A method, device and storage medium for safe communication of heavy-duty vehicles in closed scenarios

By performing distributed key negotiation and identity authentication in the heavy-duty vehicle negotiation order and using pseudonymous certificates for encrypted communication, the communication security issue after the central node of a heavy-duty vehicle fleet is attacked in a closed scenario is solved, ensuring the secure transmission of sensitive information.

CN115967489BActive Publication Date: 2025-09-16SINO TRUK JINAN POWER CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211634883.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-19
Publication Date
2025-09-16
Estimated Expiration
2042-12-19

AI Technical Summary

Technical Problem

In a closed scenario, once the central node of a heavy-duty vehicle fleet is attacked, the communication of the entire fleet will be affected, and there will be problems of illegal device access and key sharing in insecure channels.

Method used

By performing distributed key negotiation in the heavy-duty vehicle negotiation order, using key negotiation operation information for identity authentication and key negotiation, and using pseudonym certificates for encrypted communication, it is ensured that keys are shared in insecure channels, and the correctness of the keys is verified through hash operations.

Benefits of technology

It achieves communication security when the fleet center node is attacked, prevents illegal equipment from accessing, ensures the secure communication of sensitive information, and solves the problem of key sharing in insecure channels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115967489B_ABST
    Figure CN115967489B_ABST
Patent Text Reader

Abstract

The present application provides a method, device and storage medium for secure communication of heavy-duty vehicles in a closed scenario, and relates to a secure communication technology for the Internet of Vehicles of heavy-duty vehicles. The method comprises: each heavy-duty vehicle among N heavy-duty vehicles obtains a heavy-duty vehicle negotiation order and key negotiation operation information; the N heavy-duty vehicles form a negotiation chain according to the heavy-duty vehicle negotiation order, and use the key negotiation operation information to perform key negotiation and identity authentication in sequence until each heavy-duty vehicle obtains the same key KN; the N heavy-duty vehicles use the key for encrypted communication. The method of the present application solves the problem that the central node of the fleet is attacked and the communication of the entire fleet will be affected through the negotiation order of heavy-duty vehicles; solves the problem of illegal device access and access through the key negotiation operation information; solves the problem of key sharing in an unsafe channel through the key negotiation operation information; and solves the problem of secure communication of sensitive information through the key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to a heavy-duty vehicle network safety communication technology, and in particular to a heavy-duty vehicle safety communication method, device and storage medium in a closed scenario. Background Art

[0002] With the application of emerging technologies such as autonomous driving and vehicle-infrastructure collaboration, heavy-duty vehicles have become mobile, interactive, and intelligent terminals. During IoV broadcast communications, heavy-duty vehicles broadcast sensitive information, including but not limited to vehicle information and location status. The leakage of this sensitive information could not only cause personal property damage but also endanger national public security. Therefore, during direct communication, both communicating parties encrypt sensitive information using a pre-agreed key before sending it.

[0003] In a fleet of several heavy-duty vehicles, a cloud server or a heavy-duty vehicle is usually selected as the central node, and other heavy-duty vehicles perform centralized mutual authentication and key negotiation with the central node.

[0004] However, once the central node is attacked, the communication of the entire fleet will be affected. Summary of the Invention

[0005] The present application provides a method, device and storage medium for safe communication of heavy-duty vehicles in a closed scenario, which is used to solve the problem that once the central node is attacked, the communication of the entire fleet will be affected.

[0006] In a first aspect, the present application provides a method for safe communication of heavy-duty vehicles in a closed scenario. The safe communication method is applied to a closed scenario, wherein the closed scenario includes N heavy-duty vehicles communicating with each other, where N is an integer greater than or equal to 2. The safe communication method includes:

[0007] Each of the N heavy-duty vehicles obtains a heavy-duty vehicle negotiation order and key negotiation operation information;

[0008] N heavy-duty vehicles form a negotiation chain in the order of heavy-duty vehicle negotiation, and use key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N ;

[0009] N heavy vehicles use key K N Conduct encrypted communications.

[0010] In a possible design, the N heavy-duty vehicles include an i-th heavy-duty vehicle, where i is an integer greater than or equal to 1 and less than or equal to N;

[0011] Accordingly, N heavy-duty vehicles form a negotiation chain in the order of heavy-duty vehicle negotiation, and use key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N ,include:

[0012] The i-1th heavy-duty vehicle among the N heavy-duty vehicles obtains a random number r i-1 ;

[0013] The i-1th heavy-duty vehicle among N heavy-duty vehicles is assigned a random number r. i-1 , obtain a random public key P i-1 ;

[0014] If i is equal to 1, the i-1th heavy-duty vehicle among the N heavy-duty vehicles is the Nth heavy-duty vehicle. The Nth heavy-duty vehicle negotiates the key with the first heavy-duty vehicle according to the negotiation chain;

[0015] If i is an integer greater than or equal to 2 and less than or equal to N, the i-1th heavy-duty vehicle among the N heavy-duty vehicles performs key negotiation with the i-th heavy-duty vehicle;

[0016] The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 ;

[0017] The i-th heavy-duty vehicle among N heavy-duty vehicles receives the random public key P i-1 ;

[0018] The i-th heavy-duty vehicle among N heavy-duty vehicles is assigned a random public key P i-1 , random number r i , get the first intermediate value K i1 ;

[0019] The i-th heavy-duty vehicle among the N heavy-duty vehicles is calculated based on the first intermediate value K i1 , get the first key K where N is equal to 2 N=2 .

[0020] In one possible design, N heavy-duty vehicles perform N-1 rounds of key negotiation, including the j-th round of key negotiation, where j is an integer greater than or equal to 1 and less than or equal to N-1;

[0021] Accordingly, N heavy vehicles are divided into two groups according to the first intermediate value K. i1, Get the first key K where N is equal to 2 N=2 After that, it also includes:

[0022] In the jth round of key negotiation among N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1th intermediate value K i-1,j - 1 ;

[0023] The i-th heavy-duty vehicle among the N heavy-duty vehicles is calculated based on the j-1th intermediate value K i-1,j-1 , random number r i , get the jth intermediate value K i,j ;

[0024] Each of the N heavy-duty vehicles is calculated based on the j-th intermediate value K i,j , obtain the second key K where N is greater than or equal to 3 N≥3 .

