Data transmission methods, devices, electronic equipment and storage media

By generating temporary public-private key pairs and a standard public key, and combining them with symmetric keys and interactive identification information, an interactive key is generated, which solves the problem of low security of symmetric keys and achieves high security for data transmission and authorization verification.

CN115865460BActive Publication Date: 2026-04-03YUANFENG TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Symmetric key encryption methods are easily cracked and have low security.

Method used

Generate a first temporary public-private key pair. Combine the first standard public key, symmetric key, and interaction identification information to generate an interaction key, including an authentication key and a secure channel key. Generate authentication information using the authentication key and obtain and decrypt the interaction data when the verification is successful.

Benefits of technology

It enables the combined use of symmetric and asymmetric keys, improving the security of data transmission and enhancing the security of data transmission authorization verification and encryption/decryption processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115865460B_ABST
    Figure CN115865460B_ABST
Patent Text Reader

Abstract

This invention discloses a data transmission method, apparatus, electronic device, and storage medium. The method includes: generating a first temporary public-private key pair, the first temporary public-private key pair including a first temporary public key and a first temporary private key; obtaining a first standard public key, a symmetric key, and interaction identification information; generating an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information, the interaction key including an authentication key and a secure channel key; generating first authentication information based on the authentication key; and sending the first authentication information, the first temporary public key, and the interaction identification information to a second interacting party, so that the second interacting party verifies the first authentication information, and upon successful verification, obtains and decrypts the interaction data encrypted based on the secure channel key transmitted by the first interacting party. This invention achieves the combined use of symmetric and asymmetric keys, improving data transmission security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data transmission technology, and in particular to a data transmission method, apparatus, electronic device and storage medium. Background Technology

[0002] Encryption of data is widely used during data transmission.

[0003] Currently, data can be encrypted using symmetric key encryption.

[0004] However, symmetric key encryption is easily cracked and has low security. Summary of the Invention

[0005] This invention provides a data transmission method, apparatus, electronic device, and storage medium, which improves the security of data transmission.

[0006] According to one aspect of the present invention, a data transmission method is provided, characterized in that it is applied to a first interacting party, and the method includes:

[0007] Generate a first temporary public-private key pair, which includes a first temporary public key and a first temporary private key;

[0008] Obtain the first standard public key, symmetric key, and interaction identification information;

[0009] Based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information, an interaction key is generated, which includes an authentication key and a secure channel key.

[0010] Generate the first authentication information based on the authentication key;

[0011] The first authentication information, the first temporary public key, and the interaction identifier information are sent to the second interaction party so that the second interaction party can verify the first authentication information and, upon successful verification, obtain and decrypt the interaction data transmitted by the first interaction party that is encrypted based on the secure channel key.

[0012] According to another aspect of the present invention, a data transmission method is provided, characterized in that it is applied to a second interacting party, and the method includes:

[0013] Receive the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party;

[0014] Obtain the first standard public-private key pair and symmetric key, and generate an interaction key based on the first temporary public key, the first standard private key, the symmetric key and interaction identification information. The interaction key includes an authentication key and a secure channel key.

[0015] The first authentication information is verified based on the authentication key;

[0016] Upon successful verification, the encrypted interaction data sent by the first interacting party is retrieved;

[0017] The encrypted interactive data is decrypted using the secure channel key to obtain the interactive data.

[0018] According to another aspect of the present invention, a data transmission apparatus is provided, characterized in that it is applied to a first interacting party, and the apparatus comprises:

[0019] The first temporary key generation module is used to generate a first temporary public-private key pair, which includes a first temporary public key and a first temporary private key.

[0020] The first standard key acquisition module is used to acquire the first standard public key, symmetric key, and interaction identification information;

[0021] The first interactive key generation module is used to generate an interactive key based on the first temporary private key, the first standard public key, the symmetric key and interactive identification information. The interactive key includes an authentication key and a secure channel key.

[0022] The first authentication information generation module is used to generate the first authentication information based on the authentication key;

[0023] The first authentication information sending module is used to send the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, so that the second interaction party can verify the first authentication information and, when the verification is successful, obtain and decrypt the interaction data transmitted by the first interaction party based on the secure channel key encryption.

[0024] According to another aspect of the present invention, a data transmission apparatus is provided, characterized in that it is applied to a second interacting party, and the apparatus comprises:

[0025] The first authentication information receiving module is used to receive the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interaction party.

[0026] The second interactive key generation module is used to obtain the first standard public-private key pair and the symmetric key, and generate an interactive key based on the first temporary public key, the first standard private key, the symmetric key and interactive identification information. The interactive key includes an authentication key and a secure channel key.

[0027] The first authentication information verification module is used to verify the first authentication information based on the authentication key;

[0028] The encrypted interaction data acquisition module is used to acquire the encrypted interaction data sent by the first interacting party when the verification is successful.

[0029] The encrypted interactive data decryption module is used to decrypt the encrypted interactive data using a secure channel key to obtain the interactive data.

[0030] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:

[0031] At least one processor; and

[0032] A memory communicatively connected to the at least one processor; wherein,

[0033] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data transmission method described in any embodiment of the present invention.

[0034] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the data transmission method described in any embodiment of the present invention.

[0035] The technical solution of this invention, through generating a first temporary public-private key pair (including a first temporary public key and a first temporary private key), obtains a first standard public key, a symmetric key, and interaction identification information; generates an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information, the interaction key including an authentication key and a secure channel key; generates first authentication information based on the authentication key; and sends the first authentication information, the first temporary public key, and the interaction identification information to a second interaction party, enabling the second interaction party to verify the first authentication information and, upon successful verification, acquire and decrypt the interaction data encrypted based on the secure channel key transmitted by the first interaction party. This solves the problem of low security of symmetric keys, realizes the integrated use of symmetric and asymmetric keys, and improves the security of data transmission.

[0036] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0038] Figure 1This is a flowchart of a data transmission method provided according to Embodiment 1 of the present invention;

[0039] Figure 2 This is a flowchart of a data transmission method provided according to Embodiment 2 of the present invention;

[0040] Figure 3 This is a signaling flowchart of a data transmission method according to Embodiment 3 of the present invention;

[0041] Figure 4 This is a signaling flowchart of a data transmission method according to Embodiment 3 of the present invention;

[0042] Figure 5 This is a schematic diagram of a data transmission device according to Embodiment 4 of the present invention;

[0043] Figure 6 This is a schematic diagram of the structure of a data transmission device according to Embodiment 5 of the present invention;

[0044] Figure 7 This is a schematic diagram of the structure of an electronic device that implements the data transmission method of this invention. Detailed Implementation

[0045] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0046] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0047] Example 1

[0048] Figure 1This is a flowchart illustrating a data transmission method according to Embodiment 1 of the present invention. This embodiment is applicable to situations requiring encrypted data transmission. The method can be executed by a data transmission device, which can be implemented in hardware and / or software. This data transmission device can be configured in an electronic device that carries data transmission functionality, particularly a client device and a server device. The client device can include a mobile terminal, computer, or vehicle-mounted terminal, etc., and the server device can include a vehicle server, etc. The mobile terminal can include a microcontroller device and a mobile phone, etc. The microcontroller device can include a Bluetooth MCU (Micro Control Unit), etc.

[0049] See Figure 1 The data transmission method shown, applied to the first interacting party, includes:

[0050] S110. Generate a first temporary public-private key pair, which includes a first temporary public key and a first temporary private key.

[0051] The first and second interacting parties transmit data. Typically, the data transmitted between them requires authorized devices to access and process it. The first and second interacting parties need to verify each other's identities; only after successful verification can either party access the data transmitted by the other. The first and second interacting parties can be electronic devices, and their specific types are not specifically limited. For example, the first interacting party may include a mobile terminal or a vehicle server, etc.

[0052] The first temporary public-private key pair can be a public-private key pair temporarily generated by the first interacting party. Optionally, the first interacting party can generate the first temporary public-private key pair according to the Elliptic Curve Cryptography (ECC) algorithm. For example, the first temporary public-private key pair can be generated according to the KeyPair function.

[0053] S120. Obtain the first standard public key, symmetric key, and interaction identification information.

