A security authentication method and system of a vehicle-mounted unit, a terminal and a storage medium

By sending authentication information to the roadside intelligent station when the roadside unit and the vehicle-mounted unit are incompatible, and then having the roadside intelligent station perform security authentication, the problem of incompatibility between OBU and RSU is solved, security authentication of OBU is realized, and maintenance costs are reduced.

CN116321150BActive Publication Date: 2026-01-16SHENZHEN CHENGGU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310212363.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-02-27
Publication Date
2026-01-16
Estimated Expiration
2043-02-27

AI Technical Summary

Technical Problem

In a vehicle-road cooperative system, when the OBU and RSU are incompatible, the RSU cannot perform security authentication on the OBU.

Method used

When the roadside unit is incompatible with the vehicle-mounted unit, the authentication information is sent to the roadside intelligent station, which then forwards it to the target roadside unit that is compatible with the vehicle-mounted unit for security authentication and obtains the authentication result.

Benefits of technology

This solves the problem of RSU being unable to perform security authentication when OBU and RSU are incompatible, reduces the maintenance cost of OBU, and improves the real-time performance and efficiency of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116321150B_ABST
    Figure CN116321150B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of intelligent transportation, and mainly provides a safety authentication method and system of an on-board unit, a terminal and a storage medium. When the on-board unit and the road side unit are incompatible, the application sends the authentication information generated by the on-board unit to the road side intelligent station by the road side unit, sends the authentication information to the target road side unit compatible with the on-board unit by the road side intelligent station for safety authentication, and obtains an authentication result, thereby solving the problem that the road side unit cannot perform safety authentication on the on-board unit when the on-board unit and the road side unit are incompatible.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of intelligent transportation, and particularly relates to a security authentication method and system of an on-board unit, a terminal and a storage medium. BACKGROUND

[0002] An on-board unit (OBU) is a microwave device that uses dedicated short-range communication (DSRC) technology to communicate with a road-side unit (RSU) erected on the roadside. In an electronic toll collection (ETC) system, the OBU is configured on a vehicle, and when the vehicle passes through the RSU at high speed, the OBU and the RSU use microwave communication to complete the toll business. It is similar to the communication between contactless cards, but the communication distance between the OBU and the RSU is farther and the frequency is higher.

[0003] When the OBU and the RSU communicate, both sides need to perform identity legality authentication based on a psam-esam security authentication mechanism. However, with the increase in the types of OBUs and RSUs, the OBU and the RSU are often incompatible in the current vehicle-road cooperative system, which causes the RSU connected to the OBU to be unable to perform security authentication on the OBU. SUMMARY

[0004] The application provides a security authentication method and system of an on-board unit, a terminal and a storage medium, which can solve the problem that the RSU cannot perform security authentication on the OBU when the OBU and the RSU are incompatible.

[0005] An embodiment of the application provides a security authentication method of an on-board unit, applied to a road-side unit, and the security authentication method comprises the following steps.

[0006] Receiving authentication information sent by the on-board unit;

[0007] Judging whether the on-board unit and the road-side unit are compatible based on the authentication information;

[0008] When the on-board unit and the road-side unit are incompatible, sending the authentication information to a road-side intelligent station, and sending, by the road-side intelligent station, the authentication information to a target road-side unit compatible with the on-board unit;

[0009] Receiving an authentication result obtained by performing security authentication on the on-board unit by the target road-side unit and sent by the road-side intelligent station.

[0010] The second aspect of the embodiment of the application further provides a safety authentication method of a vehicle-mounted unit, applied to a roadside intelligent station, and the safety authentication method comprises the following steps:

[0011] receiving authentication information; the authentication information is authentication information generated by the vehicle-mounted unit and sent to the roadside intelligent station by the roadside unit when the roadside unit is incompatible with the vehicle-mounted unit;

[0012] sending the authentication information to a target roadside unit compatible with the vehicle-mounted unit, so that the target roadside unit performs safety authentication on the vehicle-mounted unit;

[0013] receiving an authentication result of the vehicle-mounted unit sent by the target roadside unit, and sending the authentication result to the roadside unit.

[0014] The third aspect of the embodiment of the application provides a safety authentication system of a vehicle-mounted unit, and the safety authentication system comprises a vehicle-mounted unit, a roadside unit and a roadside intelligent station.

[0015] The vehicle-mounted unit is configured to generate authentication information and send the authentication information to the roadside unit; the roadside unit is configured to perform the steps of the safety authentication method of the first aspect; and the roadside intelligent station is configured to perform the steps of the safety authentication method of the second aspect.

