Trusted root data aggregation method and control system

By aggregating trusted root certificate data from different V2X-PKI-N systems through the V2X-PKI system, the problem of vehicle networking devices needing to connect to multiple SCMS systems is solved, thereby reducing network dependence and computing resource consumption.

CN116668098BActive Publication Date: 2026-02-13CHINA IND INTERNET RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310560857.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-17
Publication Date
2026-02-13
Estimated Expiration
2043-05-17

AI Technical Summary

Technical Problem

Vehicle-to-everything (V2X) devices need to connect to multiple SCMS systems to download trusted root certificate data during operation, which increases development costs and consumes too many computing resources.

Method used

By aggregating trusted root certificate data from different V2X-PKI-N systems through the V2X-PKI system, the trusted root management function of the SCMS system is optimized, enabling terminal vehicle networking devices to download trusted root certificate data from multiple trusted domains after aggregation by connecting to only one SCMS system, thereby reducing network dependence and computational pressure.

Benefits of technology

This effectively reduces the network dependence and computing resource consumption of vehicle networking devices on multiple SCMS cloud systems, thereby reducing the development cost and computing pressure of the devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668098B_ABST
    Figure CN116668098B_ABST
Patent Text Reader

Abstract

The application relates to a trusted root data collection method and a control system. The method comprises the following steps: a V2X-PKI system downloads a trusted root certificate list from a trusted root platform, wherein the V2X-PKI system manages a security certificate through an SCMS system, and the SCMS system obtains the trusted root certificate list; the SCMS system analyzes the trusted root certificate list to obtain a trusted domain certificate list download address of different V2X-PKI-N systems; the SCMS system integrates the trusted domain certificate lists of the different V2X-PKI-N systems and re-encapsulates the same to obtain a new trusted domain certificate list and the trusted root certificate list; and a terminal device obtains the new trusted domain certificate list and the trusted root certificate list by accessing the V2X-PKI system. According to the application, the trusted root data of different V2X-PKI-N systems is collected through the SCMS system, so that the terminal vehicle networking device does not need to download and analyze multiple trusted root lists, thereby reducing the network dependence of the vehicle networking device on multiple cloud systems and relieving the computing pressure.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of trusted root data management, in particular to a trusted root data collection method and control system. BACKGROUND

[0002] In a vehicle-to-everything (V2X) system, multiple independent public key infrastructure (PKI) systems are used to provide certificate services for V2X devices, and the service range of each independent PKI system becomes an authentication domain. The authentication domain is responsible for maintaining all certificates of the PKI system and constitutes a trusted domain. Cross-authentication domain authentication refers to that a V2X device in one authentication domain can authenticate the certificate of a V2X device issued by another authentication domain. Specifically, in a PKI mutual trust process, a V2X device needs to download trusted CA certificate data from multiple security credential management system (SCMS) servers according to a download address in a downloaded trusted root certificate list, and provide trusted root download services for vehicle network devices at the vehicle end and roadside through the SCMS to realize a trusted certificate management function.

[0003] The V2X device connects to multiple SCMS servers according to the number of trusted domains managed by a system trusted root certificate list management mechanism. Since the device relies on multiple SCMS servers during operation, the development cost of a trusted root data maintenance module of the V2X device is increased. Meanwhile, the V2X device needs to perform signature verification operations on all downloaded data, which occupies a large amount of device computing power. SUMMARY

[0004] To solve the above problems, the present application provides a trusted root data collection method and control system to solve the above problems.

[0005] In a first aspect of the present application, a trusted root data collection method is provided, including the following steps:

[0006] A V2X-PKI system downloads a trusted root certificate list from a trusted root platform, wherein the V2X-PKI system manages security certificates through an SCMS system, and the SCMS system obtains the trusted root certificate list;

[0007] The SCMS system parses the trusted root certificate list to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems;

[0008] The V2X-PKI system integrates and re-encapsulates the trusted domain certificate lists of different V2X-PKI-N systems to obtain a new trusted domain certificate list and a trusted root certificate list;

[0009] The terminal device obtains the new trusted domain certificate list and the trusted root certificate list by accessing the SCMS system.

[0010] As an optional embodiment of the present application, optionally, the trusted root certificate list includes trusted domain certificate download addresses of different V2X-PKI-N systems, and signature information of the trusted root certificate list.

[0011] As an optional embodiment of the present application, optionally, the SCMS system parses the trusted root certificate list to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems, including:

[0012] The SCMS system verifies the signature information of the trusted root certificate list by using the public key certificate of the trusted root platform;

[0013] After verification, the trusted root certificate list is parsed by using JAVA language to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems.

