Vehicle Communication Method, Terminal, Vehicle, and Computer-Readable Storage Medium
By using encrypted communication methods between the vehicle end and the mobile end in intelligent connected vehicles, the challenges of vehicle data security and user privacy protection are solved, and high-security vehicle communication is achieved.
Patent Information
- Application Number
- CN202210870053.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-07-22
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2042-07-22
AI Technical Summary
In intelligent connected cars, there are challenges in data security and user privacy protection generated by vehicles, especially in scenarios such as guard mode and vehicle-end calendar synchronization, it is difficult for the existing technology to effectively protect user privacy and meet compliance requirements.
The private key and public key are generated through the vehicle end, and the certification center distributes the vehicle end certificate. The vehicle end receives the mobile certificate and verifies the signature information through graphical code to realize encrypted communication between the vehicle end and the mobile end.
This method improves the security of vehicle communication, ensures the reliability of certificates between the vehicle and the mobile terminal, prevents intermediaries from tampering, realizes end-to-end encrypted communication, and protects user privacy.
Smart Images

Figure CN115334104B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of vehicle privacy protection. Specifically, it relates to a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium. Background Art
[0002] With the development of intelligent connected vehicles, communication security has increasingly attracted the attention of users. In the intelligent electric vehicle industry, an extremely important area of security is data security, which underlies user privacy, property, and even life safety. As vehicles become more intelligent and connected, the amount of data generated by intelligent vehicles is increasing, and much of this data is related to user privacy. If this data is leaked, it will have a significant impact on user privacy, property, and even life safety. In scenarios such as the guard mode and vehicle calendar synchronization, the end-to-end encrypted vehicle networking privacy protection solution based on the authentication center system in the offline scenario can not only protect user privacy but also meet compliance requirements.
[0003] In view of this, there is a need to propose an improved communication method. Summary of the Invention
[0004] Embodiments of this application provide a vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium for improving the security of vehicle communication.
[0005] According to one aspect of this application, a vehicle communication method is provided. The method includes: generating, by the vehicle end, a corresponding vehicle-end private key and a vehicle-end public key, and distributing, via an authentication center, a vehicle-end certificate based on the vehicle-end public key to the mobile end; receiving, by the vehicle end, a mobile-end certificate distributed by the authentication center, where the mobile-end certificate is generated based on a mobile-end public key, and the mobile-end public key and its corresponding mobile-end private key are generated by the mobile end; presenting, by the vehicle end, a graphical code of first signature information about the mobile-end certificate, where the graphical code is for the mobile end to read and verify the first signature information through the mobile-end public key; and signing, by the vehicle end, test data with the vehicle-end private key and encrypting the signed information with the mobile-end certificate to generate test information, and sending the test information to the mobile end, where the test information is decrypted by the mobile end with the mobile-end private key and the second signature information in the decrypted data is verified based on the vehicle-end certificate.
[0006] In some embodiments of this application, optionally, the graphical code is a QR code.
[0007] In some embodiments of the present application, optionally, the vehicle terminal receiving the mobile terminal certificate distributed by the authentication center includes: binding the ID of the vehicle terminal certificate and the ID of the mobile terminal certificate corresponding to the vehicle identification code of the vehicle terminal; and the vehicle terminal determining the ID of the mobile terminal certificate through the vehicle identification code and obtaining the mobile terminal certificate thereby.
[0008] In some embodiments of the present application, optionally, the method further includes: generating, by the vehicle terminal, a seed key and session information, and encrypting them with the mobile terminal certificate to generate an encrypted seed key and encrypted session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; encrypting session content with the session key to generate encrypted session content; and sending the encrypted seed key, the encrypted session information, and the encrypted session content to the mobile terminal.
[0009] In some embodiments of the present application, optionally, the method further includes: the mobile terminal decrypting the encrypted seed key and the encrypted session information according to the mobile terminal private key to generate a seed key and session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; and decrypting the encrypted session content with the session key to generate the session content.
