Communication method, device, equipment and storage medium based on secure transport layer protocol
By using the combination of V2X short certificate and X.509 certificate in V2X secure communication, the problem of large resource occupation and insufficient timeliness in V2X secure communication is solved, low-cost and high-efficiency TLS connection is achieved, and the high-time efficiency requirements of the Internet of Vehicles is adapted.
Patent Information
- Application Number
- CN202211047539.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-29
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2042-08-29
AI Technical Summary
In the prior art, using the X.509 certificate in V2X secure communication will occupy a large amount of resources, resulting in high costs, and the timeliness of the X.509 certificate cannot achieve the high timeliness requirements of the Internet of Vehicles.
The client sends a connection request for the secure transport layer TLS protocol to the server, and the request includes a handshake message. The handshake message includes a type extension of the client certificate and a type extension of the server certificate. The client certificate includes a V2X short certificate, and the server certificate includes at least one of the V2X short certificate and X.509 certificate, thereby realizing two-way TLS identity authentication.
There is no need to establish an X.509 security certificate management system, which reduces costs. Due to the characteristics of V2X short certificates, faster connections are achieved in TLS connections, adapting to the requirements of high timeliness scenarios.
Smart Images

Figure CN115499837B_ABST
Abstract
Description
Technical Field
[0001] The present application belongs to the field of communication technology, and in particular, relates to a communication method, device, equipment and storage medium based on a secure transport layer protocol. Background Art
[0002] As the level of automobile intelligence continues to increase, more and more new technologies and products are being applied to automobiles. While changes in the automobile industry have brought convenience to travel, the issue of automobile information security has also received increasing attention.
[0003] The communication security of cellular vehicle to X (C-V2X) is mainly divided into four directions: vehicle-to-cloud security communication, vehicle-to-vehicle security communication, vehicle-to-road security communication, and vehicle-to-device security communication. Among them, vehicle-to-cloud security communication will be based on the cryptographic digital certificate of the digital certificate standard X.509 for secure connection of the vehicle-to-cloud secure transport layer protocol (Transport Layer Security, TLS). Vehicle-to-vehicle, vehicle-to-road, and vehicle-to-device security communications will be based on V2X short certificates for data signing and encryption. Therefore, according to the different business divisions, in order to meet the business needs of vehicle-to-cloud communications, it is necessary to establish an X.509 security certificate management system, and in order to meet the security business needs of V2X, it is necessary to establish a V2X security certificate management system.
[0004] Since the X.509 security certificate management system and the V2X security certificate management system are two independent systems, and the X.509 certificate has more bytes than the V2X short certificate, if the X.509 certificate is used in V2X security communication, it will occupy a large amount of resources and cause high costs; the timeliness of the X.509 certificate and the V2X short certificate cannot meet the high timeliness requirements of the Internet of Vehicles. Summary of the invention
[0005] The embodiments of the present application provide a communication method, apparatus, device and storage medium based on a secure transport layer protocol, which can solve the problem in the prior art that using X.509 certificates in V2X secure communications will occupy a large amount of resources and cause high costs, and the timeliness of X.509 certificates and V2X short certificates cannot meet the high timeliness requirements of the Internet of Vehicles.
[0006] In a first aspect, an embodiment of the present application provides a communication method based on a secure transport layer protocol, the method being applied to a client, comprising:
[0007] Sending a connection request of the secure transport layer TLS protocol to the server, the request comprising a handshake message, the handshake message comprising a type extension of the client certificate and a type extension of the server certificate, the client certificate comprising a V2X short certificate, and the server certificate comprising at least one of a V2X short certificate and an X.509 certificate;
[0008] Receiving a response message sent by the server based on the request, the response message including at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate;
[0009] Based on the response message, verify the signature information using the public key corresponding to the server certificate;
[0010] If the verification is successful, based on the first certificate application information in the response message, a V2X short certificate is sent to the server, so as to complete the TLS communication connection if the server verifies the V2X short certificate successfully.
[0011] In one implementation, the response message includes a temporary public key generated by the server; the method further includes:
[0012] A shared key is generated based on the temporary public key, and the shared key is used to encrypt a message transmitted to the server.
[0013] In one embodiment, before sending a connection request of the Transport Security Layer TLS protocol to the server, the method further includes:
[0014] Sending second certificate application information to a preset authorization agency, wherein the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key, so that the authorization agency can verify the second certificate application information based on the public key;
[0015] Receive an X.509 certificate corresponding to the certificate type sent by the authorization agency when the verification is successful.
[0016] In one embodiment, before sending a connection request of the Transport Security Layer TLS protocol to the server, the method further includes:
[0017] Sending an application certificate application request to a preset V2X security certificate management system, wherein the application certificate application request includes a signature of a private key of an identity certificate, so that the V2X security certificate management system verifies the application certificate application request based on the public key of the identity certificate, and generates application certificate application response information after the verification passes;
[0018] Sending an application certificate download request to the V2X security certificate management system based on the application certificate request response message sent by the V2X security certificate management system;
[0019] An application certificate download request response message sent by the V2X security certificate management system is received, where the application certificate download request response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download request.