[0054] The first standard public key can be the public key from the standard public-private key pair of the second interacting party. Typically, if the second interacting party remains unchanged, the first standard public-private key pair remains constant. Compared to the first temporary public-private key pair, the first temporary public-private key pair can be generated temporarily, while the first standard public-private key pair usually remains unchanged. That is, different temporary first public-private key pairs are generated temporarily in different interactions, while the first standard public-private key pair remains the same across different interactions. The first standard public-private key pair can be an asymmetric key. The first standard public-private key pair can include a first standard public key and a first standard private key. The second interacting party or a third party sends the first standard public key to the first interacting party. The symmetric key can be generated by any interacting party or by a third party and sent to the interacting party that needs to transmit data. Optionally, the symmetric keys of the two interacting parties transmitting data can be the same; they can also be different, but the two parties can generate the other party's symmetric key based on information. Specifically, the symmetric key of the other party can be derived from the symmetric key of one interacting party and the interaction identification information. The symmetric keys of the two interacting parties remain constant throughout different interactions. Interaction identification information may include the identification information of the first interacting party and / or the identification information of the second interacting party. For example, identification information includes ID (Identify).

[0055] S130. Generate an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information. The interaction key includes an authentication key and a secure channel key.

[0056] An interaction key can be used by the first and second interacting parties to transmit interactive data. An authentication key can be used to verify the data transmission permissions of the interacting parties. A secure channel key can be used to encrypt and decrypt the secure channel. The secure channel is used for securely transmitting interactive data.

[0057] Specifically, the first temporary private key, the first standard public key, the symmetric key, and the interaction identifier information are used as input parameters, and the interaction key is generated using Key Derivation Functions (KDF).

[0058] S140. Generate the first authentication information based on the authentication key.

[0059] The first authentication information can be used to verify the data transmission rights of the first interacting party. The second interacting party verifies the first authentication information to determine whether the second interacting party has the right to obtain the data of the first interacting party.

[0060] Specifically, the CMAC (Cipher Block Chaining-Message Authentication Code) algorithm can be used on the authentication key to generate the first authentication information.

[0061] S150. Send the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party so that the second interaction party can verify the first authentication information and, upon successful verification, obtain and decrypt the interaction data transmitted by the first interaction party that is encrypted based on the secure channel key.

[0062] Optionally, the interaction identification information sent by the first interacting party to the second interacting party may include the identification information of both the first and second interacting parties. Since the second interacting party locally stores its own identification information, the interaction identification information sent by the first interacting party to the second interacting party may also include only the identification information of the first interacting party.

[0063] When the second party confirms that the authentication information verification is successful, it can receive the interactive data encrypted based on the secure channel key transmitted by the first party. It then uses the generated secure channel key to decrypt the encrypted interactive data, obtain the interactive data, and perform post-processing.

[0064] The technical solution of this invention generates a first temporary public-private key pair, including a first temporary public key and a first temporary private key; obtains a first standard public key, a symmetric key, and interaction identification information; generates an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information, the interaction key including an authentication key and a secure channel key, thus realizing the fusion use of symmetric and asymmetric keys; generates first authentication information based on the authentication key; and sends the first authentication information, the first temporary public key, and the interaction identification information to the second interaction party, enabling the second interaction party to verify the first authentication information. Upon successful verification, the second interaction party acquires and decrypts the interaction data encrypted based on the secure channel key transmitted by the first interaction party. The generation of the first authentication information through the authentication key enables the second interaction party to verify the data transmission permission of the first interaction party. Based on the secure channel key, the encryption of the interaction data by the first interaction party and the decryption of the encrypted interaction data by the second interaction party are realized, thereby achieving data transmission from the first interaction party to the second interaction party and improving the security of data transmission.

[0065] In an optional embodiment of the present invention, the interaction key is generated based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information. Specifically, this is achieved by generating a first shared secret based on the first temporary private key and the first standard public key, and generating the interaction key based on the first shared secret, the symmetric key, and the interaction identification information.

[0066] Since the first temporary private key is different for each interaction, the first shared secret generated each time by mixing the first temporary private key and the first standard public key is random. This randomly generated first shared secret is used to generate the interaction key, further increasing the complexity of the interaction key and thus improving the security of data transmission.

[0067] Specifically, the first shared secret can be generated by using the ECDH (Elliptic-curve Diffie–Hellman) algorithm on the first temporary private key and the first standard public key; then, the first shared secret, the symmetric key, and the interaction identification information can be used as input parameters to generate the interaction key using the key derivation function.

[0068] This scheme generates a first shared secret based on a first temporary private key and a first standard public key, thereby achieving hybrid encryption of the first temporary public-private key pair of the first interacting party and the first standard public-private key pair of the second interacting party. Based on the first shared secret, the symmetric key, and the interaction identification information, an interaction key is generated, which increases the complexity of the interaction key and further enhances the security of data transmission.

[0069] Optionally, the transmission of interactive data between the first and second interacting parties can be achieved by the second interacting party generating a second temporary public-private key pair after triggering authentication conditions. This second temporary public-private key pair includes a second temporary public key and a second temporary private key. The second interacting party then sends the second temporary public key to the first interacting party. Upon receiving the second temporary public key, the first interacting party generates an interaction key, thereby enabling data transmission between the two parties. For example, the first interacting party can be a mobile terminal, and the second interacting party can be an in-vehicle terminal.

[0070] In an optional embodiment of the present invention, before generating the interaction key based on the first shared secret, the symmetric key, and the interaction identifier information, the method further includes: receiving a second temporary public key sent by the second interacting party. Generating the interaction key based on the first shared secret, the symmetric key, and the interaction identifier information is specifically defined as: generating a second shared secret based on the first temporary private key and the second temporary public key; and generating the interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

[0071] The second temporary public-private key pair can be a public-private key pair temporarily generated by the second interacting party. This pair can be generated temporarily each time an interaction occurs. The description of the second temporary public-private key pair can be referenced from that of the first temporary public-private key pair. The second temporary public-private key pair can include a second temporary public key and a second temporary private key. The second interacting party sends the second temporary public key to the first interacting party. The second shared secret is used to mix the first temporary private key and the second temporary public key. The second shared secret and the first shared secret are generated in the same way. However, the second shared secret is a mixture of the first interacting party's first temporary private key and the second interacting party's second temporary public key, while the first shared secret is a mixture of the first interacting party's first temporary private key and the second interacting party's first standard public key. Since the temporary public-private key pairs are generated temporarily each time, the second shared secret generated using two temporary public-private key pairs increases the randomness across different interactions. Compared to the first shared secret generated using a single temporary public-private key pair, the second shared secret has higher randomness. The first temporary private key and the second temporary public key are mixed to obtain the second shared secret. Further processing of the first and second temporary private keys, and then generating an interaction key based on the second shared secret, increases the complexity of the interaction key generation process and further ensures the security of the interaction key. Generating the interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information further increases the complexity of the interaction key.

[0072] Specifically, the first interacting party can receive the second temporary public key sent by the second interacting party. The first temporary private key and the second temporary public key can be used with the ECDH (Elliptic-curve Diffie-Hellman, key negotiation) algorithm to generate a second shared secret. The first shared secret, the second shared secret, the symmetric key, and the interaction identifier information can be used as input parameters, and a key derivation function can be used to generate the interaction key.

[0073] This scheme receives a second temporary public key sent by the second interacting party, and generates a second shared secret based on the first temporary private key and the second temporary public key, thus achieving hybrid encryption of the first interacting party's first temporary public-private key pair and the second interacting party's second temporary public-private key pair. Furthermore, it generates an interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information, further increasing the complexity of the interaction key. Simultaneously, the second temporary public-private key pair, incorporated into the generation of the interaction key, provides forward security for subsequent data transmission, further enhancing the security of data transmission.

[0074] In an optional embodiment of the present invention, after sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the method further includes: receiving the second authentication information sent by the second interaction party; verifying the second authentication information using an authentication key; encrypting the interaction data using a secure channel key and transmitting it to the second interaction party when the verification passes; obtaining the encrypted interaction data sent by the second interaction party and decrypting it to obtain the interaction data sent by the second interaction party.