[0014] As an optional embodiment of the present application, optionally, the SCMS system integrates the trusted domain certificate lists of different V2X-PKI-N systems and then re-encapsulates to obtain new trusted domain certificate list and trusted root certificate list, including:

[0015] The SCMS system accesses trusted domain certificate list download addresses of different V2X-PKI-N systems to obtain different trusted domain certificate lists.

[0016] The contents of different trusted domain certificate lists are integrated, and the integrated trusted domain certificate list and the trusted root certificate list are obtained according to the standard format coding;

[0017] The summary information of the integrated trusted root certificate list is generated.

[0018] The summary information is digitally signed by using the signature private key of the SCMS system to re-encapsulate to obtain new trusted root certificate list and trusted domain certificate list.

[0019] As an optional embodiment of the present application, optionally, before the V2X-PKI system downloads the trusted root certificate list from the trusted root platform, it further includes:

[0020] Different V2X-PKI-N systems are connected with the trusted root platform, and identity verification is performed by digital signature. Different V2X-PKI-N systems are managed by different SCMS-N systems.

[0021] As an optional embodiment of the present application, optionally further comprising:

[0022] The terminal device verifies the new trusted root certificate list through the signature information in the new trusted root certificate list, and normally uses the new trusted root certificate list after verification.

[0023] As an optional embodiment of the present application, the standard format coding is OER coding for the trusted domain certificate list content.

[0024] The second aspect of the present application also provides a control system, comprising:

[0025] A processor;

[0026] A memory for storing processor executable instructions;

[0027] The processor is configured to implement the trusted root data collection method of any of the above when executing the executable instructions.

[0028] Technical effects of the present application:

[0029] The method of the present application collects the trusted root certificate data of different V2X-PKI-N systems through the V2X-PKI system, that is, optimizes the trusted root management function of the SCMS system, and realizes the collection of the trusted root certificate data required for the Internet of Vehicles device with the cloud, so that the terminal Internet of Vehicles device does not need to download and analyze multiple trusted root lists, thereby reducing the network dependence of the Internet of Vehicles device on multiple SCMS cloud systems and relieving the computing pressure. Specifically, the V2X-PKI system is connected with the trusted root platform, and the trusted root certificate list is downloaded from the trusted root platform, wherein the V2X-PKI system manages the security certificate through the SCMS system, that is, the SCMS system obtains the trusted root certificate list. The trusted root certificate list includes the trusted domain certificate list download address and the root certificate of different V2X-PKI-N systems, and the signature value of the trusted root certificate list. It should be noted that the signature value of the trusted root certificate list is the signature information generated by the trusted root platform using its own certificate, which prevents the issued trusted root certificate list from being tampered with and achieves the effect of non-repudiation. After the V2X-PKI system downloads the trusted root certificate list, the trusted root certificate list is parsed to obtain the trusted domain certificate list download address and the root certificate of different V2X-PKI-N systems, and the trusted domain certificate list of different V2X-PKI-N systems is obtained by accessing the trusted domain certificate list download address. It should be noted that the trusted domain certificate lists of different V2X-PKI-N systems are integrated, and the integrated trusted domain certificate list is re-encapsulated into a new trusted domain certificate list. The new trusted domain certificate list is a complete trusted domain certificate list, which is written into the terminal Internet of Vehicles device. The Internet of Vehicles device can obtain the trusted certificate data in different trust domains by accessing the new trusted domain certificate list, and the signature verification operation only needs to be performed once, effectively reducing the computing pressure of the terminal Internet of Vehicles device for data verification, and reducing the occupation of device network and computing resources.

[0030] Other features and aspects of the present disclosure will become apparent from the following detailed description of example embodiments, taken in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS

[0031] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate example embodiments, features, and aspects of the present disclosure and serve to explain the principles of the present disclosure.

[0032] Figure 1 A schematic block diagram of the trusted root data collection method of the present application is shown;

[0033] Figure 2 A schematic diagram of the trusted root data collection process of the present application is shown. DETAILED DESCRIPTION

[0034] Various exemplary embodiments, features, and aspects of the present disclosure will be described in detail below with reference to the accompanying drawings. The same reference numbers in different drawings represent the same or similar elements. Although various aspects of embodiments are illustrated in the drawings, the drawings are not necessarily drawn to scale unless specifically noted.

