An in-vehicle communication optimization method and system based on AES-128 dynamic random encryption

By using AES-128 dynamic random encryption and MD5 identity authentication methods in on-board communication, the security risks caused by static keys are solved, and the security of on-board communication and data transmission reliability are improved.

CN116566606BActive Publication Date: 2025-07-29YANBIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310593514.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-24
Publication Date
2025-07-29
Estimated Expiration
2043-05-24

AI Technical Summary

Technical Problem

The existing on-vehicle communication methods have security risks due to the use of static keys and cannot effectively deal with security threats to on-vehicle networks.

Method used

AES-128 dynamic random encryption method is adopted to perform dynamic key fusion processing on the transmission end of the communication data frame, and identity authentication is performed on the receiving end to ensure that each frame of data is encrypted and decrypted using dynamic keys, and identity authentication is performed in combination with the MD5 algorithm.

Benefits of technology

It improves the security of on-board communication, reduces the disadvantages of key storage, avoids resource waste, ensures the security of data transmission, and prevents malicious messages from passing identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116566606B_ABST
    Figure CN116566606B_ABST
Patent Text Reader

Abstract

This application relates to the field of information security technology, and particularly to an in-vehicle communication optimization method and system based on AES-128 dynamic random encryption. The method includes: at the transmitting end, obtaining a communication data group with a safety level of ASIL D; determining a communication data frame as a data frame to be encrypted and determining an initial key; performing an encryption process on the data frame to be encrypted to obtain a ciphertext, and determining a dynamic key during the encryption process; performing a fusion process on the dynamic key and the initial key to obtain a fusion key; updating the data frame to be encrypted and updating the initial key; until all the packaged data are transmitted; at the receiving end, performing a decryption process on the ciphertext to obtain a decrypted data group; verifying the identity verification code, and if the verification is passed, confirming that the decrypted data group is the communication data group. The dynamic random encryption method of this application changes the fixed original key into a dynamic key that changes dynamically with each frame of data, which can reduce the disadvantages of key storage and improve the security of encryption.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security technology, and in particular, to an in-vehicle communication optimization method and system based on AES-128 dynamic random encryption. Background Art

[0002] The development of the complexity and connectivity of modern automotive buses has led to a significant increase in the security risks of in-vehicle networks. In-vehicle Ethernet faces security threats such as network information tampering and virus intrusion. These network threats directly affect the normal use of in-vehicle devices and cause adverse effects such as user information leakage. While in-vehicle Ethernet meets the bandwidth requirements of multimedia applications, autonomous driving, and safety applications, it also needs to bring higher quality of service (QoS). With the rapid development of the Internet of Vehicles and intelligent transportation systems, in-vehicle Ethernet will become an important infrastructure for future automotive communication, and its security and reliability will also receive more and more attention and emphasis. Therefore, it is necessary to strengthen the research and exploration of encryption algorithms to ensure the secure operation of in-vehicle Ethernet.

[0003] The ISO 26262 standard specifies a set of functional safety standards for the design and development of automotive electronic systems, including the definition of safety goals, risk analysis and assessment, and the safety design and verification of hardware and software development. Among them, ASIL (Automotive Safety Integrity Level) is a concept defined in the ISO 26262 standard, which is used to classify and evaluate different safety requirements and determine the safety level of automotive electronic systems.

[0004] This standard divides the automotive safety integrity level (ASIL) into four different levels according to the safety requirements of in-vehicle system functions, the severity, probability, and controllability of potential hazards, from high to low in turn are ASIL D, ASIL C, ASIL B, and ASIL A. Each level has corresponding safety requirements and safety methods. The discrimination basis is to determine its ASIL level according to the safety requirements of its function, potential hazards, and controllability. For example, if a failure of the IVI system may cause driver distraction and thus may lead to an accident, then the ASIL level of this system will be determined to be a higher level. If a failure of this system will cause some minor problems, then the ASIL level of this system may be determined to be a lower level.