[0075] The second authentication information can be used to verify the data transmission permissions of the second interacting party. Verification of the second authentication information determines whether the first interacting party has the permission to access the data from the second interacting party. The first authentication information can be used to verify the data transmission permissions of the first interacting party. The first and second authentication information are the authentication information of the two interacting parties involved in data transmission. Through the verification of the first authentication information by the second interacting party and the verification of the second authentication information by the first interacting party, mutual verification between the first and second interacting parties is completed, achieving secure data transmission between the first and second interacting parties.

[0076] Specifically, the authentication key generated by the second party is used to verify the first authentication information. If the authentication key generated by the second party is the same as the authentication key contained in the first authentication information, the verification passes; otherwise, the verification fails. If the verification passes, the second party has the right to transmit data from the first party. The second party can use its own generated secure channel key to decrypt the interactive data transmitted by the first party and obtain the interactive data transmitted by the first party. The authentication key generated by the first party is used to verify the second authentication information. If the authentication key generated by the first party is the same as the authentication key contained in the second authentication information, the verification passes; otherwise, the verification fails. If the verification passes, the first party has the right to transmit data from the second party. The first party can use its own generated secure channel key to decrypt the interactive data transmitted by the second party and obtain the interactive data transmitted by the second party.

[0077] This scheme achieves mutual verification between the first and second parties by receiving the second authentication information sent by the second interaction party and verifying the second authentication information using an authentication key. When the verification is successful, the first interaction party encrypts the interaction data using a secure channel key and transmits it to the second interaction party. The first interaction party then obtains the encrypted interaction data sent by the second interaction party and decrypts it, thus achieving secure data transmission between the first and second interaction parties.

[0078] Optionally, the transmission of interactive data between the first and second interacting parties can be a unidirectional process where the first interacting party sends interactive data to the second interacting party. This interactive data can be offline update data. For example, the first interacting party can be a vehicle server, and the second interacting party can be an in-vehicle terminal.

[0079] In an optional embodiment of the present invention, before sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the method further includes: obtaining interaction verification information; obtaining offline data and encrypting it using a secure channel key to obtain encrypted interaction data. Simultaneously with sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the method further includes: sending the interaction verification information and the encrypted interaction data to the second interaction party, so that the second interaction party verifies the interaction verification information, and when the interaction verification information passes verification, verifies the first authentication information, and when the first authentication information passes verification, decrypts and processes the encrypted interaction data.

[0080] Interaction verification information can be used to verify the identity of the second interacting party. Interaction verification information is sent to the second interacting party to confirm whether the party to whom the first interacting party intends to exchange data is indeed the second interacting party. Interaction verification information differs from the first authentication information. Interaction verification information is used to verify the second interacting party before generating the interaction key. The first authentication information, however, is used to verify the second interacting party after the interaction verification information has passed, specifically to determine whether the second interacting party has the authority to access the data. Offline data can be interaction data that the first interacting party can send offline to the second interacting party. Before sending offline data, the second interacting party does not need to send data to the first interacting party; that is, the first interacting party does not need to pay attention to the status of the second interacting party to send data. For example, if the second interacting party is a vehicle terminal, the interaction verification information can be the vehicle's authentication serial number. Offline data is data used by the second interacting party to update local data.

[0081] Specifically, while sending the first authentication information, the first temporary public key, and the interaction identifier information to the second party, interaction verification information and encrypted interaction data can also be sent to the second party. The second party can first verify the interaction verification information. If the interaction verification information passes the verification, it can then generate an interaction key to verify the first authentication information. If the first authentication information passes the verification, it can then decrypt and process the encrypted interaction data.

[0082] This scheme obtains offline data by acquiring interaction verification information and encrypting it using a secure channel key, resulting in encrypted interaction data. Simultaneously, it sends the interaction verification information and encrypted interaction data to the second party, along with the first authentication information, the first temporary public key, and the interaction identifier information. This allows the second party to verify the interaction verification information. If the interaction verification information passes, the first authentication information is verified, and if the first authentication information passes, the encrypted interaction data is decrypted and processed. By sending offline data to the second party, one-way offline updates of data from the first party to the second party are achieved. Furthermore, by sending interaction verification information to the second party, the first party adds verification to the first authentication information, achieving dual verification of the second party and improving the security of data transmission from the first party to the second party.

[0083] Example 2

[0084] Figure 2 This is a flowchart illustrating a data transmission method according to Embodiment 2 of the present invention. This embodiment is applicable to situations requiring encrypted data transmission. The method can be executed by a data transmission device, which can be implemented in hardware and / or software. This data transmission device can be configured in an electronic device carrying data transmission functionality, particularly a client device and a server device. The client device can include a mobile terminal, computer, or vehicle-mounted terminal, etc., and the server device can include a vehicle server, etc. The mobile terminal can include a microcontroller device and a mobile phone, etc. The microcontroller device can include a Bluetooth MCU (Micro Control Unit), etc.

[0085] See Figure 2 The data transmission method shown, applied to the second interacting party, includes:

[0086] S210: Receive the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party.

[0087] The second party transmits data with the first party. After the data transmission permission verification is passed, the second party can obtain the data transmitted by the first party. The first authentication information is used to verify the data transmission permission to the first party. The first temporary public key can be a public key temporarily generated by the first party. The interaction identification information can include the identification information of both the first and second parties, or it can only include the identification information of the first party, specifically consistent with the interaction identification information sent by the first party.

[0088] S220. Obtain the first standard public-private key pair and the symmetric key, and generate an interaction key based on the first temporary public key, the first standard private key, the symmetric key and the interaction identifier information. The interaction key includes an authentication key and a secure channel key.

[0089] The first standard public-private key pair can be a public-private key pair generated by the second interacting party. The second interacting party's first standard public-private key pair can include a first standard public key and a first standard private key. Typically, the first standard public-private key pair remains fixed. Compared to the first standard public-private key pair, the first temporary public key can be generated temporarily, while the first standard public-private key pair usually remains unchanged. The symmetric key can be generated by either interacting party or by a third party and distributed to the interacting parties that need to transmit data. Optionally, when the symmetric keys of the two interacting parties are the same, the symmetric key can be directly the symmetric key local to the interacting party; for example, the symmetric key can be the symmetric key of the second interacting party. When the symmetric keys of the two interacting parties are different, the symmetric key of the other interacting party can be derived from the symmetric key local to one interacting party and the identification information of the other interacting party. The symmetric keys of the two interacting parties remain unchanged in different interaction processes. The interaction key can be the key required by the first and second interacting parties to transmit interactive data. The authentication key can be used to authenticate the interacting parties' authorization to transmit data. The secure channel key can be used to encrypt and decrypt the secure channel.

[0090] Specifically, the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information are used as input parameters, and the interaction key is generated using Key Derivation Functions (KDF).

[0091] S230. Verify the first authentication information based on the authentication key.

[0092] Specifically, the first authentication information can be verified using the authentication key generated by the second party. Verification information is generated based on the authentication key generated by the second party. If the generated verification information is the same as the first authentication information, the second party has passed the authentication of the first party's identity and has the right to obtain the data transmission of the first party. Otherwise, the verification fails.

[0093] By verifying the first authentication information based on the authentication key of the second party, it can be confirmed whether the second party has the authority to obtain the data transmitted by the first party; on the other hand, it can be ensured that the interaction key generated by the second party is the same as the interaction key generated by the first party, thus ensuring that the interaction data sent by the first party can be decrypted through the secure channel key generated by the second party.

[0094] S240. Upon successful verification, obtain the encrypted interaction data sent by the first interacting party.

[0095] Specifically, if the verification passes, the second party has the authority to obtain the encrypted interaction data sent by the first party, and the second party obtains the encrypted interaction data sent by the first party.

[0096] S250. Use the secure channel key to decrypt the encrypted interactive data to obtain the interactive data.

[0097] Specifically, the encrypted interactive data can be decrypted using the secure channel key generated by the second party to obtain the interactive data.