[0025] In a possible design, each of the N heavy-duty vehicles is pre-installed with an initialized pseudonym certificate S i , pseudonym certificate S i Contains private key and public key;

[0026] Correspondingly, the i-th heavy-duty vehicle among N heavy-duty vehicles receives the random public key P i-1 Previously, including:

[0027] The i-1th heavy-duty vehicle among the N heavy-duty vehicles is identified by the pseudonym certificate S i-1 The private key is used to obtain the random public key P i-1 The signature value S i-1,p ;

[0028] The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 , signature value S i-1,p and a pseudonym certificate S i-1 First public information;

[0029] The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the first public information;

[0030] Verify pseudonym certificate S of the i-th heavy-duty vehicle among N heavy-duty vehicles i-1 the legitimacy of

[0031] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles will be registered according to the pseudonym certificate S i-1 The public key decrypts the signature value S i-1,p , obtain the first decrypted information D i-1,p ;

[0032] The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D i-1,p and a random public key P i-1 consistency;

[0033] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles stores the pseudonym certificate S i-1 And the random public key P i-1 ;

[0034] Correspondingly, in the jth round of key negotiation among N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1th intermediate value K i-1,j-1 Previously, including:

[0035] The i-1th heavy-duty vehicle among the N heavy-duty vehicles is identified by the pseudonym certificate S i-1 The private key of the j-1 intermediate value K is obtained i-1,j-1 The signature value S i-1,j-1 ;

[0036] The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a message including the j-1th intermediate value K to the i-th heavy-duty vehicle. i-1,j-1 And the signature value S i-1,j-1 Second public information;

[0037] The i-th heavy-duty vehicle among the N heavy-duty vehicles receives and verifies the signature of the second public information.

[0038] In one possible design, the i-th heavy-duty vehicle among N heavy-duty vehicles verifies the key K N ;

[0039] Accordingly, N heavy-duty vehicles form a negotiation chain in the order of heavy-duty vehicle negotiation, and use key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N After that, including;

[0040] The i-1th heavy-duty vehicle among the N heavy-duty vehicles is assigned a key K N , random public key P i-1 , through hash operation, obtain the first verification information H K、P,i-1 ;

[0041] The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends verification information H to the i-th heavy-duty vehicle. K、P,i-1 ;

[0042] The i-th heavy-duty vehicle among N heavy-duty vehicles is assigned a key K N , the stored random public key P i-1 , through hash operation, obtain the second verification information H K、P,i ;

[0043] The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first verification information H K、P,i-1 and the second verification information H K、P,i-1 consistency;

[0044] The i-th heavy-duty vehicle among N heavy-duty vehicles stores the key K N .

[0045] In one possible design, one heavy-duty vehicle is randomly selected from N heavy-duty vehicles as the group leader;

[0046] Accordingly, before each of the N heavy-duty vehicles obtains the heavy-duty vehicle negotiation order and key negotiation operation information, the following steps are performed:

[0047] The group leader among N heavy trucks obtains the negotiated order of heavy trucks;

[0048] The group head among N heavy vehicles obtains the key agreement protocol;

[0049] The group heads of the N heavy-duty vehicles obtain key negotiation operation information according to the key negotiation protocol;

[0050] The group head of the N heavy-duty vehicles sends heavy-duty vehicle negotiation order and key negotiation operation information to each heavy-duty vehicle.

[0051] In one possible design, the i-th heavy truck among N heavy trucks broadcasts sensitive information M i ;

[0052] The N heavy-duty vehicles include the qth heavy-duty vehicle, where q is an integer greater than or equal to 1 and less than or equal to N, and q is not equal to i;

[0053] Accordingly, N heavy trucks use the key K N Conduct encrypted communications, including:

[0054] The i-th heavy-duty vehicle among N heavy-duty vehicles is assigned a key K N 、Sensitive informationM i , through encryption operation, obtain the first encrypted information C i ;

[0055] The i-th heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second encrypted information H C,i ;

[0056] The i-th heavy-duty vehicle among N heavy-duty vehicles is assigned a pseudonym certificate S i The private key is used to obtain the second encrypted information H C,i The signature value S i,H ;

[0057] The i-th heavy-duty vehicle among the N heavy-duty vehicles broadcasts the first encrypted information C i And the signature value S i,H Direct communication information;

[0058] The qth heavy-duty vehicle among the N heavy-duty vehicles receives the direct communication information;

[0059] The qth heavy-duty vehicle among the N heavy-duty vehicles is issued according to the false name certificate S i The public key decrypts the signature value S i,H , obtain the first decrypted information D q,H ;

[0060] The qth heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second decryption information H C,q ;

[0061] The qth heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D q,H and the second decrypted information H C,q consistency;

[0062] If the verification is successful, the qth heavy-duty vehicle among the N heavy-duty vehicles will be detected according to the key K N , first encrypted information C i , through decryption operation, obtain sensitive information M i .

[0063] In a second aspect, the present application provides a sensitive information security communication device, including a key negotiation module, a certificate management module, and an encryption communication module;

[0064] The key negotiation module is used to form a negotiation chain of N heavy-duty vehicles in the order of heavy-duty vehicle negotiation, and to perform key negotiation in sequence using key negotiation operation information until all heavy-duty vehicles obtain the same key K. N ;

[0065] The certificate management module is used for the negotiation chain formed by N heavy-duty vehicles in the order of heavy-duty vehicle negotiation, and uses the key negotiation operation information to perform identity authentication in sequence until each heavy-duty vehicle obtains the same key K N ;

[0066] The encrypted communication module is used for N heavy-duty vehicles using the key K N Conduct encrypted communications.

[0067] In a third aspect, the present application provides an electronic device, comprising a processor and a memory communicatively connected to the processor;

[0068] Memory stores computer-executable instructions;

[0069] The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 7.

[0070] In a fourth aspect, the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the method according to any one of claims 1 to 7.

[0071] The present application provides a method, device, and storage medium for secure communication of heavy-duty vehicles in a closed scenario, which achieve the following technical effects: distributed key negotiation is performed through the negotiation order of heavy-duty vehicles, solving the problem that the central node of the fleet is attacked and the communication of the entire fleet will be affected; identity authentication is performed through key negotiation operation information, solving the problem of illegal device access and access; key negotiation is performed through key negotiation operation information, solving the problem of key sharing in an insecure channel; and encrypted communication of sensitive information is performed through keys, solving the problem of secure communication of sensitive information. BRIEF DESCRIPTION OF THE DRAWINGS

[0072] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0073] Figure 1 A schematic diagram of a process for a heavy-duty vehicle safety communication method in a closed scenario provided in an embodiment of the present application Figure 1 ;

[0074] Figure 2 A schematic diagram of the structure of a negotiation chain formed by a heavy-duty vehicle negotiation order provided in an embodiment of the present application Figure 1 ;

[0075] Figure 3 A schematic diagram of a process for obtaining heavy-duty vehicle negotiation order and key negotiation operation information provided in an embodiment of the present application Figure 2 ;