[0005] Cryptographic algorithms are the basic methods to ensure information security. AES-128 is a symmetric block cipher algorithm used to encrypt sensitive data to protect its confidentiality. The AES encryption algorithm uses a fixed-length block (128 bits) to encrypt data. For a symmetric-key cryptosystem like AES, the key represents the shared secret in the communication system and can ensure the transmission of private information. Compared with asymmetric-key encryption, the disadvantage of the symmetric-key encryption system is that the key is completely static, so the key must be exchanged in advance and confirmed to be securely stored. When this static key is stolen, all information will be completely exposed. Summary of the Invention

[0006] This application provides an optimized method and system for in-vehicle communication based on AES-128 dynamic random encryption, which can solve the problem of potential security risks existing in the existing in-vehicle communication methods due to the use of static keys.

[0007] The first technical solution of this application is an optimized method for in-vehicle communication based on AES-128 dynamic random encryption, including:

[0008] S1: At the transmitting end, obtain a communication data group with a safety level of ASIL D, where each communication data group includes a number of communication data frames arranged in sequence;

[0009] S2: In each communication data group, determine the communication data frame arranged at the first position in sequence as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted;

[0010] S3: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key to obtain ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing;

[0011] Perform fusion processing on the dynamic key and the initial key to obtain a fusion key;

[0012] S4: In each communication data group, update the next communication data frame arranged in sequence as the data frame to be encrypted and update the fusion key as the initial key;

[0013] S5: Repeat steps S3 - S4 until ciphertext corresponding to several communication data frames in the communication data group is obtained;

[0014] Determine the identity authentication code corresponding to the ciphertext of the communication data group and perform packaging processing on the ciphertext and the identity authentication code to obtain the packaged data corresponding to the communication data group, and transmit the packaged data;

[0015] S6: Repeat steps S2 - S5 until the packaged data corresponding to several communication data groups are all transmitted;

[0016] S7: At the receiving end, perform AES-128 dynamic random decryption processing corresponding to the security level of ASIL D on the ciphertext in each packetized data to obtain a decrypted data group corresponding to each packetized data;

[0017] Verify the identity verification code corresponding to the communication data group. If the verification is passed, confirm that the decrypted data group is the communication data group.

[0018] Optionally, the step S1 includes:

[0019] S11: At the transmitting end, obtain a plurality of original data frames with a data frame length of 128 bits;

[0020] Based on the classification standard of the security level ASIL, confirm whether the security level of the plurality of original data frames is ASIL D;

[0021] S12: For a plurality of communication data frames with a security level of ASIL D, perform grouping processing with 100 as the grouping unit to obtain a plurality of communication data groups;

[0022] S13: Perform sorting processing on 100 communication data frames in each group to obtain a plurality of communication data groups each including a plurality of communication data frames arranged in sequence.

[0023] Optionally, the step S2 includes:

[0024] S21: In each communication data group, perform segmentation processing and sorting processing on each communication data frame in sequence to obtain 8 encrypted data units arranged in sequence;

[0025] S22: Among the 8 encrypted data units arranged in sequence, determine the encrypted data unit arranged at the first position as the key update unit;

[0026] S23: Determine the communication data frame arranged at the first position in sequence as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted;

[0027] And, the step S3 includes:

[0028] S31: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key to obtain ciphertext, and during the AES-128 dynamic random encryption processing, determine the dynamic key according to the key update unit;

[0029] S32: Perform fusion processing on the dynamic key and the initial key to obtain a fusion key.

[0030] Optionally, the step S31 includes:

[0031] S311: Determine a counter with an initial count of 0;

[0032] S312: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted using the initial key to obtain ciphertext, and increment the count of the counter by 1;

[0033] During the AES-128 dynamic random encryption processing, determine the data obtained after the key update unit performs the 10th round of row shift as the dynamic key;

[0034] And, the step S32 includes:

[0035] S321: Perform an exclusive OR operation on the dynamic key and the initial key to obtain a fusion key;

[0036] And, the step S5 includes:

[0037] S51: Repeat the steps S3 to S4 until ciphertext corresponding to several communication data frames in the communication data group is obtained;

[0038] S52: Clear the encryption data device;

[0039] Reset the initial key;

[0040] S53: Determine the authentication code for the ciphertext corresponding to the communication data group;

[0041] Pack the ciphertext and the authentication code to obtain the packed data corresponding to the communication data group, and transmit the packed data.