[0098] The technical solution of this invention receives first authentication information, a first temporary public key, and interaction identifier information sent by a first interacting party; obtains a first standard public-private key pair and a symmetric key; and generates an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information. The interaction key includes an authentication key and a secure channel key. By generating the interaction key for the second interacting party, the second interacting party achieves the fusion use of symmetric and asymmetric keys. The first authentication information is verified based on the authentication key. If the verification passes, the encrypted interaction data sent by the first interacting party is obtained, thus realizing the verification of the first authentication information by the second interacting party. The encrypted interaction data is decrypted using the secure channel key to obtain the interaction data, thereby realizing the process of the second interacting party obtaining the interaction data transmitted by the first interacting party and improving the security of data transmission.

[0099] Optionally, the transmission of interactive data between the first and second interacting parties can be achieved by the second interacting party generating a second temporary public-private key pair after triggering authentication conditions and sending the second temporary public key to the first interacting party. Upon receiving the second temporary public key, the first interacting party generates an interaction key and, based on the authentication key, generates first authentication information and sends the first authentication information to the second interacting party. Upon receiving the first authentication information, the second interacting party generates an interaction key and verifies the first authentication information based on the authentication key. If the verification passes, data transmission between the second and first interacting parties is achieved. For example, the first interacting party can be a mobile terminal, and the second interacting party can be an in-vehicle terminal.

[0100] In an optional embodiment of the present invention, before receiving the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the method further includes: generating a second temporary public-private key pair and sending the second temporary public key to the first interacting party. The generation of the interaction key based on the first temporary public key, the second temporary private key, the first standard public-private key pair, the symmetric key, and the interaction identifier information is specifically defined as: generating a first shared secret based on the first temporary public key and the first standard private key; obtaining the second temporary private key; generating a second shared secret based on the first temporary public key and the second temporary private key; and generating the interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

[0101] The first shared secret is used to mix the first temporary public-private key pair and the first standard public-private key pair. The second shared secret is used to mix the first temporary public-private key pair and the second temporary public-private key pair. First, the first temporary public key and the first standard private key are mixed to obtain the first shared secret. Then, the first temporary public key and the second temporary private key are mixed to obtain the second shared secret. Further processing of the first and second shared secrets yields the interaction key. This increases the complexity of the interaction key generation process for the second interacting party. Simultaneously, unifying the interaction key generation process of the second interacting party with that of the first interacting party ensures that the data transmitted by the first interacting party can be verified and decrypted using the interaction key generated by the second interacting party.

[0102] Due to the characteristics of the ECDH (Elliptic-curve Diffie-Hellman, key negotiation) algorithm, although both the first and second parties generate a first shared secret based on a first temporary private key and a first standard public key, the first shared secret generated by the first and second parties is identical. Similarly, the second shared secret generated by the first and second parties is also identical. Therefore, the interaction key generated by the second party can verify the first party's initial authentication information and decrypt the encrypted interaction data from the first party.

[0103] Specifically, the second interacting party can generate a second temporary public-private key pair when the authentication conditions are triggered. This second temporary public-private key pair can include a second temporary public key and a second temporary private key. For example, if the second interacting party is a vehicle-mounted terminal, the authentication conditions can include: approaching the vehicle, unlocking the vehicle, opening the vehicle door, or triggering a command to start the vehicle, etc.

[0104] Specifically, the ECDH algorithm can be applied to the first standard private key in the first temporary public key and the first standard public-private key pair to generate the first shared secret. The ECDH algorithm can then be applied to the second temporary private key in the first and second temporary public-private key pairs to generate the second shared secret. Finally, the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information can be used as input parameters, and a key derivation function can be employed to generate the interaction key.

[0105] Optionally, after the second party verifies the first authentication information, the method further includes: generating second authentication information and sending it to the first party so that the first party can verify the second authentication information, and after the verification is successful, enabling mutual transmission of interactive data between the first party and the second party.

[0106] This scheme generates a second temporary public-private key pair and sends it to the first interacting party before receiving the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party. Based on the first temporary public key and the first standard private key, a first shared secret is generated, and the second temporary public-private key pair is obtained. Based on the first temporary public key and the second temporary private key, a second shared secret is generated. Finally, based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information, an interaction key is generated. This increases the complexity of the interaction key and ensures consistency between the process of the second interacting party generating the interaction key and the process of the first interacting party generating the interaction key. This guarantees that the second interacting party can verify the first authentication information and decrypt the interaction data encrypted by the first interacting party. Since both parties simultaneously generate temporary public-private key pairs to generate the interaction key, subsequent data transmission based on the secure channel possesses forward security, further improving the security of data transmission between the first and second interacting parties.

[0107] Optionally, the transmission of interactive data between the first and second interacting parties can be a unidirectional process where the first interacting party sends interactive data to the second interacting party. This interactive data can be offline update data. For example, the first interacting party can be a vehicle server, and the second interacting party can be an in-vehicle terminal.

[0108] In an optional embodiment of the present invention, upon receiving the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the method further includes: acquiring the interaction verification information and encrypted interaction data sent by the first interacting party; acquiring pre-stored local verification information and verifying the interaction verification information. Specifically, an interaction key is generated based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information. This is further specified as: when the interaction verification information passes verification, an interaction key is generated based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information. After decrypting the encrypted interaction data using the secure channel key to obtain the interaction data, the method further includes: updating the local data using the interaction data.

[0109] Interaction verification information can be used to verify the identity of the second interacting party. The interaction verification information sent by the first interacting party is obtained to confirm whether the party to which the first interacting party intends to exchange data is the second interacting party. Local verification information and interaction verification information are stored separately by the two parties exchanging data. By comparing the local verification information and the interaction verification information, a preliminary verification of the second interacting party is achieved. The interaction verification information differs from the first authentication information; it is used to verify the second interacting party before generating the interaction key. The first authentication information, however, is used to verify the second interacting party after the interaction verification information has passed, specifically verifying whether the second interacting party has the permission to access data. Interaction data can include offline data. Updating local data with interaction data can be understood as updating the second interacting party's local data with offline data. Offline data can be interaction data that the first interacting party can send offline to the second interacting party.

[0110] Specifically, the interaction verification information sent by the first interacting party can be compared with the local verification information pre-stored by the second interacting party. If they are the same, the interaction verification information passes; otherwise, the verification fails. If the interaction verification information passes, the first temporary public key, the first standard private key in the first standard public-private key pair, the symmetric key, and the interaction identifier information can be used as input parameters to generate the interaction key using Key Derivation Functions (KDF).

[0111] This scheme, upon receiving the first authentication information, first temporary public key, and interaction identifier information from the first interacting party, simultaneously obtains the interaction verification information and encrypted interaction data sent by the first interacting party, acquires pre-stored local verification information, and verifies the interaction verification information. If the interaction verification information passes verification, an interaction key is generated based on the first temporary public key, first standard private key, symmetric key, and interaction identifier information. The pre-stored local verification information is used to verify the interaction verification information, thus achieving preliminary verification of the second interacting party before generating the interaction key. After decrypting the encrypted interaction data using the secure channel key, the local data is updated using the interaction data. This approach balances data transmission security with offline updates to the local data.

[0112] In the above embodiments, the first interaction party and the second interaction party can be interchanged. It can be understood that the first interaction party may also include an in-vehicle terminal, etc. The second interaction party may also include a mobile terminal or a vehicle server, etc. The specific implementation process is the same as in the above embodiments, and will not be repeated here.

[0113] Example 3

[0114] Figure 3 This is a signaling flowchart of a data transmission method provided in Embodiment 3 of the present invention. Based on the above embodiments, this embodiment provides a preferred embodiment in which a first interacting party and a second interacting party interact to perform data transmission. Figure 3 As shown, the first interacting party is a mobile terminal, and the second interacting party is an in-vehicle terminal. The mobile terminal stores its symmetric key and a first standard public key, while the in-vehicle terminal stores its symmetric key, the first standard public key, and a first standard private key.

[0115] See Figure 3 The data transmission method shown includes:

[0116] S301, The vehicle terminal generates a second temporary public-private key pair.

[0117] Specifically, when the authentication conditions are triggered, the vehicle terminal can generate a second temporary public-private key pair based on the elliptic curve cryptography algorithm.

