Method and system for authorizing generation and secure endorsement of digital certificates for intelligent connected vehicles
Through the method of authorization generation and secure signing of intelligent connected car digital certificates, the vehicle terminal security chip and password machine and other equipment, combined with the key dispersion mechanism, the authorization authentication and signing of intelligent connected car digital certificates are solved, and the independent and controllable security signing process is realized to ensure the security of Internet of Vehicles communication and identity legality.
Patent Information
- Application Number
- CN202211245361.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-12
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2042-10-12
AI Technical Summary
In the prior art, the security issues of digital certificate authorization, authentication and visa registration of intelligent connected vehicles have not been effectively resolved, resulting in security risks such as identity forgery, privacy leakage and cyber attacks.
Design a method for generating and secure signing for digital certificates in intelligent connected vehicles. Through the initial security configuration of the on-board terminal security chip, the digital certificate authorization generation and secure signing process, the asymmetric and symmetric cryptographic algorithm is adopted, combined with the key dispersion mechanism, to ensure the identity legality of the on-board terminal and the certificate security signing.
It realizes the independent and controllable authorization generation and security signing of intelligent connected vehicle digital certificates, eliminates the application of certificates by in-vehicle terminals without initial security configuration, and ensures the security and identity legality of Internet of Vehicle communications.
Smart Images

Figure CN115915123B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and more specifically, to a method and system for authorizing the generation and secure signing of digital certificates for intelligent connected vehicles. Background Art
[0002] In recent years, my country's intelligent connected vehicle (ICV) technology has rapidly developed, and the ICV industry has continued to expand. However, as ICV construction and vehicle-road collaboration progress from testing and verification to large-scale deployment, ICV security issues have gradually emerged, such as identity forgery, privacy leaks, and cyberattacks. To address these issues, ICV communication requires secure authentication of the identities of participants, including onboard devices and roadside infrastructure. This prevents ICV infrastructure from being attacked by hackers, misleading vehicles into making incorrect decisions, or even causing dangerous incidents such as collisions. Therefore, identity authentication and secure trust in ICV communications are crucial, and digital certificates are at the core of this security authentication. In this context, ICV CAs are issuing digital certificates to ICVs. Using digital certificates and digital signatures to ensure vehicle identity legitimacy, the integrity and confidentiality of communication messages, and to protect against malicious attacks such as forgery, tampering, and privacy theft, has become a popular technology for ensuring secure ICV communications.
[0003] The prerequisite for achieving connected vehicle identity authentication is to ensure the security of the intelligent connected vehicle's digital certificate and the corresponding public and private keys. These digital certificates and public and private keys are typically stored in the vehicle's security chip. This raises two issues: how to verify the legitimacy of the vehicle terminal applying for the digital certificate, and how to securely sign the intelligent connected vehicle's digital certificate to the vehicle's security chip.
[0004] To sum up, in order to solve the problems of authorization and authentication, signing security of digital certificates for intelligent connected vehicles, this patent is based on the research and design of a method for authorization generation and secure signing of digital certificates for intelligent connected vehicles, providing more reliable security support and protection for the issuance and signing of digital certificates for intelligent connected vehicles. Summary of the Invention
[0005] In order to solve the deficiencies in the prior art, the present invention provides a method and system for authorizing the generation and secure signing of digital certificates for intelligent connected vehicles, so as to solve the problems of authorization authentication, signing security and other issues in the prior art for digital certificates for intelligent connected vehicles.
[0006] As a first aspect of the present invention, a method for authorizing the generation and secure endorsement of a digital certificate for an intelligent connected vehicle is provided, comprising:
[0007] Step S1: initial security configuration phase of the vehicle terminal security chip;
[0008] Step S2: Intelligent connected vehicle digital certificate authorization generation stage;
[0009] Step S3: Smart connected vehicle digital certificate security endorsement stage.