[0010] In some embodiments of the present application, optionally, the method further includes: receiving the encrypted seed key, the encrypted session information, and the encrypted session content from the mobile terminal; decrypting the encrypted seed key and the encrypted session information according to the vehicle terminal private key to generate a seed key and session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; and decrypting the encrypted session content with the session key to generate the session content.
[0011] In some embodiments of the present application, optionally, the encrypted seed key and the encrypted session information are generated by the mobile terminal encrypting the seed key and the session information with the vehicle terminal certificate; and the mobile terminal performs encryption derivation with the seed key and the session information to generate a session key, and encrypts the session content with the session key to generate the encrypted session content.
[0012] In some embodiments of the present application, optionally, the session information includes at least one of the following: a timestamp, a random number.
[0013] According to another aspect of the present application, a vehicle communication terminal is provided. The terminal includes: a key management and encryption / decryption module configured to generate a corresponding vehicle private key and a vehicle public key; an authentication center client module configured to generate a vehicle certificate based on the vehicle public key and distribute it to the mobile terminal via the authentication center, and receive the mobile terminal certificate based on the mobile terminal public key distributed by the authentication center, wherein the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal; and a verification module configured to present a graphical code of first signature information about the mobile terminal certificate, the graphical code being used for the mobile terminal to read and verify the first signature information through the mobile terminal public key; the verification module is further configured to sign test data through the vehicle private key and encrypt the signed information through the mobile terminal certificate to generate test information, and send the test information to the mobile terminal, wherein the test information is decrypted by the mobile terminal through the mobile terminal private key, and the second signature information in the decrypted data is verified through the vehicle certificate.
[0014] In some embodiments of the present application, optionally, the terminal further includes: a session management module configured to generate session information, the session information including at least one of the following: a timestamp, a random number.
[0015] In some embodiments of the present application, optionally, the key management and encryption / decryption module is further configured to: generate a seed key, and encrypt the seed key and the session information respectively through the mobile terminal certificate to generate an encrypted seed key and encrypted session information; perform encryption derivation through the seed key and the session information to generate a session key; encrypt session content through the session key to generate encrypted session content; and send the encrypted seed key, the encrypted session information, and the encrypted session content to the mobile terminal.
[0016] According to another aspect of the present application, a vehicle communication terminal is provided. The terminal includes: a memory configured to store instructions; and a processor configured to execute the instructions to perform any one of the vehicle communication methods described above.
[0017] According to another aspect of the present application, a vehicle is provided. The vehicle includes any one of the vehicle communication terminals described above.
[0018] According to another aspect of the present application, a computer-readable storage medium is provided, wherein instructions are stored in the computer-readable storage medium, and when the instructions are executed by a processor, the processor is caused to perform any one of the vehicle communication methods described above.
[0019] A vehicle communication method, a terminal, a vehicle, and a computer-readable storage medium according to some embodiments of the present application can verify the reliability of a certificate for interaction between a vehicle end and a mobile end, and can implement encrypted communication based on the reliable certificate. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] From the following detailed description in conjunction with the accompanying drawings, the above and other objects and advantages of the present application will become more fully apparent, wherein like or similar elements are denoted by the same reference numerals.
[0021] Figure 1 FIG. shows a vehicle communication method according to an embodiment of the present application;
[0022] Figure 2 FIG. shows a vehicle communication terminal according to an embodiment of the present application;
[0023] Figure 3 FIG. shows a vehicle communication terminal according to an embodiment of the present application;
[0024] Figure 4 FIG. shows a mobile end according to an embodiment of the present application;
[0025] Figure 5 FIG. shows a vehicle communication system according to an embodiment of the present application and its working principle. DETAILED DESCRIPTION
[0026] For the sake of simplicity and illustrative purposes, the principles of the present application are mainly described herein with reference to its exemplary embodiments. However, those skilled in the art will readily recognize that the same principles can be equivalently applied to all types of vehicle communication methods, terminals, vehicles, and computer-readable storage media, and these same or similar principles can be implemented therein, and any such variations do not depart from the true spirit and scope of the present application.