[0035] The term "exemplary" is used herein to mean "serving as an example, instance, or illustration." Any implementation described herein as "exemplary" is not necessarily to be construed as preferred or advantageous over other implementations.

[0036] In addition, for the purpose of convenience and brevity, detailed descriptions of well-known functions and structures incorporated in the disclosure will be omitted. It will be appreciated that those skilled in the art will be able to devise various modes of implementing the advantageous aspects of the disclosure without the application of inventive faculty being rendered inoperative.

[0037] In the Internet of Vehicles system, multiple independent PKI systems provide certificate services for Internet of Vehicles devices. All certificates of the PKI system constitute a trusted domain. The terminal Internet of Vehicles devices under different authentication domains are respectively connected to multiple SCMS systems to download trusted CA certificate data according to the number of trusted domains managed by the trusted root platform, which increases the development cost of the terminal Internet of Vehicles devices for the trusted root data maintenance module, and depends on multiple SCMS systems in the running process. In view of this, the present application provides a trusted root data collection method, which connects the terminal Internet of Vehicles devices to multiple SCMS systems to download trusted root certificate data, and optimizes the multiple signature verification processes of the SCMS system, realizes the collection of the trusted root certificate data required by the Internet of Vehicles devices. That is, by parsing the download address of the trusted domain certificate list in the trusted root list of other trust domains, and sequentially accessing the download address, the trusted certificate data of other trust domains is obtained, and after verification, it is assembled into a data format suitable for the use of Internet of Vehicles devices, so that the Internet of Vehicles devices only need to connect one SCMS system, and the trusted root certificate data under multiple trust domains after collection can be downloaded.

[0038] The present application will be further described below.

[0039] Embodiment 1

[0040] As shown in Figure 1 and Figure 2 The present application provides a trusted root data collection method, comprising the following steps:

[0041] The V2X-PKI system downloads a trusted root certificate list from a trusted root platform, and the V2X-PKI system manages security certificates through an SCMS system, and the SCMS system obtains the trusted root certificate list;

[0042] The SCMS system parses the trusted root certificate list to obtain the trusted domain certificate list download address of different V2X-PKI-N systems;

[0043] The SCMS system integrates the trusted domain certificate lists of different V2X-PKI-N systems and then re-encapsulates to obtain a new trusted domain certificate list and a trusted root certificate list;

[0044] The terminal device obtains the new trusted domain certificate list and the trusted root certificate list by accessing the SCMS system.

[0045] In this embodiment, the V2X-PKI system collects the trusted root certificate data of different V2X-PKI-N systems, that is, optimizes the trusted root management function of the SCMS system, and collects the trusted root certificate data of the terminal vehicle Internet of Things device with the cloud to reduce the network dependence of the terminal vehicle Internet of Things device on multiple SCMS cloud systems and relieve the computing pressure. Specifically, the V2X-PKI system is connected with the trusted root platform and downloads the trusted root certificate list from the trusted root platform. The V2X-PKI system manages the security certificate through the SCMS system, that is, the SCMS system obtains the trusted root certificate list, the trusted root certificate list includes the trusted domain certificate list download address and the root certificate of different V2X-PKI-N systems, and the signature value of the trusted root certificate list. It should be noted that the signature value of the trusted root certificate list is the signature information generated by the trusted root platform using its own certificate, which prevents the trusted root certificate list from being tampered with and achieves the effect of non-repudiation. After the V2X-PKI system downloads the trusted root certificate list, the trusted root certificate list is parsed to obtain the trusted domain certificate list download address and the root certificate of different V2X-PKI-N systems. The trusted domain certificate list of different V2X-PKI-N systems is obtained by accessing the trusted domain certificate list download address. It should be particularly noted that the SCMS system integrates the trusted domain certificate lists of different V2X-PKI-N systems, and re-encapsulates the integrated trusted domain certificate list into a new trusted domain certificate list. The new trusted domain certificate list is a complete trusted domain certificate list. After the new trusted domain certificate list is written into the terminal vehicle Internet of Things device, the vehicle Internet of Things device can obtain the trusted certificate data in different trust domains by accessing the new trusted domain certificate list, which can effectively reduce the network dependence of the vehicle Internet of Things device on multiple cloud SCMS systems. The vehicle Internet of Things device only needs to be connected to one SCMS system to download the trust root certificate data in multiple trust domains after aggregation. The signature verification operation only needs to be performed once, which effectively reduces the computing pressure of the terminal vehicle Internet of Things device on data verification, and reduces the occupation of network and computing resources of the device.

