A method and system for encrypting and transmitting event information between a roadside unit and an onboard unit

By introducing an encrypted transmission method between roadside units and vehicle-mounted units in the ETC system, the sub-encryption key and message authentication code ensure the secure transmission and decryption of event information, the existing ETC event information release scheme has been solved, and efficient and secure event information release has been achieved.

CN118612726BActive Publication Date: 2025-05-20BEIJING YILUHANG TECH CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410762582.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-13
Publication Date
2025-05-20
Estimated Expiration
2044-06-13

AI Technical Summary

Technical Problem

The existing ETC event information release scheme has low transmission efficiency and low security.

Method used

Through the encryption transmission method between the roadside unit and the vehicle-mounted unit, the main encryption key, area number and contract sequence number are used to generate a sub-encryption key, the event information is encrypted, and the data is verified through the message authentication code, and finally decrypted and broadcast the event information on the vehicle-mounted device.

Benefits of technology

It realizes efficient and secure event information release, improving transmission efficiency and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118612726B_ABST
    Figure CN118612726B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for encrypting and transmitting event information between a roadside unit and a vehicle-mounted unit, broadcasting a beacon service table to the vehicle-mounted unit, obtaining the area number and contract serial number of the vehicle-mounted unit; calling a consumer security access module, generating a sub-encryption key according to the main encryption key, the area number and the contract serial number; encrypting event information using the sub-encryption key; generating a sub-calculation key according to the main encryption key, the area number and the contract serial number; calculating a message authentication code using the sub-calculation key, a random number of the roadside unit and the encrypted event information to obtain an authentication code; sending the encrypted event information and the authentication code to the vehicle-mounted unit; the vehicle-mounted unit uses a key to calculate a message authentication code for the encrypted event information to verify the legitimacy of the data; if it is legal, the vehicle-mounted unit decrypts the encrypted event information, obtains the event information and broadcasts it. The method provided by the present invention can efficiently and safely realize the release of event information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent transportation, and particularly to a method and system for encrypting and transmitting event information between a roadside unit and an on-vehicle unit. Background Art

[0002] In 2019, the provincial boundary toll stations on expressways were cancelled, and an electronic toll collection (ETC) gantry system was set up to charge vehicles in sections. ETC vehicles use an on-board unit (OBU) as a passing medium and a toll collection medium, and manual semi-automatic toll collection (MTC) vehicles use a 5.8 GHz composite passing card (CPC card) as a passing medium to achieve "sectional charging and exit toll collection", which greatly improves the expressway passing efficiency, reduces labor costs, and saves fuel consumption. As of the first quarter of 2024, China has built a total of 20,704 ETC gantries and 42,518 ETC dedicated lanes, and the number of issued ETC users has reached 223 million.

[0003] In recent years, with the further development of intelligent transportation, it has been proposed to deepen the expansion application of the expressway electronic toll collection system (ETC) and promote the construction of facilities such as vehicle-road collaboration. Among them, the research on the ETC event information release scheme is relatively less. Summary of the Invention

[0004] In view of this, the embodiments of the present invention provide a method and system for encrypting and transmitting event information between a roadside unit and an on-vehicle unit to eliminate or improve one or more defects existing in the prior art and solve the problems of low transmission efficiency and low security of the existing ETC event information release scheme.

[0005] On the one hand, the present invention provides a method for encrypting and transmitting event information between a roadside unit and an on-vehicle unit. The method is implemented based on ETC transactions and is executed in roadside equipment. The method includes the following steps:

[0006] Broadcast a beacon service table to the on-vehicle unit and receive the vehicle service table replied by the on-vehicle unit to obtain the area number and contract serial number of the on-vehicle device;

[0007] Call the consumption security access module to generate a sub-encryption key according to the main encryption key, the area number and the contract serial number; call the consumption security access module to encrypt the event information with the sub-encryption key to generate encrypted event information;

[0008] Invoke the consumption security access module to generate a sub-computation key for message authentication code calculation based on the master encryption key, the area number, and the contract serial number; invoke the consumption security access module to calculate the message authentication code using the sub-computation key, the random number of the roadside device, and the encrypted event information to obtain the authentication code; wherein, the random number of the roadside device is the random number used for encrypting the vehicle information of the on-vehicle device in obtaining the security information service during the ETC transaction.