[0076] Figure 4 A schematic diagram of a key negotiation and identity authentication process provided in an embodiment of the present application Figure 3 ;

[0077] Figure 5 A schematic diagram of a key negotiation and identity authentication process provided in an embodiment of the present application Figure 4 ;

[0078] Figure 6 Schematic diagram of the process of key negotiation and identity authentication between three heavy-duty vehicles provided in the embodiment of this application Figure 5 ;

[0079] Figure 7 A schematic diagram of an encrypted communication process provided in an embodiment of the present application Figure 6 ;

[0080] Figure 8 Schematic diagram of the encrypted communication process between three heavy-duty vehicles provided in this application embodiment Figure 7 ;

[0081] Figure 9 Schematic diagram of the structure of the sensitive information security communication device provided in the embodiment of the present application Figure 2 ;

[0082] Figure 10 Schematic diagram of the structure of the electronic device provided in the embodiment of the present application Figure 3 . DETAILED DESCRIPTION

[0083] The exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0084] First, the relevant concepts or terms involved in this application are explained:

[0085] Closed scenarios: These include, but are not limited to, scenarios involving autonomous driving fleets operating in closed campuses, closed ports, or on highways. Fleet communications in closed scenarios only involve vehicle-to-vehicle communication within the fleet and do not involve communication between vehicles within the fleet and other vehicles.

[0086] Key negotiation: This is the process by which at least two heavy-duty vehicles in a fleet negotiate and jointly establish a key. Any participant can influence the outcome, and key negotiation does not require any trusted third party.

[0087] Key negotiation protocol: This refers to the protocol used to calculate the key during the key negotiation process. The key is derived from parameters generated by each protocol participant through a specific calculation.

[0088] Figure 1 A schematic diagram of a process for a heavy-duty vehicle safety communication method in a closed scenario provided in an embodiment of the present application Figure 1 ;

[0089] Figure 2 A schematic diagram of the principle of a negotiation chain formed by a negotiation order of heavy-duty vehicles provided in an embodiment of the present application.

[0090] The secure communication method is applied to a closed scene, wherein the closed scene includes N heavy vehicles communicating with each other, where N is an integer greater than or equal to 2; Figure 1 As shown, the method includes:

[0091] S101: Each heavy-duty vehicle among N heavy-duty vehicles obtains a heavy-duty vehicle negotiation order and key negotiation operation information;

[0092] Specifically, assume that there are three heavy-duty vehicles involved in the communication in the fleet, which are represented as the first heavy-duty vehicle, the second heavy-duty vehicle, and the third heavy-duty vehicle. The three heavy-duty vehicles perform distributed key negotiation based on the negotiation chain formed by the negotiation order of the heavy-duty vehicles. Figure 2 As shown, the negotiation chain is as follows: the first heavy-duty vehicle negotiates a key with the second heavy-duty vehicle; after the negotiation, the second heavy-duty vehicle negotiates a key with the third heavy-duty vehicle; after the negotiation, the third heavy-duty vehicle negotiates a key with the first heavy-duty vehicle.

[0093] The three heavy-duty vehicles perform key negotiation and identity authentication based on the key negotiation operation information.

[0094] S102: N heavy-duty vehicles form a negotiation chain in the order of heavy-duty vehicle negotiation, and use key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N ;

[0095] Specifically, the three heavy-duty vehicles perform key negotiation in sequence according to a pre-agreed negotiation chain. First, the legitimacy of the initiator of the key negotiation is verified to prevent unauthorized access. Second, the three heavy-duty vehicles generate encryption keys for sensitive information, allowing the keys to be shared over an insecure channel.

[0096] S103: N heavy vehicles use key K N Conduct encrypted communications;

[0097] Specifically, First Heavy Industries uses the key K N , encrypt sensitive information including but not limited to vehicle information and location status, obtain and send encrypted information; the second heavy-duty vehicle and the third heavy-duty vehicle receive and decrypt the encrypted information to obtain the sensitive information of the first heavy-duty vehicle.

[0098] The method provided in this embodiment achieves the following technical effects for each of the N heavy-duty vehicles: distributed key negotiation is performed through the negotiation order of the heavy-duty vehicles, thereby resolving the problem that if the central node of the fleet is attacked, the communication of the entire fleet will be affected; identity authentication is performed through key negotiation operation information, thereby resolving the problem of illegal device access and access; key negotiation is performed through key negotiation operation information, thereby resolving the problem of key sharing in an insecure channel; and encrypted communication of sensitive information is performed through the key, thereby resolving the problem of secure communication of sensitive information.

[0099] The following uses a specific embodiment to describe in detail the safe communication method for heavy-duty vehicles in a closed scenario of the present application.

[0100] Figure 3 A schematic diagram of a process for obtaining heavy-duty vehicle negotiation order and key negotiation operation information provided in an embodiment of the present application Figure 2 ;

[0101] Figure 4 A schematic diagram of a key negotiation and identity authentication process provided in an embodiment of the present application Figure 3 ;

[0102] Figure 5 A schematic diagram of a key negotiation and identity authentication process provided in an embodiment of the present application Figure 4 ;

[0103] Figure 6 Schematic diagram of the process of key negotiation and identity authentication between three heavy-duty vehicles provided in the embodiment of this application Figure 5 ;

[0104] Figure 7 A schematic diagram of an encrypted communication process provided in an embodiment of the present application Figure 6 ;

[0105] Figure 8 Schematic diagram of the encrypted communication process between three heavy-duty vehicles provided in this application embodiment Figure 7 .

[0106] Randomly select a heavy-duty vehicle from N heavy-duty vehicles as the group leader;

[0107] Accordingly, S101: before each of the N heavy-duty vehicles obtains the heavy-duty vehicle negotiation order and key negotiation operation information, the process includes:

[0108] S301: The group leader of N heavy-duty vehicles obtains the negotiated order of heavy-duty vehicles;

[0109] S302: The group heads of N heavy-duty vehicles obtain a key negotiation protocol;

[0110] S303: The group heads of the N heavy-duty vehicles obtain key negotiation operation information according to the key negotiation protocol;

[0111] S304: The group head of the N heavy-duty vehicles sends heavy-duty vehicle negotiation order and key negotiation operation information to each heavy-duty vehicle.

[0112] Specifically, the group head selects a key agreement protocol and discloses relevant parameters in the protocol among the fleet. In this embodiment, the key agreement protocol selected by the group head is the elliptic curve Diffie-Hellman key exchange. The group head selects the parameters and base point G of the elliptic curve. Based on the security of the elliptic curve discrete logarithm, the group head can publicly distribute it to all heavy-duty vehicles in the fleet.