[0020] In a second aspect, an embodiment of the present application provides a communication method based on a secure transport layer protocol, the method being applied to a server, comprising:
[0021] Receiving a connection request of a secure transport layer TLS protocol sent by a client, the request comprising a handshake message, the handshake message comprising a type extension of a client certificate and a type extension of a server certificate, the client certificate comprising a V2X short certificate, and the server certificate comprising at least one of a V2X short certificate and an X.509 certificate;
[0022] Sending a response message to the client based on the request, the response message including at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate, so that the client verifies the signature information based on the response message using a public key corresponding to the server certificate, and, if the verification passes, sends the V2X short certificate to the server based on the first certificate application information in the response message;
[0023] The V2X short certificate sent by the client is verified, and if the verification passes, the TLS communication connection is completed.
[0024] In one implementation, the handshake message includes information of a pre-shared key; and the method further includes:
[0025] A shared key is generated according to the pre-shared key and the temporary public key, and the shared key is used to encrypt a message transmitted to the client.
[0026] In a third aspect, an embodiment of the present application provides a communication device based on a secure transport layer protocol, the device being applied to a client, comprising:
[0027] A sending module, configured to send a connection request of a secure transport layer TLS protocol to a server, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate;
[0028] a receiving module, configured to receive a response message sent by the server based on the request, wherein the response message includes at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate;
[0029] A verification module, used to verify the signature information based on the response message using the public key corresponding to the server certificate;
[0030] The sending module is further used to send the V2X short certificate to the server based on the first certificate application information in the response message when the verification is successful, so as to complete the TLS communication connection when the server verifies the V2X short certificate.
[0031] In one embodiment, the response message includes a temporary public key generated by the server; the communication device based on the secure transport layer protocol also includes a generation module;
[0032] A generation module is used to generate a shared key based on the temporary public key, and the shared key is used to encrypt the message transmitted to the server.
[0033] In one embodiment, the sending module is further used to send second certificate application information to a preset authorization agency before sending a connection request of a secure transport layer TLS protocol to the server, wherein the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key, so that the authorization agency can verify the second certificate application information based on the public key;
[0034] The receiving module is further configured to receive an X.509 certificate corresponding to the certificate type sent by the authorization agency when the verification is successful.
[0035] In one embodiment, the sending module is further used to send an application certificate application request to a preset V2X security certificate management system before sending a connection request of a secure transport layer TLS protocol to the server, wherein the application certificate application request includes an identity certificate private key signature, so that the V2X security certificate management system verifies the application certificate application request based on the identity certificate public key, and generates application certificate application response information after the verification passes;
[0036] The sending module is further configured to send an application certificate download request to the V2X security certificate management system based on the application certificate application response message sent by the V2X security certificate management system;
[0037] The receiving module is further configured to receive an application certificate download request response message sent by the V2X security certificate management system, wherein the application certificate download request response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download request.
[0038] In a fourth aspect, an embodiment of the present application provides a communication device based on a secure transport layer protocol, the device being applied to a server, comprising:
[0039] A receiving module, configured to receive a connection request of a secure transport layer TLS protocol sent by a client, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate;
[0040] a sending module, configured to send a response message to the client based on the request, wherein the response message includes at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the signature information is obtained by the server using a private key corresponding to the server certificate to sign the handshake message, so that the client verifies the signature information based on the response message using a public key corresponding to the server certificate, and, if the verification is successful, sends the V2X short certificate to the server based on the first certificate application information in the response message;
[0041] A verification module is used to verify the V2X short certificate sent by the client, and complete the TLS communication connection if the verification passes.
[0042] In one embodiment, the handshake message includes information of a pre-shared key; the communication device based on the secure transport layer protocol also includes a generation module;
[0043] A generating module is used to generate a shared key according to the pre-shared key and the temporary public key, wherein the shared key is used to encrypt a message transmitted to the client.
[0044] In a fifth aspect, an embodiment of the present application provides an electronic device, the electronic device comprising: a processor and a memory storing computer program instructions;
[0045] When the processor executes the computer program instructions, the communication method based on the secure transport layer protocol as described in any one of the embodiments of the first aspect is implemented.
[0046] In a sixth aspect, an embodiment of the present application provides a computer storage medium on which computer program instructions are stored. When the computer program instructions are executed by a processor, a communication method based on a secure transport layer protocol as described in any one of the embodiments of the first aspect is implemented.
[0047] The communication method, device, equipment and computer storage medium based on the secure transport layer protocol of the embodiment of the present application, sends a connection request of the secure transport layer TLS protocol to the server through the client, wherein the request includes a handshake message, the handshake message includes the type extension of the client certificate and the type extension of the server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of the V2X short certificate and the X.509 certificate. In this way, the client performs identity authentication through the V2X short certificate, and the server can select the certificate type of the V2X short certificate or the X.509 certificate for identity authentication. Then, the client receives a response message sent by the server based on the request, and the response message includes at least one of the V2X short certificate and the X.509 certificate, the information that the server uses the private key corresponding to the server certificate to sign the handshake message, and the first certificate application information. Then, the client verifies the signature information using the public key corresponding to the server certificate, and sends the V2X short certificate to the server based on the first certificate application information if the verification is successful, so as to complete the TLS communication connection if the server verifies the V2X short certificate successfully. In this way, the client can directly use the V2X short certificate for TLS connection. The V2X short certificate can realize two-way TLS identity authentication between the server and the client. There is no need to establish an X.509 security certificate management system, which reduces costs. In addition, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can adapt to high timeliness scenario requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0048] In order to more clearly illustrate the technical solution of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0049] Figure 1 This is one of the flow diagrams of a communication method based on a secure transport layer protocol provided by an embodiment of the present application;
[0050] Figure 2 This is a second flow chart of a communication method based on a secure transport layer protocol provided by an embodiment of the present application;
[0051] Figure 3 This is a schematic diagram of the process of applying for an X.509 certificate provided by an embodiment of the present application;
[0052] Figure 4 It is a schematic diagram of the process of applying for an AC application certificate provided by an embodiment of the present application;
[0053] Figure 5 This is one of the structural schematic diagrams of a communication device based on a secure transport layer protocol provided by an embodiment of the present application;
[0054] Figure 6 This is a second structural diagram of a communication device based on a secure transport layer protocol provided by an embodiment of the present application;
[0055] Figure 7 It is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0056] The features and exemplary embodiments of various aspects of the present application will be described in detail below. In order to make the purpose, technical solutions and advantages of the present application clearer, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain the present application, rather than to limit the present application. For those skilled in the art, the present application can be implemented without the need for some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by illustrating the examples of the present application.
