of the data exchanged between the vehicle terminal and the mobile terminal. The specific working principle of the above steps of method 10 will be described in detail below.

[0034] To clearly illustrate the working principle of method 10, the following will be described in conjunction with Figure 6 the vehicle communication system shown. As Figure 6 shown, the vehicle communication system includes a vehicle terminal, a mobile terminal, a telematics service provider (TSP), etc. Some examples of end-to-end encryption (E2EE) communication using the session key will be described below. At this time, the data transmitted between the sending end and the receiving end (including intermediate receiving ends) is E2EE encrypted data. The following operations will be performed among the above entities, and the numbers of the following operations correspond to the numbers in the figure:

[0035] ① QR code scanning. Figure 6 The scheme shown can be an end-to-end encryption scheme for privacy protection in an offline scenario of the Internet of Vehicles. Before establishing an offline session, the seed key needs to be synchronized by scanning a QR code. This seed key is the basis for the rotation of the subsequent end-to-end encryption session key. In addition to the seed key information, the QR code can also contain information related to the identity of the vehicle terminal (for example, the vehicle identification code of the vehicle terminal), etc. These information can be protected by a password. After the mobile terminal scans the code, it needs to input the password to decode and obtain the seed key and the information related to the identity of the vehicle terminal.

[0036] ② Offline data upload (to the server). In an offline session scenario, the session request end (vehicle terminal or mobile terminal) will encrypt the session content with the session key to obtain encrypted session content, and then package and send the encrypted session content and session information to the cloud TSP.

[0037] ③ (From the server) Offline data download. In an offline session scenario, the session receiving end (mobile device or vehicle end) downloads the offline packaged data from the cloud, including: encrypted session content and session information. Then, a session key for the offline session can be generated through a key generation algorithm and based on the session information (received together with the encrypted session content) and the seed key (locally saved). Finally, the encrypted session content is decrypted using the session key to generate the session content.

[0038] What is described in the above process is sending data from the vehicle end to the mobile device. Sending data from the mobile device to the vehicle end can be performed in a similar manner. It should be noted that Figure 6 and the above description is intended to provide the reader with a sufficient but unnecessary complete solution to enable the reader to thoroughly understand the basic principle of this application. However, this solution is not intended to limit other embodiments.

[0039] Return Figure 1 , different from describing the communication system as a whole, Method 10 mainly views how to execute the communication method from the perspective of the vehicle end. Method 10 generates a seed key in step S102 and presents a graphical code regarding the seed key. Among them, the information carried in the graphical code can be encrypted by a password, and can be used for the mobile device that needs to communicate with the vehicle end to read. The seed key generated in step S102 will enable information to be encrypted by means such as symmetric encryption in subsequent processes. Subsequently, the receiving end (mobile device) of the seed key can extract the seed key from the information carried in the graphical code through the password. In some examples, the graphical code can be a QR code; in some other examples, the graphical code can also be other graphical codes that can be machine-readable, such as barcodes. In some embodiments of this application, the information carried in the graphical code also includes information such as the vehicle identification code of the vehicle end.

[0040] Method 10 generates a session key through a key generation algorithm based on the seed key and session information formed according to a preset rule in step S104. In some embodiments of this application, the session information includes at least one of the following: timestamp, random number. As for generating a session key for symmetric encryption based on the random session information and the seed key, it can be carried out according to the prior art and will not be elaborated herein. The preset rule here can be, for example, capturing the current time to form timestamp data, etc.

[0041] Method 10 encrypts the session content using the session key to generate the encrypted session content in step S106. The session content encrypted using the session key will have higher security, and even if it is intercepted midway, it will not cause information leakage. In addition, since the session information is continuously updated, the session key generated accordingly is also continuously updated, which also increases the difficulty for attackers to brute-force the information.

[0042] Method 10 sends encrypted session content and session information to the mobile device in step S108 (via a relay server).

[0043] In this way, Method 10 can encrypt the offline session content using symmetric encryption, thus ensuring the security of communication. Since the session content itself is relatively large, a symmetric encryption method with real-time key changes can be used to encrypt it, achieving a balance between security and efficiency.

[0044] In some embodiments of the present application, as described above, Method 10 can be used for the transmission of offline data. For example, the session content can be videos pushed from the vehicle side to the mobile device, calendar synchronization data between the vehicle side and the mobile device, etc.

[0045] The above steps mainly describe the working scenario when the vehicle side is the session initiator. Similarly, the vehicle side can also be the receiver. Specifically, Method 10 may further include the following steps (not shown in the figure): receiving encrypted session content (referred to as the second encrypted session content for distinction) and session information (referred to as the second session information for distinction) from the mobile device, where the second session information is formed by the mobile device according to a preset rule; generating a session key (referred to as the second session key for distinction) through a key generation algorithm based on the seed key (already saved) and the second session information (received together with the second encrypted session content); and decrypting the second encrypted session content with the second session key to obtain the second session content.