[0118] For example, the second temporary public-private key pair can be generated using the following formula:

[0119] (Vehicle_eSK,Vehicle_ePK)=KeyPair();

[0120] In the formula, Vehicle_eSK is the second temporary private key of the vehicle terminal; Vehicle_ePK is the second temporary public key of the vehicle terminal; and KeyPair is the key pair function of the elliptic curve cryptography algorithm.

[0121] S302. The vehicle terminal sends the second temporary public key and the vehicle terminal's identification information to the mobile terminal.

[0122] The identification information of the vehicle terminal can be the vehicle ID.

[0123] S303, The mobile terminal generates the first temporary public-private key pair.

[0124] Specifically, the mobile terminal can generate a first temporary public-private key pair based on the elliptic curve cryptography algorithm.

[0125] For example, the first temporary public-private key pair can be generated using the following formula:

[0126] (DigitalKey_eSK,DigitalKey_ePK)=KeyPair();

[0127] In the formula, DigitalKey_eSK is the first temporary private key of the mobile terminal; DigitalKey_ePK is the first temporary public key of the mobile terminal; and KeyPair is the key pair function of the elliptic curve cryptography algorithm.

[0128] S304. The mobile terminal generates a first shared secret based on the first temporary private key and the first standard public key.

[0129] Specifically, the ECDH algorithm can be used to generate the first shared secret from the first temporary private key and the first standard public key.

[0130] For example, the first shared secret can be generated using the following formula:

[0131] Kdhse=ECDH(DigitalKey_eSK,Vehicle_PK);

[0132] In the formula, Kdhse is the first shared secret; ECDH is the key negotiation algorithm; DigitalKey_eSK is the first temporary private key; and Vehicle_PK is the first standard public key.

[0133] S305. The mobile terminal generates a second shared secret based on the first temporary private key and the second temporary public key.

[0134] Specifically, the ECDH algorithm can be used to generate a second shared secret from the first temporary private key and the second temporary public key.

[0135] For example, the second shared secret can be generated using the following formula:

[0136] Kdhee=ECDH(DigitalKey_eSK,Vehicle_ePK);

[0137] In the formula, Kdhee is the second shared secret; ECDH is the key negotiation algorithm; DigitalKey_eSK is the first temporary private key; and Vehicle_ePK is the second temporary public key.

[0138] S306. The mobile terminal derives the interaction key by mixing the first shared secret, the second shared secret, the symmetric key, and the interaction identification information.

[0139] Specifically, the first shared secret, the second shared secret, the symmetric key, and the interaction identification information can be used as input parameters, and the interaction key can be generated using a key derivation function.

[0140] For example, the following formula can be used to generate the interaction key:

[0141] KDFParameters=Dkey||Kdhee||VehicleID||DigitalKeyID;

[0142] KVmac||KDmac||Kenc||Kmac=KDF(Kdhse, Parameters, 64);

[0143] In the formula, KDFParameter is the input parameter of the key derivation function; DKey is the symmetric key; Kdhee is the second shared secret; VehicleID is the identification information of the vehicle terminal; DigitalKeyID is the identification information of the mobile terminal; Kdhse is the first shared secret; KDF is the key derivation function; KVmac and KDmac are the authentication keys; and Kenc and Kmac are the secure channel keys.

[0144] S307. The mobile terminal uses the authentication key to generate the first authentication information.

[0145] Specifically, the mobile terminal can use the authentication key corresponding to the mobile terminal, the first temporary public key, and the second temporary public key to generate the first authentication information using the CMAC algorithm.

[0146] For example, the following formula can be used to generate the first authentication information:

[0147] AuthParameters=DigitalKey_ePK.x||Vehicle_ePK.x;

[0148] DigitalKeyAuthCode=AES_CMAC(KDmac,AuthParameters,128);

[0149] In the formula, AuthParameters are the input parameters of the CMAC algorithm; DigitalKey_ePK.x is the x value of the first temporary public key; Vehicle_ePK.x is the x value of the second temporary public key; DigitalKeyAuthCode is the first authentication information; AES (Advanced Encryption Standard) is the symmetric key algorithm; CMAC is the Cipher Block Chaining-Message Authentication Code algorithm; and KDmac is the authentication key corresponding to the mobile terminal.

[0150] S308. The mobile terminal sends an authentication request to the vehicle terminal.

[0151] The authentication request includes the mobile terminal's identification information, the first temporary public key, and the first authentication information.

[0152] S309. The vehicle terminal derives the symmetric key of the mobile terminal based on the symmetric key of the vehicle terminal and the identification information of the mobile terminal.

[0153] Specifically, the symmetric key of the vehicle terminal is different from that of the mobile terminal. The symmetric key of the mobile terminal can be derived from the symmetric key of the vehicle terminal and the identification information of the mobile terminal.

[0154] S310, the vehicle terminal generates a first shared secret based on the first standard private key and the first temporary public key.

[0155] Specifically, the ECDH algorithm can be used to generate the first shared secret from the first standard private key and the first temporary public key.

[0156] For example, the first shared secret can be generated using the following formula:

[0157] Kdhse=ECDH(Vehicle_SK,DigitalKey_ePK);

[0158] In the formula, Kdhse is the first shared secret; ECDH is the key negotiation algorithm; Vehicle_SK is the first standard private key; and DigitalKey_ePK is the first temporary public key.

[0159] S311. The vehicle terminal generates a second shared secret based on the second temporary private key and the first temporary public key.

[0160] Specifically, the ECDH algorithm can be used to generate a second shared secret from the second temporary private key and the first temporary public key.

[0161] For example, the second shared secret can be generated using the following formula:

[0162] Kdhee=ECDH(Vehicle_eSK,DigitalKey_ePK);

[0163] In the formula, Kdhee is the second shared secret; ECDH is the key negotiation algorithm; Vehicle_eSK is the second temporary private key; and DigitalKey_ePK is the first temporary public key.

[0164] S312. The vehicle terminal derives the interaction key by mixing the first shared secret, the second shared secret, the symmetric key, and the interaction identification information.

[0165] Specifically, the first shared secret, the second shared secret, the symmetric key, and the interaction identification information can be used as input parameters, and the interaction key can be generated using a key derivation function.

[0166] For example, the following formula can be used to generate the interaction key:

[0167] KDFParameters=Dkey||Kdhee||VehicleID||DigitalKeyID;

[0168] KVmac||KDmac||Kenc||Kmac=KDF(Kdhse,KDFParameters,64);

[0169] In the formula, KDFParameters are the input parameters of the key derivation function; DKey is the symmetric key; Kdhee is the second shared secret; VehicleID is the identification information of the vehicle terminal; DigitalKeyID is the identification information of the mobile terminal; Kdhse is the first shared secret; KDF is the key derivation function; KVmac and KDmac are the authentication keys; and Kenc and Kmac are the secure channel keys.

[0170] S313. The vehicle terminal uses the authentication key to verify the first authentication information.

[0171] Specifically, the vehicle-mounted terminal can use the authentication key of the mobile terminal generated by the vehicle-mounted terminal to verify the first authentication information. As in the example above, the vehicle-mounted terminal can use its own generated KDmac to calculate the verification authentication information, and then compare the verification authentication information with the first authentication information to verify the first authentication information.

[0172] S314. After successful verification, the vehicle terminal uses the authentication key to generate second authentication information.

[0173] Specifically, the vehicle terminal can use the authentication key, the first temporary public key and the second temporary public key corresponding to the vehicle terminal, and the CMAC algorithm to generate the second authentication information.

[0174] For example, the following formula can be used to generate the second authentication information:

[0175] AuthParameters=DigitalKey_ePK.x||Vehicle_ePK.x;

[0176] VehicleAuthCode=AES_CMAC(KVmac,AuthParameters,128);

[0177] In the formula, AuthParameters are the input parameters of the CMAC algorithm; DigitalKey_ePK.x is the x value of the first temporary public key; Vehicle_ePK.x is the x value of the second temporary public key; VehicleAuthCode is the second authentication information; AES is the symmetric key algorithm; CMAC is the Cipher Block Linking-Message Authentication Code algorithm; and KDmac is the authentication key corresponding to the mobile terminal.