[0009] Send the encrypted event information and the authentication code to the on-vehicle device; the on-vehicle device calculates the message authentication code for the encrypted event information using its key to obtain a temporary authentication code; compare the temporary authentication code with the authentication code to verify the data legality; in the case of legality, the on-vehicle device decrypts the encrypted event information using its key to obtain the event information and broadcasts the event information.

[0010] In some embodiments of the present invention, invoking the consumption security access module to generate a sub-encryption key according to the master encryption key, the area number, and the contract serial number further includes:

[0011] Connect the master encryption key with the high 4 bytes of two area numbers, and connect the connection result with the contract serial number to obtain a data string;

[0012] Encrypt the data string using the SM4 algorithm to obtain the sub-encryption key.

[0013] In some embodiments of the present invention, invoking the consumption security access module to encrypt the event information using the sub-encryption key to generate the encrypted event information further includes:

[0014] Represent the event information in a preset encoding format;

[0015] Use the SM4 algorithm with the sub-encryption key as the key to encrypt the event information in the preset encoding format to obtain the encrypted event information.

[0016] In some embodiments of the present invention, invoking the consumption security access module to generate a sub-computation key for message authentication code calculation based on the master encryption key, the area number, and the contract serial number further includes:

[0017] Connect the master encryption key with the high 4 bytes of two area numbers, and connect the connection result with the contract serial number to obtain a data string;

[0018] Use the SM4 algorithm to encrypt the data string to obtain the sub-computation key.

[0019] In some embodiments of the present invention, both the encryption of the event information using the sub-encryption key and the decryption of the encrypted event information by the vehicle-mounted device using its key employ the SM4-based counter block cipher algorithm.

[0020] In some embodiments of the present invention, the encryption of the event information using the sub-encryption key further includes:

[0021] Encrypting each count variable to obtain a ciphertext output variable;

[0022] Performing an exclusive OR operation on the plaintext data block and the corresponding ciphertext output variable to obtain a ciphertext variable; repeating this step to obtain a sequence of ciphertext variables;

[0023] Selecting the value of the preset number of bits of the ciphertext output variable at the leftmost as the screening output variable;

[0024] Performing an exclusive OR operation on the last plaintext data block and the screening output variable to obtain a final ciphertext variable;

[0025] Concatenating all the ciphertext variables and the final ciphertext variable to obtain the final ciphertext data.

[0026] In some embodiments of the present invention, the decryption of the encrypted event information by the vehicle-mounted device using its key further includes:

[0027] Encrypting each count variable to obtain a ciphertext output variable;

[0028] Performing an exclusive OR operation on the ciphertext data block and the corresponding ciphertext output variable to obtain a plaintext variable; repeating this step to obtain a sequence of plaintext variables;

[0029] Selecting the value of the preset number of bits of the ciphertext output variable at the leftmost as the screening output variable;

[0030] Performing an exclusive OR operation on the last ciphertext data block and the screening output variable to obtain a final plaintext variable;

[0031] Concatenating all the plaintext variables and the final plaintext variable to obtain the final plaintext data.

[0032] On the other hand, the present invention provides an event information encryption transmission system between a roadside unit and a vehicle-mounted unit, the system including:

[0033] A parameter acquisition module, configured to broadcast a beacon service table from a roadside device to a vehicle-mounted unit and receive a vehicle service table replied by the vehicle-mounted unit, so as to obtain the area number and contract serial number of the vehicle-mounted device;

[0034] A data encryption module, which is used for the roadside device to call the consumption security access module to generate a sub-encryption key according to the main encryption key, the area number and the contract serial number; and use the sub-encryption key to encrypt the event information to generate encrypted event information;

[0035] A data verification module, which is used for the roadside device to call the consumption security access module to generate a sub-calculation key for message authentication code calculation according to the main encryption key, the area number and the contract serial number; and use the sub-calculation key, the random number of the roadside device, and the encrypted event information to calculate the message authentication code to obtain an authentication code; wherein, the random number of the roadside device is the random number used for encrypting the vehicle information of the on-vehicle device in obtaining the security information service in the ETC transaction;

[0036] A data decryption module, which is used for the roadside device to send the encrypted event information and the authentication code to the on-vehicle device; the on-vehicle device uses its key to calculate the message authentication code for the encrypted event information to obtain a temporary authentication code; compare the temporary authentication code with the authentication code to verify the data legality; in the case of legality, the on-vehicle device uses its key to decrypt the encrypted event information to obtain the event information;

[0037] A broadcast module, which is used for the on-vehicle device to broadcast the decrypted time information.

