A secure authentication access method, device, equipment and storage medium
By sending encrypted information and verifying its accuracy in the production line system of V2X vehicle networking equipment manufacturers, and combining two-way authentication between equipment manufacturers and certificate authorization platforms with private key and public key certificate replacement, the reliability and accuracy issues of vehicle manufacturers' security authentication information access are resolved, and the automation and confidentiality of security authentication information are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- HUIZHOU DESAY SV AUTOMOTIVE
- Filing Date
- 2023-08-30
- Publication Date
- 2026-05-29
AI Technical Summary
Vehicle manufacturers rely on manual access to security authentication information for V2X devices, which makes it impossible to guarantee the credibility and accuracy of the information and poses a risk of information leakage.
The V2X vehicle-to-everything (V2X) equipment manufacturer's production line system sends encrypted information to the device and uses a cryptographic hash function to verify accuracy, achieving two-way authentication between the device and the vehicle manufacturer's platform. It generates and replaces private and public key certificates and uses the device manufacturer and certificate authorization platform to access secure authentication information.
It eliminates the need for manual intervention, ensuring the credibility and accuracy of information, preventing the leakage of security authentication information, and improving the confidentiality of security authentication information.
Smart Images

Figure CN116996868B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure communication technology for vehicle networks, and in particular to a secure authentication access method, apparatus, device, and storage medium. Background Technology
[0002] In recent years, with the rapid development of technologies such as artificial intelligence, the Internet of Things, big data, and information and communication, the core technologies of intelligent connected vehicles have made continuous breakthroughs, the basic support has been improved, the industrial ecosystem has gradually matured, a new era of automobiles is emerging, and human travel is facing an unprecedented and profound transformation.
[0003] With the evolution of product forms and the Industrial Internet of Things (IIoT), the production and delivery process of V2X (Vehicle-to-Everything) devices has evolved. Because the backend network for connected vehicles requires information from the vehicle's infotainment system, the delivery of V2X equipment now includes not only traditional hardware and software delivery but also the delivery of security certifications. Under the V2X business model, many OEMs have seen new changes in their demands for V2X equipment. For example, they now require services for V2X device security certification.
[0004] However, vehicle manufacturers typically rely on manual methods to access security authentication information for V2X devices, which cannot guarantee the reliability and accuracy of the information and poses a risk of information leakage. Summary of the Invention
[0005] This invention provides a secure authentication access method, apparatus, device, and storage medium to solve the problem of inability to guarantee security and accuracy when accessing secure authentication information.
[0006] In a first aspect, the present invention provides a secure authentication access method, comprising:
[0007] The encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and the accuracy of the encrypted information in the V2X vehicle networking equipment is verified by using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate.
[0008] After the accuracy verification is passed, the V2X vehicle networking device uses the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform. After the two-way authentication is passed, the product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device.
[0009] The production line system uses diagnostic instructions to instruct the V2X vehicle networking device to generate a second private key, and the V2X vehicle networking device replaces the first decryption information with the second decryption information. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
[0010] Secondly, the present invention provides a secure authentication access device, comprising:
[0011] An accuracy verification module is used to send encrypted information to V2X vehicle networking equipment through the production line system of V2X vehicle networking equipment factory, and to verify the accuracy of encrypted information in V2X vehicle networking equipment using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate.
[0012] The certificate acquisition module is used to perform two-way authentication between the V2X vehicle networking device and the vehicle manufacturer's first platform using the encrypted information after the accuracy verification is passed, and to obtain the product certificate from the first platform using a preset serial number after the two-way authentication is passed; wherein, the first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device;
[0013] The information replacement module is used to instruct the V2X vehicle networking device to generate a second private key through the production line system using diagnostic instructions, and to replace the first decryption information with the second decryption information through the V2X vehicle networking device. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
[0014] Thirdly, the present invention provides an electronic device comprising:
[0015] At least one processor;
[0016] and memory that is communicatively connected to at least one processor;
[0017] The memory stores a computer program that can be executed by at least one processor, which enables the at least one processor to perform the security authentication access method described in the first aspect.
[0018] Fourthly, the present invention provides a computer-readable storage medium storing computer instructions that, when executed by a processor, implement the security authentication access method of the first aspect described above.