[0027] According to one aspect of the present application, a vehicle communication method is provided. As Figure 1As shown, the vehicle communication method 10 (hereinafter referred to as method 10) includes the following steps: In step S102, the vehicle terminal generates a corresponding vehicle terminal private key and a vehicle terminal public key, and distributes the vehicle terminal certificate based on the vehicle terminal public key to the mobile terminal via the certification center; In step S104, the vehicle terminal receives the mobile terminal certificate distributed by the certification center; In step S106, the vehicle terminal presents a graphical code of the first signature information regarding the mobile terminal certificate; And in step S108, the vehicle terminal signs the test data with the vehicle terminal private key and encrypts the signed information with the mobile terminal certificate to generate test information, and sends the test information to the mobile terminal. Through the above steps of method 10, it is possible to verify the certificates of the peer received by the vehicle terminal and the mobile terminal, and avoid the certificates being tampered with midway. The verified certificates can be used for encrypted communication, thus ensuring the reliability of the communication between the vehicle terminal and the mobile terminal. The specific working principle of the above steps of method 10 will be described in detail below.
[0028] To clearly illustrate the working principle of method 10, the following will be described in conjunction with Figure 5 the vehicle communication system shown. As Figure 5 shown, the vehicle communication system includes a vehicle terminal, a mobile terminal, a certification center (PKI / CA, public key infrastructure / certificate authority), a telematics service provider (TSP, telematics service provider), etc. The following operations will be performed among the above entities, and the numbers of the following operations correspond to the numbers in the figure:
[0029] ① Certificate issuance. Figure 5 The shown solution can be an end-to-end encryption solution for privacy protection in an offline scenario of the vehicle networking. Before establishing an offline session, the two ends of the session (vehicle terminal, mobile terminal) need to generate end-side certificates. The preferred solution is for both ends to generate a pair of public keys and private keys respectively, specifically including a mobile terminal public key and a mobile terminal private key pair, a vehicle terminal public key and a vehicle terminal private key pair, and then both ends request the PKI / CA system to issue certificates for the peer side respectively.
[0030] ② Certificate request (as shown in the figure, specifically obtaining the mobile terminal certificate and obtaining the vehicle terminal certificate respectively). Before establishing an offline session, the session request end (vehicle terminal or mobile terminal) obtains the session receiving end (mobile terminal or vehicle terminal) certificate through the PKI / CA system, and at the same time, the request end locally can manage the received certificate through the certificate management module.
[0031] ③ QR code scanning for verification. After the vehicle terminal and the mobile terminal have installed the certificates of each other, the mobile terminal needs to scan the QR code to verify the certificate installed on the vehicle terminal (the vehicle terminal can display the signature of the mobile terminal certificate installed locally, and the mobile terminal compares whether the signature information is the same by scanning the QR code). If the verification is passed, the vehicle terminal can generate random information, sign the random information with the private key of the vehicle terminal, and then encrypt the signed information with the mobile terminal certificate and send it to the mobile terminal. The mobile terminal can decrypt the data with the private key of the local mobile terminal and verify the signed information with the vehicle terminal certificate installed locally, so as to prevent a man-in-the-middle from tampering with the certificate.
[0032] Through the above process, it can be determined whether the vehicle terminal and the mobile terminal have correctly received the certificates of each other. The correct certificate is the basis for subsequent other communication steps. Some examples of end-to-end encryption (E2EE) communication using the verified certificates will be described below. At this time, the data transmitted between the sending end and the receiving end (including the intermediate receiving end) is E2EE encrypted data.
[0033] ④ Offline data upload (to the server). In an offline session scenario, the session request end (vehicle terminal or mobile terminal) will encrypt the session content with the session key to obtain the encrypted session content, encrypt the seed key and session information with the certificate of the receiving end, and finally package and send the encrypted session content, encrypted seed key, and encrypted session information to the cloud TSP.