[0038] On the other hand, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of any one of the methods mentioned above are implemented.

[0039] On the other hand, the present invention also provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of any one of the methods mentioned above are implemented.

[0040] The beneficial effects of the present invention are at least:

[0041] The present invention provides a method and system for encrypting and transmitting event information between a roadside unit and a vehicle-mounted unit, which broadcasts a beacon service table to the vehicle-mounted unit to obtain the area number and contract serial number of the vehicle-mounted device; calls a consumption security access module to generate a sub-encryption key according to the main encryption key, area number and contract serial number; encrypts the event information by using the sub-encryption key; generates a sub-computation key for message authentication code calculation according to the main encryption key, area number and contract serial number; calculates the message authentication code by using the sub-computation key, the random number of the roadside device and the encrypted event information to obtain the authentication code; sends the encrypted event information and the authentication code to the vehicle-mounted device; the vehicle-mounted device calculates the message authentication code by using the key for the encrypted event information to verify the data legality; in the case of being legal, the vehicle-mounted device decrypts the encrypted event information, and after obtaining the event information, it makes a broadcast. The method provided by the present invention can efficiently and securely publish event information.

[0042] Additional advantages, objects, and features of the present invention will be partly described below, and will partly become apparent to those of ordinary skill in the art after studying the following text, or can be learned from the practice of the present invention. The objects and other advantages of the present invention can be realized and obtained by the structure specifically pointed out in the specification and the drawings.

[0043] Those skilled in the art will understand that the objects and advantages that can be achieved by the present invention are not limited to the above specifically described, and the above and other objects that the present invention can achieve will be more clearly understood according to the following detailed description. Brief Description of the Drawings

[0044] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application, and do not constitute a limitation to the present invention. In the drawings:

[0045] Figure 1 It is a schematic diagram of the steps of the method for encrypting and transmitting event information between a roadside unit and a vehicle-mounted unit in an embodiment of the present invention.

[0046] Figure 2 It is a schematic flowchart of the method for encrypting and transmitting event information between a roadside unit and a vehicle-mounted unit in an embodiment of the present invention.

[0047] Figure 3 It is the encryption and decryption process based on the SM4 counter block cipher algorithm in an embodiment of the present invention. Detailed Embodiments

[0048] To make the objects, technical solutions, and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in combination with the embodiments and the drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but do not limit the present invention.

[0049] Here, it should also be noted that in order to avoid obscuring the present invention with unnecessary details, only the structures and / or processing steps closely related to the solution according to the present invention are shown in the drawings, while other details less relevant to the present invention are omitted.

[0050] It should be emphasized that the term "comprising / including" as used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.

[0051] Here, it should also be noted that unless otherwise specified, the term "connection" in this document can refer not only to direct connection, but also to indirect connection with intermediaries.

[0052] In the following, embodiments of the present invention will be described with reference to the drawings. In the drawings, the same reference numerals represent the same or similar components, or the same or similar steps.

[0053] It should be emphasized here that the step labels mentioned below do not limit the order of the steps. Instead, it should be understood that the steps can be executed in the order mentioned in the embodiments, or different from the order in the embodiments, or several steps can be executed simultaneously.

[0054] To solve the problems of low transmission efficiency and low security in the existing ETC event information publishing scheme, the present invention proposes an encrypted transmission method for event information between a roadside unit and an on-vehicle unit, as Figure 1 shown. This method is implemented based on ETC transactions, executed in roadside devices, and includes the following steps S101 to S104:

[0055] Step S101: Broadcast a beacon service table to the on-vehicle unit and receive the vehicle service table replied by the on-vehicle unit to obtain the area number and contract serial number of the on-vehicle device.

[0056] Step S102: Invoke the consumption security access module to generate a sub-encryption key according to the master encryption key, area number and contract serial number; invoke the consumption security access module to encrypt the event information with the sub-encryption key to generate encrypted event information.