[0010] Furthermore, the step S1 further includes:
[0011] Step S11: Initialize the endorsement device to send initial configuration instructions to the vehicle terminal security chip;
[0012] Step S12: After receiving the initial configuration instruction, the vehicle terminal security chip randomly generates a temporary public-private key pair, uses the temporary private key to sign the unique serial number of the vehicle terminal security chip to obtain a first signature value, and returns the unique serial number of the vehicle terminal security chip, the first signature value, and the temporary public key to the initialization signing device;
[0013] Step S13: the initialization endorsement device requests initial authorization from the unified authorization and authentication management system, and the request parameters include the unique serial number of the vehicle terminal security chip, the first signature value and the temporary public key;
[0014] Step S14: After receiving the initial authorization request, the unified authorization and authentication management system uses the temporary public key of the vehicle terminal security chip to verify the first signature value, and verifies that the unique serial number of the vehicle terminal security chip is respectively subjected to key dispersion operation by using the system root key and the single card authentication root key to generate an initial session key and a single card authentication key. After filing the unique serial number of the vehicle terminal security chip, the initial session key and the single card authentication key are encrypted using the temporary public key of the vehicle terminal security chip to obtain an initial session key ciphertext and a single card authentication key ciphertext, and the initial session key ciphertext and the single card authentication key ciphertext are returned to the initialization endorsement device;
[0015] Step S15: the initialization endorsement device sends the initial session key ciphertext and the single card authentication key ciphertext to the vehicle terminal security chip;
[0016] Step S16: The vehicle terminal security chip uses the temporary private key of the vehicle terminal security chip to decrypt the initial session key ciphertext and the single card authentication key ciphertext, and safely stores the initial session key and the single card authentication key.
[0017] Furthermore, the step S2 further includes:
[0018] Step S21: The certificate endorsement device requests the unified authorization and authentication management system to generate a digital certificate. The unified authorization and authentication management system generates a first random number R1 and initiates an authentication request for the vehicle terminal security chip. The authentication request is returned to the certificate endorsement device.
[0019] Step S22: After receiving the authentication request, the certificate signing device forwards it to the vehicle-mounted terminal security chip. After receiving the authentication request, the vehicle-mounted terminal security chip randomly generates a public-private key pair, signs the public key with the private key and generates a certificate request file, then encrypts the first random number R1 with the initial session key to obtain an authorization certificate, and finally signs the authorization certificate and the unique serial number of the vehicle-mounted terminal security chip with the private key to obtain a second signature value, and returns the authorization certificate, the unique serial number of the vehicle-mounted terminal security chip, the second signature value and the certificate request file to the certificate signing device;
[0020] Step S23: The certificate endorsement device forwards the received authorization certificate, the unique serial number of the vehicle terminal security chip, the second signature value and the certificate request file to the unified authorization and authentication management system;
[0021] Step S24: After receiving the certificate request file, the unified authorization and authentication management system first verifies the certificate request file. After the verification is passed, it uses the public key to verify the second signature value. After the verification is passed, it uses the system root key to perform a decentralized operation on the unique serial number of the vehicle terminal security chip to generate the initial session key. The authorization certificate is decrypted using the initial session key, and the decrypted random number R1' is compared with the initially generated first random number R1 to see if they are consistent. If they are consistent, the authorization and authentication are passed, and a request is made to the vehicle network CA system to generate a certificate.
[0022] Step S25: After receiving the certificate request, the Internet of Vehicles CA system issues a digital certificate and returns the digital certificate to the unified authorization and authentication management system. The unified authorization and authentication management system returns the certificate generation result to the certificate signing device.
[0023] Furthermore, the step S3 further includes:
[0024] Step S31: The certificate signing device requests the vehicle terminal security chip to sign the certificate. After receiving the request, the vehicle terminal security chip generates a second random number R2 and returns the second random number R2 and the unique serial number of the vehicle terminal security chip to the certificate signing device.
[0025] Step S32: The certificate signing device calculates the Hmac1 value for the received second random number R2, generates a new third random number R3, and sends the Hmac1 value and the third random number R3 to the vehicle terminal security chip; the vehicle terminal security chip verifies the Hmac1 value using the generated second random number R2, and if it passes, calculates the third random number R3 generated by the certificate signing device to obtain the Hmac2 value, and sends the Hmac2 value to the certificate signing device;
[0026] Step S33: The certificate endorsement device verifies the Hmac2 value using the generated third random number R3. If the verification is successful, the device applies to the unified authorization and authentication management system for downloading the digital certificate. The application parameters include the unique serial number of the vehicle terminal security chip.
[0027] Step S34: After receiving the certificate download request, the unified authorization and authentication management system generates a fourth random number R4 and initiates identity authentication of the certificate signing device;
[0028] Step S35: the certificate signing device signs the fourth random number R4 to obtain a third signature value, and sends the third signature value and the certificate signing device certificate to the unified authorization and authentication management system;
[0029] Step S36: The unified authorization and authentication management system verifies the certificate signing device certificate. If the verification is successful, the third signature value is verified using the public key of the certificate signing device certificate. If the verification is successful, the corresponding digital certificate is found based on the unique serial number of the vehicle terminal security chip in the application parameters, and the corresponding digital certificate is returned to the certificate signing device.