[0057] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the statement "include..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0058] As described in the background technology, the TLS protocol in the prior art determines the identity of the client and the server based on the verification of the X.509 certificate. In the application scenario of the Internet of Vehicles, the OEM and the demonstration area need to establish an X.509 security certificate management system to meet the needs of the vehicle-cloud communication business, and to meet the security business needs of V2X, a V2X security certificate management system needs to be established. However, the X.509 security certificate management system and the V2X security certificate management system are two independent systems. From a technical point of view, the X.509 certificate is about 100 bytes larger than the V2X short certificate. If the X.509 certificate is used in V2X security communication, it will occupy a lot of resources, resulting in a waste of manpower and cost, and cannot achieve the high timeliness requirements of the Internet of Vehicles. When in the application scenario of the intelligent transportation system, in order to achieve efficient use of functions such as remote control and over-the-air technology (OTA), it is necessary to have efficient transmission and high reliability during TLS secure connection, and the X.509 certificate cannot achieve a faster connection in the TLS connection.
[0059] In order to solve the above problems, the embodiments of the present application provide a communication method, device, equipment and computer storage medium based on the secure transport layer protocol. The communication method based on the secure transport layer protocol can send a connection request of the secure transport layer TLS protocol to the server through the client, wherein the request includes a handshake message, the handshake message includes the type extension of the client certificate and the type extension of the server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of the V2X short certificate and the X.509 certificate. In this way, the client performs identity authentication through the V2X short certificate, and the server can choose the certificate type of the V2X short certificate or the X.509 certificate for identity authentication. Then, the client receives a response message sent by the server based on the request, and the response message includes at least one of the V2X short certificate and the X.509 certificate, the information that the server uses the private key corresponding to the server certificate to sign the handshake message, and the first certificate application information. Then the client verifies the signature information using the public key corresponding to the server certificate, and if the verification is successful, sends the V2X short certificate to the server based on the first certificate application information, so as to complete the TLS communication connection when the server verifies the V2X short certificate. In this way, the client can directly use the V2X short certificate for TLS connection, and the V2X short certificate can realize two-way TLS identity authentication between the server and the client, without the need to establish an X.509 security certificate management system, thus reducing costs. Moreover, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can meet the requirements of high timeliness scenarios.
[0060] The embodiments of the present application can be applied to scenarios where both the client and the server use V2X short certificates, and can also be applied to scenarios where the client uses a short certificate and the server uses an X.509 certificate. The following first introduces the communication method based on the secure transport layer protocol provided in the embodiments of the present application.
[0061] Figure 1 A flow chart of a communication method based on a secure transport layer protocol provided in one embodiment of the present application is shown.
[0062] like Figure 1 As shown, the communication method based on the secure transport layer protocol may specifically include the following steps:
[0063] S110, the client sends a connection request of the secure transport layer TLS protocol to the server, the request may include a handshake message, the handshake message may include the type extension of the client certificate and the type extension of the server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate.
[0064] The client sends a connection request of the Transport Layer Security (TLS) protocol to the server, wherein the Transport Layer Security protocol is used to provide confidentiality and data integrity between two communicating applications, the client may be a vehicle terminal, and the server may be, for example, the cloud. The connection request may include a handshake message "Client Hello", which may include a client certificate type "client_certificate_type" extension and a server certificate type "server_certificate_type" extension, wherein "client_certificate_type" is a V2X short certificate, and "server_certificate_type" may support at least one of a V2X short certificate and an X.509 certificate, and the server may select the first (optimal) certificate type from the server_certificate_type.
[0065] S120, the server signs the handshake message using the private key corresponding to the server certificate to obtain signature information.
[0066] The server signs the handshake message "Client Hello" using the private key corresponding to the server certificate, where the server certificate can be a V2X short certificate or an X.509 certificate selected by the server.
[0067] S130, the server sends a response message to the client based on the request, and the response message may include at least one server certificate of the V2X short certificate and the X.509 certificate, signature information, and first certificate application information.
[0068] The server replies with a response message "Server Hello" to the client. The response message may include the server certificate selected by the server, signature information, and first certificate application information "Certificate Request", wherein the first certificate application information is used to apply for a client certificate.
[0069] S140: Based on the response message, the client verifies the signature information using the public key corresponding to the server certificate.