[0034] ⑤ Offline data download (from the server). In an offline session scenario, the session receiving end (mobile terminal or vehicle terminal) downloads the offline packaged data from the cloud, including: encrypted session content, encrypted seed key, and encrypted session information. Then, it decrypts the encrypted seed key and encrypted session information with the private key of the receiving end to obtain the seed key and session information, derives the session key from the seed key and session information using the key derivation algorithm, and finally decrypts the encrypted session content with the derived session key to generate the session content.
[0035] It should be noted that Figure 5 and the above description is intended to provide the reader with a complete solution that is sufficient but not necessary, so that the reader can thoroughly understand the basic principle of this application. However, this solution is not intended to limit other embodiments.
[0036] Return Figure 1, different from describing the communication system as a whole, Method 10 mainly views how to execute the communication method from the vehicle side perspective. In step S102 of Method 10, the vehicle side generates a corresponding vehicle private key and vehicle public key, and distributes the vehicle certificate based on the vehicle public key to the mobile terminal via the certification center. The vehicle private key and vehicle public key generated in step S102 will make it possible to encrypt information through asymmetric encryption in subsequent processes. In addition, in step S104 of Method 10, the vehicle side receives the mobile terminal certificate distributed by the certification center. Among them, the mobile terminal certificate is generated based on the mobile terminal public key, and the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal. After steps S102 and S104, the mobile terminal and the vehicle side can exchange certificates, and the received certificates at both ends can be used for subsequent encrypted communication.
[0037] In some embodiments of the present application, in step S104, the ID of the vehicle certificate and the ID of the mobile terminal certificate can be bound through the vehicle identification code of the vehicle side, and the vehicle side can determine the ID of the mobile terminal certificate through the vehicle identification code and obtain the mobile terminal certificate accordingly.
[0038] In step S106 of Method 10, the vehicle side presents a graphical code of the signature information of the mobile terminal certificate (also called the first signature information for distinction). The graphical code can be read by the mobile terminal, and the mobile terminal can verify the first signature information included in the graphical code through the mobile terminal public key, so as to verify the reliability of the first signature information, and further determine whether the mobile terminal certificate received by the vehicle side is reliable. In some examples, the graphical code can be a QR code; in other examples, the graphical code can also be other graphical codes that can be machine-read, such as barcodes.
[0039] In step S108 of Method 10, the vehicle side signs the test data with the vehicle private key and encrypts the signed information with the mobile terminal certificate to generate test information, and sends the test information to the mobile terminal. The test information can then be received by the mobile terminal, and the mobile terminal can decrypt the test information with the mobile terminal private key. Subsequently, the mobile terminal can verify the signature information (also called the second signature information for distinction) in the decrypted data based on the vehicle certificate.
[0040] In some embodiments of the present application, the offline session can be initiated by the vehicle side. At this time, Method 10 further includes the following steps (not shown in the figure): generating a seed key and session information by the vehicle side, and encrypting them with the mobile terminal certificate to generate an encrypted seed key and encrypted session information respectively; performing encryption derivation through the seed key and session information to generate a session key; encrypting the session content with the session key to generate encrypted session content; and sending the encrypted seed key, encrypted session information, and encrypted session content to the mobile terminal (via the relay server).
[0041] In this way, both symmetric encryption and asymmetric encryption can be used to encrypt the offline session content simultaneously, thus ensuring the security of communication. Among them, asymmetric encryption is performed on the seed key and session information. This is because such information is relatively small, so using asymmetric encryption will effectively improve the security of the information. In addition, since the session content itself is relatively large, symmetric encryption can be used to encrypt it, and symmetric encryption makes a balance between security and efficiency.
[0042] Subsequently, the mobile device can receive the offline data packet from the relay server and further process the data packet. Method 10 further includes (not shown in the figure): the mobile device decrypts the encrypted seed key and encrypted session information according to the mobile device private key to generate the seed key and session information respectively; performs encryption derivation through the seed key and session information to generate a session key; and decrypts the encrypted session content using the session key to generate the session content.