[0042] Optionally, the step S53 includes:

[0043] S531: Confirm the authentication code for the ciphertext corresponding to each communication data group based on the MD5 algorithm;

[0044] S532: Take the communication data group as the packing unit, pack the ciphertext and the authentication code to obtain the packed data corresponding to the communication data group, and transmit the packed data;

[0045] And, the step S7 includes:

[0046] S71: At the receiving end, perform AES-128 dynamic random decryption processing on the ciphertext in each packed data corresponding to a safety level of ASIL D to obtain the decrypted data group corresponding to each packed data;

[0047] S72: Verify the identity verification code corresponding to the communication data group based on the MD5 algorithm. If the verification is passed, confirm that the decrypted data group is the communication data group.

[0048] Optionally, the step S72 includes:

[0049] S721: Recombine the identity authentication code corresponding to the communication data group to obtain a recombined verification code corresponding to each packed data.

[0050] S722: Verify the recombined authentication code corresponding to the communication data group based on the MD5 algorithm. If the verification is passed, confirm that the decrypted data group is the communication data group.

[0051] The second technical solution of this application is a vehicle communication optimization system based on AES-128 dynamic random encryption, including: a dynamic random encryption module, an identity authentication module, a dynamic random decryption module, and an identity verification module;

[0052] The dynamic random encryption module is used to obtain a communication data group with a safety level of ASIL D, each of which includes a plurality of communication data frames arranged in sequence;

[0053] It is also used to determine the communication data frame arranged at the head in sequence in each communication data group as the data frame to be encrypted and accordingly determine the initial key of the data frame to be encrypted.

[0054] It is also used to perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key in each communication data group to obtain ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing; perform fusion processing on the dynamic key and the initial key to obtain a fusion key.

[0055] It is also used to update the next communication data frame arranged in sequence in each communication data group as the data frame to be encrypted and update the fusion key as the initial key.

[0056] It is also used to repeat the relevant steps until ciphertexts corresponding to a plurality of communication data groups are obtained respectively;

[0057] The identity authentication module is used to determine the identity authentication code corresponding to the ciphertext of each communication data group and perform packing processing on the ciphertext and the identity authentication code to obtain packed data corresponding to each communication data group, and transmit the packed data corresponding to a plurality of communication data groups respectively;

[0058] The dynamic random decryption module is used to perform AES-128 dynamic random decryption processing corresponding to a safety level of ASIL D on the ciphertext in each packed data to obtain a decrypted data group corresponding to each packed data;

[0059] The authentication module is used to authenticate the identity verification code corresponding to the communication data group. If the verification is passed, it is confirmed that the decrypted data group is the communication data group.

[0060] Beneficial effects:

[0061] (1) This application can perform dynamic random encryption on communications with a safety level of ASIL D, meeting the requirements of different data frames for different security risks, and avoiding the waste of resources caused by reusing resources for the same type of risk.

[0062] (2) The dynamic random encryption method of this application changes the fixed original key into a dynamic key that changes dynamically with each frame of data, which can reduce the disadvantages of key storage and improve the security of encryption.

[0063] (3) In the dynamic random encryption method of this application, since the dynamic key is dynamically random, and since the key update count is performed for each round, and also because the MD5 algorithm is used for identity authentication, the security of data transmission is ensured. Even if there is a malicious message input that is very similar to the original message, an identity authentication code that is completely inconsistent with the original data will be generated because the updated round key and the order of the current data cannot be obtained, and the data that fails the identity authentication will be deleted.