[0030] Step S37: The certificate signing device sends a certificate signing instruction to the vehicle terminal security chip, and the vehicle terminal security chip securely stores the digital certificate.
[0031] As a second aspect of the present invention, a system for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles is provided, comprising a vehicle network CA system, a unified authorization and authentication management system, an initialization endorsement device, a certificate endorsement device, and an in-vehicle terminal. The unified authorization and authentication management system further comprises a cryptographic machine, the certificate endorsement device further comprises a hardware security module, and the in-vehicle terminal further comprises a security chip.
[0032] The Internet of Vehicles CA system is used to provide digital certificate issuance services for intelligent connected vehicles;
[0033] The unified authorization and authentication management system is used to provide intelligent connected vehicle digital certificate authorization and authentication and security management functions;
[0034] The initialization endorsement device is used for the initial security configuration of the vehicle terminal;
[0035] The certificate signing device is used to securely sign the digital certificate to the security chip;
[0036] The vehicle-mounted terminal is installed on the intelligent connected vehicle and is used to communicate with the initialization endorsement device and the certificate endorsement device respectively, and provide authentication and authorization data processing and forwarding functions.
[0037] Furthermore, the security chip is used to store digital certificates and keys of intelligent connected vehicles and provide secure cryptographic computing services.
[0038] Furthermore, the cryptographic machine is used to provide key dispersion, data encryption and decryption, and data signature verification security cryptographic operations, and is called by the unified authorization and authentication management system.
[0039] Furthermore, the hardware security module is used to provide key generation, data encryption and decryption, and data signature verification security cryptographic operations, and is embedded in the certificate signing device and called by the certificate signing device according to actual business processes.
[0040] The method and system for authorized generation and secure endorsement of digital certificates for intelligent connected vehicles (ICVs) provided by this invention offer the following advantages: Leveraging security devices such as on-board terminal security chips and cryptographic machines, an initial authorization and key distribution mechanism is designed to implement initial security configuration for ICVs. This system establishes an authorized generation mechanism for ICV digital certificates and a secure endorsement mechanism based on asymmetric and symmetric cryptographic algorithms, preventing ICVs from applying for digital certificates without initial security configuration, and securely endorses ICV digital certificates to the ICV terminal security chip. The entire solution utilizes proprietary Chinese cryptographic algorithms, ensuring independent control over authorized generation and secure endorsement of digital certificates. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The accompanying drawings are used to provide further understanding of the present invention and constitute a part of the specification. Together with the following specific embodiments, they are used to explain the present invention, but do not constitute a limitation of the present invention.
[0042] Figure 1 This is an overall flow chart of the method for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles provided by the present invention.
[0043] Figure 2 This is a schematic diagram of the initial security configuration process of the vehicle terminal security chip provided by the present invention.
[0044] Figure 3 This is a schematic diagram of the authorization generation process for the intelligent connected vehicle digital certificate provided by the present invention.
[0045] Figure 4 Schematic diagram of the secure endorsement process for the digital certificate of an intelligent connected vehicle provided by the present invention.
[0046] Figure 5 This is a structural block diagram of the intelligent connected vehicle digital certificate authorization generation and security endorsement system provided by the present invention.
[0047] Figure 6This is a working principle diagram of the intelligent connected vehicle digital certificate authorization generation and security endorsement system provided by the present invention. DETAILED DESCRIPTION
[0048] To further illustrate the technical means and effectiveness of the present invention in achieving its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, describes in detail the specific implementation, structure, features, and effectiveness of the method and system for authorized generation and secure endorsement of digital certificates for intelligent connected vehicles proposed in accordance with the present invention. It should be understood that the described embodiments are only a subset of the embodiments of the present invention, not all of them. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present invention without inventive effort are intended to fall within the scope of protection of the present invention.
[0049] In this embodiment, a method for authorizing the generation and security signing of a digital certificate for an intelligent connected vehicle is provided. Figure 1 As shown, the method for authorizing the generation and security endorsement of digital certificates for intelligent connected vehicles includes:
[0050] Step S1: initial security configuration phase of the vehicle terminal security chip;
[0051] Step S2: Intelligent connected vehicle digital certificate authorization generation stage;
[0052] Step S3: Smart connected vehicle digital certificate security endorsement stage.