[0016] The fourth aspect of the embodiment of the application provides a safety authentication device of a vehicle-mounted unit, configured in a roadside unit, and comprising the following units:

[0017] a first receiving unit configured to receive authentication information sent by the vehicle-mounted unit;

[0018] a judging unit configured to judge whether the vehicle-mounted unit is compatible with the roadside unit based on the authentication information;

[0019] a first sending unit configured to, when the vehicle-mounted unit is incompatible with the roadside unit, send the authentication information to a roadside intelligent station, so that the roadside intelligent station sends the authentication information to a target roadside unit compatible with the vehicle-mounted unit;

[0020] a second receiving unit configured to receive an authentication result obtained by the target roadside unit performing safety authentication on the vehicle-mounted unit and sent by the roadside intelligent station.

[0021] The fifth aspect of the embodiment of the application provides a safety authentication device of a vehicle-mounted unit, configured in a roadside intelligent station, and comprising the following units:

[0022] a third receiving unit configured to receive authentication information; the authentication information is authentication information generated by the vehicle-mounted unit and sent to the roadside intelligent station by the roadside unit when the roadside unit is incompatible with the vehicle-mounted unit;

[0023] a second sending unit, configured to send the authentication information to a target road side unit compatible with the vehicle-mounted unit, so as to perform security authentication on the vehicle-mounted unit by the target road side unit;

[0024] a fourth receiving unit, configured to receive an authentication result of the vehicle-mounted unit sent by the target road side unit, and send the authentication result to the road side unit.

[0025] The sixth aspect of the embodiment of the present application provides a terminal, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the computer program implements the steps of the security authentication method in the first aspect or the second aspect when executed by the processor.

[0026] The seventh aspect of the embodiment of the present application provides a computer readable storage medium, which stores a computer program, and the computer program implements the steps of the security authentication method in the first aspect or the second aspect when executed by a processor.

[0027] In the embodiment of the present application, when the vehicle-mounted unit is incompatible with the road side unit, the authentication information generated by the vehicle-mounted unit is sent to the road side intelligent station by the road side unit, the authentication information is sent to the target road side unit compatible with the vehicle-mounted unit by the road side intelligent station, security authentication is performed, and an authentication result is obtained, thereby solving the problem that the road side unit cannot perform security authentication on the OBU when the OBU is incompatible with the road side unit. BRIEF DESCRIPTION OF DRAWINGS

[0028] Figure 1 The first implementation flowchart of the security authentication method of the vehicle-mounted unit provided by the embodiment of the present application is shown.

[0029] Figure 2 The second implementation flowchart of the security authentication method of the vehicle-mounted unit provided by the embodiment of the present application is shown.

[0030] Figure 3 The determination flowchart of the target road side unit provided by the embodiment of the present application is shown.

[0031] Figure 4 The signal flow direction diagram of the security authentication method of the vehicle-mounted unit provided by the embodiment of the present application is shown.

[0032] Figure 5 The structure diagram of the security authentication system of the vehicle-mounted unit provided by the embodiment of the present application is shown.

[0033] Figure 6 The structure diagram of the terminal provided by the embodiment of the present application is shown. DETAILED DESCRIPTION

[0034] In order to make the purposes, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and should not be used to limit the present application.

[0035] It should be understood that in the present application specification and the appended claims, the term "comprising" indicates the presence of described features, whole, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, whole, steps, operations, elements, components and / or sets thereof.

[0036] In addition, in the description of the present application specification and the appended claims, the terms "first", "second" and the like are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0037] In the present application specification, the reference "one embodiment" or "some embodiments" and the like means that the specific features, structures or characteristics described in connection with the embodiment are included in one or more embodiments of the present application. Therefore, the statements "in one embodiment", "in some embodiments", "in other some embodiments", "in further some embodiments" and the like appearing in different places in the specification are not necessarily all referring to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized.

[0038] Abbreviations:

[0039] ETC (Electronic Toll Collection), electronic non-stop toll collection;

[0040] esam (Embedded Secure Access Module), embedded secure access module;

[0041] psam (Purchase Secure Access Module), point-of-sale terminal secure access module;

[0042] OBU (On Board Unit), vehicle-mounted unit;

[0043] RSU (Road Side Unit), road side unit;

[0044] RSF (Roadside Facilities), roadside intelligent station;

[0045] The vehicle-mounted unit is a device installed on a vehicle and supports information exchange with the road side unit, the road side unit is an antenna and control device installed on the road side for communication with the vehicle-mounted unit on the passing vehicle, and the road side intelligent station is a software and hardware system deployed on the road side and having functions of information aggregation, information processing, decision generation and distribution.