[0064] In summary, this application can solve the problem of potential security hazards in existing vehicle communication methods due to the use of static keys. Brief description of the drawings

[0065] In order to more clearly illustrate the technical solutions of this application, the drawings required for the embodiments will be briefly introduced below. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0066] Figure 1 It is a schematic flowchart of an optimized vehicle communication method based on AES-128 dynamic random encryption in an embodiment of this application;

[0067] Figure 2 It is a schematic logical diagram of an optimized vehicle communication method based on AES-128 dynamic random encryption in an embodiment of this application;

[0068] Figure 3 It is a schematic logical diagram of the dynamic random encryption process based on AES-128 in an embodiment of this application;

[0069] Figure 4 It is a schematic logical diagram of the dynamic random decryption process based on AES-128 in an embodiment of this application;

[0070] Figure 5 This is a schematic structural diagram of an in-vehicle communication optimization system based on AES-128 dynamic random encryption in an embodiment of the present application;

[0071] In the figure, 1 - dynamic random encryption module; 2 - identity authentication module; 3 - dynamic random decryption module;

[0072] 4 - identity verification module. Detailed implementation manners

[0073] The embodiments will be described in detail below, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following embodiments do not represent all implementation manners consistent with the present application. They are only examples of systems and methods consistent with some aspects of the present application detailed in the claims.

[0074] The first technical solution of the present application is an in-vehicle communication optimization method based on AES-128 dynamic random encryption, as Figure 1 and Figure 2 shown, Figure 1 This is a schematic flowchart of the in-vehicle communication optimization method based on AES-128 dynamic random encryption in an embodiment of the present application, Figure 2 This is a schematic logic diagram of the in-vehicle communication optimization method based on AES-128 dynamic random encryption in an embodiment of the present application. The method includes:

[0075] S1: At the transmitting end, obtain a communication data group with a security level of ASIL D, where the communication data group includes a plurality of communication data frames arranged in sequence.

[0076] Specifically, at the receiving end, the dynamic random encryption method based on AES-128 is divided into three parts: security level classification (S1), dynamic random encryption (S2 - S6), and identity authentication (S5 - S6). Since the dynamic random encryption part and the identity authentication process are carried out concomitantly, there is some overlap in the steps.

[0077] Among them, step S1 includes:

[0078] S11: At the transmitting end, obtain a plurality of original data frames with a data frame length of 128 bit.

[0079] Based on the classification standard of the security level ASIL, confirm whether the security level of a plurality of original data frames is ASIL D.

[0080] Specifically, first, classify in - vehicle Ethernet data frames according to the Automotive Safety Integration Level (ASIL level). The Automotive Safety Integrity Level (ASIL) is divided into four different levels according to the safety requirements of in - vehicle system functions, the severity, possibility, and controllability of potential hazards, from high to low are D, C, B, and A in turn.

[0081] In the in - vehicle network control system environment, once in - vehicle components such as airbags, anti - lock braking systems, and power steering systems are attacked, it will cause inestimable consequences to the driver's life safety. In the embodiments of this application, such in - vehicle components are set to the highest safety level, that is, ASIL D, and their data frame IDs are recorded and stored in the ID library for use during detection.

[0082] S12: For several communication data frames with a safety level of ASIL D, group them in units of 100 to obtain several communication data groups.

[0083] Specifically, in the embodiments of this application, dynamic random encryption communication processing is performed on several communication data frames with a safety level of ASIL D. For data frames of other ASIL A, B, and C levels, normal AES - 128 data encryption and MD5 identity authentication are adopted to verify the input and output values.

[0084] In specific operations, when there is an input of an original data frame, first judge the ID of the original data frame;

[0085] Data frames belonging to ASIL D enter the subsequent steps. Data frames not belonging to ASIL D enter the normal AES - 128 data encryption module and MD5 authentication module, and then are forwarded. The embodiments of this application will not elaborate further.

[0086] Data frames belonging to ASIL D perform dynamic random encryption and identity authentication operations in sequence and then are forwarded.

[0087] S13: Sort the 100 communication data frames in each group to obtain several communication data groups, each of which includes several communication data frames arranged in sequence.

[0088] Specifically, taking in - vehicle Ethernet data frames with a data segment of 128bit as an example. Take 100 messages as a group, set as M1 - M100, as shown in Table 1.

[0089] Table 1 Symbol and meaning table of dynamic random encryption based on AES - 128

[0090]

[0091] S2: In each communication data group, determine the communication data frame arranged at the first position in sequence as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted.