[0053] Preferably, if Figure 2 As shown, the step S1 further includes:
[0054] Step S11: In a safe and reliable production environment, the initialization endorsement device sends an initial configuration instruction InitConfig to the vehicle terminal via NFC or V2X PC5 communication protocol, and the vehicle terminal forwards the initial configuration instruction to the embedded security chip;
[0055] Step S12: After receiving the initial configuration instruction InitConfig, the vehicle terminal security chip randomly generates a temporary public-private key pair TmpPubpriKey internally, uses the temporary private key TmpPriKey to sign the unique serial number SerialNum of the vehicle terminal security chip to obtain a first signature value Sign1, and returns the unique serial number SerialNum of the vehicle terminal security chip, the first signature value Sign1 and the temporary public key TmpPubKey to the initialization signing device. The vehicle terminal returns the data to the initialization signing device through NFC or V2X PC5 communication protocol;
[0056] Step S13: After the initialization endorsement device receives the data returned by the vehicle terminal, the initialization endorsement device requests initial authorization from the unified authorization and authentication management system. The request parameters include the unique serial number SerialNum of the vehicle terminal security chip, the first signature value Sign1, and the temporary public key TmpPubKey;
[0057] Step S14: After receiving the initial authorization request, the unified authorization and authentication management system calls the cryptographic machine and uses the temporary public key TmpPubKey of the vehicle terminal security chip to verify the first signature value Sign1. If the verification succeeds, the process proceeds to step S141. If the verification fails, an error is returned to the initialization signing device, and the process terminates.
[0058] Step S141: After the unique serial number of the vehicle terminal security chip is filed with the unified authorization and authentication management system, the cryptographic machine is called to perform a key dispersion operation on the unique serial number SerialNum of the vehicle terminal security chip using the system root key SysRootKey and the single card authentication root key AuthRootKey respectively, to generate the initial session key InitSessKey and the single card authentication key DkAuthKey, and to encrypt the initial session key InitSessKey and the single card authentication key DkAuthKey using the temporary public key TmpPubKey of the vehicle terminal security chip to obtain the initial session key ciphertext InitSessKeyEnc and the single card authentication key ciphertext DkAuthKeyEnc, and return the initial session key ciphertext InitSessKeyEnc, the single card authentication key ciphertext DkAuthKeyEnc and the vehicle network CA certificate to the initialization endorsement device;
[0059] Step S15: The initialization endorsement device sends the initial session key ciphertext InitSessKeyEnc, the single card authentication key ciphertext DkAuthKeyEnc, and the Internet of Vehicles CA certificate to the vehicle terminal via NFC or V2X PC5 communication protocol. The vehicle terminal forwards InitSessKeyEnc, DkAuthKeyEnc, and the Internet of Vehicles CA certificate to the embedded security chip.
[0060] Step S16: The vehicle terminal security chip uses the temporary private key TmpPriKey to decrypt the initial session key ciphertext and the single card authentication key ciphertext, obtains the initial session key InitSessKey and the single card authentication key DkAuthKey and stores them securely, and also stores the Internet of Vehicles CA certificate.
[0061] Preferably, if Figure 3 As shown, the step S2 further includes:
[0062] Step S21: After the initial security configuration of the on-board terminal security chip of the intelligent connected vehicle is completed, when the vehicle enters a vehicle management office, registration service station, inspection station, or other place to handle registration, safety inspection, and other services, a staff member uses a mobile certificate endorsement device or a fixed certificate endorsement device to request the unified authorization and authentication management system to generate a digital certificate. After receiving the digital certificate generation request, the unified authorization and authentication management system generates a first random number R1 and initiates an authentication request (including R1) for the on-board terminal security chip. The authentication request is returned to the certificate endorsement device.
[0063] Step S22: After receiving the authentication request, the certificate signing device forwards the authentication request (including R1) to the vehicle terminal through the NFC or V2X PC5 communication protocol. The vehicle terminal forwards the authentication request and the random number R1 to the embedded security chip. After receiving the authentication request, the vehicle terminal security chip randomly generates a public-private key pair SolidPubpriKey internally, signs the public key SolidPubKey with the private key SolidPriKey and generates a certificate request file Csr. It then encrypts the first random number R1 with the initial session key InitSessKey to obtain the authorization certificate AuthProof. Finally, it signs the authorization certificate AuthProof and the unique serial number of the vehicle terminal security chip with the private key SolidPriKey to obtain a second signature value Sign2. The authorization certificate AuthProof, the unique serial number SerialNum of the vehicle terminal security chip, the second signature value Sign2 and the certificate request file Csr are packaged into certificate application data and returned to the certificate signing device.