[0046] In the current vehicle-road cooperative system, it is generally defaulted that the OBU and the RSU share the same psam-esam security authentication system, that is, the OBU and the RSU are mutually compatible and can realize mutual authentication. However, with the increase of types of the OBU and the RSU, the problem of incompatibility between the OBU and the RSU often occurs in the current vehicle-road cooperative system, resulting in that the RSU connected with the OBU cannot realize security authentication on the OBU.

[0047] Based on this, the embodiment of the present application provides a security authentication method and system of a vehicle-mounted unit, a terminal and a storage medium. When the vehicle-mounted unit and the road side unit are incompatible, the road side unit sends the authentication information generated by the vehicle-mounted unit to the road side intelligent station, the road side intelligent station sends the authentication information to the target road side unit compatible with the vehicle-mounted unit for security authentication, and obtains an authentication result, thereby solving the problem that the RSU cannot realize security authentication on the OBU when the OBU and the RSU are incompatible.

[0048] As shown in Figure 1 Fig. 1 is a flowchart of an implementation process of a security authentication method of a vehicle-mounted unit provided by the embodiment of the present application, and the security authentication method is applied to a road side unit and can be implemented based on the following steps 101 to 104.

[0049] Step 101, receiving authentication information sent by a vehicle-mounted unit.

[0050] In the embodiment of the present application, the vehicle-mounted unit is installed on a vehicle. When the vehicle travels into the communication range of the road side unit, the vehicle-mounted unit will communicate with the road side unit by microwaves. At this time, the vehicle-mounted unit can send the authentication information generated by its security authentication module (i.e., the esam authentication module) to the road side unit, so that the road side unit verifies the identity legality thereof.

[0051] Step 102, judging whether the vehicle-mounted unit and the road side unit are compatible based on the authentication information.

[0052] In the embodiment of the present application, the roadside unit is provided with a psam authentication module. The psam authentication module can receive the authentication information uploaded by the OBU, and determine whether the on-board unit is compatible with the roadside unit based on the authentication information, that is, whether the same set of psam-esam security authentication system is shared. When it is determined that the on-board unit is compatible with the roadside unit, the psam authentication module can perform security authentication on the on-board unit based on the authentication information, and when it is confirmed that the on-board unit is a legal on-board unit, generate new authentication information and send it to the on-board unit, so that the on-board unit completes the legality authentication of the roadside unit, thereby realizing the mutual authentication between the on-board unit and the roadside unit.

[0053] In step 103, when the on-board unit is not compatible with the roadside unit, the authentication information is sent to the roadside intelligent station, and the roadside intelligent station sends the authentication information to the target roadside unit compatible with the on-board unit.

[0054] In the embodiment of the present application, when the psam authentication module of the roadside unit determines that the on-board unit is not compatible with the roadside unit, that is, the psam authentication module of the roadside unit and the esam authentication module of the on-board unit are not the same set of psam-esam security authentication system, the roadside unit needs to send the authentication information to the roadside intelligent station (RSF) connected thereto, and the roadside intelligent station sends the authentication information to the target roadside unit compatible with the on-board unit, and then the target roadside unit performs security authentication on the on-board unit based on the authentication information, and returns the authentication result to the roadside intelligent station after obtaining the authentication result. The roadside intelligent station sends the authentication result to the roadside unit connected with the on-board unit, and then the roadside unit executes step 104, thereby realizing the legality authentication of the on-board unit by the roadside unit.

[0055] In step 104, the authentication result obtained by the target roadside unit performing security authentication on the on-board unit is received by the roadside intelligent station.

[0056] In the embodiment of the present application, when the on-board unit is not compatible with the roadside unit, the roadside unit sends the authentication information generated by the on-board unit to the roadside intelligent station, and the roadside intelligent station sends the authentication information to the target roadside unit compatible with the on-board unit for security authentication, and obtains the authentication result, thereby solving the problem that the RSU cannot perform security authentication on the OBU when the OBU and the RSU are not compatible.

[0057] Optionally, in some embodiments of the present application, the above-mentioned authentication information can carry the type information of the on-board unit, and the roadside unit can determine whether the on-board unit is compatible with it based on the type information of the on-board unit, that is, whether the same set of psam-esam security authentication system is shared.

[0058] For example, in practical application scenarios, the above-mentioned vehicle-mounted units can include the following three types of vehicle-mounted units: OBU1.0, OBU1.5, and OBU2.0; among them, OBU1.0 and OBU1.5 are vehicle-mounted units equipped with toll collection esam, which share the same psam-esam security authentication system with the roadside unit RSU1.5 equipped with toll collection psam; OBU2.0 is a vehicle-mounted unit equipped with extended service esam, which shares the same psam-esam security authentication system with the roadside unit RSU2.0 equipped with extended service psam.