[0019] The secure authentication access scheme provided by this invention sends encrypted information to the V2X vehicle-to-everything (V2X) device through the production line system of a V2X device manufacturer. The accuracy of the encrypted information within the V2X device is verified using a first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate. After the accuracy verification is successful, the V2X device uses the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform. After successful two-way authentication, a product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X device certificate authorization platform, and the preset serial number is the product serial number of the V2X device. The production line system uses diagnostic commands to instruct the V2X device to generate a second private key. The V2X device then replaces the first decrypted information with the second decrypted information. The first decrypted information includes the first private key and the first public key certificate, and the second decrypted information includes the second private key and a second public key certificate generated by the vehicle manufacturer's second platform, which is a public key certificate authorization platform. By adopting the above technical solution, and utilizing the equipment manufacturer's production line system, V2X vehicle networking equipment certificate authorization platform, and public key certificate authorization platform, the access to the security authentication information of V2X vehicle networking equipment is realized. This does not rely on manual intervention, ensuring the credibility and accuracy of the information. Furthermore, diagnostic commands are used to replace the security authentication information within the V2X vehicle networking equipment, preventing the leakage of security authentication information and further improving the confidentiality of the security authentication information.
[0020] It should be understood that the description in this section is not intended to identify key or essential features of the invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0021] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0022] Figure 1 This is a flowchart of a secure authentication access method provided according to Embodiment 1 of the present invention;
[0023] Figure 2 This is a flowchart of a secure authentication access method provided according to Embodiment 2 of the present invention;
[0024] Figure 3 This is a schematic diagram of the structure of a security authentication access device provided according to Embodiment 3 of the present invention;
[0025] Figure 4 This is a schematic diagram of the structure of an electronic device provided according to Embodiment 4 of the present invention. Detailed Implementation
[0026] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0027] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. In the description of this invention, unless otherwise stated, "a plurality of" means two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist; for example, A and / or B can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or devices.
[0028] Example 1
[0029] Figure 1The flowchart below provides a secure authentication access method according to Embodiment 1 of the present invention. This embodiment is applicable to the case of secure authentication for V2X devices. The method can be executed by a secure authentication access device, which can be implemented in hardware and / or software. The secure authentication access device can be configured in an electronic device, which can be composed of two or more physical entities or a single physical entity.
[0030] like Figure 1 As shown, the secure authentication access method provided in Embodiment 1 of the present invention specifically includes the following steps:
[0031] S101. The encrypted information is sent to the V2X vehicle networking device through the production line system of the V2X vehicle networking device factory, and the accuracy of the encrypted information in the V2X vehicle networking device is verified by using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate.
[0032] In this embodiment, the V2X vehicle-to-everything (V2X) equipment manufacturer's public key infrastructure (PKI) platform generates and encrypts a first private key and a first public key certificate. After obtaining the encrypted information, it is sent to the production line system. The PKI platform is a platform built on a PKI (Public Key Infrastructure) management system, which provides encryption and digital signature services for internet applications. The V2X production line system then sends the stored encrypted information to the V2X equipment (hereinafter referred to as the V2X equipment) through a preset engineering mode. The engineering mode can be understood as an in-plant debugging mode. The first public key certificate can be an X.509 certificate. X.509 certificates are mainly used to identify identities in internet communications and computer networks and protect data transmission security; they are digital certificates based on the X.509 standard developed by the International Telecommunication Union (ITU). Then, after the V2X device receives the encrypted information, the production line system can again verify the accuracy of the encrypted information within the V2X device through engineering mode. This verifies whether the encrypted information within the V2X device is consistent with the encrypted information sent by the production line system. The verification method is not limited here. Specifically, after receiving the encrypted information, the V2X device can save the encrypted information and its decryption information to a preset encryption chip, such as an HSM (Hardware Security Module) chip.
[0033] S102. After the accuracy verification is passed, the V2X vehicle networking device uses the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform. After the two-way authentication is passed, the product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device.
[0034] In this embodiment, after the accuracy verification is passed, the V2X device can perform two-way authentication with the vehicle manufacturer's first platform via encrypted information. For example, the V2X device can first decrypt the encrypted information, and then use the decrypted X.509 certificate to perform two-way authentication with the first platform to verify the reliability of the identities of the V2X device and the first platform. If the two-way authentication is successful, it indicates that the identities of both the V2X device and the first platform are reliable, and a reliable communication channel can be established. Using this communication channel, product certificates, such as vehicle product EC (Equipment Certificate) and PC (Product Certificate), can be obtained from the first platform.