[0064] Step S23: the certificate endorsement device forwards the received authorization certificate AuthProof, the unique serial number SerialNum of the vehicle terminal security chip, the second signature value and the certificate request file to the unified authorization and authentication management system;
[0065] Step S24: After receiving the certificate application data from the vehicle terminal security chip, the unified authorization and authentication management system calls the cryptographic machine to first verify the certificate request file Csr. If the verification passes, the process proceeds to step S241. If the verification fails, an error is returned to the certificate signing device, and the process terminates.
[0066] Step S241: The unified authorization and authentication management system calls the cryptographic machine and uses the public key SolidPubKey in the certificate request file Csr to verify the second signature value Sign2. If the verification succeeds, the process proceeds to step S242. If the verification fails, an error is returned to the certificate signing device and the process terminates.
[0067] Step S242: The unified authorization and authentication management system calls the cryptographic machine and uses the system root key SysRootKey to perform a key dispersion operation on the unique serial number SerialNum of the vehicle terminal security chip to generate the initial session key InitSessKey. The initial session key InitSessKey is used to decrypt the authorization certificate AuthProof to obtain a random number R1'. The decrypted random number R1' is compared with the initially generated random number R1 to see if they are consistent. If they are consistent, the authorization authentication is passed and the process proceeds to step S25 to request the Internet of Vehicles CA system to generate a certificate. If they are inconsistent, an error is returned to the certificate signing device and the process terminates.
[0068] Step S25: After receiving the certificate request, the Internet of Vehicles CA system issues a digital certificate ObuCert and returns the digital certificate ObuCert to the unified authorization and authentication management system. The unified authorization and authentication management system returns the certificate generation result to the certificate signing device.
[0069] Preferably, if Figure 4 As shown, the step S3 further includes:
[0070] Step S31: After receiving the certificate generation result returned by the unified authorization and authentication management system, the certificate signing device can start the digital certificate signing process and send an authentication request to the vehicle terminal via NFC or V2X PC5 communication protocol. The vehicle terminal forwards the authentication request to the embedded security chip. After receiving the authentication request, the security chip internally generates a second random number R2 and returns the second random number R2 and the unique serial number SerialNum of the vehicle terminal security chip to the vehicle terminal. The vehicle terminal returns the second random number R2 and the unique serial number SerialNum of the vehicle terminal security chip to the certificate signing device via NFC or V2X PC5 communication protocol.
[0071] Step S32: After receiving the second random number R2 and the unique serial number SerialNum of the vehicle terminal security chip, the certificate signing device calls the embedded hardware security module, uses the single card authentication root key AuthRootKey to perform a key dispersion operation on the unique serial number SerialNum of the vehicle terminal security chip to obtain the single card authentication key DkAuthKey, uses the single card authentication key DkAuthKey to calculate the Hmac1 value of the second random number R2, generates a third random number R3 internally, and sends the Hmac1 value and the third random number R3 to the vehicle terminal via NFC or V2X PC5 communication protocol. The vehicle terminal forwards the Hmac1 value and the third random number R3 to the embedded security chip; the vehicle terminal security chip uses the stored single card authentication key DkAuthKey to calculate the Hmac1' value of the second random number R2, compares the Hmac1' value with the Hmac1 value, and if they are consistent, proceeds to step S321; if they are inconsistent, an error is returned to the vehicle terminal, and the process terminates;
[0072] Step S321: The vehicle terminal security chip uses the stored single card authentication key DkAuthKey to calculate the third random number R3 to obtain the Hmac2 value, and returns the Hmac2 value to the vehicle terminal. The vehicle terminal sends the Hmac2 value to the certificate endorsement device via NFC or V2X PC5 communication protocol;
[0073] Step S33: The certificate signing device calls the embedded hardware security module, uses the single card authentication key DkAuthKey to calculate the Hmac2' value of the third random number R3, and compares the Hmac2' value with the Hmac2 value. If they are consistent, the process proceeds to step S331. If they are inconsistent, an error is returned to the vehicle terminal, and the process terminates.