[0070] After receiving the response message, the client verifies the signature information using the public key corresponding to the server certificate to verify the validity of the server certificate. The specific verification process can be: the server generates the public key and private key corresponding to the server certificate, downloads the server certificate and certificate chain, and stores them in the specified location to generate a certificate configuration file. When verifying the validity of the certificate, the TLS1.3 program reads and calls the certificate file from the directory of the certificate configuration file, and then the TLS1.3 program verifies the certificate file based on the public key and private key corresponding to the server certificate, the server certificate and the certificate chain.
[0071] S150: When the verification is successful, the client sends the V2X short certificate to the server based on the first certificate application information in the response message.
[0072] When the client verifies that the server certificate is valid, the client sends a response message "CertificateResponse" of the first certificate application information to the server based on the first certificate application information "Certificate Request" in the response message. The "Certificate Response" may include the V2X short certificate, that is, the client certificate.
[0073] S160: The server verifies the V2X short certificate sent by the client, and completes the TLS communication connection if the verification passes.
[0074] The specific method by which the server verifies the V2X short certificate sent by the client is the same as the method for verifying the validity of the server certificate described above. If the verification is successful, the TLS communication connection is completed.
[0075] In an embodiment of the present application, a connection request of the secure transport layer TLS protocol is sent from the client to the server, wherein the handshake message in the request includes the type extension of the client certificate and the type extension of the server certificate, the client certificate includes the V2X short certificate, and the server certificate includes at least one of the V2X short certificate and the X.509 certificate. In this way, the client performs identity authentication through the V2X short certificate, and the server can select the certificate type of the V2X short certificate or the X.509 certificate for identity authentication. Then, the client receives a response message sent by the server based on the request, and the response message includes at least one of the V2X short certificate and the X.509 certificate, the information that the server uses the private key corresponding to the server certificate to sign the handshake message, and the first certificate application information. Then, the client verifies the signature information using the public key corresponding to the server certificate, and if the verification is successful, sends the V2X short certificate to the server based on the first certificate application information, so as to complete the TLS communication connection when the server verifies the V2X short certificate successfully. In this way, the client can directly use the V2X short certificate for TLS connection. The V2X short certificate can realize two-way TLS identity authentication between the server and the client. There is no need to establish an X.509 security certificate management system, which reduces costs. In addition, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can adapt to high timeliness scenario requirements.
[0076] Based on this, Figure 2 A flow chart of a communication method based on a secure transport layer protocol provided by an embodiment of the present application is shown, and the communication method based on a secure transport layer protocol is applied to a client.
[0077] like Figure 2 As shown, the communication method based on the secure transport layer protocol may specifically include the following steps:
[0078] S210, sending a connection request of the secure transport layer TLS protocol to the server, the request including a handshake message, the handshake message including the type extension of the client certificate and the type extension of the server certificate, the client certificate including the V2X short certificate, and the server certificate including at least one of the V2X short certificate and the X.509 certificate.
[0079] S220, receiving a response message sent by the server based on the request, the response message including at least one server certificate of a V2X short certificate and an X.509 certificate, signature information and first certificate application information, the signature information being obtained by the server signing the handshake message using a private key corresponding to the server certificate.
[0080] S230, based on the response message, verify the signature information using the public key corresponding to the server certificate.
[0081] S240, when the verification is successful, based on the first certificate application information in the response message, the V2X short certificate is sent to the server, so as to complete the TLS communication connection when the server verifies the V2X short certificate successfully.
[0082] In an embodiment of the present application, a connection request of the secure transport layer TLS protocol is sent from the client to the server, wherein the handshake message in the request includes the type extension of the client certificate and the type extension of the server certificate, the client certificate includes the V2X short certificate, and the server certificate includes at least one of the V2X short certificate and the X.509 certificate. In this way, the client performs identity authentication through the V2X short certificate, and the server can select the certificate type of the V2X short certificate or the X.509 certificate for identity authentication. Then, the client receives a response message sent by the server based on the request, and the response message includes at least one of the V2X short certificate and the X.509 certificate, the information that the server uses the private key corresponding to the server certificate to sign the handshake message, and the first certificate application information. Then, the client verifies the signature information using the public key corresponding to the server certificate, and if the verification is successful, sends the V2X short certificate to the server based on the first certificate application information, so as to complete the TLS communication connection when the server verifies the V2X short certificate successfully. In this way, the client can directly use the V2X short certificate for TLS connection. The V2X short certificate can realize two-way TLS identity authentication between the server and the client. There is no need to establish an X.509 security certificate management system, which reduces costs. In addition, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can adapt to high timeliness scenario requirements.
[0083] In some embodiments, the response message may include a temporary public key generated by the server; the communication method based on the secure transport layer protocol may also include:
[0084] Generate a shared secret key based on the temporary public key.
[0085] The client receives the response message sent by the server based on the request. The response message may include the temporary public key generated by the server. The client generates the shared key required for the session based on the temporary public key. The shared key is used to encrypt the message transmitted to the server. The response message may include a Key Share message. The temporary public key generated by the server can be sent to the client through the KeyShare message.
[0086] Exemplarily, the handshake message "Client Hello" may also include parameters such as the protocol version, session ID, cipher suite, and compression algorithm supported by the client, so that the server can select one parameter from the protocol version, cipher suite, and compression algorithm supported by the client to generate a temporary public key, and then send it to the client. The client generates a shared key based on the temporary public key.
[0087] In an embodiment of the present application, a response message is received by the client, and the response message includes a temporary public key generated by the server. The client generates a shared key based on the temporary public key. The shared key is used to encrypt messages transmitted to the server, which can ensure the security of the message and improve the security of information transmission.