[0092] Among them, step S2 includes:

[0093] S21: In each communication data group, perform segmentation processing and sorting processing on each communication data frame in sequence to obtain 8 encrypted data units arranged in sequence.

[0094] Specifically, the 128-bit data in each data frame is divided into 16 * 8 bits, denoted as D1 - D8, for subsequent encryption operations.

[0095] S22: Among the 8 encrypted data units arranged in sequence, determine the encrypted data unit arranged at the first position as the key update unit.

[0096] S23: Determine the communication data frame arranged at the first position in sequence as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted.

[0097] Specifically, M1 is the first communication data frame to be operated in this communication data group, and the encryption process of M1 is the traditional AES-128 data encryption process.

[0098] S3: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key to obtain the ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing.

[0099] Perform fusion processing on the dynamic key and the initial key to obtain the fusion key.

[0100] Among them, step S3 includes:

[0101] S31: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key to obtain the ciphertext, and determine the dynamic key according to the key update unit during the AES-128 dynamic random encryption processing.

[0102] Among them, S311: Determine the counter with an initial count of 0.

[0103] S312: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key to obtain the ciphertext, and increment the count of the counter by 1.

[0104] Specifically, the plaintext M1 and the initial key K1 perform an AES operation to generate the ciphertext C1. The counter Dk is incremented by 1. The formula is as follows:

[0105] C1 = AES(M1, K1);

[0106] Dk = Dk + 1.

[0107] In the process of AES-128 dynamic random encryption, the data obtained by the key update unit after the 10th round of row shift is determined as the dynamic key.

[0108] S32: Perform a fusion process on the dynamic key and the initial key to obtain a fusion key.

[0109] Among them, step S32 includes:

[0110] S321: Perform an exclusive OR operation on the dynamic key and the initial key to obtain a fusion key.

[0111] Specifically, in the encryption process, the dynamic key S1 generated after the 10th round of row shift of D1 is exclusive ORed with the initial key K1 to generate a new key, that is, the fusion key K2. K2 replaces the initial key K1 as the initial key for the next communication data frame M2.

[0112] The formula is as follows:

[0113] K2 = S1 ⊕ K1;

[0114] The encryption process of M1 ends.

[0115] S4: In each communication data group, update the next sequentially arranged communication data frame as the data frame to be encrypted and update the fusion key as the initial key.

[0116] S5: Repeat steps S3 - S4 until the ciphertext corresponding to several communication data frames in the communication data group is obtained.

[0117] Determine the identity authentication code corresponding to the ciphertext of the communication data group and perform a packaging process on the ciphertext and the identity authentication code to obtain the packaged data corresponding to the communication data group, and transmit the packaged data.

[0118] Among them, step S5 includes:

[0119] S51: Repeat steps S3 - S4 until the ciphertext corresponding to several communication data frames in the communication data group is obtained.

[0120] Specifically, at the beginning of the second encryption, the initial key of the plaintext M2 is updated to K2, M2 and K2 perform an AES dynamic encryption operation to generate the ciphertext C2, and the counter Dk is incremented by 1. The formula is as follows:

[0121] C2 = AES(M2, K2);

[0122] Dk = Dk + 1;

[0123] During the encryption process, the key S2 generated by D1 in M2 after the tenth-round row shift is XORed with the original key K2 to generate a new dynamic key K3. K3 is used to replace the initial key K2 as the initial key for the next data frame M3.

[0124] The formula is as follows:

[0125]

[0126] The encryption process of M2 ends.

[0127] The operations of M3 - M100 are performed in sequence.

[0128] S52: Clear the encryption data device. Reset the initial key.

[0129] Specifically, when the counter reaches 100, that is, after the dynamic encryption of the M100 communication data frame, reset the value of the counter and reset the initial key to the original key K1, and then perform the next group of AES - 128 dynamic random encryption.

[0130] As Figure 3 shown, Figure 3 is the logic diagram of the dynamic random encryption process based on AES - 128 in the embodiment of the present application. Each round of data frame encryption process has to go through three steps: AES - 128 operation, updating the initial key, and counter counting.