[0046] According to another aspect of the present application, a vehicle communication method is provided. As Figure 2 shown, the vehicle communication method 20 (hereinafter referred to as Method 20) includes the following steps performed by the mobile device: reading a graphical code presented by the vehicle side communicating with the mobile device in step S202; decrypting the information carried in the graphical code with a password in step S204 to obtain a seed key; receiving encrypted session content and session information from the vehicle side in step S206, where the session information is formed by the vehicle side according to a preset rule; generating a session key through a key generation algorithm based on the seed key and the session information in step S208; and decrypting the encrypted session content with the session key to obtain the session content in step S210.

[0047] The above steps mainly describe the working scenario when the mobile device is the session receiving end. Similarly, the mobile device can also be the initiating end. Specifically, method 20 may further include the following steps (not shown in the figure): generating a session key (referred to as the second session key for distinction) through a key generation algorithm according to the seed key and session information formed according to a preset rule (referred to as the second session information for distinction); encrypting the session content (referred to as the second session content for distinction) using the second session key to generate encrypted session content (referred to as the second encrypted session content for distinction); and sending the second encrypted session content and the second session information.

[0048] It should be noted that the vehicle end and the mobile device are in an unequal position only when scanning the code (the vehicle end needs to present the QR code while the mobile device scans the QR code), and in other cases, the two are equal and the working processes can refer to each other.

[0049] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 3 shown, the vehicle communication terminal 30 (hereinafter referred to as terminal 30) includes a memory 302 and a processor 304. Among them, the processor 304 can read data from the memory 302 and write data into the memory 302. The memory 302 can store instructions, and the processor 304 can execute the instructions stored in the memory 302 to perform any one of the vehicle communication methods as described above.

[0050] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 4 shown, the vehicle communication terminal 40 (hereinafter referred to as terminal 40) includes a key management and encryption / decryption module, a verification module, and a session management module.

[0051] The key management and encryption / decryption module of terminal 40 can be used to generate a seed key. The verification module of terminal 40 can be used to present a graphical code about the seed key. The information carried in the graphical code is encrypted by a password for the mobile device communicating with the vehicle end to read. In some examples, the graphical code can be a QR code; in other examples, the graphical code can also be other machine-readable graphical codes, such as barcodes. In addition, the information carried in the graphical code also includes the vehicle identification code of the vehicle end. Specifically, the verification module integrates the two functions of generating and displaying the QR code. The QR code contains information such as the seed key (the seed key is derived from the master key) and the vehicle end identity information. These information are encoded and then encrypted by the password. Random information can be added during the QR code encoding to ensure that each generated QR code is different and prevent the QR code information from being reverse-analyzed.

[0052] The session management module of the terminal 40 can form session information according to preset rules. In some embodiments of the present application, the session information includes at least one of the following: timestamp, random number. Specifically, the session management module can be used for offline session management and real-time session management. The session management module manages session-related information for offline sessions and real-time sessions, including vehicle-side identity information, mobile-side identity information, timestamp, random number, and other information of the vehicle side. The information of these sessions will be synchronized to both ends through a secure encryption channel. Both ends can use a key generation algorithm and generate an offline session key based on the session information and the seed key for subsequent end-to-end data encryption transmission.

[0053] In addition, the key management, encryption and decryption module of the terminal 40 is further configured to generate a session key through a key generation algorithm according to the seed key and the session information, encrypt the session content using the session key to generate encrypted session content, and send the encrypted session content and the session information.

[0054] Specifically, the key management, encryption and decryption module is also used for key management such as master key, seed key, session key, etc. involved in end-to-end encryption, as well as functions such as encryption and decryption, key derivation. The master key is generated by the offline session initiating end, the seed key is derived from the master key and synchronized to the offline session receiving end by scanning the code. The session key is used for end-to-end data encryption transmission in offline and real-time session scenarios. The encryption and decryption function provides encryption and decryption interfaces, and the key derivation algorithm is used for session key generation. The key generation algorithm can use the seed key and perform key derivation based on the application type and time factor, and generate a one-time session key through methods such as rotation permutation. This algorithm derives a one-time symmetric key, a one-time initialization vector, and a key digest based on the event time. The one-time symmetric key and the one-time initialization vector are used to encrypt the data, and the key digest is used to verify the key.