[0046] As an optional implementation of the present application, the trusted root certificate list includes trusted domain certificate download addresses of different V2X-PKI-N systems and signature information of the trusted root certificate list.

[0047] In the embodiment, the trusted relationship between different trusted domains is implemented by a trusted root certificate list, which includes trusted domain certificate download addresses of different V2X-PKI-N systems connected with the trusted root platform, root certificates, and signature information of the trusted root certificate list. The signature information is generated by the trusted root platform using its own certificate, which provides digital signature protection for the trusted root certificate list to prevent the trusted root certificate list data downloaded by the SCMS system from being tampered with, thereby ensuring data security and reliability in the interaction process.

[0048] As an optional implementation of the present application, the SCMS system parses the trusted root certificate list to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems, including:

[0049] The SCMS system verifies the signature information of the trusted root certificate list using the public key certificate of the trusted root platform.

[0050] After verification, the trusted root certificate list is parsed using JAVA language to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems.

[0051] In the embodiment, before parsing and obtaining the trusted domain certificate list download addresses, the SCMS system needs to verify the signature information in the trusted root certificate list using the public key certificate of the trusted root platform to ensure that the trusted root certificate list is signed by the expected trusted root platform and that the content of the trusted root certificate list has not been tampered with. After the identity and signature verification, the trusted root certificate list is parsed to obtain trusted domain certificate list download addresses of different V2X-PKI-N systems. For the parsing of the trusted root certificate list, the SCMS system uses JAVA language, thereby making the system more portable and easier to maintain.

[0052] As an optional implementation of the present application, the SCMS system integrates and re-encapsulates the trusted domain certificate lists of different V2X-PKI-N systems to obtain new trusted domain certificate lists and trusted root certificate lists, including:

[0053] The SCMS system accesses trusted domain certificate list download addresses of different V2X-PKI-N systems to obtain different trusted domain certificate lists.

[0054] Integrate the contents of different trusted domain certificate lists, and encode according to a standard format to obtain an integrated trusted domain certificate list and a trusted root certificate list;

[0055] Generate summary information of the integrated trusted domain certificate list;

[0056] Digitally sign the summary information by a signature private key of the SCMS system, and repackage to obtain a new trusted root certificate list and trusted domain certificate list.

[0057] In this embodiment, the SCMS system accesses the trusted domain certificate list download address of different N2X-PKI systems to obtain different trusted domain certificate lists, and further integrates the contents of different trusted domain certificate lists and encodes the data OER according to a standard format. The integrated trusted root certificate list is digitally summarized by a hash algorithm to generate summary information, and the summary information is digitally signed by a signature private key. The signature and the verification public key are repackaged to generate a new trusted root certificate list. After the digital signature by the private key, the terminal vehicle networking device can verify the legality and authenticity of the trusted root certificate list. Since the new trusted root certificate list obtained by the present application includes the trusted domain certificate lists of different V2X-PKI-N systems, when the terminal vehicle networking device connects the SCMS system of the present application, it can obtain the trusted root data in different trust domains through a signature verification. By accessing the download address in the trusted root certificate list, the trusted certificate data of other trust domains can be obtained by sequentially accessing the download address. There is no need to rely on different trust domain network systems when facing different requirements, and the downloaded data needs to be verified. This can effectively relieve the computing pressure of the terminal vehicle networking device.

[0058] As an optional embodiment of the present application, optionally, before the V2X-PKI system downloads the trusted root certificate list from the trusted root platform, it further includes:

[0059] Different V2X-PKI-N systems are connected to the trusted root platform and are authenticated by digital signature. Different V2X-PKI-N systems are managed by different SCMS-N systems.

[0060] In this embodiment, each independent V2X-PKI-N system is connected with a trusted root platform, the trusted root platform issues a trusted root certificate list, stores the root certificate of each trust domain and the download address of the trusted domain certificate list. After the terminal vehicle networking device obtains the new trusted root certificate list of the SCMS system integration of the application, the root certificate of each V2X-PKI-N system is obtained, and each trusted domain certificate chain is obtained through the trusted domain certificate list download address, so as to realize the purpose of downloading the trust root data of multiple trust domains at one time, and the trusted certificate data of multiple SCMS-N systems is collected.

[0061] As an optional embodiment of the application, optionally, the method further comprises:

[0062] The terminal device verifies the new trusted root certificate list through the signature information in the new trusted root certificate list, and normally uses the new trusted root certificate list after verification.