[0178] S315. The vehicle terminal sends an authentication response to the mobile terminal.

[0179] The authentication response includes second authentication information.

[0180] S316. The mobile terminal uses the authentication key to verify the second authentication information.

[0181] Specifically, the mobile terminal can use the authentication key generated by the mobile terminal to verify the second authentication information. As in the example above, the mobile terminal can use its own generated KVmac to calculate the verification information, and then compare the verification information with the second authentication information to verify the second authentication information.

[0182] S317. After successful verification, the mobile terminal and the vehicle terminal transmit interactive data to each other based on the secure channel key.

[0183] As in the example above, mobile terminals and vehicle terminals can exchange data based on secure channel keys Kenc and Kmac.

[0184] This scheme specifically uses a mobile terminal as the first interacting party and an in-vehicle terminal as the second interacting party. It generates a first shared secret and a second shared secret, and integrates the keys of the first and second interacting parties. The scheme also increases the randomness and complexity of the key generation process. An interaction key is generated by mixing the first shared secret, the second shared secret, a symmetric key, and interaction identification information, thus achieving the integrated use of symmetric and asymmetric keys. The first and second interacting parties each generate their own interaction keys, and authentication keys are used to verify the data transmission permissions of either party. After successful verification, a secure channel key is used to transmit the interactive data, thereby improving the security of data transmission between the first and second interacting parties.

[0185] The mobile terminal and vehicle terminal in the above example can be interchanged. The specific implementation process is the same as in the above example, and will not be repeated here.

[0186] Figure 4 This is a signaling flowchart of a data transmission method provided in Embodiment 3 of the present invention. Based on the above embodiments, this embodiment provides a preferred embodiment in which a first interaction direction and a second interaction direction unilaterally send interactive data to perform data transmission. Figure 4 As shown, the first interacting party is a vehicle server, and the second interacting party is an in-vehicle terminal. The vehicle server includes a TSM (Trusted Service Manager) module, and the in-vehicle terminal includes an ECU (Electronic Control Unit) and a security module. The vehicle server stores a symmetric key and a first standard public key, while the in-vehicle terminal stores a symmetric key, a first standard public key, and a first standard private key.

[0187] See Figure 4 The data transmission method shown includes:

[0188] S401, The vehicle server obtains interaction verification information and interaction identification information.

[0189] The interactive verification information can be the vehicle authentication serial number. The interactive identification information can include the identification information of the in-vehicle terminal security module and the identification information of the vehicle server. For example, the identification information of the in-vehicle terminal security module can include the in-vehicle terminal security module SEID (Security Module Identifier), and the identification information of the vehicle server can include the server ID.

[0190] S402, The vehicle server generates the first temporary public-private key pair.

[0191] Specifically, the vehicle server can generate a first temporary public-private key pair based on the elliptic curve cryptography algorithm.

[0192] For example, the first temporary public-private key pair can be generated using the following formula:

[0193] (Server_eSK,Server_ePK)=KeyPair();

[0194] In the formula, Server_eSK is the first temporary private key of the vehicle server; Server_ePK is the first temporary public key of the vehicle server; and KeyPair is the key pair function of the elliptic curve cryptography algorithm.

[0195] S403. The vehicle server generates a first shared secret based on the first temporary private key and the first standard public key.

[0196] Specifically, the ECDH algorithm can be used to generate the first shared secret from the first temporary private key and the first standard public key.

[0197] For example, the first shared secret can be generated using the following formula:

[0198] Kdh=ECDH(Server_eSK,Vehicle_PK);

[0199] In the formula, Kdh is the first shared secret; ECDH is the key negotiation algorithm; Server_eSK is the first temporary private key; and Vehicle_PK is the first standard public key.

[0200] S404. The vehicle server generates an interaction key based on the first shared secret, the symmetric key, and the interaction identification information.

[0201] Specifically, the first shared secret, the symmetric key, and the interaction identification information can be used as input parameters, and the interaction key can be generated using a key derivation function.

[0202] For example, the following formula can be used to generate the interaction key:

[0203] KDFParameters=VKey||SEID||ServerID;

[0204] KVmac||KDmac||Kenc||Kmac=KDF(Kdh,KDFParameters,64);

[0205] In the formula, KDFParameters are the input parameters of the key derivation function; VKey is the symmetric key; Kdh is the first shared secret; SEID is the identification information of the vehicle terminal security module; ServerID is the identification information of the vehicle server; KDF is the key derivation function; KVmac and KDmac are the authentication keys; and Kenc and Kmac are the secure channel keys.

[0206] S405. The vehicle server uses the authentication key to generate the first authentication information.

[0207] Specifically, using the authentication key corresponding to the vehicle server, the first authentication information is generated by applying the CMAC algorithm to the interactive verification information and the first temporary public key.

[0208] For example, the following formula can be used to generate the first authentication information:

[0209] AuthParameters=VehicleAuthenticationSN||Server_ePK;

[0210] ServerAuthCode=AES_CMAC(KDmac,AuthParameters,128);

[0211] In the formula, AuthParameters are the input parameters of the CMAC algorithm; VehicleAuthenticationSN is the interactive verification information; Server_ePK is the first temporary public key of the vehicle server; ServerAuthCode is the first authentication information; AES (Advanced Encryption Standard) is the symmetric key algorithm; CMAC (CipherBlock Chaining-Message Authentication Code) is the CipherBlock Chaining-Message Authentication Code algorithm; and KDmac is the authentication key corresponding to the vehicle server.

[0212] S406. The vehicle server uses a secure channel key to generate encrypted offline data.

[0213] S407, The vehicle server sends an authentication request and encrypted offline data to the vehicle terminal ECU.

[0214] The authentication request includes a first temporary public key, first authentication information, and interaction identification information.

[0215] S408, the vehicle terminal ECU sends an authentication request to the vehicle terminal security module.

[0216] S409. The vehicle terminal security module verifies the interactive verification information based on the pre-stored local verification information.

[0217] S410. Upon successful verification, a first shared secret is generated based on the first standard private key and the first temporary public key.

[0218] Specifically, the ECDH algorithm can be used to generate the first shared secret from the first standard private key and the first temporary public key.

[0219] For example, the first shared secret can be generated using the following formula:

[0220] Kdh=ECDH(Vehicle_SK,Server_ePK);

[0221] In the formula, Kdh is the first shared secret; ECDH is the key negotiation algorithm; Vehicle_SK is the first standard private key; and Server_ePK is the first temporary public key.

[0222] S411. The vehicle terminal derives the interaction key based on the first shared secret, the symmetric key, and the interaction identification information.

[0223] Specifically, the first shared secret, the symmetric key, and the interaction identification information can be used as input parameters, and the interaction key can be generated using a key derivation function.

[0224] For example, the following formula can be used to generate the interaction key:

[0225] KDFParameters=VKey||SEID||ServerID;

[0226] KVmac||KDmac||Kenc||Kmac=KDF(Kdh,KDFParameters,64);

[0227] In the formula, KDFParameters are the input parameters of the key derivation function; VKey is the symmetric key; Kdh is the first shared secret; SEID is the identification information of the vehicle terminal security module; ServerID is the identification information of the vehicle server; KDF is the key derivation function; KVmac and KDmac are the authentication keys; and Kenc and Kmac are the secure channel keys.

[0228] S412, The vehicle terminal security module uses the authentication key to verify the first authentication information.

[0229] Specifically, the vehicle terminal security module can use the authentication key of the vehicle server generated by the vehicle terminal security module to verify the first authentication information. As in the example above, the vehicle terminal security module can use its own generated KDmac to generate verification information, and then compare the verification information with the first authentication information to verify the first authentication information.

[0230] S413. The vehicle terminal uses the authentication key to generate second authentication information.

[0231] Specifically, using the authentication key corresponding to the vehicle terminal security module, the second authentication information is generated by applying the CMAC algorithm to the interactive verification information and the first temporary public key.