[0074] Step S331: After completing the two-way identity authentication with the vehicle terminal, the certificate signing device applies to the unified authorization and authentication management system to download the digital certificate ObuCert, and the application parameters include the unique serial number SerialNum of the vehicle terminal security chip;
[0075] Step S34: After receiving the certificate download request, the unified authorization and authentication management system generates a fourth random number R4 and initiates identity authentication of the certificate signing device;
[0076] Step S35: After receiving the fourth random number R4, the certificate signing device calls the embedded hardware security module and signs the fourth random number R4 using the certificate signing device private key InsertDevicePriKey to obtain a third signature value Sign3, and sends the third signature value Sign3 and the certificate signing device certificate InsertDeviceCert to the unified authorization and authentication management system;
[0077] Step S36: After receiving the third signature value Sign3 and the certificate signing device certificate InsertDeviceCert, the unified authorization and authentication management system calls the cryptographic machine and uses the root public key to verify the certificate signing device certificate InsertDeviceCert. If the verification succeeds, the process proceeds to step S361. If the verification fails, an error is returned to the certificate signing device, and the process terminates.
[0078] Step S361: The unified authorization and authentication management system calls the cryptographic machine and uses the public key of the certificate signing device certificate to verify the third signature value Sign3. If the verification succeeds, the process proceeds to step S362. If the verification fails, an error is returned to the certificate signing device and the process terminates.
[0079] Step S362: The unified authorization and authentication management system queries the corresponding vehicle terminal digital certificate ObuCert according to the unique serial number SerialNum of the vehicle terminal security chip in the application parameter, and returns ObuCert to the certificate signing device;
[0080] Step S37: The certificate endorsement device sends a certificate endorsement instruction (including ObuCert) to the vehicle terminal via NFC or the V2X PC5 communication protocol. The vehicle terminal forwards ObuCert to the embedded security chip. The vehicle terminal security chip verifies the digital certificate ObuCert using the stored public key of the Internet of Vehicles CA certificate. If verification succeeds, the digital certificate ObuCert is securely stored. If verification fails, an error message is returned to the vehicle terminal. This concludes the entire intelligent connected vehicle digital certificate authorization generation and secure endorsement process.
[0081] The method for authorized generation and secure endorsement of digital certificates for intelligent connected vehicles (ICVs) provided by this invention leverages security devices such as onboard terminal security chips and cryptographic machines to design an initial authorization and key distribution mechanism. This allows for initial security configuration of the ICV's onboard terminals. This method establishes an authorized generation mechanism for ICV digital certificates and a secure endorsement mechanism based on asymmetric and symmetric cryptographic algorithms. This prevents ICV terminals from applying for digital certificates without initial security configuration, and enables secure endorsement of ICV digital certificates to the onboard terminal security chip. The entire solution fully utilizes domestic cryptographic algorithms with proprietary intellectual property rights, ensuring independent and controllable digital certificate authorization generation and secure endorsement.
[0082] As another embodiment of the present invention, Figure 5-6As shown, a system for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles is provided, which includes a vehicle network CA system, a unified authorization and authentication management system, an initialization endorsement device, a certificate endorsement device, and an on-board terminal. The unified authorization and authentication management system also includes a cryptographic machine, the certificate endorsement device also includes a hardware security module, and the on-board terminal also includes a security chip.
[0083] The Internet of Vehicles CA system is used to provide digital certificate issuance services for intelligent connected vehicles;
[0084] The unified authorization and authentication management system is used to provide intelligent connected vehicle digital certificate authorization and authentication and security management functions;
[0085] The initialization signing device is used for the initial security configuration of the vehicle terminal; specifically, it is used to communicate with the vehicle terminal during the initial security configuration of the vehicle terminal security chip, and is mainly responsible for signing the initial key, etc. to the vehicle terminal security chip.
[0086] The certificate signing device is used to securely sign the digital certificate into the security chip; it is specifically used to communicate with the on-board terminal during the authorization generation and secure signing process of the digital certificate of the intelligent connected vehicle, and is mainly responsible for signing the digital certificate, etc. into the security chip of the on-board terminal.
[0087] The vehicle-mounted terminal is installed on the intelligent connected vehicle and is used to communicate with the initialization endorsement device and the certificate endorsement device respectively, and provide relevant data processing and forwarding functions such as authentication authorization.
[0088] Preferably, the security chip is used to store digital certificates and keys of intelligent connected vehicles and provide secure cryptographic computing services.