[0063] In this embodiment, when the terminal vehicle networking device such as a roadside device and a vehicle-mounted device authenticates the certificate issued by other trust domain to the vehicle networking device in the domain, the signature information in the new trusted root certificate list re-encapsulated by the application is verified, and the trusted root certificate list is normally used after verification.

[0064] As an optional embodiment of the application, optionally, the standard format coding is OER coding for the content of the trusted domain certificate list.

[0065] It should be noted that although the above is introduced as an example, those skilled in the art can understand that the present disclosure should not be limited thereto. In fact, the user can flexibly set according to the actual application scene, as long as the technical function of the application can be realized according to the above technical method.

[0066] Embodiment 2

[0067] Further, the second aspect of the application further provides a control system, comprising:

[0068] a processor;

[0069] a memory for storing processor executable instructions;

[0070] The processor is configured to implement the trusted root data collection method of any of the above when executing the executable instructions.

[0071] The control system of the embodiment of the present disclosure comprises a processor and a memory for storing processor executable instructions. Wherein, the processor is configured to implement the trusted root data collection method of any of the above when executing the executable instructions.

[0072] It should be pointed out here that the number of processors can be one or more. Meanwhile, the control system of the embodiments of the present disclosure can also include input devices and output devices. The processors, memories, input devices and output devices can be connected through buses or other means, which is not limited here.

[0073] The memory, as a computer readable storage medium, can be used to store software programs, computer executable programs and various modules, such as programs or modules corresponding to the embodiments of the present disclosure. The processor executes the software programs or modules stored in the memory, thereby performing various functional applications and data processing of the control system.

[0074] The input device can be used to receive input numbers or signals. The signals can be key signals related to the user settings and function control of the device / terminal / server. The output device can include display devices such as display screens.

[0075] The above has described the embodiments of the present disclosure, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes are obvious to those skilled in the art without departing from the scope and spirit of the described embodiments. The selection of terms used herein is intended to best explain the principles, practical applications or technical improvements of the technology in the market of the embodiments, or to enable other ordinary skilled persons in the art to understand the embodiments disclosed herein.

Claims

1. A trusted root data aggregation method, characterized by, The method comprises the following steps: The V2X-PKI system downloads a trusted root certificate list from a trusted root platform, wherein the V2X-PKI system manages security certificates through an SCMS system, and the SCMS system obtains the trusted root certificate list; The trusted root certificate list comprises trusted domain certificate download addresses of different V2X-PKI-N systems and signature information of the trusted root certificate list; The SCMS system parses the trusted root certificate list to obtain the trusted domain certificate list download addresses of different V2X-PKI-N systems, comprising: The SCMS system verifies the signature information of the trusted root certificate list by using a public key certificate of the trusted root platform; After verification, the trusted root certificate list is parsed by using JAVA language to obtain the trusted domain certificate list download addresses of different V2X-PKI-N systems; The SCMS system integrates the trusted domain certificate lists of different V2X-PKI-N systems and re-encapsulates to obtain new trusted domain certificate lists and trusted root certificate lists, comprising: The SCMS system accesses the trusted domain certificate list download addresses of different V2X-PKI-N systems to obtain different trusted domain certificate lists; The contents of different trusted domain certificate lists are integrated and encoded according to a standard format to obtain integrated trusted domain certificate lists and trusted root certificate lists; The SCMS system generates digest information of the integrated trusted root certificate list; The SCMS system digitally signs the digest information by using a signature private key to re-encapsulate to obtain new trusted root certificate lists and trusted domain certificate lists; A terminal device obtains the new trusted domain certificate lists and trusted root certificate lists by accessing the SCMS system; The terminal device verifies the new trusted root certificate lists by using signature information in the new trusted root certificate lists, and normally uses the new trusted root certificate lists after verification. The vehicle networking device only needs to connect to one SCMS system, and the signature verification operation only needs to be performed once.

2. The trusted root data aggregation method of claim 1, wherein, Before the V2X-PKI system downloads the trusted root certificate list from the trusted root platform, the method further comprises: Different V2X-PKI-N systems are connected to the trusted root platform and are authenticated by digital signature, and different V2X-PKI-N systems manage security certificates through different SCMS-N systems.

3. The trusted root data aggregation method of claim 1, wherein, The standard format coding is OER coding of the trusted domain certificate list content.

4. A control system characterized by, The method comprises: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to implement the trusted root data collection method of any one of claims 1 to 3 when executing the executable instructions.

Citation Information

Patent Citations

  • Vehicle communication method and device, storage medium and program product

    CN113271565A