[0088] In some embodiments, before sending a connection request of the secure transport layer TLS protocol to the server, the communication method based on the secure transport layer protocol may further include:
[0089] Sending second certificate application information to a preset authorization agency, where the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key for the authorization agency to verify the second certificate application information based on the public key;
[0090] The receiving authority sends an X.509 certificate corresponding to the certificate type if the verification is successful.
[0091] The client sends the second certificate application information to the preset authorization agency, wherein the preset authorization agency may be a certificate authority (CA). The second certificate application information may be a certificate application request, which may include the type of certificate applied for and a verification request, and may also include information such as the certificate type and certificate number, wherein the verification request may include a P10 request, and after receiving the second certificate application information, the CA agency may verify the second certificate application information based on the public key in the P10 request. If the verification is successful, the preset authorization agency sends the X.509 certificate corresponding to the certificate type to the client.
[0092] As an example, Figure 3 As shown, the client generates a certificate application request and sends it to the CA in the X.509 security certificate management system. The certificate application request file contains the certificate type, document type, document number and P10 request. The CA institution certificate receives the certificate application request and verifies the validity of the certificate application request based on the P10 request. After the validity is verified, the CA returns the certificate file to the client, which contains the X.509 certificate and root certificate file.
[0093] In an embodiment of the present application, by sending second certificate application information to a preset authorization agency, the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key, so that the authorization agency can verify the second certificate application information based on the public key. Then, by receiving the X.509 certificate corresponding to the certificate type sent by the authorization agency when the verification is successful, the security of applying for the X.509 certificate can be guaranteed.
[0094] In some embodiments, before sending a connection request of the secure transport layer TLS protocol to the server, the communication method based on the secure transport layer protocol may further include:
[0095] Sending an application certificate application request to a preset V2X security certificate management system, where the application certificate application request includes a signature of the identity certificate private key, so that the V2X security certificate management system verifies the application certificate application request based on the identity certificate public key, and generates application certificate application response information after the verification passes;
[0096] Sending an application certificate download request to the V2X security certificate management system based on the application certificate request response message sent by the V2X security certificate management system;
[0097] An application certificate download request response message sent by the V2X security certificate management system is received, where the application certificate download request response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download request.
[0098] The V2X short certificate is an AC application certificate. The application certificate application request can be a request for an application certificate certified by an Assessment Center (AC), and can include an identity certificate private key signature. After receiving the application certificate application request, the V2X security certificate management system verifies the legitimacy of the application certificate application request based on the identity certificate public key, and generates an application certificate application response message after the verification passes. The verification of the application certificate application request here can be based on certificate chain verification. After receiving the application certificate application response message, the client sends an application certificate download request to the V2X security certificate management system to apply for downloading the application certificate. The application certificate application response message can also include download time information of the application certificate. In addition, the terminal's pseudonym certificate can be used instead of the application certificate for TLS secure connection.
[0099] As an example, Figure 4As shown, the client generates an application certificate application request and signs it with the private key of the identity certificate, and sends the application certificate application request to the V2X security certificate management system. The V2X security certificate management system verifies the legitimacy of the application certificate application request. After the verification, it will generate an application certificate application response and return the application certificate application response to the client. The application certificate application response contains the download time information of the applied certificate. Then, after receiving the application certificate application response, the client generates an application certificate download request and signs it with the identity certificate, and then sends the application certificate download request to the V2X security certificate management system. The V2X security certificate management system returns the application certificate download response information (the compressed package file of the application certificate) to the client. In addition, the way the server applies for the AC application certificate is the same as the way the client applies for the AC application certificate.
[0100] In the embodiment of the present application, an application certificate application request is sent to a preset V2X security certificate management system, and the application certificate application request includes an identity certificate private key signature, so that the V2X security certificate management system verifies the application certificate application request based on the identity certificate public key, generates application certificate application response information after the verification is passed, and sends an application certificate download application to the V2X security certificate management system based on the application certificate application response message sent by the V2X security certificate management system. Then, an application certificate download application response message sent by the V2X security certificate management system is received, and the application certificate download application response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download application, so that the security of the application certificate V2X short certificate can be guaranteed.
[0101] Based on this, another embodiment of the present application provides a communication method based on the secure transport layer protocol, which is applied to the server and may specifically include the following steps:
[0102] Receive a connection request of a secure transport layer TLS protocol sent by a client, the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate;
[0103] Send a response message to the client based on the request, the response message including at least one of the V2X short certificate and the X.509 certificate, the signature information and the first certificate application information, the signature information is obtained by the server using the private key corresponding to the server certificate to sign the handshake message, so that the client can verify the signature information based on the response message using the public key corresponding to the server certificate, and send the V2X short certificate to the server based on the first certificate application information in the response message if the verification is successful;
[0104] Verify the V2X short certificate sent by the client, and complete the TLS communication connection if the verification passes.