[0059] When a vehicle equipped with OBU1.0 or OBU1.5 passes through RSU1.5, RSU1.5 can detect that the OBU sending the authentication information is OBU1.0 or OBU1.5, and determine that it shares the same PSAM-ESAM security authentication system with the OBU that sent the authentication information. Then, it directly performs security authentication on the OBU. In other words, RSU1.5 directly performs security authentication on OBU1.0 or OBU1.5.

[0060] When a vehicle equipped with OBU1.0 or OBU1.5 passes through RSU2.0, RSU2.0 can detect that the OBU sending the authentication information is OBU1.0 or OBU1.5 and determine that it does not share the same PSAM-ESAM security authentication system with the OBU that sent the authentication information. That is, the two are incompatible. RSU2.0 needs to send the authentication information generated by OBU1.0 or OBU1.5 to RSF. RSF then sends the authentication information to RSU1.5, which is compatible with OBU1.0 and OBU1.5. RSU1.5 then performs security authentication on OBU1.0 or OBU1.5 based on the authentication information and returns the authentication result to RSF. RSF then sends the authentication result to RSU2.0, thus realizing security authentication between RSU2.0 and OBU1.0 or OBU1.5.

[0061] Similarly, when a vehicle equipped with OBU2.0 passes through RSU2.0, RSU2.0 can detect that the OBU sending the authentication information is OBU2.0 and determine that it shares the same psam-esam security authentication system with the OBU that sent the authentication information. That is, the two are compatible with each other, and then directly perform security authentication on the OBU2.0.

[0062] like Figure 2 As shown, this application embodiment also provides a security authentication method for an on-board unit. This security authentication method is applied to a roadside smart station and can be implemented based on the following steps 201 to 203.

[0063] Step 201: Receive authentication information.

[0064] In the embodiment of the present application, the authentication information generated by the on-board unit is sent to the roadside intelligent station by the roadside unit when the roadside unit and the on-board unit are incompatible.

[0065] Specifically, in the embodiment of the present application, the on-board unit is installed on the vehicle. When the vehicle travels into the communication range of the roadside unit, the on-board unit will communicate with the roadside unit through microwaves. At this time, the on-board unit can send the authentication information generated by its security authentication module (i.e., esam authentication module) to the roadside unit. The roadside unit is provided with a psam authentication module. The psam authentication module can receive the authentication information uploaded by the OBU and determine whether the on-board unit and the roadside unit are compatible based on the authentication information, i.e., whether they share the same psam-esam security authentication system. When the psam authentication module of the roadside unit determines that the on-board unit and the roadside unit are incompatible, i.e., the psam authentication module of the roadside unit and the esam authentication module of the on-board unit do not share the same psam-esam security authentication system, the roadside unit needs to send the authentication information to the roadside intelligent station (RSF) connected thereto. The roadside intelligent station then performs the following steps 202 and 203, thereby realizing the legality authentication of the on-board unit by the roadside unit.

[0066] Step 202: Send the authentication information to the target roadside unit compatible with the on-board unit, so as to perform security authentication of the on-board unit by the target roadside unit.

[0067] Step 203: Receive the authentication result of the on-board unit sent by the target roadside unit, and send the authentication result to the roadside unit.

[0068] In the embodiment of the present application, the target roadside unit is provided with a psam authentication module, which can perform security authentication of the on-board unit based on the received authentication information.

[0069] Optionally, in some embodiments of the present application, the target roadside unit is determined by the roadside intelligent station in the following steps 301 to 303. Figure 1 and Figure 2 The target roadside unit in the embodiment shown in FIG. 6 can be determined by the roadside intelligent station in the following steps 301 to 303.

[0070] Step 301: Detect whether there is a roadside unit compatible with the on-board unit in the roadside units connected to the roadside intelligent station.

[0071] In actual application, the roadside intelligent station can be connected to one or more roadside units through a serial port or a network port, and can also be connected to other roadside intelligent stations, for example, the roadside intelligent station can also be connected to the upstream roadside intelligent station and the downstream roadside intelligent station in the direction of vehicle travel.

[0072] In the embodiments of the present application, in order to improve the real-time performance of communication, when the roadside intelligent station receives the authentication information generated by the vehicle-mounted unit, the roadside intelligent station can first detect whether there is a roadside unit compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station, and when there is a roadside unit compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station, directly send the authentication information to the roadside unit for security authentication of the vehicle-mounted unit, or send the authentication information to the roadside unit connected to the roadside intelligent station and compatible with the vehicle-mounted unit for security authentication of the vehicle-mounted unit by performing steps 302 to 303.

[0073] In step 302, if there is a roadside unit compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station, the adaptability of the roadside intelligent station is calculated based on the number of roadside units compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station and the vehicle flow of the roadside intelligent station.