[0057] Step S103: Invoke the consumption security access module to generate a sub-computation key for message authentication code calculation according to the master encryption key, area number and contract serial number; invoke the consumption security access module to calculate the message authentication code using the sub-computation key, the random number of the roadside device, and the encrypted event information to obtain the authentication code. Among them, the random number of the roadside device is the random number used for encrypting the vehicle information of the on-vehicle device in obtaining the security information service in the ETC transaction.

[0058] Step S104: Send the encrypted event information and the authentication code to the in-vehicle device; the in-vehicle device calculates the message authentication code for the encrypted event information using its key to obtain a temporary authentication code; compare the temporary authentication code with the authentication code to verify the data legality; in the case of legality, the in-vehicle device decrypts the encrypted event information using its key to obtain the event information and broadcasts the event information.

[0059] For better understanding, first, the design concept of the present invention will be described.

[0060] The present invention analyzes and researches based on the principle of minimizing the changes to the existing toll collection system and ETC transaction process. The batch data interaction between the Road Side Unit (RSU) and the On board Unit (OBU) occurs in the ICC-RSE consumption transaction stage. Among them, ICC-RSE is a control and communication module for the road side device RSE in the intelligent transportation system. Adding an event information publishing process has the least impact on the three interaction processes in this stage. The event information to be published relies on the TransferChannel service primitive to carry. The TransferChannel service primitive provides a channel transmission function for the communication between the RSU and the OBU. In the ETC application, the TransferChannel primitive can provide a transparent channel for operating the OBE-SAM. Among them, OBE-SAM is a security access control module for the in-vehicle device OBE and related systems, which is used to ensure the security of communication and data transmission inside the vehicle.

[0061] Based on the considerations of system security and data security, necessary protection measures should be taken for the event information to be published. The main security protection means of the ETC system are as follows:

[0062] Access permission: Permission credentials should be provided to access data, and access is only allowed after the OBE verification passes.

[0063] Information authentication: A set of authentication codes is transmitted together with the key data, and the data is determined to be legal only after the RSE verification.

[0064] Encryption protection: Encrypt the data during the transmission process.

[0065] Based on the above description, the event information publishing of the present invention relies on the existing ETC transaction to implement, and only needs to encrypt and protect the event information and authenticate the transmitted data.

[0066] As Figure 2 shown, it is the processing flow chart of the event information encryption transmission method between the road side unit and the in-vehicle unit.

[0067] In step S101, the roadside device first broadcasts the Beacon Service Table (BST) to the on-vehicle unit, and the on-vehicle unit OBU replies with the Vehicle Station Table (VST). The area number and contract serial number of the on-vehicle device OBU are obtained from the VST. Exemplarily, the area number is denoted as areaNumber, and the contract serial number is denoted as contractSerialNumber.

[0068] In step S102, the roadside device RSE calls the Purchase Secure Access Module (PSAM). Among them, keys that may be required in the consumption process, such as consumption keys, external authentication keys, and OBU vehicle information decryption keys, are usually stored in the PSAM, and are generally placed in the card-writing peripheral devices of the toll collection system, such as the antenna control box of the ETC toll collection system and the card reader of the MTC toll collection system. The sub-encryption key is generated by using the obtained master encryption key, as well as the area number and contract serial number obtained in step S101.

[0069] In some embodiments, the method for generating the sub-encryption key includes the following steps:

[0070] Connect the master encryption key with the high 4 bytes of two area numbers, connect the connection result with the contract serial number to obtain a data string; encrypt the data string using the SM4 algorithm to obtain the sub-encryption key.

[0071] It can be expressed by the algorithm as:

[0072] subEncryptKey = SM4(SM4(MasterEncryptKey, areaNumber (high 4 bytes) || areaNubmer (high 4 bytes)), contractSerialNumber || contractSerialNumber).

[0073] Among them, subEncryptKey represents the sub-encryption key; SM4() represents the SM4 algorithm; MasterEncryptKey represents the master encryption key; areaNumber represents the area number; contractSerialNumber represents the contract serial number.

[0074] After generating the sub-encryption key, the roadside device calls the Purchase Secure Access Module again, and encrypts the event information by using the sub-encryption key to generate the encrypted event information.

[0075] In some embodiments, the method for generating the encrypted event information includes the following steps:

[0076] Represent the event information in the GB2312-80 encoding format; use the SM4 algorithm with the sub-encryption key as the key to encrypt the event information encoded in GB2312-80 to obtain the encrypted event information. Among them, GB2312-80 is a Chinese character encoding standard, usually used to represent simplified Chinese characters.