[0131] S53: Determine the authentication code corresponding to the ciphertext of the communication data group.

[0132] Pack the ciphertext and the authentication code to obtain the packed data corresponding to the communication data group, and transmit the packed data.

[0133] Among them, step S53 includes:

[0134] S531: Confirm the authentication code corresponding to the ciphertext of each communication data group based on the MD5 algorithm.

[0135] Specifically, considering that the encryption efficiency of the AES - 128 dynamic random encryption algorithm becomes lower than before. This is because the complexity of the algorithm increases, resulting in an increase in encryption time;

[0136] Therefore, reduce the time used for MD5 authentication of data frames with its ASIL D level;

[0137] Divide the 128 - bit output data into two groups. Bits 0 - 63 are the first group, denoted as T1; bits 64 - 127 are the second group, denoted as T2. And add them to get the hash value, and the output result T = T1 + T2.

[0138] S532: Pack the ciphertext and the identity authentication code with the communication data group as the packing unit to obtain the packed data corresponding to the communication data group, and transmit the packed data.

[0139] Specifically, send the identity authentication code and the data to be encrypted together.

[0140] S6: Repeat steps S2 to S5 until the packed data corresponding to several communication data groups are all transmitted.

[0141] S7: At the receiving end, perform AES-128 dynamic random decryption processing corresponding to the security level ASIL D on the ciphertext in each packed data to obtain the decrypted data group corresponding to each packed data; verify the identity verification code corresponding to the communication data group, and if the verification passes, confirm that the decrypted data group is the communication data group.

[0142] Specifically, at the receiving end, first confirm whether it is the packed data of the security level ASIL D through the ID. If so, perform AES-128 dynamic decryption and MD5 identity authentication in sequence.

[0143] When the identity authentication passes, update the initial key, count the counter, and receive the data frame. The data frames that cannot pass the identity authentication will be deleted.

[0144] Among them, step S7 includes:

[0145] S71: At the receiving end, perform AES-128 dynamic random decryption processing corresponding to the security level ASIL D on the ciphertext in each packed data to obtain the decrypted data group corresponding to each packed data.

[0146] Specifically, as Figure 4 shown, Figure 4 is the logical schematic diagram of the dynamic random decryption process based on AES-128 in the embodiment of the present application. When receiving, first judge the ID of the data frame. When it is found that the ID does not belong to the ASIL D type, perform normal AES-128 data decryption and MD5 identity authentication.

[0147] When it is found that the ID belongs to the ASIL D type, perform dynamic decryption and MD5 identity authentication.

[0148] S72: If the verification passes, perform AES-128 dynamic random decryption processing corresponding to the security level ASIL D on the ciphertext to obtain the communication data group corresponding to each packed data.

[0149] Among them, step S72 includes:

[0150] S721: Reorganize the authentication code corresponding to the communication data group to obtain the reorganized verification code corresponding to each packet of data.

[0151] Specifically, use MD5 to determine whether the authentication codes generated during sending and receiving are the same. If they are not the same, delete the ciphertext; if they are the same, receive the ciphertext. Considering that the encryption efficiency of the dynamic random encryption algorithm is lower than before improvement. Therefore, when using the MD5 algorithm for authentication of data at ASIL D level, reorganize the 128-bit authentication code and change it to a 64-bit authentication code before authentication.

[0152] By this method, the length of the output result of the MD5 algorithm is reduced, thereby improving the calculation efficiency and transmission speed. At the same time, the output result can be made more randomized, increasing the difficulty for attackers to crack the authentication.

[0153] S722: Verify the reorganized authentication code corresponding to the communication data group based on the MD5 algorithm. If the verification passes, confirm that the decrypted data group is the communication data group.

[0154] Specifically, when it is confirmed that the decrypted data group is the communication data group, the communication data frame can be received.

[0155] The second technical solution of this application is an in-vehicle communication optimization system based on AES-128 dynamic random encryption, as Figure 5 shown Figure 5 is a schematic structural diagram of the in-vehicle communication optimization system based on AES-128 dynamic random encryption in the embodiment of this application, including: a dynamic random encryption module 1, an identity authentication module 2, a dynamic random decryption module 3, and an identity verification module 4.