[0074] In step 303, if the adaptability of the roadside intelligent station is greater than the first threshold, the roadside unit connected to the roadside intelligent station and compatible with the vehicle-mounted unit is taken as the target roadside unit.

[0075] In the embodiments of the present application, because the number of roadside units is small and the vehicle flow of the roadside intelligent station is large, it is possible to cause a large delay in the security authentication process. Therefore, in order to further improve the real-time performance of communication, after determining that there is a roadside unit compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station, the adaptability of the roadside intelligent station can be calculated based on the number of roadside units compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station and the vehicle flow of the roadside intelligent station, and when the adaptability of the roadside intelligent station is greater than the first threshold, the roadside unit connected to the roadside intelligent station and compatible with the vehicle-mounted unit is taken as the target roadside unit.

[0076] Optionally, in the process of implementing step 302, the ratio M / ω of the number M of roadside units compatible with the vehicle-mounted unit in the roadside units connected to the roadside intelligent station to the vehicle flow ω of the roadside intelligent station can be taken as the adaptability of the roadside intelligent station.

[0077] The first threshold can be the average number of vehicle-mounted units authenticated by a single roadside unit compatible with the vehicle-mounted unit.

[0078] Optionally, in some embodiments of the present application, as Figure 3As shown, when there is no roadside unit compatible with the vehicle-mounted unit in the roadside unit connected with the roadside intelligent station, or the adaptation degree of the roadside intelligent station is less than or equal to the first threshold value, the above target roadside unit can also be determined by the roadside intelligent station in the following step 304.

[0079] Step 304, determine the target roadside intelligent station with the highest adaptation degree among the upstream and downstream roadside intelligent stations within the preset distance range of the roadside intelligent station, and take the roadside unit compatible with the vehicle-mounted unit in the roadside unit connected with the target roadside intelligent station as the target roadside unit.

[0080] Wherein, when determining the target roadside intelligent station with the highest adaptation degree among the upstream and downstream roadside intelligent stations within the preset distance range of the roadside intelligent station, the to-be-determined roadside intelligent stations can be first screened from each upstream roadside intelligent station and each downstream roadside intelligent station, then the adaptation degrees of each to-be-determined roadside intelligent station are calculated, and the to-be-determined roadside intelligent station with the highest adaptation degree is taken as the target roadside intelligent station.

[0081] Specifically, the to-be-determined roadside intelligent stations can be screened from each upstream roadside intelligent station and each downstream roadside intelligent station based on the number of roadside units compatible with the vehicle-mounted unit in the roadside units connected with the upstream roadside intelligent stations, the number of roadside units compatible with the vehicle-mounted unit in the roadside units connected with the downstream roadside intelligent stations, the vehicle flow of the upstream roadside intelligent station, and the vehicle flow of the downstream roadside intelligent station.

[0082] For example, the upstream roadside intelligent station or the downstream roadside intelligent station with M’ / ω’ greater than the first threshold value is taken as the to-be-determined roadside intelligent station.

[0083] Wherein, M’ is the number of roadside units compatible with the vehicle-mounted unit in the roadside units connected with one of the upstream roadside intelligent stations or one of the downstream roadside intelligent stations. ω’ is the vehicle flow of the one of the upstream roadside intelligent stations or the one of the downstream roadside intelligent stations.

[0084] In the process of calculating the adaptation degree of a single to-be-determined roadside intelligent station, M’ / (ω’*λ) can be taken as the adaptation degree of the to-be-determined roadside intelligent station, wherein λ is the node number of the roadside intelligent station that needs to route the authentication information, and finally, the to-be-determined roadside intelligent station with the maximum M’ / (ω’*λ) is taken as the target roadside intelligent station.

[0085] Specifically, the more the number of road side units compatible with the on-board unit, the more the authentication information that can be processed, so the adaptation degree of M' to the road side intelligent station is proportional; the greater the traffic flow, the higher the processing requirement of the road side unit, so the adaptation degree of ω' to the road side intelligent station is inversely proportional; the more the number of routing nodes of the authentication information, the higher the authentication delay, which affects real-time performance, so the adaptation degree of λ to the road side intelligent station is inversely proportional.

[0086] For ease of understanding, the following will be illustrated in combination with Figure 4 the above-mentioned Figure 3 embodiments of the present application.