[0077] It can be expressed by the algorithm as:

[0078] encryptData = SM4(subEncryptKey, event information GB2312-80 encoding).

[0079] Among them, encryptData represents the encrypted event information; SM4() represents the SM4 algorithm; subEncryptKey represents the sub-encryption key.

[0080] In step S103, the roadside device calls the consumption security access module to generate a sub-computation key for message authentication code calculation based on the master encryption key, area number, and contract serial number. Among them, the Message Authentication Code (MAC) is a technology used to verify the integrity and authenticity of a message. The MAC can generate a short fixed-length value by performing algorithmic processing on the message and the key, and this value is called the MAC value. During message transmission, the sender usually appends the MAC value to the end of the message and sends it to the receiver. The receiver processes the received message and the key through the same algorithm and calculates the MAC value, and then compares the calculated MAC value with the received MAC value. If the two are equal, it means that the message has not been tampered with or forged.

[0081] In some embodiments, the method for generating the sub-computation key includes the following steps:

[0082] Connect the master encryption key with the high 4 bytes of two area numbers, connect the connection result with the contract serial number to obtain a data string; use the SM4 algorithm to encrypt the data string to obtain the sub-computation key.

[0083] It can be expressed by the algorithm as:

[0084] subMACKey = SM4(SM4(MasterEncryptKey, areaNumber (high 4 bytes) || areaNubmer (high 4 bytes)), contractSerialNumber || contractSerialNumber).

[0085] Among them, subMACKey represents the sub - calculation key; SM4() represents the SM4 algorithm; MasterEncryptKey represents the master encryption key; areaNumber represents the area number; contractSerialNumber represents the contract serial number.

[0086] The roadside device calls the consumption security access module again, re - using the random number for encrypting vehicle information of the in - vehicle device in the GetSecure service, as well as the sub - calculation key and the encrypted event information to calculate the message authentication code, and obtains the authentication code. Among them, the GetSecure service is a service for obtaining security information. In the intelligent transportation system, it is usually used to provide the parameters and data required for vehicle security authentication and encryption.

[0087] In some embodiments, the algorithm of the message authentication code can be expressed as:

[0088] authenticator = SM4(subMACKey, RandRSE, encryptData).

[0089] Among them, authenticator represents the authentication code; SM4() represents the SM4 algorithm; subMACKey represents the sub - calculation key; RandRSE represents the roadside device random number; encryptData represents the encrypted event information.

[0090] In step S104, the roadside device sends the encrypted event information and the authentication code to the in - vehicle device.

[0091] In some embodiments, the roadside device uses the TransferChannel service to send the encrypted event information and the authentication code to the in - vehicle device. In the intelligent transportation system, the TransferChannel service is a service primitive for data transmission between the roadside device and the in - vehicle device.

[0092] The in - vehicle device uses its key to calculate the message authentication code for the encrypted event information, obtaining a temporary authentication code. The in - vehicle device compares the temporary authentication code with the received authentication code. If the two are equal, it means the data is legal; if the two are not equal, the data is illegal.

[0093] In the legal case, the in - vehicle device uses its key to decrypt the encrypted event information. Exemplarily, it decrypts using the SM4 algorithm to obtain the decrypted event information, and then the in - vehicle device broadcasts the event information.

[0094] In some embodiments, the decryption algorithm using the SM4 algorithm can be expressed as:

[0095] decryptData = SM4-1 (EncryptKey, encryptData).

[0096] Among them, decryptData represents the decrypted event information; EncryptKey represents the key of the vehicle-mounted device; encryptData represents the encrypted event information.

[0097] In some embodiments, the vehicle-mounted device calls a text-to-speech (TTS) module to perform voice broadcast of the decrypted event information.

[0098] In some embodiments, the encryption of the event information using the sub-encryption key in step S102 and the decryption of the encrypted event information by the vehicle-mounted device using its key in step S104 both adopt the SM4-based counter (CTR) block cipher algorithm. Specifically, as Figure 3 shown:

[0099] Input variable definition:

[0100] Group the plaintext data into a sequence composed of P 1 , P 2 ,..., P n . Among them, P 1 , P 2 ,..., P n-1 are all 128 bits, and P n is m bits;

[0101] Key K, K = OBU_EK02 Decentralized_key ;

[0102] A sequence composed of n counting variables T 1 , T 2 ,..., T n-1 , T n . Each variable is 128 bits.