[0043] In some embodiments of the present application, the offline session can be initiated by the mobile device. At this time, method 10 further includes the following steps (not shown in the figure): receiving the encrypted seed key, encrypted session information, and encrypted session content from the mobile device; decrypting the encrypted seed key and encrypted session information according to the vehicle-side private key to generate the seed key and session information respectively; performing encryption derivation through the seed key and session information to generate a session key; and decrypting the encrypted session content using the session key to generate the session content. Among them, the data received by the vehicle side comes from the mobile device. Specifically: the encrypted seed key and encrypted session information are generated by the mobile device through vehicle-side certificate encryption according to the seed key and session information; and the mobile device performs encryption derivation through the seed key and session information to generate a session key, and encrypts the session content using the session key to generate the encrypted session content.
[0044] In some embodiments of the present application, the session information includes at least one of the following: timestamp, random number.
[0045] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 2 shown, the vehicle communication terminal 20 (hereinafter referred to as terminal 20) includes a memory 202 and a processor 204. Among them, the processor 204 can read data from the memory 202 and write data into the memory 202. The memory 202 can store instructions, and the processor 204 can execute the instructions stored in the memory 202 to perform any one of the vehicle communication methods as described above.
[0046] According to another aspect of the present application, a vehicle communication terminal is provided. As Figure 3As shown in the figure, the vehicle communication terminal 30 (hereinafter referred to as terminal 30) includes a key management, encryption and decryption module, an authentication center client module, and a verification module.
[0047] The key management, encryption and decryption module of terminal 30 is used to generate corresponding vehicle private key and vehicle public key. Specifically, the key management, encryption and decryption module can provide functions such as encryption, decryption, offline session key management, real-time session key management, certificate management, and private key management.
[0048] The authentication center client module of terminal 30 can generate a vehicle certificate based on the vehicle public key and distribute it to the mobile terminal via the authentication center, and receive the mobile terminal certificate based on the mobile terminal public key distributed by the authentication center. Among them, the mobile terminal public key and its corresponding mobile terminal private key are generated by the mobile terminal. Specifically, the authentication center client module can provide certificate issuance and certificate download functions: Certificate issuance can be used to generate vehicle certificates in the offline scenario. The vehicle terminal generates a public-private key pair locally, and then requests the PKI / CA system to issue a certificate; Certificate download is used for the vehicle terminal to request the mobile terminal certificate from the mobile terminal in the offline scenario.
[0049] The verification module of terminal 30 can present a graphical code of the first signature information about the mobile terminal certificate. The graphical code is used for the mobile terminal to read and verify the first signature information through the mobile terminal public key; The verification module is also configured to sign the test data with the vehicle private key and encrypt the signed information with the mobile terminal certificate to generate test information, and send the test information to the mobile terminal. Among them, the test information is decrypted by the mobile terminal through the mobile terminal private key, and the second signature information in the decrypted data is verified through the vehicle certificate.
[0050] Specifically, the verification module can provide a two-dimensional code scanning verification function: The vehicle terminal displays the signature information of the installed mobile terminal certificate. The mobile terminal compares whether the signatures are consistent through two-dimensional code scanning. If they are consistent, the vehicle terminal sends encrypted signature information (the vehicle terminal signs random information with the private key and encrypts the signature information with the locally installed mobile terminal certificate) to the mobile terminal, and the mobile terminal verifies the encrypted signature information.
[0051] In some embodiments of the present application, the terminal further includes a session management module. The session management module can generate session information, and the session information includes at least one of the following: timestamp, random number. Specifically, the session management module can provide offline session management and real-time session management. The session management module manages session information for offline sessions and real-time sessions, including information such as vehicle VIN, mobile terminal identity information, timestamp, and random number. These session information can be synchronized to both ends through a secure encryption channel. For the offline scenario, the offline session request end can encrypt the session key using the session receiving end certificate.
[0052] In some embodiments of the present application, the key management and encryption / decryption module is further configured to: generate a seed key, and encrypt the seed key and session information respectively through the mobile terminal certificate to generate an encrypted seed key and encrypted session information; perform encryption derivation through the seed key and session information to generate a session key; use the session key to encrypt the session content to generate encrypted session content; and send the encrypted seed key, encrypted session information, and encrypted session content to the mobile terminal.