[0113] Elliptic Curve Diffie-Hellman key exchange (ECDH) is a method for exchanging private keys. It's primarily used to establish secure shared encryption data over an insecure channel. Generally, the private key is exchanged, which is used by both parties as the key for symmetric encryption in subsequent data transmissions.

[0114] The N heavy-duty vehicles include the i-th heavy-duty vehicle, where i is an integer greater than or equal to 1 and less than or equal to N;

[0115] N heavy-duty vehicles perform N-1 rounds of key negotiation, including the jth round of key negotiation, where j is an integer greater than or equal to 1 and less than or equal to N-1;

[0116] Correspondingly, S102: N heavy-duty vehicles form a negotiation chain in accordance with the negotiation order of the heavy-duty vehicles, and use the key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N ,include;

[0117] S401: The i-1th heavy-duty vehicle among N heavy-duty vehicles obtains a random number r i-1 ;

[0118] S402: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is generated according to the random number r i-1 , obtain a random public key P i-1 ;

[0119] If i is equal to 1, the i-1th heavy-duty vehicle among the N heavy-duty vehicles is the Nth heavy-duty vehicle. The Nth heavy-duty vehicle negotiates the key with the first heavy-duty vehicle according to the negotiation chain;

[0120] If i is an integer greater than or equal to 2 and less than or equal to N, the i-1th heavy-duty vehicle among the N heavy-duty vehicles performs key negotiation with the i-th heavy-duty vehicle;

[0121] S403: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 ;

[0122] S404: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key P i-1 ;

[0123] S405: The i-th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the random public key P i-1 , random number r i , get the first intermediate value K i1 ;

[0124] S406: The i-th heavy-duty vehicle among the N heavy-duty vehicles is calculated based on the first intermediate value K i1 , get the first key K where N is equal to 2 N=2 ;

[0125] S407: In the jth round of key negotiation among N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1th intermediate value K i-1,j-1 ;

[0126] S408: The i-th heavy-duty vehicle among the N heavy-duty vehicles is determined according to the j-1-th intermediate value K i-1,j-1 , random number r i , get the jth intermediate value K i,j ;

[0127] S409: Each of the N heavy-duty vehicles is calculated based on the j-th intermediate value K i,j , obtain the second key K where N is greater than or equal to 3 N≥3 ;

[0128] S410: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the key K N , random public key P i-1 , through hash operation, obtain the first verification information H K、P,i-1 ;

[0129] S411: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends verification information H to the i-th heavy-duty vehicle. K、P,i-1 ;

[0130] S412: The i-th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the key K N , the stored random public key P i-1 , through hash operation, obtain the second verification information H K、P,i ;

[0131] S413: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first verification information H K、P,i-1 and the second verification information HK、P,i-1 consistency;

[0132] S414: The i-th heavy-duty vehicle among the N heavy-duty vehicles stores the key K N .

[0133] like Figure 5 As shown, each of the N heavy-duty vehicles has a preset initialized pseudonym certificate S i , pseudonym certificate S i Contains private key and public key;

[0134] Correspondingly, S404: the i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key P i-1 Previously, including:

[0135] S511: The i-1th heavy-duty vehicle among N heavy-duty vehicles is issued according to the pseudonym certificate S i-1 The private key is used to obtain the random public key P i-1 The signature value S i-1,p ;

[0136] S512: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 , signature value S i-1,p and a pseudonym certificate S i-1 First public information;

[0137] S513: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the first public information;

[0138] S514: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the pseudonym certificate S i-1 the legitimacy of

[0139] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles will be registered according to the pseudonym certificate S i-1 The public key decrypts the signature value S i-1,p , obtain the first decrypted information D i-1,p ;

[0140] S515: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D i-1,p and a random public key P i-1 consistency;

[0141] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles stores the pseudonym certificate S i-1 And the random public key P i-1 ;

[0142] Correspondingly, S407: In the jth round of key negotiation among N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1th intermediate value K i-1,j-1Previously, including:

[0143] S521: The i-1th heavy-duty vehicle among N heavy-duty vehicles is issued according to the pseudonym certificate S i-1 The private key of the j-1 intermediate value K is obtained i-1,j-1 The signature value S i-1,j-1 ;

[0144] S522: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a message including the j-1th intermediate value K to the i-th heavy-duty vehicle. i-1,j-1 And the signature value S i-1,j-1 Second public information;

[0145] S523: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives and verifies the signature of the second public information;

[0146] Specifically, assume that the communication involves three heavy-duty vehicles in a convoy, which are denoted as the first heavy-duty vehicle, the second heavy-duty vehicle, and the third heavy-duty vehicle. Figure 6 As shown, the three heavy vehicles negotiate keys and calculate keys in turn.

[0147] S611: First Heavy Automobile generates a random number r1 and calculates a random public key P1, where P1 = r1*G; uses the private key of the pseudonym certificate S1 to sign the random public key P1 and obtain the signature value S 1,P ;

[0148] S612: The first heavy-duty vehicle sends a message including the random public key P1 and the signature value S to the second heavy-duty vehicle. 1,P and the first public information F of the pseudonym certificate S1 1,P ;

[0149] S621: The Second Heavy Automobile receives and verifies the first public information F 1,P ;

[0150] S622: The second heavy-duty vehicle generates a random number r2 and calculates a random public key P2, where P2 = r2*G; uses the private key of the pseudonym certificate S2 to sign the random public key P2 and obtain the signature value S 2,P ;

[0151] S623: The second heavy-duty vehicle sends a message including the random public key P2 and the signature value S to the third heavy-duty vehicle. 2,P and the first public information F of the pseudonym certificate S2 2,P ;

[0152] S631: The Third Heavy Vehicle receives and verifies the first public information F 2,P ;

[0153] S632: The third heavy-duty vehicle generates a random number r3 and calculates a random public key P3, where P3 = r3*G; uses the private key of the pseudonym certificate S3 to sign the random public key P3 and obtain the signature value S 3,P ;

[0154] S633: The third heavy-duty vehicle sends a message including the random public key P3 and the signature value S to the first heavy-duty vehicle. 3,P and the first public information F of the pseudonym certificate S3 3,P ;

[0155] S613: First Heavy Automobile receives and verifies the first public information F 3,P ;

[0156] S614: First Heavy Truck calculates the first intermediate value K 11 , the first intermediate value K 11 = P3*r1; Use the private key of the pseudonym certificate S1 to calculate the first intermediate value K 11 Sign and obtain the signature value S 1,1 ;

[0157] S615: The first heavy-duty vehicle sends a message including the first intermediate value K to the second heavy-duty vehicle. 11 , signature value S 1,1 The second public information F 1,1 ;

[0158] S624: The Second Heavy Automobile receives and verifies the first public information F 1,P ;