[0087] As Figure 4 shown, when the vehicle installed with the OBU 1.5 passes the RSU 2.0, the OBU 1.5 sends the authentication information to the RSU 2.0, which can detect that the OBU sending the authentication information is the OBU 1.5, and determine that it is not compatible with the OBU sending the authentication information in the same set of psam-esam security authentication system, that is, the two are incompatible, at this time the RSU 2.0 sends the authentication information generated by the OBU 1.5 to the local RSF connected thereto; the local RSF first determines whether there is an RSU 1.5 in its coverage range, if there is, it determines whether the ratio M / ω of the number M of RSU 1.5 connected to the local RSF to the traffic flow ω of the local RSF is greater than the first threshold value, if it is greater than the first threshold value, the RSU 1.5 connected to the local RSF is taken as the target road side unit, and the authentication information is sent to the RSU 1.5 connected to the local RSF for security authentication; if there is no RSU 1.5 in the coverage range of the local RSF, or the ratio M / ω of the number M of RSU 1.5 connected to the local RSF to the traffic flow ω of the local RSF is less than or equal to the first threshold value, the upstream or downstream road side intelligent station with M' / ω' greater than the first threshold value is taken as the above-mentioned to-be-determined road side intelligent station, the to-be-determined road side intelligent station with the maximum M' / (ω'*λ) is taken as the target road side unit, and the authentication information is sent to the RSU 1.5 connected to the to-be-determined road side intelligent station for security authentication; after the RSU 1.5 obtains the authentication result, the authentication result is returned to the local RSF, and the local RSF sends the authentication result to the RSU 2.0, realizing the security authentication between the RSU 2.0 and the OBU 1.0 or the OBU 1.5.

[0088] It can be understood that in the above-mentioned steps 303 and 304, when the number of target road side units is multiple, a target road side unit for authenticating the above-mentioned authentication information can be obtained by the road side intelligent station connected to the target road side unit based on the working state of each target road side unit.

[0089] In the embodiments of the present application, the target road side unit is selected by combining the traffic flow, the number of road side units and the number of routing nodes, the resource of the psam authentication module in the RSU is dynamically allocated, the psam authentication module existing in the current network can be maximally utilized, and the above authentication method sends the authentication information generated by the OBU to other RSUs in the RSF for security authentication when the OBU and the RSU are incompatible, so that the OBU does not need to be upgraded along with the RSU, and the maintenance cost of the OBU is reduced.

[0090] Optionally, in the above various embodiments of the present application, in order to improve the efficiency of security authentication and maximize the utilization of the psam authentication module, after receiving the authentication result of the vehicle unit sent by the target road side unit, the above road side intelligent station can also send the authentication result to the downstream road side intelligent station connected with the road side intelligent station as the historical authentication result of the vehicle unit, so that when the vehicle enters the area belonging to the downstream road side intelligent station, the downstream road side intelligent station can query the historical authentication result of the vehicle unit according to the vehicle unit identity information carried by the authentication information, and does not need to re-verify the vehicle unit.

[0091] That is, in some embodiments of the present application, before the step 202 of sending the authentication information to the target road side unit compatible with the vehicle unit, the historical authentication result of the vehicle unit can be queried based on the vehicle unit identity information carried by the authentication information; if the historical authentication result of the vehicle unit is queried, the historical authentication result is sent to the road side unit.

[0092] The historical authentication result of the vehicle unit based on the vehicle unit identity information carried by the authentication information can include: querying the historical authentication result of the vehicle unit based on the vehicle unit identity information carried by the authentication information in the local storage space of the road side intelligent station, and querying the historical authentication result of the vehicle unit in the upstream road side intelligent station connected with the road side intelligent station.

[0093] Specifically, when the downstream road side intelligent station queries the historical authentication result of the vehicle unit based on the vehicle unit identity information carried by the authentication information locally, if the query is successful, the vehicle unit is no longer authenticated; if the query is not successful, the authentication information query request can also be sent to the upstream road side intelligent station, if the authentication result of the vehicle unit sent by the upstream road side intelligent station based on the authentication information query request is received, the security authentication of the vehicle unit can be directly completed, otherwise, the authentication information is re-sent to the target road side unit compatible with the vehicle unit by the downstream road side intelligent station for security verification.

[0094] For example, the authentication information query request can be sent to the upstream road side intelligent station through the RSF, and the authentication result of the vehicle unit sent by the upstream road side intelligent station based on the authentication information query request can be received through the RSF. Figure 5As shown, the embodiments of the present application also provide a security authentication system of a vehicle-mounted unit, which comprises a vehicle-mounted unit 51, a road-side unit 52 and a road-side intelligent station 53. The road-side intelligent station can be connected with one or more road-side units 52 through a serial port or a network port. When the vehicle-mounted unit 51 on the vehicle passes through the road-side unit 52, the vehicle-mounted unit 51 can establish a communication connection with the road-side unit 52. In addition, the road-side intelligent station can also be connected with other road-side intelligent stations, for example, the road-side intelligent station can be connected with a road-side intelligent station upstream of the vehicle driving direction and a road-side intelligent station downstream of the vehicle driving direction.