[0053] Specifically, the key management and encryption / decryption module derives the offline session key through the key derivation algorithm and encrypts and protects the key for offline session key management. The self-developed key generation algorithm uses the offline session seed key, and based on the application type and time factor, performs key derivation, and generates a one-time session key through methods such as rotation permutation. This algorithm derives a one-time symmetric key, a one-time initialization vector, and a key digest based on the event time. It uses the one-time symmetric key and the one-time initialization vector to encrypt the data, and uses the key digest to verify the key; the certificate management module is used to manage the locally downloaded certificates; the private key management is mainly used for the private keys generated at both ends.
[0054] In addition, the terminal 30 may further include a hardware security module (not shown in the figure), and this module may be an abstraction layer of the vehicle-end underlying security hardware module HSM, and is used to provide key generation, management, and data encryption / decryption capabilities.
[0055] According to another aspect of the present application, a mobile terminal is provided. As Figure 4 shown, the mobile terminal 40 includes a key management and encryption / decryption module, an authentication center client module, and a verification module. During the communication process, the terminal 30 and the mobile terminal 40 are peer-to-peer ends with equal status, so each module in the mobile terminal 40 may have the same functions as the corresponding module of the terminal 30. To save space, the functions and working principles of each module of the mobile terminal 40 will not be elaborated herein.
[0056] According to another aspect of the present application, a vehicle is provided. The vehicle includes any one of the vehicle communication terminals as described above. The layout of the vehicle in the present application is not limited (for example, wheeled vehicles, tracked vehicles, etc.), nor is the driving force of the vehicle limited (for example, motor drive, gasoline engine drive, etc.). The vehicles in the present application cover various vehicles currently known in the art and vehicles to be developed in the future.
[0057] According to another aspect of the present application, there is provided a computer-readable storage medium storing instructions that, when executed by a processor, cause the processor to perform any one of the vehicle communication methods described above. The computer-readable medium referred to in the present application includes various types of computer storage media and can be any available medium accessible by a general-purpose or special-purpose computer. For example, the computer-readable medium may include RAM, ROM, EPROM, E 2 PROM, registers, hard disks, removable disks, CD-ROMs or other optical disk memories, magnetic disk memories or other magnetic storage devices, or any other transient or non-transient medium capable of carrying or storing desired program code units in the form of instructions or data structures and accessible by a general-purpose or special-purpose computer or a general-purpose or special-purpose processor. As used herein, disks typically magnetically replicate data, while discs optically replicate data with a laser. The above combinations should also be included within the scope of protection of the computer-readable medium. An exemplary storage medium is coupled to the processor such that the processor can read from / write to the storage medium. In an alternative, the storage medium may be integrated into the processor. The processor and the storage medium may reside in an ASIC. The ASIC may reside in a user terminal. In an alternative, the processor and the storage medium may reside in the user terminal as discrete components.
[0058] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Those skilled in the art can think of other feasible changes or substitutions based on the technical scope disclosed in the present application, and such changes or substitutions are all covered by the scope of protection of the present application. Without conflict, the embodiments of the present application and the features in the embodiments can also be combined with each other. The scope of protection of the present application is subject to the claims.
Claims
1. A vehicle communication method, characterized in that, the method includes: generating a corresponding vehicle private key and vehicle public key by the vehicle end, and distributing a vehicle certificate based on the vehicle public key to the mobile end via an authentication center; receiving, by the vehicle end, a mobile end certificate distributed via the authentication center, wherein the mobile end certificate is generated based on a mobile end public key, and the mobile end public key and its corresponding mobile end private key are generated by the mobile end; presenting, by the vehicle end, a graphical code of first signature information about the mobile end certificate, the graphical code being used for the mobile end to read and verify the first signature information with the mobile end public key; and signing, by the vehicle end, test data with the vehicle private key and encrypting the signed information with the mobile end certificate to generate test information, and sending the test information to the mobile end, wherein the test information is decrypted by the mobile end with the mobile end private key, and the second signature information in the decrypted data is verified based on the vehicle certificate.