[0159] S625: Second heavy vehicle calculates the first intermediate value K 21 , the first intermediate value K 21 =P1*r2; Use the private key of the pseudonym certificate S2 to calculate the first intermediate value K 21 Sign and obtain the signature value S 2,1 ;

[0160] S626: The second heavy-duty vehicle sends a message including the first intermediate value K to the third heavy-duty vehicle. 21 , signature value S 2,1 The second public information F 2,1 ;

[0161] S634: The Third Heavy Vehicle receives and verifies the first public information F 2,P ;

[0162] S635: Calculate the first intermediate value K for the third heavy vehicle 31 , the first intermediate value K 31 = P2*r3; Use the private key of the pseudonym certificate S3 to calculate the first intermediate value K 31 Sign and obtain the signature value S3,1 ;

[0163] S636: The third heavy-duty vehicle sends a message including the first intermediate value K to the first heavy-duty vehicle. 31 , signature value S 3,1 The second public information F 3,1 ;

[0164] S616: First Heavy Automobile receives and verifies the second public information F 3,2 ;

[0165] S617: First Heavy Truck calculates the second intermediate value K 12 , the second intermediate value K 12 =K 31 *r1; First Heavy Automobile obtains key K N=3 , key K N=3 =K 12 ;

[0166] S627: The Second Heavy Vehicle receives and verifies the second public information F 1,2 ;

[0167] S628: Calculate the second intermediate value K for the second heavy vehicle 22 , the second intermediate value K 22 =K 11 *r2; The second heavy vehicle obtains the key K N=3 , key K N=3 =K 22 ;

[0168] S637: The Third Heavy Vehicle receives and verifies the second public information F 2,2 ;

[0169] S638: Calculate the second intermediate value K for the third heavy vehicle 32 , the second intermediate value K 32 =K 21 *r3; The third heavy vehicle obtains the key K N=3 , key K N=3 =K 32 .

[0170] The above steps can be reduced to the key negotiation between two heavy vehicles in the fleet. Accordingly, the key K N=2 Equal to the first intermediate value K i1 The above steps can also be extended to the key negotiation between more than three heavy vehicles in the fleet. N Equal to the N-1th intermediate value K i,N-1 .

[0171] After N heavy trucks calculate the key, the key K is verified by hash operation. Ncorrectness.

[0172] A hash operation is a complex cryptographic operation involving the solution of a hash function. Any input string can be hashed to produce a different output string. Hash functions are one-way unique, meaning that the output of a given input is fixed, and each output corresponds to a unique input. There are no shortcuts to solving a hash operation; the correct answer can only be found through repeated attempts with random numbers.

[0173] If a heavy-duty vehicle dynamically joins or leaves the convoy, the heavy-duty vehicles in the convoy will renegotiate the key.

[0174] The i-th heavy-duty vehicle among N heavy-duty vehicles broadcasts sensitive information M i ;

[0175] The N heavy-duty vehicles include the qth heavy-duty vehicle, where q is an integer greater than or equal to 1 and less than or equal to N, and q is not equal to i;

[0176] Correspondingly, S130: N heavy-duty vehicles use key K N Conduct encrypted communications, including:

[0177] S701: The i-th heavy-duty vehicle among N heavy-duty vehicles is detected according to the key K N 、Sensitive informationM i , through encryption operation, obtain the first encrypted information C i ;

[0178] S702: The i-th heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second encrypted information H C,i ;

[0179] S703: The i-th heavy-duty vehicle among the N heavy-duty vehicles is registered according to the pseudonym certificate S i The private key is used to obtain the second encrypted information H C,i The signature value S i,H ;

[0180] S704: The i-th heavy-duty vehicle among the N heavy-duty vehicles broadcasts the first encrypted information C i And the signature value S i,H Direct communication information;

[0181] S705: The qth heavy-duty vehicle among the N heavy-duty vehicles receives direct communication information;

[0182] S706: The qth heavy-duty vehicle among N heavy-duty vehicles is issued according to the false name certificate S i The public key decrypts the signature value S i,H , obtain the first decrypted information Dq,H ;

[0183] S707: The qth heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second decryption information H C,q ;

[0184] S708: The qth heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D q,H and the second decrypted information H C,q consistency;

[0185] If the verification is successful, the qth heavy-duty vehicle among the N heavy-duty vehicles will be detected according to the key K N , first encrypted information C i , through decryption operation, obtain sensitive information M i .

[0186] Specifically, assume that the communication involves three heavy-duty vehicles in a convoy, which are denoted as the first heavy-duty vehicle, the second heavy-duty vehicle, and the third heavy-duty vehicle. Figure 8 As shown, the first heavy-duty truck broadcasts direct communication information, and the second and third heavy-duty trucks receive and verify the direct communication information.

[0187] S811: First Heavy Automobile Co., Ltd. according to key K N=3 , sensitive information M1, obtains first encrypted information C1 through symmetric encryption algorithm SM4;

[0188] S812: First Heavy Truck obtains second encrypted information H through hash operation based on the first encrypted information C1. C,1 ;

[0189] S813: First Heavy Automobile obtains the second encrypted information H based on the private key of the pseudonym certificate S1 C,1 The signature value S 1,H ;

[0190] S814: The first heavy vehicle broadcast includes the first encrypted information C1 and the signature value S 1,H Direct communication information;

[0191] S821: The Second Heavy Vehicle Company receives and verifies the direct communication information;

[0192] S822: Second heavy vehicle according to key K N=3 , decrypt the first encrypted information C1 and obtain the sensitive information M1;

[0193] S831: The Third Heavy Vehicle Company receives and verifies the direct communication information;

[0194] S832: The third heavy vehicle according to key KN=3 , decrypt the first encrypted information C1 and obtain the sensitive information M1.

[0195] With the method provided in this embodiment, each of the N heavy-duty vehicles achieves the following technical effects: distributed key negotiation is performed through the negotiation order of the heavy-duty vehicles, which solves the problem that the central node of the fleet is attacked and the communication of the entire fleet will be affected; identity authentication is performed through key negotiation operation information, which solves the problem of illegal device access and access; key negotiation is performed through key negotiation operation information, which solves the problem of key sharing in an insecure channel; encrypted communication of sensitive information is performed through the key, which solves the problem of secure communication of sensitive information; signing and decryption of public keys, intermediate values, and sensitive information are performed through pseudonym certificates, which solves the problem of identity authentication; the pseudonym certificate of the key negotiation initiator is stored, which solves the problem of repeated verification of the legitimacy of the pseudonym certificate; and the problem of dynamic entry or exit of heavy-duty vehicles in the fleet is solved by re-performing key negotiation.