[0156] The dynamic random encryption module 1 is used to obtain a communication data group with a security level of ASIL D, which includes several communication data frames arranged in sequence.

[0157] It is also used to determine, in each communication data group, the communication data frame arranged at the head as the data frame to be encrypted and accordingly determine the initial key of the data frame to be encrypted.

[0158] It is also used to perform AES-128 dynamic random encryption processing on the data frame to be encrypted through the initial key in each communication data group to obtain ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing. Perform a fusion process on the dynamic key and the initial key to obtain a fusion key.

[0159] It is also used to update the next communication data frame arranged in sequence as the data frame to be encrypted and update the fusion key as the initial key in each communication data group.

[0160] It is also used to repeat relevant steps until ciphertexts corresponding to several communication data groups are obtained respectively.

[0161] The identity authentication module 2 is used to determine the identity authentication code of the ciphertext corresponding to each communication data group, perform packaging processing on the ciphertext and the identity authentication code to obtain the packaged data corresponding to each communication data group, and transmit the packaged data corresponding to several communication data groups respectively.

[0162] The dynamic random decryption module 3 is used to perform AES-128 dynamic random decryption processing corresponding to the security level of ASIL D on the ciphertext in each packaged data to obtain the decrypted data group corresponding to each packaged data.

[0163] The authentication module 4 is used to verify the identity authentication code corresponding to the communication data group. If the verification is passed, it is confirmed that the decrypted data group is the communication data group.

[0164] The above has described the embodiments of the present application in detail, but the content is only the preferred embodiments of the present application and cannot be considered as used to limit the implementation scope of the present application. All equal changes and improvements made according to the scope of the present application should still fall within the patent coverage scope of the present application.

Claims

1. An on-vehicle communication optimization method based on AES-128 dynamic random encryption, characterized in that Including: S1: At the transmitting end, obtain several communication data groups with a safety level of ASIL D, each of which includes several communication data frames arranged in sequence; S2: In each communication data group, determine the communication data frame arranged at the head as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted; S3: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted with the initial key to obtain ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing; Perform fusion processing on the dynamic key and the initial key to obtain the fusion key; S4: In each communication data group, update the next communication data frame arranged in sequence as the data frame to be encrypted and update the fusion key as the initial key; S5: Repeat steps S3 to S4 until the ciphertext corresponding to several communication data frames in the communication data group is obtained; Determine the identity authentication code corresponding to the ciphertext of the communication data group and perform packaging processing on the ciphertext and the identity authentication code to obtain the packaged data corresponding to the communication data group, and transmit the packaged data; S6: Repeat steps S2 to S5 until the packaged data corresponding to several communication data groups are all transmitted; S7: At the receiving end, perform AES-128 dynamic random decryption processing corresponding to the safety level of ASIL D on the ciphertext in each packaged data to obtain the decrypted data group corresponding to each packaged data; Verify the identity verification code corresponding to the communication data group. If the verification is passed, confirm that the decrypted data group is the communication data group.

2. The vehicle-mounted communication optimization method based on AES-128 dynamic random encryption according to claim 1, characterized in that, The step S1 includes: S11: At the transmitting end, obtain several original data frames with a data frame length of 128 bit; Based on the classification standard of the safety level ASIL, confirm whether the safety level of several original data frames is ASIL D; S12: Group several communication data frames with a safety level of ASIL D in units of 100 to obtain several communication data groups; S13: Sort 100 communication data frames in each group to obtain several communication data groups, each of which includes several communication data frames arranged in sequence.

3. The vehicle-mounted communication optimization method based on AES-128 dynamic random encryption according to claim 1, characterized in that The step S2 includes: S21: In each communication data group, perform segmentation processing and sorting processing on each communication data frame in sequence to obtain 8 encrypted data units arranged in sequence; S22: Among the 8 encrypted data units arranged in sequence, determine the encrypted data unit arranged at the head as the key update unit; S23: Determine the communication data frame arranged at the head as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted; And, the step S3 includes: S31: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted with the initial key to obtain ciphertext, and during the AES-128 dynamic random encryption processing, determine the dynamic key according to the key update unit; S32: Perform fusion processing on the dynamic key and the initial key to obtain the fusion key.