[0095] The vehicle-mounted unit is used to generate authentication information and send the authentication information to the road-side unit. The road-side unit can be used to execute the above Figure 1 The steps of the security authentication method shown above can be executed by the road-side intelligent station. Figure 2 and Figure 3 The steps of the security authentication method shown above.

[0096] As shown in the above Figure 6 The embodiments of the present application also provide a terminal. The terminal can be applied to the security authentication method of the vehicle-mounted unit shown in the above various embodiments, and the terminal can be a server, a computer or other intelligent terminal. As shown in the above Figure 6 The terminal 6 can comprise a processor 60, a memory 61 and a computer program 62 stored in the memory 61 and executable on the processor 60. The processor 60 executes the computer program 62 to implement the steps in the above various security authentication method embodiments, for example, the steps 101 to 104 shown in the above Figure 1 or the steps 201 to 203 shown in the above. Figure 2

[0097] The processor 60 can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor, or any conventional processor, etc.

[0098] ​The memory 61 can be an internal storage unit of the terminal 6, for example, a hard disk or a memory. The memory 61 can also be an external storage device for the terminal 6, for example, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the terminal 6. Further, the memory 61 can also include both the internal storage unit and the external storage device of the terminal 6. The memory 61 is used to store the above computer program and other programs and data required by the terminal.

[0099] The above computer program can be divided into one or more units, which are stored in the above memory 61 and executed by the above processor 60 to complete the present application. The one or more units can be a series of computer program instructions capable of completing a specific function, which are used to describe the process of the above computer program executing the above security authentication method in the terminal.

[0100] For example, the above computer program can be divided into: a first receiving unit, a judging unit, a first sending unit and a second receiving unit, and the specific functions are as follows:

[0101] The first receiving unit is configured to receive authentication information sent by the on-board unit.

[0102] The judging unit is configured to judge whether the on-board unit is compatible with the roadside unit based on the authentication information.

[0103] The first sending unit is configured to send the authentication information to the roadside intelligent station when the on-board unit is not compatible with the roadside unit, so that the roadside intelligent station sends the authentication information to a target roadside unit compatible with the on-board unit.

[0104] The second receiving unit is configured to receive an authentication result of the on-board unit obtained by the target roadside unit performing security authentication on the on-board unit.

[0105] For another example, the above computer program can be divided into: a third receiving unit, a second sending unit and a fourth receiving unit, and the specific functions are as follows:

[0106] The third receiving unit is configured to receive authentication information; the authentication information is authentication information generated by the on-board unit and sent to the roadside intelligent station by the roadside unit when the roadside unit is not compatible with the on-board unit.

[0107] The second sending unit is configured to send the authentication information to a target roadside unit compatible with the on-board unit, so that the target roadside unit performs security authentication on the on-board unit.

[0108] The fourth receiving unit is configured to receive the authentication result of the vehicle-mounted unit sent by the target road side unit, and send the authentication result to the road side unit.

[0109] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the division of the above functional units and modules is exemplified, and in actual application, the above functions can be completed by different functional units or modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the above described functions. Each functional unit or module in the embodiment can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit. In addition, the specific name of each functional unit or module is only for convenient distinction, and does not limit the protection scope of the present application. The specific working process of the unit or module in the above system can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.

[0110] In the above embodiments, the description of each embodiment has its own emphasis, and the parts not described or recorded in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0111] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.

[0112] In the embodiments provided in the present application, it should be understood that the disclosed terminal and method can be implemented in other ways. For example, the terminal embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units or components shown or discussed can be indirect coupling or communication connection through some interface, system or unit, and can be electrical, mechanical or other forms.

[0113] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, i.e. may be located in one place, or may be distributed to multiple network units. Part or all of the units may be selected according to actual needs to achieve the purpose of the embodiment.

[0114] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.

[0115] If the integrated module / unit is realized in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be instructed by a computer program to related hardware to complete. The computer program can be stored in a computer readable storage medium, and the computer program can implement the steps of each method embodiment when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable file or some intermediate form. The computer readable medium can include any entity or device capable of carrying the computer program code, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier wave signal, telecommunication signal and software distribution medium, etc. It should be noted that the content included in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electric carrier wave signal and telecommunication signal.