[0196] In an embodiment of the present invention, the electronic device or main control device can be divided into functional modules according to the above method example. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one processing unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present invention is schematic and is only a logical functional division. In actual implementation, there may be other division methods.

[0197] Figure 9 Schematic diagram of the structure of the sensitive information security communication device provided in the embodiment of the present application Figure 2 .like Figure 9 As shown, the sensitive information security communication device 90 provided in the embodiment of the present application includes a key negotiation module 901, a certificate management module 902, and an encryption communication module 903;

[0198] The key negotiation module 901 is used to form a negotiation chain of N heavy-duty vehicles in the order of heavy-duty vehicle negotiation, and to perform key negotiation in sequence using key negotiation operation information until all heavy-duty vehicles obtain the same key K N ;

[0199] The certificate management module 902 is used for the negotiation chain formed by N heavy-duty vehicles in accordance with the negotiation order of heavy-duty vehicles, and uses the key negotiation operation information to perform identity authentication in sequence until each heavy-duty vehicle obtains the same key K N ;

[0200] The encryption communication module 903 is used for N heavy vehicles using the key K N Conduct encrypted communications.

[0201] Furthermore, the sensitive information security communication device 90 is specifically used to:

[0202] S101: Each heavy-duty vehicle among N heavy-duty vehicles obtains a heavy-duty vehicle negotiation order and key negotiation operation information;

[0203] S102: N heavy-duty vehicles form a negotiation chain in the order of heavy-duty vehicle negotiation, and use key negotiation operation information to perform key negotiation and identity authentication in sequence until all heavy-duty vehicles obtain the same key K N ;

[0204] S103: N heavy vehicles use key K N Conduct encrypted communications.

[0205] Furthermore, the key negotiation module 901 is specifically configured to:

[0206] S301: The group leader of N heavy-duty vehicles obtains the negotiated order of heavy-duty vehicles;

[0207] S302: The group head of N heavy-duty vehicles obtains a key negotiation protocol;

[0208] S303: The group heads of the N heavy-duty vehicles obtain key negotiation operation information according to the key negotiation protocol;

[0209] S304: The group head of the N heavy-duty vehicles sends heavy-duty vehicle negotiation order and key negotiation operation information to each heavy-duty vehicle;

[0210] S401: The i-1th heavy-duty vehicle among N heavy-duty vehicles obtains a random number r i-1 ;

[0211] S402: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is generated according to the random number r i-1 , obtain a random public key P i-1 ;

[0212] If i is equal to 1, the i-1th heavy-duty vehicle among the N heavy-duty vehicles is the Nth heavy-duty vehicle. The Nth heavy-duty vehicle negotiates the key with the first heavy-duty vehicle according to the negotiation chain;

[0213] If i is an integer greater than or equal to 2 and less than or equal to N, the i-1th heavy-duty vehicle among the N heavy-duty vehicles performs key negotiation with the i-th heavy-duty vehicle;

[0214] S403: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 ;

[0215] S404: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key Pi-1 ;

[0216] S405: The i-th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the random public key P i-1 , random number r i , get the first intermediate value K i1 ;

[0217] S406: The i-th heavy-duty vehicle among the N heavy-duty vehicles is calculated based on the first intermediate value K i1 , get the first key K where N is equal to 2 N=2 ;

[0218] S407: In the jth round of key negotiation among N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1th intermediate value K i-1,j-1 ;

[0219] S408: The i-th heavy-duty vehicle among the N heavy-duty vehicles is determined according to the j-1-th intermediate value K i-1,j-1 , random number r i , get the jth intermediate value K i,j ;

[0220] S409: Each of the N heavy-duty vehicles is calculated based on the j-th intermediate value K i,j , obtain the second key K where N is greater than or equal to 3 N≥3 ;

[0221] S410: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the key K N , random public key P i-1 , through hash operation, obtain the first verification information H K、P,i-1 ;

[0222] S411: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends verification information H to the i-th heavy-duty vehicle. K、P,i-1 ;

[0223] S412: The i-th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the key K N , the stored random public key P i-1 , through hash operation, obtain the second verification information H K、P,i ;

[0224] S413: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first verification information H K、P,i-1 and the second verification information H K、P,i-1 consistency;

[0225] S414: The i-th heavy-duty vehicle among the N heavy-duty vehicles stores the key K N .

[0226] Furthermore, the certificate management module 902 is specifically configured to:

[0227] S511: The i-1th heavy-duty vehicle among N heavy-duty vehicles is issued according to the pseudonym certificate S i-1 The private key is used to obtain the random public key P i-1 The signature value S i-1,p ;

[0228] S512: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 , signature value S i-1,p and a pseudonym certificate S i-1 First public information;

[0229] S513: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the first public information;

[0230] S514: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the pseudonym certificate S i-1 the legitimacy of

[0231] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles will be registered according to the pseudonym certificate S i-1 The public key decrypts the signature value S i-1,p , obtain the first decrypted information D i-1,p ;

[0232] S515: The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D i-1,p and a random public key P i-1 consistency;

[0233] If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles stores the pseudonym certificate S i-1 And the random public key P i-1 ;

[0234] S521: The i-1th heavy-duty vehicle among N heavy-duty vehicles is issued according to the pseudonym certificate S i-1 The private key of the j-1 intermediate value K is obtained i-1,j-1 The signature value S i-1,j-1 ;

[0235] S522: The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a message including the j-1th intermediate value K to the i-th heavy-duty vehicle. i-1,j-1 And the signature value S i-1,j-1 Second public information;

[0236] S523: The i-th heavy-duty vehicle among the N heavy-duty vehicles receives and verifies the signature of the second public information;

[0237] S703: The i-th heavy-duty vehicle among the N heavy-duty vehicles is registered according to the pseudonym certificate S i The private key is used to obtain the second encrypted information H C,i The signature value S i,H ;

[0238] S706: The qth heavy-duty vehicle among N heavy-duty vehicles is issued according to the false name certificate S i The public key decrypts the signature value S i,H , obtain the first decrypted information D q,H .

[0239] The i-th heavy-duty vehicle among the N heavy-duty vehicles receives and verifies the signature of the second public information. Further, the encryption communication module 903 is specifically used to:

[0240] S701: The i-th heavy-duty vehicle among N heavy-duty vehicles is detected according to the key K N 、Sensitive informationM i , through encryption operation, obtain the first encrypted information C i ;

[0241] S702: The i-th heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second encrypted information H C,i ;

[0242] S704: The i-th heavy-duty vehicle among the N heavy-duty vehicles broadcasts the first encrypted information C i And the signature value S i,H Direct communication information;

[0243] S705: The qth heavy-duty vehicle among the N heavy-duty vehicles receives direct communication information;

[0244] S707: The qth heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second decryption information H C,q ;

[0245] S708: The qth heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D q,H and the second decrypted information H C,q consistency;

[0246] If the verification is successful, the qth heavy-duty vehicle among the N heavy-duty vehicles will be detected according to the key K N , first encrypted information C i , through decryption operation, obtain sensitive information M i .