[0035] S103. The production line system uses diagnostic instructions to instruct the V2X vehicle networking device to generate a second private key, and the V2X vehicle networking device replaces the first decryption information with the second decryption information. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
[0036] In this embodiment, the production line system can instruct the V2X device to generate a second private key via diagnostic commands. Then, the V2X device can request a second public key certificate from a second platform, and replace its stored first private key and first public key certificate with the second private key and second public key certificate. At this point, the private key within the V2X device is known only to the V2X device, further ensuring the confidentiality of the security authentication information.
[0037] The secure authentication access method provided in this embodiment of the invention sends encrypted information to the V2X vehicle networking device through the production line system of the V2X vehicle networking device manufacturer. The accuracy of the encrypted information within the V2X vehicle networking device is verified using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate. After the accuracy verification is successful, the V2X vehicle networking device performs two-way authentication with the vehicle manufacturer's first platform using the encrypted information. After successful two-way authentication, a product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device. The production line system uses diagnostic instructions to instruct the V2X vehicle networking device to generate a second private key. The V2X vehicle networking device then replaces the first decrypted information with the second decrypted information. The first decrypted information includes the first private key and the first public key certificate, and the second decrypted information includes the second private key and a second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform. The technical solution of this invention utilizes the equipment manufacturer's production line system, V2X vehicle networking equipment certificate authorization platform, and public key certificate authorization platform to achieve access to the security authentication information of V2X vehicle networking equipment. This does not rely on manual intervention, ensuring the credibility and accuracy of the information. Furthermore, diagnostic commands are used to replace the security authentication information within the V2X vehicle networking equipment, preventing the leakage of security authentication information and further improving the confidentiality of the security authentication information.
[0038] Optionally, before sending the encrypted information to the V2X vehicle-to-everything (V2X) device via the V2X device manufacturer's production line system, and verifying the accuracy of the encrypted information within the V2X device using the first cryptographic hash function value of the encrypted information, the method further includes: encrypting the first private key and the first public key certificate using the V2X device manufacturer's public key infrastructure platform with Advanced Encryption Standard (AES) to obtain encrypted information, and determining the first cryptographic hash function value of the encrypted information; then sending the encrypted information and the first cryptographic hash function value to the V2X device manufacturer's production line system via the public key infrastructure platform. The advantage of this configuration is that by encrypting the generated private key and public key certificate using the public key infrastructure platform and calculating the cryptographic hash function value, the reliability of the private key and public key certificate can be guaranteed.
[0039] Specifically, the V2X equipment manufacturer's production line system can pre-generate multiple V2X device serial numbers according to preset serial number generation rules. These serial numbers are then sent to a public key infrastructure (PKI) platform, which generates a first private key and a corresponding CSR (Certificate Signing Request) based on the serial number. Using the CSR, the PKI platform can request a first public key certificate from the vehicle manufacturer's second platform by calling a preset interface. The PKI platform can then encrypt the first private key and the first public key certificate using AES. After obtaining the encrypted information, a first cryptographic hash function value (e.g., MD5) is calculated. The PKI platform can then send this encrypted information and the first cryptographic hash function value to the V2X equipment manufacturer's production line system, allowing the production line system to store these data.
[0040] Optionally, before sending encrypted information to the V2X vehicle-to-everything (V2X) device via the V2X device manufacturer's production line system and verifying the accuracy of the encrypted information within the V2X device using the first cryptographic hash function value of the encrypted information, the method further includes: sending a preset serial number to the V2X device manufacturer's public key infrastructure platform and the V2X device via the V2X device manufacturer's production line system; pairing the preset serial number and the encrypted first public key certificate through the public key infrastructure platform to obtain a pairing table, and synchronizing the pairing table to the first platform; wherein, obtaining the product certificate from the first platform using the preset serial number includes: sending the preset serial number to the first platform through the V2X device, and determining through the first platform whether the preset serial number is in the pairing table; if so, at least the vehicle product equipment certification certificate and the product registration certificate are sent to the V2X device. The advantage of this setup is that by pairing the preset serial number with the first public key certificate, when the V2X device requests to download the product certificate from the first platform, the V2X device can use its own product serial number to identify itself to the first platform, while also ensuring the reliability of the V2X device.