[0232] For example, the following formula can be used to generate the second authentication information:

[0233] AuthParameters=VehicleAuthenticationSN||Server_ePK;

[0234] SEAuthCode=AES_CMAC(KVmac,AuthParameters,128);

[0235] In the formula, AuthParameters are the input parameters of the CMAC algorithm; VehicleAuthenticationSN is the interactive verification information; Server_ePK is the first temporary public key of the vehicle server; SEAuthCode is the second authentication information; AES is the symmetric key algorithm; CMAC is the cryptographic block chaining-message authentication code algorithm; and KVmac is the authentication key corresponding to the vehicle terminal security module.

[0236] S414. After successful verification, the vehicle terminal security module sends an authentication response to the vehicle terminal ECU.

[0237] The authentication response includes second authentication information.

[0238] S415, The vehicle terminal ECU sends encrypted offline data to the vehicle terminal security module.

[0239] S416 The vehicle terminal security module uses a secure channel key to verify the legitimacy of offline data, and decrypts the encrypted offline data to update the local data offline.

[0240] As in the example above, the vehicle terminal security module can use the secure channel key Kmac to verify the legitimacy of offline data, use the secure channel key Kenc to decrypt the encrypted offline data, and use the offline data to update the local data.

[0241] S417, The vehicle terminal security module sends an offline data update response to the vehicle terminal ECU.

[0242] The offline data update response can be a response from the vehicle terminal security module that has completed the offline data update.

[0243] S418, Optional, the on-board ECU sends an authentication response and an offline data update response to the vehicle server.

[0244] This solution concretizes the first interacting party as a vehicle server and the second interacting party as an in-vehicle terminal. By generating verification information for interaction and the first authentication information, it achieves dual verification of the second interacting party. By generating an interaction key, it achieves the combined use of symmetric and asymmetric keys. Only when both the symmetric and asymmetric keys are leaked can the encrypted offline data be cracked, thus improving the security of data transmission. At the same time, by updating local data with offline data, it achieves offline updates of the local data of the in-vehicle terminal security module, further improving the security of data updates.

[0245] The vehicle server and vehicle terminal in the above example can also be interchanged. The specific implementation process is the same as in the above example, and will not be repeated here.

[0246] Example 4

[0247] Figure 5 This is a schematic diagram of a data transmission device provided in Embodiment 4 of the present invention. Figure 5 As shown, the device includes: a first temporary key generation module 510, a first standard key acquisition module 520, a first interactive key generation module 530, a first authentication information generation module 540, and a first authentication information sending module 550. Among them,

[0248] The first temporary key generation module 510 is used to generate a first temporary public-private key pair, which includes a first temporary public key and a first temporary private key.

[0249] The first standard key acquisition module 520 is used to acquire the first standard public key, symmetric key and interaction identification information;

[0250] The first interactive key generation module 530 is used to generate an interactive key based on the first temporary private key, the first standard public key, the symmetric key and interactive identification information. The interactive key includes an authentication key and a secure channel key.

[0251] The first authentication information generation module 540 is used to generate first authentication information based on the authentication key;

[0252] The first authentication information sending module 550 is used to send the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, so that the second interaction party can verify the first authentication information and, when the verification is successful, obtain and decrypt the interaction data transmitted by the first interaction party based on the secure channel key encryption.

[0253] The technical solution of this invention generates a first temporary public-private key pair, including a first temporary public key and a first temporary private key; obtains a first standard public key, a symmetric key, and interaction identification information; generates an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identification information, the interaction key including an authentication key and a secure channel key, thus realizing the fusion use of symmetric and asymmetric keys; generates first authentication information based on the authentication key; and sends the first authentication information, the first temporary public key, and the interaction identification information to the second interaction party, enabling the second interaction party to verify the first authentication information. Upon successful verification, the second interaction party acquires and decrypts the interaction data encrypted based on the secure channel key transmitted by the first interaction party. The generation of the first authentication information through the authentication key enables the second interaction party to verify the data transmission permission of the first interaction party. Based on the secure channel key, the encryption of the interaction data by the first interaction party and the decryption of the encrypted interaction data by the second interaction party are realized, thereby achieving data transmission from the first interaction party to the second interaction party and improving the security of data transmission.

[0254] In an optional embodiment of the present invention, the first interactive key generation module 530 includes: a first shared secret generation unit, configured to generate a first shared secret based on a first temporary private key and a first standard public key; and a first interactive key generation unit, configured to generate an interactive key based on the first shared secret, a symmetric key, and interactive identification information.

[0255] In an optional embodiment of the present invention, before the first interaction key generation unit generates the interaction key based on the first shared secret, the symmetric key, and the interaction identifier information, the first interaction key generation module 530 further includes: a second temporary public key receiving unit, used to receive a second temporary public key sent by the second interaction party; the first interaction key generation unit includes: a second shared secret generation subunit, used to generate a second shared secret based on the first temporary private key and the second temporary public key; and the first interaction key generation subunit, used to generate the interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

[0256] In an optional embodiment of the present invention, after the first authentication information sending module 550 sends the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the device further includes: a second authentication information receiving module, used to receive the second authentication information sent by the second interaction party; a second authentication information verification module, used to verify the second authentication information using an authentication key; an interaction data encryption module, used to encrypt the interaction data using a secure channel key when the verification is successful, and transmit it to the second interaction party; and an interaction data decryption module, used to obtain the encrypted interaction data sent by the second interaction party, and decrypt it to obtain the interaction data sent by the second interaction party.

[0257] The data transmission device provided in the embodiments of the present invention can execute the data transmission method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0258] Example 5

[0259] Figure 6 This is a schematic diagram of a data transmission device provided in Embodiment 5 of the present invention. Figure 6 As shown, the device includes: a first authentication information receiving module 610, a second interaction key generation module 620, a first authentication information verification module 630, an encrypted interaction data acquisition module 640, and an encrypted interaction data decryption module 650. Among them,

[0260] The first authentication information receiving module 610 is used to receive the first authentication information, the first temporary public key and the interaction identifier information sent by the first interaction party;

[0261] The second interactive key generation module 620 is used to obtain the first standard public-private key pair and the symmetric key, and generate an interactive key based on the first temporary public key, the first standard private key, the symmetric key and interactive identification information. The interactive key includes an authentication key and a secure channel key.

[0262] The first authentication information verification module 630 is used to verify the first authentication information based on the authentication key;

[0263] The encrypted interactive data acquisition module 640 is used to acquire the encrypted interactive data sent by the first interacting party when the verification is successful.

[0264] The encrypted interactive data decryption module 650 is used to decrypt the encrypted interactive data using a secure channel key to obtain the interactive data.

[0265] The technical solution of this invention receives first authentication information, a first temporary public key, and interaction identifier information sent by a first interacting party; obtains a first standard public-private key pair and a symmetric key; and generates an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information. The interaction key includes an authentication key and a secure channel key. By generating the interaction key for the second interacting party, the second interacting party achieves the fusion use of symmetric and asymmetric keys. The first authentication information is verified using the authentication key. If the verification passes, the encrypted interaction data sent by the first interacting party is obtained, thus realizing the verification of the first authentication information by the second interacting party. The encrypted interaction data is decrypted using the secure channel key to obtain the interaction data, thus realizing the process of the second interacting party obtaining the interaction data transmitted by the first interacting party and improving the security of data transmission.

[0266] In an optional embodiment of the present invention, before the first authentication information receiving module 610 receives the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the device further includes: a second temporary key generation module, used to generate a second temporary public-private key pair and send it to the first interacting party; the second interaction key generation module 620 includes: a first shared secret generation unit, used to generate a first shared secret based on the first temporary public key and the first standard private key; a second temporary key acquisition unit, used to acquire a second temporary private key; a second shared secret generation unit, used to generate a second shared secret based on the first temporary public key and the second temporary private key; and a second interaction key generation unit, used to generate an interaction key based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

[0267] In an optional embodiment of the present invention, while the first authentication information receiving module 610 receives the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the device further includes: an interaction verification information acquisition module, used to acquire the interaction verification information and encrypted interaction data sent by the first interacting party; an interaction verification information verification module, used to acquire pre-stored local verification information and verify the interaction verification information; a second interaction key generation module 620, including: a third interaction key generation unit, used to generate an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information when the interaction verification information passes verification; after the encrypted interaction data decryption module 650 decrypts the encrypted interaction data using the secure channel key to obtain the interaction data, the device further includes: a local data update module, used to update local data using the interaction data.