[0247] The sensitive information security communication device provided in this embodiment can execute a heavy-duty vehicle security communication method in a closed scenario in the above embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.

[0248] In the aforementioned implementation of the heavy-duty vehicle safety communication method in a closed scenario, each module can be implemented as a processor, and the processor can execute computer-executable instructions stored in the memory, so that the processor executes the above-mentioned heavy-duty vehicle safety communication method in a closed scenario.

[0249] Figure 10 Schematic diagram of the structure of the electronic device provided in the embodiment of the present application Figure 3 .like Figure 10 As shown, the electronic device 10 includes: at least one processor 1001 and a memory 1002. The electronic device 10 also includes a communication component 1003. The processor 1001, the memory 1002 and the communication component 1003 are connected via a bus 1004.

[0250] During the specific implementation process, at least one processor 1001 executes the computer execution instructions stored in the memory 1002, so that at least one processor 1001 executes a heavy-duty vehicle safety communication method in a closed scenario as executed by the electronic device side above.

[0251] The specific implementation process of the processor 1001 can be found in the above method embodiment. Its implementation principle and technical effects are similar and will not be repeated here in this embodiment.

[0252] In the above embodiments, it should be understood that the processor may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. A general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the present invention may be directly implemented by a hardware processor or implemented by a combination of hardware and software modules in the processor.

[0253] The memory may include a high-speed RAM memory, and may also include a non-volatile storage NVM, such as at least one disk storage.

[0254] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus. Buses can be classified into address buses, data buses, and control buses. For ease of illustration, the buses in the drawings of this application are not limited to just one bus or just one type of bus.

[0255] The above-mentioned functions implemented by the electronic device and the main control device have introduced the solutions provided by the embodiments of the present invention. It can be understood that in order to implement the above-mentioned functions, the electronic device or the main control device includes hardware structures and / or software modules corresponding to the execution of each function. In combination with the units and algorithm steps of the various examples described in the embodiments disclosed in the embodiments of the present invention, the embodiments of the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiments of the present invention.

[0256] The present application also provides a computer-readable storage medium, which stores computer-executable instructions. When a processor executes the computer-executable instructions, a method for safe communication of heavy-duty vehicles in a closed scenario as described above is implemented.

[0257] The computer-readable storage medium mentioned above can be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk. The computer-readable storage medium can be any available medium that can be accessed by a general-purpose or special-purpose computer.

[0258] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be an integral part of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in an electronic device or a main control device.

[0259] The present application also provides a computer program product, which includes: a computer program, which is stored in a readable storage medium. At least one processor of an electronic device can read the computer program from the readable storage medium, and at least one processor executes the computer program so that the electronic device executes the solution provided by any of the above embodiments.

[0260] Those skilled in the art will appreciate that all or part of the steps in the above-described method embodiments can be implemented using hardware associated with program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0261] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects, and do not limit their order. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity or execution order, and words such as "first" and "second" do not necessarily mean different.

[0262] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0263] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal connections between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.

[0264] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0265] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. A method for safe communication of heavy-duty vehicles in a closed environment, characterized in that: The method is applied to a closed scene, wherein the closed scene includes N heavy vehicles communicating with each other, where N is an integer greater than or equal to 2, and the method includes: Each of the N heavy-duty vehicles obtains a heavy-duty vehicle negotiation order and key negotiation operation information; The N heavy-duty vehicles form a negotiation chain in accordance with the negotiation order of the heavy-duty vehicles, and use the key negotiation operation information to perform key negotiation and identity authentication in sequence until each heavy-duty vehicle obtains the same key K N ; The N heavy vehicles use the key K N Conduct encrypted communications; The N heavy-duty vehicles include the i-th heavy-duty vehicle, where i is an integer greater than or equal to 1 and less than or equal to N; accordingly, the N heavy-duty vehicles form the negotiation chain in accordance with the negotiation order of the heavy-duty vehicles, and use the key negotiation operation information to perform the key negotiation and the identity authentication in sequence until each heavy-duty vehicle obtains the same key K N ,include: The i-1th heavy-duty vehicle among the N heavy-duty vehicles obtains a random number r i-1 ; The i-1th heavy-duty vehicle among the N heavy-duty vehicles is selected according to the random number r i-1 , obtain a random public key P i-1 ; If i is equal to 1, the (i-1)th heavy-duty vehicle among the N heavy-duty vehicles is the Nth heavy-duty vehicle, and the Nth heavy-duty vehicle performs the key negotiation with the first heavy-duty vehicle according to the negotiation chain; If i is an integer greater than or equal to 2 and less than or equal to N, the (i-1)th heavy-duty vehicle among the N heavy-duty vehicles performs the key negotiation with the (i)th heavy-duty vehicle; The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 ; The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key P i-1 ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is detected according to the random public key P i-1 , random number r i , get the first intermediate value K i1 ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is i1 , obtain the first key K where N is equal to 2 N=2 .

2. The method according to claim 1, characterized in that The N heavy-duty vehicles perform N-1 rounds of key negotiation, including the j-th round of key negotiation, where j is an integer greater than or equal to 1 and less than or equal to N-1; Accordingly, the N heavy vehicles are i1, Obtain the first key K where N is equal to 2 N=2 After that, it also includes: In the jth round of key negotiation among the N heavy vehicles, the i-th heavy vehicle receives the j-1th intermediate value K i-1,j-1 ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is determined according to the j-1-th intermediate value K i-1,j-1 , random number r i , get the jth intermediate value K i,j ; Each of the N heavy-duty vehicles is based on the j-th intermediate value K i,j , obtain the second key K where N is greater than or equal to 3 N≥3 .