[0103] Intermediate result definition:

[0104] A sequence composed of n ciphertext output variables X 1 , X 2 ,..., X n . Each variable is 128 bits;

[0105] An m-bit ciphertext output variable Z.

[0106] Output variable definition:

[0107] A sequence composed of n ciphertext variables C 1 , C 2 ,..., C n . Among them, C1 , C 2 ,..., C n-1 are all 128 bits, and C n is m bits.

[0108] Based on the above definitions, the encryption process can be expressed as follows:

[0109] Encrypt each count variable to obtain a ciphertext output variable, and the expression is as shown in formula (1):

[0110] X i = E K (T i ), i = 1, 2,..., n; (1)

[0111] where X i represents the i-th ciphertext output variable; E K (·) represents encryption with the key K; T i represents the i-th count variable.

[0112] Perform an exclusive OR operation on the plaintext data group and the corresponding ciphertext output variable to obtain a ciphertext variable; repeat this step to obtain a sequence of ciphertext variables, and the expression is as shown in formula (2):

[0113]

[0114] where C i represents the i-th ciphertext variable sequence; P u represents the i-th plaintext data group; X i represents the i-th ciphertext output variable; represents the exclusive OR operation.

[0115] Select the value of the leftmost preset number of bits of the ciphertext output variable as the screening output variable, and the expression is as shown in formula (3):

[0116] Z = X n ~m; (3)

[0117] where Z represents the value of the leftmost preset number m bits of the ciphertext output variable X n .

[0118] Perform an exclusive OR operation on the last plaintext data group and the screening output variable to obtain the final ciphertext variable, and the expression is as shown in formula (4):

[0119]

[0120] where C n represents the n-th ciphertext variable (the final ciphertext variable); P nDenote the nth plaintext data packet; Z denotes the value of the leftmost m bits of the preset number of password output variables.

[0121] Concatenate all ciphertext variables and the final ciphertext variable, that is, concatenate C 1 , C 2 ,..., C n-1 , C n to obtain the final ciphertext data.

[0122] Based on the above definitions, the decryption process can be expressed as:

[0123] Encrypt each counting variable to obtain a password output variable, and the expression is as shown in formula (5):

[0124] X i = E K (T i ), i = 1, 2,..., n; (5)

[0125] where, X i denotes the ith password output variable; E K (·) denotes encryption with the key K; T i denotes the ith counting variable.

[0126] Perform an exclusive OR operation on the ciphertext data packet and the corresponding password output variable to obtain a plaintext variable; repeat this step to obtain a sequence of plaintext variables, and the expression is as shown in formula (6):

[0127]

[0128] where, P i denotes the ith plaintext data packet; C i denotes the ith ciphertext variable sequence; X i denotes the ith password output variable; denotes the exclusive OR operation.

[0129] Select the value of the leftmost m bits of the preset number of password output variables as the screening output variable, and the expression is as shown in formula (7):

[0130] Z = X n ~ m; (7)

[0131] where, Z denotes the value of the leftmost m bits of the preset number of password output variables X n .

[0132] Perform an exclusive OR operation on the last ciphertext data packet and the screening output variable to obtain the final plaintext variable, and the expression is as shown in formula (8):

[0133]

[0134] Among them, P n represents the nth plaintext data packet (final plaintext variable); C n represents the nth ciphertext variable; Z represents the value of the leftmost preset number m-bit password output variable.

[0135] Concatenate all plaintext variables and the final plaintext variable, that is, concatenate P 1 , P 2 ,..., P n-1 , P n to obtain the final plaintext data.

[0136] Corresponding to the method for encrypting and transmitting event information between the roadside unit and the on-vehicle unit, the present invention also provides a system for encrypting and transmitting event information between the roadside unit and the on-vehicle unit, and the system includes:

[0137] A parameter acquisition module, configured to broadcast a beacon service table from the roadside device to the on-vehicle unit, and receive the vehicle service table replied by the on-vehicle unit, so as to obtain the area number and contract serial number of the on-vehicle device.

[0138] A data encryption module, configured to call a consumption security access module by the roadside device, generate a sub-encryption key according to the main encryption key, area number and contract serial number; encrypt the event information by using the sub-encryption key to generate encrypted event information.