[0268] The data transmission device provided in the embodiments of the present invention can execute the data transmission method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.

[0269] Example 6

[0270] Figure 7 A schematic diagram of an electronic device 700 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.

[0271] like Figure 7 As shown, the electronic device 700 includes at least one processor 701 and a memory, such as a read-only memory (ROM) 702 and a random access memory (RAM) 703, communicatively connected to the at least one processor 701. The memory stores computer programs executable by the at least one processor. The processor 701 can perform various appropriate actions and processes based on the computer program stored in the ROM 702 or loaded into the RAM 703 from storage unit 708. The RAM 703 can also store various programs and data required for the operation of the electronic device 700. The processor 701, ROM 702, and RAM 703 are interconnected via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0272] Multiple components in electronic device 700 are connected to I / O interface 705, including: input unit 706, such as keyboard, mouse, etc.; output unit 707, such as various types of displays, speakers, etc.; storage unit 708, such as disk, optical disk, etc.; and communication unit 709, such as network card, modem, wireless transceiver, etc. Communication unit 709 allows electronic device 700 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0273] Processor 701 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. Processor 701 performs the various methods and processes described above, such as data transfer methods.

[0274] In some embodiments, the data transfer method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 700 via ROM 702 and / or communication unit 709. When the computer program is loaded into RAM 703 and executed by processor 701, one or more steps of the data transfer method described above may be performed. Alternatively, in other embodiments, processor 701 may be configured to perform the data transfer method by any other suitable means (e.g., by means of firmware).

[0275] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0276] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0277] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0278] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0279] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.

[0280] A computing system can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system. It addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability.

[0281] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.

[0282] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.

Claims

1. A data transmission method, characterized in that, Applied to the first interacting party, the method includes: Generate a first temporary public-private key pair, the first temporary public-private key pair including a first temporary public key and a first temporary private key; Obtain a first standard public key, a symmetric key, and interaction identifier information; wherein, the first standard public key is the public key in a first standard public-private key pair, and the first standard public-private key pair remains unchanged when the second interaction party remains unchanged; the symmetric key is generated by either interaction party or by a third party, and the symmetric keys of the two interaction parties remain unchanged in different interaction processes; An interaction key is generated based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identifier information. The interaction key includes an authentication key and a secure channel key. Generate first authentication information based on the authentication key; The first authentication information, the first temporary public key, and the interaction identifier information are sent to the second interaction party so that the second interaction party can verify the first authentication information and, upon successful verification, obtain and decrypt the interaction data encrypted based on the secure channel key transmitted by the first interaction party.

2. The method according to claim 1, characterized in that, The step of generating an interaction key based on the first temporary private key, the first standard public key, the symmetric key, and the interaction identifier information includes: A first shared secret is generated based on the first temporary private key and the first standard public key; An interaction key is generated based on the first shared secret, the symmetric key, and the interaction identifier information.

3. The method according to claim 2, characterized in that, Before generating the interaction key based on the first shared secret, the symmetric key, and the interaction identifier information, the method further includes: Receive the second temporary public key sent by the second interacting party; The step of generating an interaction key based on the first shared secret, the symmetric key, and the interaction identifier information includes: A second shared secret is generated based on the first temporary private key and the second temporary public key; An interaction key is generated based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

4. The method according to claim 3, characterized in that, After sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the process further includes: Receive the second authentication information sent by the second interacting party; The authentication key is used to verify the second authentication information; Upon successful verification, the secure channel key is used to encrypt the interactive data, which is then transmitted to the second interacting party. The encrypted interaction data sent by the second interacting party is obtained and decrypted to obtain the interaction data sent by the second interacting party.

5. The method according to claim 2, characterized in that, Before sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the method further includes: Obtain interaction verification information; Acquire offline data and encrypt it using the secure channel key to obtain encrypted interactive data; While sending the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, the method also includes: The interaction verification information and the encrypted interaction data are sent to the second interaction party so that the second interaction party can verify the interaction verification information, and when the interaction verification information passes the verification, verify the first authentication information, and when the first authentication information passes the verification, decrypt and process the encrypted interaction data.

6. A data transmission method, characterized in that, Applied to the second interacting party, the method includes: Receive the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party; Obtain a first standard public-private key pair and a symmetric key, and generate an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information. The interaction key includes an authentication key and a secure channel key. Wherein, when the second interaction party remains unchanged, the first standard public-private key pair remains unchanged. The symmetric key is generated by either interaction party or by a third party, and the symmetric keys of the two interaction parties remain unchanged in different interaction processes. The first authentication information is verified based on the authentication key; Upon successful verification, the encrypted interaction data sent by the first interacting party is retrieved; The encrypted interactive data is decrypted using the secure channel key to obtain the interactive data.

7. The method according to claim 6, characterized in that, Before receiving the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the process also includes: Generate a second temporary public-private key pair and send the second temporary public key to the first interacting party; The step of generating an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information includes: A first shared secret is generated based on the first temporary public key and the first standard private key; Obtain the second temporary private key; A second shared secret is generated based on the first temporary public key and the second temporary private key; An interaction key is generated based on the first shared secret, the second shared secret, the symmetric key, and the interaction identifier information.

8. The method according to claim 6, characterized in that, Upon receiving the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interacting party, the following are also included: Obtain the interaction verification information and encrypted interaction data sent by the first interacting party; Obtain the pre-stored local verification information and verify the interactive verification information; The step of generating an interaction key based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information includes: When the interaction verification information passes the verification, an interaction key is generated based on the first temporary public key, the first standard private key, the symmetric key, and the interaction identifier information; After decrypting the encrypted interactive data using the secure channel key to obtain the interactive data, the method further includes: The local data is updated using the interactive data.

9. A data transmission device, characterized in that, Applied to the first interacting party, the device includes: The first temporary key generation module is used to generate a first temporary public-private key pair, wherein the first temporary public-private key pair includes a first temporary public key and a first temporary private key; The first standard key acquisition module is used to acquire a first standard public key, a symmetric key, and interaction identification information; wherein, the first standard public key is the public key in the first standard public-private key pair, and the first standard public-private key pair remains unchanged when the second interaction party remains unchanged; the symmetric key is generated by either interaction party or by a third party, and the symmetric keys of the two interaction parties remain unchanged in different interaction processes; The first interactive key generation module is used to generate an interactive key based on the first temporary private key, the first standard public key, the symmetric key and the interactive identification information, wherein the interactive key includes an authentication key and a secure channel key; The first authentication information generation module is used to generate first authentication information based on the authentication key; The first authentication information sending module is used to send the first authentication information, the first temporary public key, and the interaction identifier information to the second interaction party, so that the second interaction party can verify the first authentication information and, when the verification is successful, obtain and decrypt the interaction data encrypted based on the secure channel key transmitted by the first interaction party.

10. A data transmission device, characterized in that, Applied to the second interacting party, the device includes: The first authentication information receiving module is used to receive the first authentication information, the first temporary public key, and the interaction identifier information sent by the first interaction party. The second interaction key generation module is used to obtain a first standard public-private key pair and a symmetric key, and generate an interaction key based on the first temporary public key, the first standard private key, the symmetric key and the interaction identifier information. The interaction key includes an authentication key and a secure channel key. Wherein, when the second interaction party remains unchanged, the first standard public-private key pair remains unchanged. The symmetric key is generated by either interaction party or by a third party, and the symmetric keys of the two interaction parties remain unchanged in different interaction processes. The first authentication information verification module is used to verify the first authentication information according to the authentication key; The encrypted interaction data acquisition module is used to acquire the encrypted interaction data sent by the first interacting party when the verification is successful. The encrypted interactive data decryption module is used to decrypt the encrypted interactive data using the secure channel key to obtain the interactive data.

11. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the data transmission method according to any one of claims 1-8.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that are used to cause a processor to execute the data transmission method of any one of claims 1-8.

Citation Information

Patent Citations

  • Communication method and device, and computer storage medium

    CN111342955A