3. The method according to claim 2, characterized in that Each of the N heavy-duty vehicles has a preset initialized pseudonym certificate S i , the pseudonym certificate S i Contains private key and public key; Correspondingly, the i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key P i-1 Previously, including: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is identified by the pseudonym certificate S i-1 The private key of the random public key P is obtained i-1 The signature value S i-1,p ; The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a data packet including the random public key P to the i-th heavy-duty vehicle. i-1 , the signature value S i-1,p and the pseudonym certificate S i-1 First public information; The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the first public information; The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the pseudonym certificate S i-1 the legitimacy of If the verification is successful, the i-th heavy-duty vehicle among the N heavy-duty vehicles is registered according to the pseudonym certificate S i-1 The public key decrypts the signature value S i-1,p , obtain the first decrypted information D i-1,p ; The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first decryption information D i-1,p and the random public key P i-1 consistency; If the verification is successful, the i-th heavy-duty vehicle of the N heavy-duty vehicles stores the pseudonym certificate S i-1 And the random public key P i-1 ; Correspondingly, in the j-th round of key negotiation among the N heavy-duty vehicles, the i-th heavy-duty vehicle receives the j-1-th intermediate value K i-1,j-1 Previously, including: The i-1th heavy-duty vehicle among the N heavy-duty vehicles is identified by the pseudonym certificate S i-1 The private key of the j-1th intermediate value K is obtained i-1,j-1 The signature value S i-1,j-1 ; The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a message including the j-1th intermediate value K to the i-th heavy-duty vehicle. i-1,j-1 And the signature value S i-1,j-1 Second public information; The i-th heavy-duty vehicle among the N heavy-duty vehicles receives and verifies the second public information.

4. The method according to claim 3, characterized in that The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the key K N ; Accordingly, the N heavy-duty vehicles form the negotiation chain in the order of the heavy-duty vehicle negotiation, and use the key negotiation operation information to perform the key negotiation and identity authentication in sequence until each heavy-duty vehicle obtains the same key K N After that, including; The i-1th heavy-duty vehicle among the N heavy-duty vehicles is driven by the key K N , the random public key P i-1 , through hash operation, obtain the first verification information H K、P,i-1 ; The i-1th heavy-duty vehicle among the N heavy-duty vehicles sends the verification information H to the i-th heavy-duty vehicle. K、P,i-1 ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is driven by the key K N , the stored random public key P i-1 , through hash operation, obtain the second verification information H K、P,i ; The i-th heavy-duty vehicle among the N heavy-duty vehicles verifies the first verification information H K、P,i-1 and the second verification information H K、P,i-1 consistency; The i-th heavy-duty vehicle of the N heavy-duty vehicles stores the key K N .

5. The method according to claim 4, characterized in that Randomly select a heavy-duty vehicle from the N heavy-duty vehicles as the group leader; Accordingly, before each of the N heavy-duty vehicles obtains the heavy-duty vehicle negotiation order and the key negotiation operation information, the process includes: The group leader of the N heavy-duty vehicles obtains the heavy-duty vehicle negotiation order; The group heads in the N heavy-duty vehicles obtain a key agreement protocol; The group heads of the N heavy-duty vehicles obtain the key negotiation operation information according to the key negotiation protocol; The group heads of the N heavy-duty vehicles send the heavy-duty vehicle negotiation order and the key negotiation operation information to each heavy-duty vehicle.

6. The method according to claim 5, characterized in that The i-th heavy-duty vehicle among the N heavy-duty vehicles broadcasts sensitive information M i ; The N heavy-duty vehicles include the qth heavy-duty vehicle, where q is an integer greater than or equal to 1 and less than or equal to N, and q is not equal to i; Accordingly, the N heavy-duty vehicles use the key K N Performing the encrypted communication includes: The i-th heavy-duty vehicle among the N heavy-duty vehicles is driven by the key K N , the sensitive information M i , through encryption operation, obtain the first encrypted information C i ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second encrypted information H C,i ; The i-th heavy-duty vehicle among the N heavy-duty vehicles is identified by the pseudonym certificate S i The private key is used to obtain the second encrypted information H C,i The signature value S i,H ; The i-th heavy-duty vehicle among the N heavy-duty vehicles broadcasts the first encrypted information C i And the signature value S i,H Direct communication information; The qth heavy-duty vehicle among the N heavy-duty vehicles receives the direct communication information; The qth heavy-duty vehicle among the N heavy-duty vehicles is registered according to the pseudonym certificate S i The public key decrypts the signature value S i,H , obtain the first decrypted information D q,H ; The qth heavy-duty vehicle among the N heavy-duty vehicles is encrypted according to the first encrypted information C i , through hash operation, obtain the second decryption information H C,q ; The qth heavy-duty vehicle among the N heavy-duty vehicles verifies the first decrypted information D q,H and the second decrypted information H C,q consistency; If the verification is successful, the qth heavy-duty vehicle among the N heavy-duty vehicles is detected according to the key K N , the first encrypted information C i , through decryption operation, obtain the sensitive information M i .

7. A sensitive information security communication device, characterized in that: include: Key negotiation module, certificate management module, and encryption communication module; The key negotiation module is used for the negotiation chain formed by N heavy-duty vehicles in the order of heavy-duty vehicle negotiation, and performs key negotiation in sequence using key negotiation operation information until all heavy-duty vehicles obtain the same key K N ; The certificate management module is used for the negotiation chain formed by the N heavy-duty vehicles in accordance with the negotiation order of the heavy-duty vehicles, and uses the key negotiation operation information to perform identity authentication in sequence until each heavy-duty vehicle obtains the same key K N ; The encryption communication module is used for the N heavy-duty vehicles to use the key K N Conduct encrypted communications; The N heavy-duty vehicles include the i-th heavy-duty vehicle, where i is an integer greater than or equal to 1 and less than or equal to N; accordingly, the certificate management module is specifically used for the i-1-th heavy-duty vehicle among the N heavy-duty vehicles to obtain the random number r i-1 The i-1th heavy-duty vehicle among the N heavy-duty vehicles is selected according to the random number r i-1 , obtain a random public key P i-1 If i is equal to 1, the i-1th heavy-duty vehicle among the N heavy-duty vehicles is the Nth heavy-duty vehicle, and the Nth heavy-duty vehicle performs the key negotiation with the first heavy-duty vehicle according to the negotiation chain; if i is an integer greater than or equal to 2 and less than or equal to N, the i-1th heavy-duty vehicle among the N heavy-duty vehicles performs the key negotiation with the i-th heavy-duty vehicle; the i-1th heavy-duty vehicle among the N heavy-duty vehicles sends a random public key P to the i-th heavy-duty vehicle. i-1 The i-th heavy-duty vehicle among the N heavy-duty vehicles receives the random public key P i-1 The i-th heavy-duty vehicle among the N heavy-duty vehicles is determined according to the random public key P i-1 , random number r i , get the first intermediate value K i1 The i-th heavy-duty vehicle of the N heavy-duty vehicles is based on the first intermediate value K i1 , obtain the first key K where N is equal to 2 N=2 .

8. An electronic device, characterized in that: include: a processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the method according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which are used to implement the method according to any one of claims 1 to 6 when executed by a processor.

Citation Information

Patent Citations

  • Secure communication method and device

    CN112640504A