2. The method according to claim 1, wherein, the graphical code is a QR code.
3. The method according to claim 1, wherein, receiving, by the vehicle end, a mobile end certificate distributed via the authentication center includes: binding, by the vehicle end, the ID of the corresponding vehicle certificate and the ID of the mobile end certificate with a vehicle identification code; and the vehicle end determining the ID of the mobile end certificate by the vehicle identification code and obtaining the mobile end certificate thereby.
4. The method according to claim 1, further includes: generating, by the vehicle end, a seed key and session information, and encrypting them with the mobile end certificate to generate an encrypted seed key and encrypted session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; encrypting session content with the session key to generate encrypted session content; and sending the encrypted seed key, the encrypted session information and the encrypted session content to the mobile end.
5. The method according to claim 4, further includes: decrypting, by the mobile end, the encrypted seed key and the encrypted session information with the mobile end private key to generate a seed key and session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; and decrypting the encrypted session content with the session key to generate the session content.
6. The method according to claim 1, further includes: receiving an encrypted seed key, encrypted session information and encrypted session content from the mobile end; decrypting, according to the vehicle private key, the encrypted seed key and the encrypted session information to generate a seed key and session information respectively; performing encryption derivation with the seed key and the session information to generate a session key; and decrypting the encrypted session content with the session key to generate the session content.
7. The method according to claim 6, wherein, The encrypted seed key and the encrypted session information are generated by the mobile device according to the seed key and the session information through encryption with the vehicle-side certificate; and The mobile device encrypts and derives the session key through the seed key and the session information, and encrypts the session content with the session key to generate the encrypted session content.
8. The method according to any one of claims 4-7, wherein, The session information includes at least one of the following: timestamp, random number.
9. A vehicle communication terminal, characterized in that, The terminal includes: A key management and encryption / decryption module configured to generate a corresponding vehicle-side private key and vehicle-side public key; An authentication center client module configured to generate a vehicle-side certificate based on the vehicle-side public key and distribute it to the mobile device via the authentication center, and receive a mobile device certificate based on the mobile device public key distributed by the authentication center, wherein the mobile device public key and its corresponding mobile device private key are generated by the mobile device; and A verification module configured to present a graphical code of the first signature information about the mobile device certificate, and the graphical code is used for the mobile device to read and verify the first signature information through the mobile device public key; wherein, The verification module is further configured to sign the test data with the vehicle-side private key and encrypt the signed information with the mobile device certificate to generate test information, and send the test information to the mobile device, and the test information is decrypted by the mobile device through the mobile device private key, and the second signature information in the decrypted data is verified through the vehicle-side certificate.
10. The terminal according to claim 9, further including: A session management module configured to generate session information, and the session information includes at least one of the following: timestamp, random number.
11. The terminal according to claim 10, wherein, The key management and encryption / decryption module is further configured to: generate a seed key, and encrypt the seed key and the session information respectively with the mobile device certificate to generate an encrypted seed key and encrypted session information; Encrypt and derive a session key through the seed key and the session information; Encrypt the session content with the session key to generate encrypted session content; and Send the encrypted seed key, the encrypted session information and the encrypted session content to the mobile device.
12. A vehicle communication terminal, characterized in that, The terminal includes: A memory configured to store instructions; and A processor configured to execute the instructions to perform the method according to any one of claims 1-8.
13. A computer-readable storage medium, in which instructions are stored, characterized in that, When the instructions are executed by a processor, the processor is caused to execute the method according to any one of claims 1-8.
14. A vehicle, characterized in that, The vehicle includes the vehicle communication terminal according to any one of claims 9-12.
Citation Information
Patent Citations
Digital certificate implementation method and device based on symmetric algorithm, equipment and medium
CN114448644A
Digital key service method and system thereof
KR102175408B1