[0055] On the other hand, the terminal 40 can also be used as the receiving end of the session. At this time, the key management, encryption and decryption module is further configured to: receive the second encrypted session content and the second session information from the mobile terminal, where the second session information is formed by the mobile terminal according to preset rules; generate a second session key through a key generation algorithm according to the seed key and the second session information; and decrypt the second encrypted session content through the second session key to obtain the second session content.

[0056] In some embodiments of the present application, the session content includes at least one of the following: video pushed to the mobile terminal, calendar synchronization data.

[0057] In addition, the terminal 40 may further include a hardware security module (not shown in the figure), which can be an abstraction layer of the vehicle-side underlying security hardware module HSM, and is used to provide key generation, management, and data encryption and decryption capabilities.

[0058] According to another aspect of the present application, a mobile terminal for vehicle communication is provided. As Figure 5 shown, the mobile terminal 50 includes a key management, encryption and decryption module, an authentication module, and a session management module. Among them, the key management, encryption and decryption module and the session management module of the mobile terminal 50 can have the same functions as the corresponding modules of the terminal 40. Specifically:

[0059] The authentication module of the mobile terminal 50 can read the graphical code presented by the vehicle terminal communicating with the mobile terminal. The authentication module of the mobile terminal 50 integrates the function of scanning two-dimensional codes. The mobile terminal scans the two-dimensional code information of the vehicle terminal, and can obtain information such as the seed key, vehicle terminal identity information, timestamp, and signature of the vehicle terminal after decrypting through an encrypted password.

[0060] The key management, encryption and decryption module of the mobile terminal 50 can decrypt the information carried in the graphical code through a password to obtain the seed key. The session management module of the mobile terminal 50 can receive the encrypted session content and session information from the vehicle terminal. Among them, the key management, encryption and decryption module is further configured to generate a session key through a key generation algorithm according to the seed key and session information, and decrypt the encrypted session content through the session key to obtain the session content.

[0061] On the other hand, the mobile terminal 50 can also be the initiator of the session. At this time, the key management, encryption and decryption module is further configured to: generate a second session key through a key generation algorithm according to the seed key and second session information formed according to a preset rule; encrypt the second session content with the second session key to generate a second encrypted session content; and send the second encrypted session content and the second session information.

[0062] Similarly, the mobile terminal 50 may further include a hardware security module (not shown in the figure), and this module can be an abstraction layer of the vehicle terminal underlying security hardware module HSM, and is used to provide key generation, management, and data encryption and decryption capabilities.

[0063] According to another aspect of the present application, a vehicle is provided. The vehicle includes any one of the vehicle communication terminals as described above. In the present application, the layout of the vehicle (for example, wheeled vehicle, tracked vehicle, etc.) is not limited, nor is the driving force of the vehicle (for example, motor drive, gasoline engine drive, etc.). The vehicles of the present application cover various vehicles currently known in the art and vehicles to be developed in the future.

[0064] According to another aspect of the present application, there is provided a computer-readable storage medium storing instructions which, when executed by a processor, cause the processor to execute any one of the vehicle communication methods described above. The computer-readable medium referred to in the present application includes various types of computer storage media and can be any available medium accessible by a general or special-purpose computer. For example, the computer-readable medium may include RAM, ROM, EPROM, E 2 PROM, registers, hard disks, removable disks, CD-ROMs or other optical disk memories, magnetic disk memories or other magnetic storage devices, or any other transient or non-transient medium capable of carrying or storing desired program code units in the form of instructions or data structures and accessible by a general or special-purpose computer or a general or special-purpose processor. As used herein, disks typically magnetically reproduce data, while discs optically reproduce data with a laser. The above combinations should also be included within the scope of protection of the computer-readable medium. An exemplary storage medium is coupled to the processor such that the processor can read from / write to the storage medium. In an alternative, the storage medium may be integrated into the processor. The processor and the storage medium may reside in an application specific integrated circuit (ASIC). The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside in the user terminal as discrete components.

[0065] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Those skilled in the art can think of other feasible changes or substitutions according to the technical scope disclosed in the present application, and such changes or substitutions are all covered by the scope of protection of the present application. Without conflict, the embodiments of the present application and the features in the embodiments can also be combined with each other. The scope of protection of the present application shall be subject to the claims.

Claims

1. A vehicle communication method, characterized in that, The method includes the following steps executed by the vehicle end: Generating a master key, deriving a seed key from the master key, and presenting a graphical code regarding the seed key, wherein the information carried in the graphical code is encrypted by a password, and the graphical code is for being read by a mobile terminal communicating with the vehicle end; Generating a session key through a key generation algorithm according to the seed key and session information dynamically formed according to a preset rule, wherein the session information includes vehicle end identity information, mobile terminal identity information, a time stamp, and a random number; Encrypting session content by using the session key to generate encrypted session content; and Uploading the encrypted session content and the session information to a server for the mobile terminal to download.