4. The vehicle-mounted communication optimization method based on AES-128 dynamic random encryption according to claim 3, wherein The step S31 includes: S311: Determine a counter with an initial count of 0; S312: In each communication data group, perform AES-128 dynamic random encryption processing on the data frame to be encrypted using the initial key to obtain ciphertext, and increment the count of the counter by 1; During the AES-128 dynamic random encryption processing, determine the data obtained after the 10th round of row shift by the key update unit as the dynamic key; And, the step S32 includes: S321: Perform an exclusive OR operation on the dynamic key and the initial key to obtain a fused key; And, the step S5 includes: S51: Repeat the steps S3 to S4 until ciphertext corresponding to several communication data frames in the communication data group is obtained; S52: Clear the encryption data device; Reset the initial key; S53: Determine the identity authentication code for the ciphertext corresponding to the communication data group; Pack the ciphertext and the identity authentication code to obtain the packed data corresponding to the communication data group, and transmit the packed data.

5. The vehicle communication optimization method based on AES-128 dynamic random encryption according to claim 4, characterized in that, The step S53 includes: S531: Confirm the identity authentication code for the ciphertext corresponding to each communication data group based on the MD5 algorithm; S532: Take the communication data group as the packing unit, pack the ciphertext and the identity authentication code to obtain the packed data corresponding to the communication data group, and transmit the packed data; And, the step S7 includes: S71: At the receiving end, perform AES-128 dynamic random decryption processing on the ciphertext in each packed data corresponding to a safety level of ASIL D to obtain the decrypted data group corresponding to each packed data; S72: Verify the identity verification code corresponding to the communication data group based on the MD5 algorithm. If the verification passes, confirm that the decrypted data group is the communication data group.

6. The vehicle-mounted communication optimization method based on AES-128 dynamic random encryption according to claim 5, wherein, The step S72 includes: S721: Recombine the identity authentication code corresponding to the communication data group to obtain the recombined verification code corresponding to each packed data; S722: Verify the recombined authentication code corresponding to the communication data group based on the MD5 algorithm. If the verification passes, confirm that the decrypted data group is the communication data group.

7. An in-vehicle communication optimization system based on AES-128 dynamic random encryption, characterized in that, Includes: A dynamic random encryption module, an identity authentication module, a dynamic random decryption module, and an identity verification module; The dynamic random encryption module is used to obtain several communication data groups with a safety level of ASIL D, each of which includes several communication data frames arranged in sequence; It is also used to determine the communication data frame arranged at the head in sequence in each communication data group as the data frame to be encrypted and correspondingly determine the initial key of the data frame to be encrypted; It is also used to perform AES-128 dynamic random encryption processing on the data frame to be encrypted using the initial key in each communication data group to obtain ciphertext, and determine the dynamic key during the AES-128 dynamic random encryption processing; perform a fusion process on the dynamic key and the initial key to obtain a fused key; It is also used to update the next communication data frame arranged in sequence in each communication data group as the data frame to be encrypted and update the fused key as the initial key; It is also used to repeat relevant steps until ciphertexts corresponding to several communication data groups are obtained respectively; The identity authentication module is used to determine the identity authentication code corresponding to the ciphertext of each communication data group, perform packaging processing on the ciphertext and the identity authentication code to obtain the packaged data corresponding to each communication data group, and transmit the packaged data corresponding to several communication data groups respectively; The dynamic random decryption module is used to perform AES-128 dynamic random decryption processing corresponding to the safety level of ASIL D on the ciphertext in each packaged data to obtain the decrypted data group corresponding to each packaged data; The authentication module is used to verify the identity verification code corresponding to the communication data group. If the verification is passed, it is confirmed that the decrypted data group is the communication data group.

Citation Information

Patent Citations

  • Method, device and system for securely transmitting data

    CN114697051A

  • Video data protection, encryption and verification method, system and device

    CN114928756A