[0105] In an embodiment of the present application, a connection request of a secure transport layer TLS protocol sent by a client is received by a server, the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate, so that the server can select a certificate type of a V2X short certificate or an X.509 certificate for identity authentication. Then, the server sends a response message to the client based on the request, the response message includes at least one of a V2X short certificate and an X.509 certificate, a server certificate, signature information, and a first certificate application information, the signature information is obtained by the server using the private key corresponding to the server certificate to sign the handshake message, so that the client can verify the signature information based on the response message using the public key corresponding to the server certificate, and if the verification is successful, send the V2X short certificate to the server based on the first certificate application information in the response message. Then, the V2X short certificate sent by the client is verified, and if the verification is successful, the TLS communication connection is completed. In this way, the client can directly use the V2X short certificate for TLS connection. The V2X short certificate can realize two-way TLS identity authentication between the server and the client. There is no need to establish an X.509 security certificate management system, which reduces costs. In addition, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can adapt to high timeliness scenario requirements.
[0106] In some embodiments, the handshake message may include information of a pre-shared key; the communication method based on the secure transport layer protocol may also include:
[0107] Generate a shared key based on the pre-shared key and the temporary public key.
[0108] The handshake message "Client Hello" may include an extended message (key sharing, pre-shared key, pre-shared key mode). The server generates a shared key based on the pre-shared key and temporary public key in the extended message. The shared key is used to encrypt messages transmitted to the client.
[0109] As an example, the handshake message sent by the client and received by the server may include information about the protocol version, session ID, cipher suite, compression algorithm, and pre-shared key supported by the client. The server selects one of the parameters of the protocol version, cipher suite, and compression algorithm supported by the client, and generates a temporary public key based on the selected parameters, and calculates a shared key for encrypting Hypertext Transfer Protocol (HTTP) messages based on the temporary public key and the pre-shared key, which is used to encrypt messages transmitted to the client.
[0110] In an embodiment of the present application, a shared key is generated based on a temporary public key and a pre-shared key in a handshake message. In this way, the client and the server can both use the generated shared key to encrypt and transmit messages, thereby ensuring the security of message transmission.
[0111] Figure 5 It is a structural diagram of a communication device 500 based on the secure transport layer protocol according to an exemplary embodiment. The communication device 500 based on the secure transport layer protocol is applied to a client.
[0112] like Figure 5 As shown, the communication device 500 based on the secure transport layer protocol may include:
[0113] A sending module 501 is used to send a connection request of a secure transport layer TLS protocol to a server, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate;
[0114] The receiving module 502 is used to receive a response message sent by the server based on the request, where the response message includes at least one server certificate of the V2X short certificate and the X.509 certificate, signature information, and first certificate application information, where the signature information is obtained by the server signing the handshake message using the private key corresponding to the server certificate;
[0115] Verification module 503, used to verify the signature information based on the response message using the public key corresponding to the server certificate;
[0116] The sending module 501 is also used to send the V2X short certificate to the server based on the first certificate application information in the response message when the verification is successful, so as to complete the TLS communication connection when the server verifies the V2X short certificate.
[0117] In one implementation, the response message may include a temporary public key generated by the server; the communication device 500 based on the secure transport layer protocol may also include a generation module;
[0118] The generation module is used to generate a shared key based on the temporary public key, and the shared key is used to encrypt the message transmitted to the server.
[0119] In one embodiment, the sending module 501 is further used to send second certificate application information to a preset authorization agency before sending a connection request of a secure transport layer TLS protocol to the server, where the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key, so that the authorization agency verifies the second certificate application information based on the public key;
[0120] The receiving module 502 is further configured to receive an X.509 certificate corresponding to the certificate type sent by the authorization agency when the verification is successful.
[0121] In one implementation, the sending module 501 is further configured to send an application certificate application request to a preset V2X security certificate management system before sending a connection request of a secure transport layer TLS protocol to the server, where the application certificate application request includes a signature of an identity certificate private key, so that the V2X security certificate management system verifies the application certificate application request based on the identity certificate public key, and generates application certificate application response information after the verification passes;
[0122] The sending module 501 is further configured to send an application certificate download request to the V2X security certificate management system based on the application certificate application response message sent by the V2X security certificate management system;
[0123] The receiving module 502 is further configured to receive an application certificate download request response message sent by the V2X security certificate management system, where the application certificate download request response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download request.
[0124] Figure 6 It is a structural diagram of a communication device 600 based on the secure transport layer protocol according to an exemplary embodiment. The communication device 500 based on the secure transport layer protocol is applied to a server.
[0125] like Figure 6 As shown, the communication device 600 based on the secure transport layer protocol may include:
[0126] A receiving module 601 is configured to receive a connection request of a secure transport layer TLS protocol sent by a client, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate;
[0127] A sending module 602 is configured to send a response message to the client based on the request, where the response message includes at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, where the signature information is obtained by the server using a private key corresponding to the server certificate to sign the handshake message, so that the client verifies the signature information based on the response message using a public key corresponding to the server certificate, and sends the V2X short certificate to the server based on the first certificate application information in the response message if the verification passes;
[0128] The verification module 603 is also used to verify the V2X short certificate sent by the client, and complete the TLS communication connection if the verification passes.
[0129] In one implementation, the handshake message may include information of the pre-shared key; the communication device 600 based on the secure transport layer protocol may also include a generation module;
[0130] The generation module is used to generate a shared key according to the pre-shared key and the temporary public key, and the shared key is used to encrypt the message transmitted to the client.