2. The method according to claim 1, wherein, The graphical code is a two-dimensional code.

3. The method according to claim 1, wherein, The information carried in the graphical code further includes the vehicle identification code of the vehicle end.

4. The method according to claim 1, wherein, The session content includes at least one of the following: video pushed to the mobile terminal, calendar synchronization data.

5. The method according to claim 1, further comprising: Receiving second encrypted session content and second session information from the mobile terminal, wherein the second session information is formed by the mobile terminal according to a preset rule; Generating a second session key through a key generation algorithm according to the seed key and the second session information; and Decrypting the second encrypted session content by using the second session key to obtain second session content.

6. A vehicle communication method, characterized in that, The method includes the following steps executed by the mobile terminal: Reading a graphical code regarding a seed key presented by a vehicle end communicating with the mobile terminal, wherein the seed key is derived from a master key generated by the vehicle end; Decrypting the information carried in the graphical code by a password to obtain the seed key; Downloading encrypted session content and session information uploaded by the vehicle end to the server from the server, wherein the session information is dynamically formed by the vehicle end according to a preset rule, and the session information includes vehicle end identity information, mobile terminal identity information, a time stamp, and a random number; Generating a session key through a key generation algorithm according to the seed key and the session information; and Decrypting the encrypted session content by using the session key to obtain session content.

7. The method according to claim 6, further comprising: Generating a second session key through a key generation algorithm according to the seed key and second session information formed according to a preset rule; Encrypting second session content by using the second session key to generate second encrypted session content; And Sending the second encrypted session content and the second session information.

8. A vehicle communication terminal, characterized in that, The terminal includes: A key management and encryption / decryption module configured to derive a seed key from a master key generated by the vehicle end; A verification module configured to present a graphical code regarding the seed key, wherein the information carried in the graphical code is encrypted by a password for being read by a mobile terminal communicating with the vehicle end; and A session management module configured to dynamically form session information according to a preset rule, wherein the session information includes vehicle end identity information, mobile terminal identity information, a time stamp, and a random number; wherein, The key management, encryption and decryption module is further configured to generate a session key through a key generation algorithm according to the seed key and the session information, encrypt session content by using the session key to generate encrypted session content, and upload the encrypted session content and the session information to a server for downloading by the mobile terminal.

9. The terminal according to claim 8, wherein, The graphical code is a QR code.

10. The terminal according to claim 8, wherein, The information carried in the graphical code further includes the vehicle identification code of the vehicle terminal.

11. The terminal according to claim 8, wherein, The session content includes at least one of the following: video pushed to the mobile terminal, calendar synchronization data.

12. The terminal according to claim 8, wherein, The key management, encryption and decryption module is further configured to: Receive second encrypted session content and second session information from the mobile terminal, where the second session information is formed by the mobile terminal according to a preset rule; Generate a second session key through a key generation algorithm according to the seed key and the second session information; and Decrypt the second encrypted session content by using the second session key to obtain second session content.

13. A mobile terminal for vehicle communication, characterized in that, The mobile terminal includes: A verification module configured to read a graphical code about a seed key presented by a vehicle terminal communicating with the mobile terminal, where the seed key is derived from a master key generated by the vehicle terminal; A key management, encryption and decryption module configured to decrypt the information carried in the graphical code by using a password to obtain the seed key; A session management module configured to download encrypted session content and session information uploaded by the vehicle terminal to the server from the server, where the session information is dynamically formed by the vehicle terminal according to a preset rule, and the session information includes vehicle terminal identity information, mobile terminal identity information, a timestamp, and a random number; where The key management, encryption and decryption module is further configured to generate a session key through a key generation algorithm according to the seed key and the session information, and decrypt the encrypted session content by using the session key to obtain session content.

14. The mobile terminal according to claim 13, wherein, The key management, encryption and decryption module is further configured to: Generate a second session key through a key generation algorithm according to the seed key and second session information formed according to a preset rule; Encrypt second session content by using the second session key to generate second encrypted session content; And Send the second encrypted session content and the second session information.

15. A vehicle communication terminal, characterized in that, The terminal includes: A memory configured to store instructions; and A processor configured to execute the instructions to cause the execution of the method according to any one of claims 1-5.

16. A computer-readable storage medium storing instructions, characterized in that, When the instructions are executed by the processor, the processor is caused to execute the method according to any one of claims 1-7.

17. A vehicle, characterized in that, The vehicle includes a vehicle communication terminal according to any one of claims 8-12, 15.

Citation Information

Patent Citations

  • Password management method and system

    CN104836660A

  • Vehicle and mobile terminal binding method and system

    CN113099457A