[0139] A data verification module, configured to call a consumption security access module by the roadside device, generate a sub-calculation key for message authentication code calculation according to the main encryption key, area number and contract serial number; calculate the message authentication code by using the sub-calculation key, the random number of the roadside device, and the encrypted event information to obtain an authentication code. Among them, the random number of the roadside device is the random number used for encrypting the vehicle information of the on-vehicle device in obtaining the security information service in the ETC transaction.

[0140] A data decryption module, configured to send the encrypted event information and the authentication code from the roadside device to the on-vehicle device; the on-vehicle device calculates the message authentication code for the encrypted event information by using its key to obtain a temporary authentication code; compare the temporary authentication code with the authentication code to verify the data legality; in the case of legality, the on-vehicle device decrypts the encrypted event information by using its key to obtain the event information.

[0141] A broadcast module, configured to broadcast the decrypted time information by the on-vehicle device.

[0142] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the method for encrypting and transmitting event information between the roadside unit and the on-vehicle unit are implemented.

[0143] Correspondingly to the above method, the present invention further provides a device, which includes a computer device. The computer device includes a processor and a memory. Computer instructions are stored in the memory. The processor is configured to execute the computer instructions stored in the memory. When the computer instructions are executed by the processor, the device implements the steps of the method described above.

[0144] An embodiment of the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of the foregoing edge computing server deployment method. The computer-readable storage medium may be a tangible storage medium, such as a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, floppy disk, hard disk, removable storage disk, CD-ROM, or any other form of storage medium known in the technical field.

[0145] In summary, the present invention provides a method and system for encrypting and transmitting event information between a roadside unit and an in-vehicle unit, which broadcasts a beacon service table to the in-vehicle unit to obtain the area number and contract serial number of the in-vehicle device; calls a consumption security access module to generate a sub-encryption key according to the master encryption key, area number, and contract serial number; encrypts the event information using the sub-encryption key; generates a sub-computation key for message authentication code calculation according to the master encryption key, area number, and contract serial number; calculates the message authentication code using the sub-computation key, the random number of the roadside device, and the encrypted event information to obtain an authentication code; sends the encrypted event information and the authentication code to the in-vehicle device; the in-vehicle device calculates the message authentication code for the encrypted event information using the key to verify the data legality; in the case of being legal, the in-vehicle device decrypts the encrypted event information to obtain the event information and then broadcasts it. The method provided by the present invention can efficiently and securely publish event information.

[0146] Those of ordinary skill in the art should understand that the various exemplary components, systems, and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software, or a combination of both. Specifically, whether to implement in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application-specific integrated circuit (ASIC), appropriate firmware, a plug-in, a functional card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium or transmitted through a data signal carried in a carrier wave on a transmission medium or a communication link.

[0147] It should be clear that the present invention is not limited to the specific configurations and processes described above and illustrated in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and illustrated as examples. However, the method process of the present invention is not limited to the specific steps described and illustrated, and those skilled in the art can make various changes, modifications, and additions, or change the order between steps after understanding the spirit of the present invention.

[0148] In the present invention, features described and / or illustrated for one embodiment can be used in the same or a similar manner in one or more other embodiments, and / or combined with the features of other embodiments or replace the features of other embodiments.

[0149] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. For those skilled in the art, various changes and modifications can be made to the embodiments of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for encrypting and transmitting event information between a roadside unit and an onboard unit, characterized in that: The method is implemented based on ETC transactions and is executed in a roadside unit. The method comprises the following steps: broadcasting a beacon service list to the vehicle-mounted unit, and receiving a vehicle service list replied by the vehicle-mounted unit to obtain the area number and contract serial number of the vehicle-mounted unit; Calling a consumer security access module to generate a sub-encryption key according to a master encryption key, the region number and the contract serial number; calling the consumer security access module to encrypt event information using the sub-encryption key to generate encrypted event information; The consumer security access module is called to generate a sub-computation key for message authentication code calculation according to the master encryption key, the area number and the contract serial number; the consumer security access module is called to perform message authentication code calculation using the sub-computation key, the random number of the roadside unit and the encrypted event information to obtain an authentication code; wherein the random number of the roadside unit is a random number used for encrypting vehicle information of the on-board unit in obtaining security information service in ETC transactions; The encrypted event information and the identification code are sent to the on-board unit; the on-board unit uses its key to perform message authentication code calculation on the encrypted event information to obtain a temporary identification code; the temporary identification code is compared with the identification code to verify the legitimacy of the data; if it is legal, the on-board unit uses its key to decrypt the encrypted event information to obtain the event information, and broadcasts the event information.

2. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 1, characterized in that: Calling a consumer security access module to generate a sub-encryption key according to a master encryption key, the region number and the contract serial number, further comprising: Concatenate the master encryption key with the upper 4 bytes of the two area numbers, and concatenate the concatenation result with the contract serial number to obtain a data string; The data string is encrypted using the SM4 algorithm to obtain the sub-encryption key.

3. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 1, characterized in that: Calling the consumer security access module, encrypting the event information using the sub-encryption key, and generating encrypted event information, further comprising: Representing the event information according to a preset coding format; The event information in a preset coding format is encrypted using the SM4 algorithm with the sub-encryption key as a key to obtain the encrypted event information.

4. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 1, characterized in that: Calling the consumer security access module to generate a sub-computation key for message authentication code calculation according to the master encryption key, the area number and the contract sequence number, further comprising: Concatenate the master encryption key with the upper 4 bytes of the two area numbers, and concatenate the concatenation result with the contract serial number to obtain a data string; The data string is encrypted using the SM4 algorithm to obtain the sub-computation key.

5. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 1, characterized in that: The encrypting of the event information by using the sub-encryption key and the decrypting of the encrypted event information by the on-board unit by using its key both adopt a counter block cipher algorithm based on SM4.

6. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 5, characterized in that: Encrypting the event information using the sub-encryption key also includes: Encrypt each counting variable to obtain a password output variable; Perform XOR operation on the plaintext data group and the corresponding password output variable to obtain the ciphertext variable; repeat this step to obtain the ciphertext variable sequence; Select the value of the leftmost preset number of password output variables as the screening output variable; Perform an XOR operation on the last plaintext data group and the screening output variable to obtain a final ciphertext variable; All ciphertext variables and the final ciphertext variable are connected in series to obtain the final ciphertext data.

7. The method for encrypting and transmitting event information between a roadside unit and an onboard unit according to claim 6, characterized in that: The on-board unit uses its key to decrypt the encrypted event information, and further includes: Encrypt each counting variable to obtain a password output variable; Perform XOR operation on the ciphertext data group and the corresponding password output variable to obtain the plaintext variable; repeat this step to obtain the plaintext variable sequence; Select the value of the leftmost preset number of password output variables as the screening output variable; Perform an XOR operation on the last ciphertext data group and the screening output variable to obtain a final plaintext variable; All plaintext variables and the final plaintext variable are connected in series to obtain final plaintext data.

8. A system for encrypting and transmitting event information between a roadside unit and an onboard unit, characterized in that: The system comprises: A parameter acquisition module, used for the roadside unit to broadcast a beacon service table to the vehicle-mounted unit, and receive a vehicle service table replied by the vehicle-mounted unit to obtain the area number and contract serial number of the vehicle-mounted unit; A data encryption module is used for the roadside unit to call the consumer security access module, generate a sub-encryption key according to the main encryption key, the area number and the contract serial number; encrypt the event information using the sub-encryption key to generate encrypted event information; A data verification module, used for the roadside unit to call the consumer security access module, generate a sub-computation key for message authentication code calculation according to the master encryption key, the area number and the contract sequence number; use the sub-computation key, the random number of the roadside unit and the encrypted event information to calculate the message authentication code to obtain an authentication code; wherein the random number of the roadside unit is the random number used for encrypting the vehicle information of the on-board unit in the security information service obtained in the ETC transaction; A data decryption module, used for the roadside unit to send the encrypted event information and the authentication code to the vehicle-mounted unit; the vehicle-mounted unit uses its key to perform message authentication code calculation on the encrypted event information to obtain a temporary authentication code; compares the temporary authentication code with the authentication code to verify the legitimacy of the data; if it is legal, the vehicle-mounted unit uses its key to decrypt the encrypted event information to obtain the event information; The broadcast module is used for the vehicle-mounted unit to broadcast the time information obtained by decryption.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instructions are executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Bidirectional authentication-based electronic toll collection system and method

    CN112785734A

  • ETC broadcast information encryption transmission method and system

    CN117041945A