[0131] Thus, a connection request of the secure transport layer TLS protocol is sent from the client to the server, wherein the handshake message in the request includes the type extension of the client certificate and the type extension of the server certificate, the client certificate includes the V2X short certificate, and the server certificate includes at least one of the V2X short certificate and the X.509 certificate. In this way, the client performs identity authentication through the V2X short certificate, and the server can select the certificate type of the V2X short certificate or the X.509 certificate for identity authentication. Then, the client receives a response message sent by the server based on the request, and the response message includes at least one of the V2X short certificate and the X.509 certificate, information that the server uses the private key corresponding to the server certificate to sign the handshake message, and the first certificate application information. Then, the client verifies the signature information using the public key corresponding to the server certificate, and if the verification is successful, sends the V2X short certificate to the server based on the first certificate application information, so as to complete the TLS communication connection when the server verifies the V2X short certificate successfully. In this way, the client can directly use the V2X short certificate for TLS connection. The V2X short certificate can realize two-way TLS identity authentication between the server and the client. There is no need to establish an X.509 security certificate management system, which reduces costs. In addition, due to the certificate characteristics of the V2X short certificate itself, a faster connection will be achieved in the TLS connection, which can adapt to high timeliness scenario requirements.
[0132] Figure 7 A schematic diagram of the electronic hardware structure provided in an embodiment of the present application is shown.
[0133] The electronic device may include a processor 701 and a memory 702 storing computer program instructions.
[0134] Specifically, the processor 701 may include a central processing unit (CPU), or an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present application.
[0135] The memory 702 may include a large capacity memory for data or instructions. By way of example and not limitation, the memory 702 may include a hard disk drive (HDD), a floppy disk drive, a flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive or a combination of two or more of these. In appropriate cases, the memory 702 may include a removable or non-removable (or fixed) medium. In appropriate cases, the memory 702 may be inside or outside the integrated gateway disaster recovery device. In a specific embodiment, the memory 702 is a non-volatile solid-state memory.
[0136] The memory may include read-only memory (ROM), random access memory (RAM), magnetic disk storage media devices, optical storage media devices, flash memory devices, electrical, optical or other physical / tangible memory storage devices. Thus, typically, the memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to an aspect of the present disclosure.
[0137] The processor 701 implements any one of the communication methods based on the secure transport layer protocol in the above embodiments by reading and executing the computer program instructions stored in the memory 702 .
[0138] In one example, the electronic device may further include a communication interface 703 and a bus 710. Figure 7 As shown, the processor 701, the memory 702, and the communication interface 703 are connected via a bus 710 and communicate with each other.
[0139] The communication interface 703 is mainly used to implement communication between various modules, devices, units and / or equipment in the embodiments of the present application.
[0140] Bus 710 includes hardware, software or both, and the parts of the communication equipment based on the secure transport layer protocol are coupled to each other. For example, but not limitation, the bus may include accelerated graphics port (AGP) or other graphics bus, enhanced industrial standard architecture (EISA) bus, front side bus (FSB), hypertransport (HT) interconnection, industrial standard architecture (ISA) bus, infinite bandwidth interconnection, low pin count (LPC) bus, memory bus, micro channel architecture (MCA) bus, peripheral component interconnection (PCI) bus, PCI-Express (PCI-X) bus, serial advanced technology attachment (SATA) bus, video electronics standard association local (VLB) bus or other suitable bus or two or more of these combinations. In appropriate cases, bus 710 may include one or more buses. Although the present application embodiment describes and shows a specific bus, the application considers any suitable bus or interconnection.
[0141] The electronic device can execute the communication method based on the secure transport layer protocol in the embodiment of the present application based on sending a connection request of the secure transport layer TLS protocol to the server, the request includes a handshake message, and the handshake message includes the type extension name of the client certificate and the type extension name of the server certificate, thereby realizing the combination Figure 1 A communication method based on the Transport Layer Security protocol is described.
[0142] In addition, in combination with the communication method based on the secure transport layer protocol in the above embodiments, the embodiments of the present application may provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when the computer program instructions are executed by the processor, any one of the communication methods based on the secure transport layer protocol in the above embodiments is implemented.
[0143] It should be clear that the present application is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present application is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present application.
[0144] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware or a combination thereof. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present application are programs or code segments that are used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link by a data signal carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, optical fiber media, radio frequency (RF) links, etc. The code segment can be downloaded via a computer network such as the Internet, an intranet, etc.
[0145] It should also be noted that the exemplary embodiments mentioned in this application describe some methods or systems based on a series of steps or devices. However, this application is not limited to the order of the above steps, that is, the steps can be performed in the order mentioned in the embodiment, or in a different order from the embodiment, or several steps can be performed simultaneously.
[0146] Aspects of the present disclosure are described above with reference to the flowchart and / or block diagram of the method, device (system) and computer program product according to the embodiment of the present disclosure. It should be understood that each box in the flowchart and / or block diagram and the combination of each box in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device to produce a machine so that these instructions executed by the processor of the computer or other programmable data processing device enable the implementation of the function / action specified in one or more boxes of the flowchart and / or block diagram. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field programmable logic circuit. It can also be understood that each box in the block diagram and / or flowchart and the combination of boxes in the block diagram and / or flowchart can also be implemented by dedicated hardware that performs a specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions.
[0147] The above is only a specific implementation of the present application. Those skilled in the art can clearly understand that for the convenience and simplicity of description, the specific working processes of the systems, modules and units described above can refer to the corresponding processes in the aforementioned method embodiments, and will not be repeated here. It should be understood that the protection scope of the present application is not limited to this. Any technician familiar with the technical field can easily think of various equivalent modifications or replacements within the technical scope disclosed in this application, and these modifications or replacements should be included in the protection scope of this application.