[0041] Specifically, the V2X equipment manufacturer's production line system can send a preset serial number to the public key infrastructure platform and the V2X equipment. The V2X equipment can return the preset serial number to the production line system. This preset serial number is not paired with the first public key certificate. The public key infrastructure platform can pair the preset serial number with the encrypted or unencrypted first public key certificate, obtain a pairing table, and synchronize this pairing table to the first platform. Simultaneously, the public key infrastructure platform can use the first cryptographic hash function value to verify the accuracy of the first public key certificate. For example, it can check whether the first cryptographic hash function value of the current first public key certificate is consistent with the first cryptographic hash function value received when the first public key certificate was first received. If they are consistent, the accuracy verification is considered successful. Before applying for a product certificate from the first platform through the V2X equipment, the preset serial number can be encapsulated as a certificate identifier in the certificate application information and sent to the first platform. If the preset serial number is in the pairing table, it indicates that the preset serial number is valid, and the first platform can issue EC certificates and PC certificates with preset periods to the V2X equipment.
[0042] Example 2
[0043] Figure 2 This is a flowchart of a secure authentication access method provided in Embodiment 2 of the present invention. The technical solution of the present invention is further optimized based on the above optional technical solutions, and provides a specific method for secure authentication of V2X device access.
[0044] Optionally, the step of sending encrypted information to the V2X vehicle-to-everything (V2X) device via the V2X device manufacturer's production line system, and verifying the accuracy of the encrypted information within the V2X device using the first cryptographic hash function value of the encrypted information, includes: sending encrypted information to the V2X device via the V2X device manufacturer's production line system, and determining the second cryptographic hash function value of the encrypted information through the V2X device; comparing the first cryptographic hash function value and the second cryptographic hash function value in the production line system to see if they match; if they match, the accuracy verification of the encrypted information within the V2X device is deemed successful. The advantage of this setup is that by comparing the cryptographic hash function value of the encrypted information received by the V2X device with the cryptographic hash function value of the encrypted information sent by the production line system, it can be determined whether the encrypted information has been accurately injected into the V2X device.
[0045] Optionally, the step of instructing the V2X vehicle-to-everything (V2X) device to generate a second private key via diagnostic instructions from the production line system, and replacing the first decryption information with the second decryption information via the V2X V2X device, includes: using the first diagnostic instructions from the production line system to request a certificate request file from the V2X V2X device; generating a second private key and a certificate request file via the V2X V2X device, and sending the certificate request file to the production line system; using the certificate request file from the vehicle manufacturer's second platform via the production line system; using the second diagnostic instructions from the V2X V2X device to obtain the second public key certificate from the production line system; performing encoding and decoding operations on the second public key certificate to obtain a decoded second public key certificate; replacing the first private key with the second private key; and replacing the first public key certificate with the decoded second public key certificate. The advantage of this setup is that by utilizing the first and second diagnostic instructions, the private key and public key certificate in the V2X device are updated simultaneously, while the encoding and decoding operations ensure the integrity of the characters in the second public key certificate.
[0046] like Figure 2 As shown in Embodiment 2 of the present invention, a secure authentication access method specifically includes the following steps:
[0047] S201. The first private key and the first public key certificate are encrypted using the Advanced Encryption Standard (AES) through the public key infrastructure platform of the V2X vehicle networking equipment manufacturer to obtain encrypted information, and the first cryptographic hash function value of the encrypted information is determined.
[0048] S202. The preset serial number is sent to the V2X vehicle networking equipment manufacturer's public key infrastructure platform and V2X vehicle networking equipment through the V2X vehicle networking equipment manufacturer's production line system.
[0049] S203. The preset serial number and the encrypted first public key certificate are paired through the public key infrastructure platform to obtain a pairing table, and the pairing table is synchronized to the first platform.
[0050] S204. The encrypted information and the first cryptographic hash function value are sent to the production line system of the V2X vehicle networking equipment factory through the public key infrastructure platform.
[0051] S205. The encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and the second cryptographic hash function value of the encrypted information is determined by the V2X vehicle networking equipment.
[0052] Specifically, the production line system can send encrypted information to the V2X device, which can calculate the (second) cryptographic hash function value of the encrypted information and save the second cryptographic hash function value to the HSM chip.
[0053] S206. Compare the first cryptographic hash function value and the second cryptographic hash function value in the production line system to see if they are consistent. If they are consistent, proceed to step 207. If they are inconsistent, end the process.
[0054] Specifically, if they match, it means that the encrypted information was successfully injected into the V2X device; if they do not match, it means that the process failed. At this point, the current process can be terminated and the reason for the failure can be analyzed.