[0089] Preferably, the cryptographic machine is used to provide key dispersion, data encryption and decryption, and data signature verification security cryptographic operations, and is called by the unified authorization and authentication management system.
[0090] Preferably, the hardware security module is used to provide key generation, data encryption and decryption, and data signature verification security cryptographic operations, is embedded in the certificate signing device, and is called by the certificate signing device according to actual business processes.
[0091] The intelligent connected vehicle digital certificate authorization generation and security endorsement system provided by the present invention adopts domestic cryptographic algorithms, relies on security equipment such as vehicle-mounted terminal security chips and cryptographic machines, designs initial authorization and key dispersion mechanisms, and realizes the writing of initial keys into the vehicle-mounted terminal security chips; relies on the initial key to generate authorization credentials, establishes an intelligent connected vehicle digital certificate authorization generation mechanism, and realizes the compliant generation of digital certificates; combines the identity authentication mechanisms of asymmetric algorithms and symmetric algorithms to construct a secure communication link, and realizes the secure endorsement of intelligent connected vehicle digital certificates to the vehicle-mounted terminal security chips.
[0092] The above description is merely a preferred embodiment of the present invention and does not constitute any form of limitation to the present invention. Although the present invention has been disclosed as a preferred embodiment, it is not intended to limit the present invention. Any technician familiar with the present profession can make slight changes or modifications to equivalent embodiments using the technical contents disclosed above without departing from the scope of the technical solution of the present invention. However, any simple modifications, equivalent changes and modifications made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention are still within the scope of the technical solution of the present invention.
Claims
1. A method for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles, characterized in that: include: Step S1: initial security configuration phase of the vehicle terminal security chip; Step S2: Intelligent connected vehicle digital certificate authorization generation stage; Step S3: Intelligent connected vehicle digital certificate security endorsement stage; Wherein, the step S1 further includes: Step S11: Initialize the endorsement device to send initial configuration instructions to the vehicle terminal security chip; Step S12: After receiving the initial configuration instruction, the vehicle terminal security chip randomly generates a temporary public-private key pair, uses the temporary private key to sign the unique serial number of the vehicle terminal security chip to obtain a first signature value, and returns the unique serial number of the vehicle terminal security chip, the first signature value, and the temporary public key to the initialization signing device; Step S13: the initialization endorsement device requests initial authorization from the unified authorization and authentication management system, and the request parameters include the unique serial number of the vehicle terminal security chip, the first signature value and the temporary public key; Step S14: After receiving the initial authorization request, the unified authorization and authentication management system uses the temporary public key of the vehicle terminal security chip to verify the first signature value, and verifies that the unique serial number of the vehicle terminal security chip is respectively subjected to key dispersion operation by using the system root key and the single card authentication root key to generate an initial session key and a single card authentication key. After filing the unique serial number of the vehicle terminal security chip, the initial session key and the single card authentication key are encrypted using the temporary public key of the vehicle terminal security chip to obtain an initial session key ciphertext and a single card authentication key ciphertext, and the initial session key ciphertext and the single card authentication key ciphertext are returned to the initialization endorsement device; Step S15: the initialization endorsement device sends the initial session key ciphertext and the single card authentication key ciphertext to the vehicle terminal security chip; Step S16: The vehicle terminal security chip decrypts the initial session key ciphertext and the single card authentication key ciphertext using the temporary private key of the vehicle terminal security chip, and securely stores the initial session key and the single card authentication key; Wherein, the step S2 further includes: Step S21: The certificate endorsement device requests the unified authorization and authentication management system to generate a digital certificate. The unified authorization and authentication management system generates a first random number R1 and initiates an authentication request for the vehicle terminal security chip. The authentication request is returned to the certificate endorsement device. Step S22: After receiving the authentication request, the certificate signing device forwards it to the vehicle-mounted terminal security chip. After receiving the authentication request, the vehicle-mounted terminal security chip randomly generates a public-private key pair, signs the public key with the private key and generates a certificate request file, then encrypts the first random number R1 with the initial session key to obtain an authorization certificate, and finally signs the authorization certificate and the unique serial number of the vehicle-mounted terminal security chip with the private key to obtain a second signature value, and returns the authorization certificate, the unique serial number of the vehicle-mounted terminal security chip, the second signature value and the certificate request file to the certificate signing device; Step S23: The certificate endorsement device forwards the received authorization certificate, the unique serial number of the vehicle terminal security chip, the second signature value and the certificate request file to the unified authorization and authentication management system; Step S24: After receiving the certificate