Claims
1. A communication method based on a secure transport layer protocol, characterized in that: The method is applied to a client and includes: Sending a connection request of the secure transport layer TLS protocol to the server, the request comprising a handshake message, the handshake message comprising a type extension of the client certificate and a type extension of the server certificate, the client certificate comprising a V2X short certificate, and the server certificate comprising at least one of a V2X short certificate and an X.509 certificate; receiving a response message sent by the server based on the request, the response message including at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the first certificate application information is used to apply for the client certificate, and the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate; Based on the response message, verify the signature information using the public key corresponding to the server certificate; If the verification is successful, based on the first certificate application information in the response message, a V2X short certificate is sent to the server, where the V2X short certificate is a certificate in the client certificate, so as to complete the TLS communication connection if the server verifies the V2X short certificate successfully.
2. The method according to claim 1, characterized in that The response message includes a temporary public key generated by the server; the method further includes: A shared key is generated based on the temporary public key, and the shared key is used to encrypt a message transmitted to the server.
3. The method according to claim 1, characterized in that: Before sending a connection request of the Transport Security Layer TLS protocol to the server, the method further includes: Sending second certificate application information to a preset authorization agency, wherein the second certificate application information includes a certificate type and a verification request, and the verification request includes a public key, so that the authorization agency can verify the second certificate application information based on the public key; Receive an X.509 certificate corresponding to the certificate type sent by the authorization agency when the verification is successful.
4. The method according to claim 1, characterized in that: Before sending a connection request of the Transport Security Layer TLS protocol to the server, the method further includes: Sending an application certificate application request to a preset V2X security certificate management system, wherein the application certificate application request includes a signature of a private key of an identity certificate, so that the V2X security certificate management system verifies the application certificate application request based on the public key of the identity certificate, and generates application certificate application response information after the verification passes; Sending an application certificate download request to the V2X security certificate management system based on the application certificate request response message sent by the V2X security certificate management system; An application certificate download request response message sent by the V2X security certificate management system is received, where the application certificate download request response message includes the application certificate downloaded by the V2X security certificate management system based on the application certificate download request.
5. A communication method based on a secure transport layer protocol, characterized in that: The method is applied to the server, and includes: Receiving a connection request of a secure transport layer TLS protocol sent by a client, the request comprising a handshake message, the handshake message comprising a type extension of a client certificate and a type extension of a server certificate, the client certificate comprising a V2X short certificate, and the server certificate comprising at least one of a V2X short certificate and an X.509 certificate; Sending a response message to the client based on the request, the response message including at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, the first certificate application information being used to apply for the client certificate, the signature information being obtained by the server signing the handshake message using a private key corresponding to the server certificate, so that the client verifies the signature information based on the response message using a public key corresponding to the server certificate, and, if the verification passes, sending a V2X short certificate to the server based on the first certificate application information in the response message, the V2X short certificate being the certificate in the client certificate; The V2X short certificate sent by the client is verified, and if the verification passes, the TLS communication connection is completed.
6. The method according to claim 5, characterized in that The handshake message includes information of a pre-shared key; and the method further includes: A shared key is generated according to the pre-shared key and a temporary public key generated by the server, and the shared key is used to encrypt a message transmitted to the client.
7. A communication device based on a secure transport layer protocol, characterized in that: The device is applied to a client and includes: A sending module, configured to send a connection request of a secure transport layer TLS protocol to a server, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate; a receiving module, configured to receive a response message sent by the server based on the request, wherein the response message includes at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the first certificate application information is used to apply for the client certificate, and the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate; A verification module, used to verify the signature information based on the response message using the public key corresponding to the server certificate; The sending module is further used to send a V2X short certificate to the server based on the first certificate application information in the response message when the verification is successful, wherein the V2X short certificate is a certificate in the client certificate, so as to complete the TLS communication connection when the server verifies the V2X short certificate successfully.
8. A communication device based on a secure transport layer protocol, characterized in that: The device is applied to a server, and includes: A receiving module, configured to receive a connection request of a secure transport layer TLS protocol sent by a client, wherein the request includes a handshake message, the handshake message includes a type extension of a client certificate and a type extension of a server certificate, the client certificate includes a V2X short certificate, and the server certificate includes at least one of a V2X short certificate and an X.509 certificate; a sending module, configured to send a response message to the client based on the request, wherein the response message includes at least one server certificate of a V2X short certificate and an X.509 certificate, signature information, and first certificate application information, wherein the first certificate application information is used to apply for the client certificate, and the signature information is obtained by the server signing the handshake message using a private key corresponding to the server certificate, so that the client verifies the signature information based on the response message using a public key corresponding to the server certificate, and, if the verification passes, sends the V2X short certificate to the server based on the first certificate application information in the response message, wherein the V2X short certificate is a certificate in the client certificate; The sending module is used to verify the V2X short certificate sent by the client, and complete the TLS communication connection if the verification passes.
9. An electronic device, characterized in that: The device comprises: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the communication method based on the secure transport layer protocol as described in any one of claims 1-6.
10. A computer storage medium, characterized in that: The computer storage medium stores computer program instructions, and when the computer program instructions are executed by the processor, the communication method based on the secure transport layer protocol as described in any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Bidirectional authentication method and communication system
CN110380852A
Communication connection method, device, equipment, medium and computer program product
CN117812567A