[0055] S207. Verification of the accuracy of encrypted information within the V2X vehicle networking device has been passed.
[0056] S208. The V2X vehicle networking device performs two-way authentication with the vehicle manufacturer's first platform using encrypted information. After the two-way authentication is successful, the V2X vehicle networking device sends the preset serial number to the first platform. The first platform then determines whether the preset serial number is in the pairing relationship table. If it is, proceed to step 209; otherwise, the process ends.
[0057] Optionally, the step of performing two-way authentication between the V2X vehicle networking device and the vehicle manufacturer's first platform using the encrypted information includes: decrypting the encrypted information using the V2X vehicle networking device to obtain at least the first public key certificate; determining, using the root certificate, whether the first public key certificate was issued by the vehicle manufacturer's first platform; if so, determining, through the first platform, whether the first public key certificate was issued by the first platform by calling the vehicle manufacturer's second platform. The advantage of this setup is that by utilizing the root certificate and the first platform, the accuracy of the two-way authentication result between the V2X device and the first platform is guaranteed.
[0058] Specifically, the encrypted information can be decrypted through the V2X device to obtain the first public key certificate, which is then used to authenticate the first platform using the root certificate. Simultaneously, the first platform calls a service on the second platform to authenticate the first public key certificate in the V2X device.
[0059] S209. At least the vehicle product equipment certification certificate and product registration certificate shall be sent to the V2X vehicle networking equipment through the first platform.
[0060] S210. Using the first diagnostic command through the production line system, apply for a certificate request document from the V2X vehicle networking device.
[0061] Specifically, the production line system can use the first diagnostic command to request the certificate request file to be read from the V2X vehicle networking device.
[0062] S211. Generate a second private key and certificate request file through the V2X vehicle networking device, and send the certificate request file to the production line system.
[0063] Specifically, the V2X vehicle-to-everything (V2X) device can respond to the above request by generating a second private key and a certificate request file, saving the second private key to an encryption chip, and then replying to the production line system with a certificate request file in base64 format. Base64 is a common encoding method used on the internet for transmitting 8-bit byte code.
[0064] S212. Obtain a second public key certificate from the vehicle manufacturer's second platform using a certificate request file through the production line system.
[0065] Specifically, the production line system can use this certificate request file to apply to the second platform for a second public key certificate.
[0066] S213. Using the second diagnostic command through the V2X vehicle networking device, obtain the second public key certificate from the production line system, encode and decode the second public key certificate to obtain the decoded second public key certificate, replace the first private key with the second private key, and replace the first public key certificate with the decoded second public key certificate.
[0067] Specifically, the V2X vehicle-to-everything (V2X) device can obtain a second public key certificate from the production line system via a second diagnostic command. It then encodes and decodes this certificate to obtain a decoded second public key certificate. The encoding and decoding operations ensure that all characters in the second public key certificate are displayed completely. Next, the first private key in the encryption chip is replaced with the second private key, and the first public key certificate in the encryption chip is replaced with the decoded second public key certificate.
[0068] Optionally, to further prevent the leakage of the first private key and the first public key certificate, the following measures 1) to 4) can be adopted:
[0069] 1) V2X vehicle networking equipment manufacturers can use Internet Protocol Security (IPSec), virtual private networks, and leased lines for internal communication, and refuse to connect to the public network.
[0070] 2) Manual copying is prohibited. The public key infrastructure platform and production line system have no HMI (Human Machine Interface), no USB (Universal Serial Bus) interface, no network disk mapping, and no File Transfer Protocol (FTP) interface.
[0071] 3) The certificate usage process leaves no trace. Except for the public key infrastructure platform, the other platforms and systems mentioned above do not have temporary files during the generation and forwarding of certificates, and all operations are carried out in memory.
[0072] 4) During the information exchange between the second platform and the public key infrastructure platform, HTTPS (Hypertext Transfer Protocol Secure) is used to ensure the security of the information exchange process.
[0073] The secure authentication access method provided in this embodiment of the invention compares the cryptographic hash function value of the encrypted information received by the V2X device with the cryptographic hash function value of the encrypted information sent by the production line system to determine whether the encrypted information has been accurately injected into the V2X device. By using the first diagnostic instruction and the second diagnostic instruction, the private key and public key certificate in the V2X device are updated, and the integrity of the characters in the second public key certificate is ensured through encoding and decoding operations.