request file, the unified authorization and authentication management system first verifies the certificate request file. After the verification is passed, it uses the public key to verify the second signature value. After the verification is passed, it uses the system root key to perform a decentralized operation on the unique serial number of the vehicle terminal security chip to generate the initial session key. The authorization certificate is decrypted using the initial session key, and the decrypted random number R1' is compared with the initially generated first random number R1 to see if they are consistent. If they are consistent, the authorization and authentication are passed, and a request is made to the vehicle network CA system to generate a certificate. Step S25: After receiving the certificate request, the Internet of Vehicles CA system issues a digital certificate and returns the digital certificate to the unified authorization and authentication management system. The unified authorization and authentication management system returns the certificate generation result to the certificate endorsement device. Wherein, the step S3 further includes: Step S31: The certificate signing device requests the vehicle terminal security chip to sign the certificate. After receiving the request, the vehicle terminal security chip generates a second random number R2 and returns the second random number R2 and the unique serial number of the vehicle terminal security chip to the certificate signing device. Step S32: The certificate signing device calculates the Hmac1 value for the received second random number R2, generates a new third random number R3, and sends the Hmac1 value and the third random number R3 to the vehicle terminal security chip; the vehicle terminal security chip verifies the Hmac1 value using the generated second random number R2, and if it passes, calculates the third random number R3 generated by the certificate signing device to obtain the Hmac2 value, and sends the Hmac2 value to the certificate signing device; Step S33: The certificate endorsement device verifies the Hmac2 value using the generated third random number R3. If the verification is successful, the device applies to the unified authorization and authentication management system for downloading the digital certificate. The application parameters include the unique serial number of the vehicle terminal security chip. Step S34: After receiving the certificate download request, the unified authorization and authentication management system generates a fourth random number R4 and initiates identity authentication of the certificate signing device; Step S35: the certificate signing device signs the fourth random number R4 to obtain a third signature value, and sends the third signature value and the certificate signing device certificate to the unified authorization and authentication management system; Step S36: The unified authorization and authentication management system verifies the certificate signing device certificate. If the verification is successful, the third signature value is verified using the public key of the certificate signing device certificate. If the verification is successful, the corresponding digital certificate is found based on the unique serial number of the vehicle terminal security chip in the application parameters, and the corresponding digital certificate is returned to the certificate signing device. Step S37: The certificate signing device sends a certificate signing instruction to the vehicle terminal security chip, and the vehicle terminal security chip securely stores the digital certificate.
2. A system for authorizing the generation and security endorsement of digital certificates for intelligent connected vehicles, for implementing the method for authorizing the generation and security endorsement of digital certificates for intelligent connected vehicles according to claim 1, characterized in that: The intelligent connected vehicle digital certificate authorization generation and security endorsement system includes a vehicle network CA system, a unified authorization and authentication management system, an initialization endorsement device, a certificate endorsement device, and an on-board terminal. The unified authorization and authentication management system also includes a cryptographic machine, the certificate endorsement device also includes a hardware security module, and the on-board terminal also includes a security chip; The Internet of Vehicles CA system is used to provide digital certificate issuance services for intelligent connected vehicles; The unified authorization and authentication management system is used to provide intelligent connected vehicle digital certificate authorization and authentication and security management functions; The initialization endorsement device is used for the initial security configuration of the vehicle terminal; The certificate signing device is used to securely sign the digital certificate to the security chip; The vehicle-mounted terminal is installed on the intelligent connected vehicle and is used to communicate with the initialization endorsement device and the certificate endorsement device respectively, and provide authentication and authorization data processing and forwarding functions.
3. The system for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles according to claim 2, characterized in that: The security chip is used to store digital certificates and keys of intelligent connected vehicles and provide secure cryptographic computing services.
4. The system for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles according to claim 2, characterized in that: The cryptographic machine is used to provide key dispersion, data encryption and decryption, and data signature verification security cryptographic operations, and is called by the unified authorization and authentication management system.
5. The system for authorizing the generation and secure endorsement of digital certificates for intelligent connected vehicles according to claim 2, characterized in that: The hardware security module is used to provide key generation, data encryption and decryption, and data signature verification security cryptographic operations, and is embedded in the certificate signing device and called by the certificate signing device according to actual business processes.
Citation Information
Patent Citations
Intelligent secret key device and information management method of intelligent secret key device
CN103929306A
Executing a cryptographic operation
US20200313886A1