[0116] The above embodiments are only used to illustrate the technical solutions of the present application, not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A method for security authentication of a vehicle-mounted unit, applied to a roadside unit, characterized in that, The safety authentication method comprises: receiving the authentication information sent by the vehicle-mounted unit; judging whether the vehicle-mounted unit is compatible with the road-side unit based on the authentication information, comprising: determining whether the vehicle-mounted unit is compatible with the road-side unit based on whether the vehicle-mounted unit and the road-side unit share the same safety authentication system; when the vehicle-mounted unit is not compatible with the road-side unit, sending the authentication information to the road-side intelligent station, and sending the authentication information to a target road-side unit compatible with the vehicle-mounted unit by the road-side intelligent station; receiving the authentication result of the vehicle-mounted unit sent by the target road-side unit. 2.A method for security authentication of a vehicle-mounted unit, applied to a roadside intelligent station, the method comprising: The safety authentication method comprises: receiving the authentication information; the authentication information is the authentication information generated by the vehicle-mounted unit and sent to the road-side intelligent station by the road-side unit when the road-side unit is not compatible with the vehicle-mounted unit; the road-side unit determines whether the vehicle-mounted unit is compatible with the road-side unit based on whether the vehicle-mounted unit and the road-side unit share the same safety authentication system; sending the authentication information to a target road-side unit compatible with the vehicle-mounted unit to perform safety authentication on the vehicle-mounted unit by the target road-side unit; receiving the authentication result of the vehicle-mounted unit sent by the target road-side unit and sending the authentication result to the road-side unit.

3. The security authentication method of the car navigation system according to claim 2, wherein The target road-side unit determines in the following way: detecting whether there is a road-side unit compatible with the vehicle-mounted unit in the road-side units connected to the road-side intelligent station; if there is, calculating the adaptation degree of the road-side intelligent station based on the number of road-side units compatible with the vehicle-mounted unit in the road-side units connected to the road-side intelligent station and the vehicle flow of the road-side intelligent station; if the adaptation degree of the road-side intelligent station is greater than a first threshold value, the road-side unit connected to the road-side intelligent station and compatible with the vehicle-mounted unit is taken as the target road-side unit.

4. The security authentication method of the car navigation system according to claim 3, wherein The safety authentication method further comprises: if there is no road-side unit compatible with the vehicle-mounted unit in the road-side units connected to the road-side intelligent station, or the adaptation degree of the road-side intelligent station is less than or equal to the first threshold value, determining the target road-side intelligent station with the highest adaptation degree among the upstream road-side intelligent stations and the downstream road-side intelligent stations within the preset distance range of the road-side intelligent station; taking the road-side unit compatible with the vehicle-mounted unit in the road-side units connected to the target road-side intelligent station as the target road-side unit.

5. The security authentication method of the car navigation unit according to claim 4, wherein The determination of the target road-side intelligent station with the highest adaptation degree among the upstream road-side intelligent stations and the downstream road-side intelligent stations within the preset distance range of the road-side intelligent station comprises: screening the road-side intelligent stations to be determined from each of the upstream road-side intelligent stations and each of the downstream road-side intelligent stations based on the number of road-side units compatible with the vehicle-mounted unit connected to the upstream road-side intelligent stations, the number of road-side units compatible with the vehicle-mounted unit connected to the downstream road-side intelligent stations, the vehicle flow of the upstream road-side intelligent stations, and the vehicle flow of the downstream road-side intelligent stations; Based on the number of roadside units compatible with the on-board unit among the roadside units connected to the roadside intelligent station to be determined, the traffic volume of the roadside intelligent station to be determined, and the number of nodes of the roadside intelligent station to which the authentication information needs to be routed, the adaptability of the roadside intelligent station to be determined is calculated, and the roadside intelligent station to be determined with the highest adaptability is taken as the target roadside intelligent station.

6. The security authentication method of a car navigation unit according to any one of claims 2 to 5, characterized by, After receiving the authentication result of the on-board unit sent by the target roadside unit, the method further comprises sending the authentication result to a downstream roadside intelligent station connected to the roadside intelligent station.

7. The security authentication method of a car navigation unit according to any one of claims 2 to 5, characterized by, Before sending the authentication information to the target roadside unit compatible with the on-board unit, the method comprises: querying the historical authentication result of the on-board unit based on the on-board unit identity information carried by the authentication information; if the historical authentication result of the on-board unit is queried, sending the historical authentication result to the roadside unit.

8. A security authentication system for a car navigation system, characterized by comprising: The security authentication system comprises an on-board unit, a roadside unit, and a roadside intelligent station; the on-board unit is configured to generate authentication information and send the authentication information to the roadside unit; the roadside unit is configured to perform the steps of the security authentication method according to claim 1; and the roadside intelligent station is configured to perform the steps of the security authentication method according to any one of claims 2 to 7.

9. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The computer program is executed by a processor to implement the steps of the security authentication method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 9. The computer program is executed by a processor to implement the steps of the security authentication method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Collaborative authentication method, V2X platform and storage medium

    CN110913364A

  • Vehicle-road cooperation system and method and roadside equipment

    CN114827955A