[0074] Based on the above embodiments, the method may further include: after receiving a certificate update instruction, the V2X vehicle networking device updates the product registration certificate in the V2X vehicle networking device by calling the after-sales service provider interface.
[0075] Specifically, after receiving a certificate update instruction, the V2X device can instruct itself to update the product registration certificate by calling the after-sales service provider's interface.
[0076] Example 3
[0077] Figure 3 This is a schematic diagram of the structure of a security authentication access device provided in Embodiment 3 of the present invention. Figure 3 As shown, the device includes: an accuracy verification module 301, a certificate acquisition module 302, and an information replacement module 303, wherein:
[0078] An accuracy verification module is used to send encrypted information to V2X vehicle networking equipment through the production line system of V2X vehicle networking equipment factory, and to verify the accuracy of encrypted information in V2X vehicle networking equipment using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate.
[0079] The certificate acquisition module is used to perform two-way authentication between the V2X vehicle networking device and the vehicle manufacturer's first platform using the encrypted information after the accuracy verification is passed, and to obtain the product certificate from the first platform using a preset serial number after the two-way authentication is passed; wherein, the first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device;
[0080] The information replacement module is used to instruct the V2X vehicle networking device to generate a second private key through the production line system using diagnostic instructions, and to replace the first decryption information with the second decryption information through the V2X vehicle networking device. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
[0081] The secure authentication access device provided in this embodiment of the invention utilizes the equipment manufacturer's production line system, V2X vehicle networking device certificate authorization platform, and public key certificate authorization platform to achieve access to the secure authentication information of V2X vehicle networking devices. It does not rely on manual intervention, ensuring the credibility and accuracy of the information. Furthermore, it uses diagnostic commands to replace the secure authentication information within the V2X vehicle networking device, preventing the leakage of secure authentication information and further improving the confidentiality of the secure authentication information.
[0082] Optional, the accuracy verification module includes:
[0083] The function value determination unit is used to send encrypted information to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and determine the second cryptographic hash function value of the encrypted information through the V2X vehicle networking equipment;
[0084] The first judgment unit is used to compare the first cryptographic hash function value and the second cryptographic hash function value in the production line system to see if they are consistent.
[0085] The verification result determination unit is used to determine that the accuracy verification of the encrypted information in the V2X vehicle networking device has passed if the information returned by the first judgment unit is consistent.
[0086] Optionally, the device may also include:
[0087] The function value determination module is used to encrypt the first private key and the first public key certificate using the Advanced Encryption Standard (AES) on the public key infrastructure platform of the V2X vehicle networking equipment manufacturer before the encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment manufacturer and the accuracy of the encrypted information in the V2X vehicle networking equipment is verified by using the first cryptographic hash function value of the encrypted information, to obtain the encrypted information, and to determine the first cryptographic hash function value of the encrypted information.
[0088] The function value sending module is used to send the encrypted information and the first cryptographic hash function value to the production line system of the V2X vehicle networking equipment factory through the public key infrastructure platform.
[0089] Optionally, the device may also include:
[0090] The serial number sending module is used to send a preset serial number to the public key infrastructure platform of the V2X vehicle networking equipment manufacturer and the V2X vehicle networking equipment before the encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment manufacturer and the V2X vehicle networking equipment is verified for accuracy using the first cryptographic hash function value of the encrypted information;
[0091] The relationship table synchronization module is used to pair the preset sequence number and the encrypted first public key certificate through the public key infrastructure platform to obtain a pairing relationship table, and synchronize the pairing relationship table to the first platform.
[0092] Optionally, the certificate acquisition module includes:
[0093] The certificate sending unit is used to send the preset serial number to the first platform through the V2X vehicle networking device, and to determine whether the preset serial number is in the pairing relationship table through the first platform. If it is, at least the vehicle product equipment certification certificate and the product registration certificate are sent to the V2X vehicle networking device.
[0094] Optionally, the certificate acquisition module includes:
[0095] The decryption unit is used to decrypt the encrypted information through the V2X vehicle networking device to obtain at least the first public key certificate;
[0096] The first authentication unit is used to determine, through the V2X vehicle networking device and the root certificate, whether the first public key certificate was issued by the vehicle manufacturer's first platform.
[0097] The first authentication unit is used to determine whether the first public key certificate was issued by the first platform by calling the second platform of the vehicle manufacturer if the information returned by the first authentication unit is yes.
[0098] Optionally, the information replacement module includes:
[0099] The request file application unit is used to apply for a certificate request file from the V2X vehicle networking device through the production line system using a first diagnostic instruction;
[0100] The request file sending unit is used to generate a second private key and a certificate request file through the V2X vehicle networking device, and send the certificate request file to the production line system;
[0101] The public key certificate acquisition unit is used to obtain a second public key certificate from the second platform of the vehicle manufacturer through the certificate request file in the production line system.
[0102] The information replacement unit is used to obtain a second public key certificate from the production line system through the V2X vehicle networking device using a second diagnostic command, perform encoding and decoding operations on the second public key certificate to obtain a decoded second public key certificate, replace the first private key with the second private key, and replace the first public key certificate with the decoded second public key certificate.
[0103] Optionally, the device may also include:
[0104] The update module is used to update the product registration certificate in the V2X vehicle networking device by calling the after-sales service provider interface after the V2X vehicle networking device receives the certificate update instruction.
[0105] The access device for security authentication provided in the embodiments of the present invention can execute the access method for security authentication provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method execution.
[0106] Example 4
[0107] Figure 4A schematic diagram of an electronic device 40 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0108] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42 or a random access memory (RAM) 43, communicatively connected to the at least one processor 41. The memory stores computer programs executable by the at least one processor. The processor 41 can perform various appropriate actions and processes based on the computer program stored in the ROM 42 or loaded into the RAM 43 from storage unit 48. The RAM 43 may also store various programs and data required for the operation of the electronic device 40. The processor 41, ROM 42, and RAM 43 are interconnected via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0109] Multiple components in electronic device 40 are connected to I / O interface 45, including: input unit 46, such as keyboard, mouse, etc.; output unit 47, such as various types of monitors, speakers, etc.; storage unit 48, such as disk, optical disk, etc.; and communication unit 49, such as network card, modem, wireless transceiver, etc. Communication unit 49 allows electronic device 40 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0110] Processor 41 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 41 performs the various methods and processes described above, such as access methods for secure authentication.
[0111] In some embodiments, the secure authentication access method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the secure authentication access method described above may be performed. Alternatively, in other embodiments, processor 41 may be configured to perform the secure authentication access method by any other suitable means (e.g., by means of firmware).
[0112] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0113] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0114] The computer equipment provided above can be used to execute the security authentication access method provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0115] Example 5
[0116] In the context of this invention, a computer-readable storage medium may be a tangible medium, and the computer-executable instructions, when executed by a computer processor, are used to perform a secure authentication access method, the method comprising:
[0117] The encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and the accuracy of the encrypted information in the V2X vehicle networking equipment is verified by using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate.
[0118] After the accuracy verification is passed, the V2X vehicle networking device uses the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform. After the two-way authentication is passed, the product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device.
[0119] The production line system uses diagnostic instructions to instruct the V2X vehicle networking device to generate a second private key, and the V2X vehicle networking device replaces the first decryption information with the second decryption information. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
[0120] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by, or in conjunction with, an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0121] The computer equipment provided above can be used to execute the security authentication access method provided in any of the above embodiments, and has corresponding functions and beneficial effects.
[0122] It is worth noting that in the above-mentioned embodiments of the security authentication access device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be achieved; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the scope of protection of the present invention.
[0123] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.
Claims
1. A secure authentication access method, characterized in that, The methods include: The encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and the accuracy of the encrypted information in the V2X vehicle networking equipment is verified by using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate. After the accuracy verification is passed, the V2X vehicle networking device uses the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform. After the two-way authentication is passed, the product certificate is obtained from the first platform using a preset serial number. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device. The production line system uses diagnostic instructions to instruct the V2X vehicle networking device to generate a second private key, and the V2X vehicle networking device replaces the first decryption information with the second decryption information. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
2. The method according to claim 1, characterized in that, The process of sending encrypted information to V2X vehicle-to-everything (V2X) devices via the production line system of the V2X device manufacturer, and verifying the accuracy of the encrypted information within the V2X V2X device using the first cryptographic hash function value of the encrypted information, includes: The encrypted information is sent to the V2X vehicle networking equipment through the production line system of the V2X vehicle networking equipment factory, and the second cryptographic hash function value of the encrypted information is determined by the V2X vehicle networking equipment. The production line system is used to compare whether the first cryptographic hash function value and the second cryptographic hash function value in the production line system are consistent. If they match, then the accuracy verification of the encrypted information in the V2X vehicle networking device is confirmed to be successful.
3. The method according to claim 1, characterized in that, Before the encrypted information is sent to the V2X vehicle-to-everything (V2X) device via the production line system of the V2X device manufacturer, and the accuracy of the encrypted information within the V2X V2X device is verified using the first cryptographic hash function value of the encrypted information, the method further includes: The first private key and the first public key certificate are encrypted using the Advanced Encryption Standard (AES) through the public key infrastructure platform of the V2X vehicle networking equipment manufacturer to obtain encrypted information, and the first cryptographic hash function value of the encrypted information is determined. The encrypted information and the first cryptographic hash function value are sent to the production line system of the V2X vehicle networking equipment factory through the public key infrastructure platform.
4. The method according to any one of claims 1-3, characterized in that, Before the encrypted information is sent to the V2X vehicle-to-everything (V2X) device via the production line system of the V2X device manufacturer, and the accuracy of the encrypted information within the V2X V2X device is verified using the first cryptographic hash function value of the encrypted information, the method further includes: The pre-set serial number is sent from the production line system of the V2X vehicle-to-everything (V2X) equipment manufacturer to the public key infrastructure platform of the V2X V2X equipment manufacturer and the V2X V2X equipment. The public key infrastructure platform is used to pair the preset serial number and the encrypted first public key certificate to obtain a pairing table, and the pairing table is synchronized to the first platform. The step of obtaining the product certificate from the first platform using a preset serial number includes: The V2X vehicle networking device sends the preset serial number to the first platform, and the first platform determines whether the preset serial number is in the pairing relationship table. If it is, at least the vehicle product equipment certification certificate and product registration certificate are sent to the V2X vehicle networking device.
5. The method according to claim 1, characterized in that, The step of using the encrypted information to perform two-way authentication with the vehicle manufacturer's first platform via the V2X vehicle networking device includes: The encrypted information is decrypted using the V2X vehicle-to-everything (V2X) device to obtain at least the first public key certificate; The V2X vehicle networking device uses the root certificate to determine whether the first public key certificate was issued by the vehicle manufacturer's first platform. If so, the first platform determines whether the first public key certificate was issued by the first platform by calling the second platform of the vehicle manufacturer.
6. The method according to claim 1, characterized in that, The step of instructing the V2X vehicle-to-everything (V2X) device to generate a second private key via diagnostic commands through the production line system, and then replacing the first decryption information with the second decryption information through the V2X V2X device, includes: The production line system uses a first diagnostic command to request a certificate request file from the V2X vehicle networking device. The V2X vehicle networking device generates a second private key and a certificate request file, and sends the certificate request file to the production line system. The production line system uses the certificate request file to obtain a second public key certificate from the vehicle manufacturer's second platform. The V2X vehicle-to-everything (V2X) device uses a second diagnostic command to obtain a second public key certificate from the production line system, performs encoding and decoding operations on the second public key certificate to obtain a decoded second public key certificate, replaces the first private key with the second private key, and replaces the first public key certificate with the decoded second public key certificate.
7. The method according to claim 4, characterized in that, Also includes: After receiving a certificate update instruction, the V2X vehicle networking device updates the product registration certificate within the V2X vehicle networking device by calling the after-sales service provider interface.
8. A secure authentication access device, characterized in that, include: An accuracy verification module is used to send encrypted information to V2X vehicle networking equipment through the production line system of V2X vehicle networking equipment factory, and to verify the accuracy of encrypted information in V2X vehicle networking equipment using the first cryptographic hash function value of the encrypted information. The encrypted information includes an encrypted first private key and an encrypted first public key certificate. The certificate acquisition module is used to perform two-way authentication between the V2X vehicle networking device and the vehicle manufacturer's first platform using the encrypted information after the accuracy verification is passed, and to obtain the product certificate from the first platform using a preset serial number after the two-way authentication is passed. The first platform is a V2X vehicle networking device certificate authorization platform, and the preset serial number is the product serial number of the V2X vehicle networking device. The information replacement module is used to instruct the V2X vehicle networking device to generate a second private key through the production line system using diagnostic instructions, and to replace the first decryption information with the second decryption information through the V2X vehicle networking device. The first decryption information includes the first private key and the first public key certificate, and the second decryption information includes the second private key and the second public key certificate generated by the vehicle manufacturer's second platform. The second platform is a public key certificate authorization platform.
9. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the secure authentication access method according to any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that, when executed by a processor, implement the secure authentication access method according to any one of claims 1-7.