Data transmission method, apparatus, device, medium, and product
By sending data processing commands and performing authentication to the vehicle terminal through dedicated network equipment, the problem of low data transmission efficiency of software in vehicles not yet shipped from the factory is solved, and efficient and secure software data transmission is achieved.
Patent Information
- Application Number
- CN202411744532.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-29
- Publication Date
- 2026-02-24
- Estimated Expiration
- 2044-11-29
AI Technical Summary
In existing technologies, the in-vehicle terminals of vehicles that have not yet left the factory have low transmission efficiency because the vehicle network SIM cards are not registered with real names. When transmitting software data via Bluetooth or wireless networks, the coverage is limited, requiring manual intervention.
The system receives the target user identifier selection input through a dedicated network device, sends data processing instructions to the vehicle terminal, and sends software data after the vehicle terminal verifies the information. The software data is transmitted using the dedicated network device, which includes communication between a dedicated AMF module, a dedicated base station, and a dedicated UPF module, to achieve secure transmission of software data.
It improves the efficiency of software data transmission, reduces human intervention, and ensures the security and privacy of transmission.
Smart Images

Figure CN119544353B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of communication technology, and in particular relates to a data transmission method, apparatus, device, medium and product. Background Technology
[0002] With the accelerated integration of automotive technologies with energy, transportation, and information and communication technologies, electrification, connectivity, and intelligence have become the development trends of the automotive industry. Against this backdrop, the methods of software data processing in vehicles are also changing, shifting from manual connection and processing to automated processing.
[0003] Currently, for vehicles not yet manufactured, the vehicle-to-everything (V2X) SIM cards built into the vehicles are not registered or activated. Software data is typically transmitted to the in-vehicle terminal via Bluetooth or a wireless network, where it is then deployed, upgraded, and maintained. However, transmitting software data via Bluetooth or a wireless network is limited by its coverage area, requiring manual intervention to transfer the data to the vehicle's in-vehicle terminal, resulting in low transmission efficiency. Summary of the Invention
[0004] This application provides a data transmission method, apparatus, device, medium, and product. When a dedicated network device receives a selection input for a target user identifier from a preset user identifier, the dedicated network device sends a data processing instruction to the vehicle terminal corresponding to the target user identifier. If the authentication information sent by the vehicle terminal passes the verification, the dedicated network device sends software data to the vehicle terminal. Based on the dedicated network device transmitting software data to the vehicle terminal, it is only necessary to select the vehicle terminal to be transmitted. After the vehicle terminal passes the verification, the software data can be transmitted, which improves the transmission efficiency.
[0005] In a first aspect, embodiments of this application provide a data transmission method applied to a dedicated network device, wherein the dedicated network device only provides services to a preset vehicle terminal corresponding to a preset user identifier, and the method includes:
[0006] Upon receiving a selection input for the target user identifier, a data processing instruction is sent to the vehicle terminal corresponding to the target user identifier, so that the vehicle terminal can respond to the data processing instruction and obtain authentication information. The preset user identifier includes the target user identifier.
[0007] Receive a first authentication request sent by the vehicle terminal, the first authentication request including authentication information;
[0008] In response to the first authentication request, the authentication information is verified, and if the authentication information meets the first preset conditions, software data is sent to the vehicle terminal.
[0009] In one possible implementation, the dedicated network device includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server; upon receiving a selection input for a target user identifier, it sends a data processing instruction to the vehicular terminal corresponding to the target user identifier, including:
[0010] When the server receives a selection input for the target user identifier, it uses a dedicated AMF module and a dedicated base station to send data processing instructions to the vehicle terminal corresponding to the target user identifier.
[0011] Receive the first authentication request sent by the vehicle terminal, including:
[0012] The server receives the first authentication request sent by the vehicle terminal using a dedicated base station and a dedicated UPF module.
[0013] In response to the first authentication request, the authentication information is verified, and if the authentication information meets the first preset conditions, software data is sent to the vehicle terminal, including:
[0014] In response to the first authentication request, the server verifies the authentication information. If the authentication information meets the first preset conditions, the software data is sent to the vehicle terminal using a dedicated UPF module and a dedicated base station.
[0015] In one possible implementation, the authentication information includes authentication token information; before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier upon receiving a selection input for the target user identifier, the method further includes:
[0016] Receive the second authentication request sent by the vehicle terminal;
[0017] In response to the second authentication request, verify the identity information in the second authentication request;
[0018] If the identity information meets the second preset condition, an authentication token information is generated according to the authentication token generation rules.
[0019] Send authentication token information to the vehicle terminal.
[0020] In one possible implementation, before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier upon receiving a selection input for the target user identifier, the method further includes:
[0021] Receive registration requests sent by the vehicle terminal. The registration request includes at least the registration type, the vehicle terminal's capability information, and the slice parameters.
[0022] If the registration request includes the subscription permanent identifier SUPI, obtain the authentication data corresponding to SUPI;
[0023] Generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule;
[0024] Generate the authentication token and the first key corresponding to the random number according to the second preset generation rule;
[0025] Send an authentication token and a random number to the vehicle terminal so that the vehicle terminal can generate a second key corresponding to the authentication token and the random number according to the second preset generation rule;
[0026] Receive the second key sent by the vehicle-mounted terminal;
[0027] Compare the first key and the second key. If the first key and the second key are the same, obtain the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters.
[0028] Connect the vehicle terminal and dedicated network equipment according to the access policy.
[0029] In one possible implementation, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0030] Receive registration requests sent by the vehicle-mounted terminal, including:
[0031] Using a dedicated base station and a dedicated AMF module, it receives registration requests sent by the vehicle-mounted terminal;
[0032] Send an authentication token and a random number to the vehicle terminal, including:
[0033] Using a dedicated AMF module and a dedicated base station, an authentication token and a random number are sent to the vehicle terminal;
[0034] The second key sent by the vehicle terminal includes:
[0035] The second key sent by the vehicle terminal is received using a dedicated base station and a dedicated AMF module;
[0036] Connecting the vehicle terminal and dedicated network equipment according to the access policy includes:
[0037] Using a dedicated AMF module, the vehicle terminal and dedicated network equipment are connected according to the access policy.
[0038] In one possible implementation, the dedicated network device further includes a dedicated unified data management function (UDM) module;
[0039] Generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule, including:
[0040] Using a dedicated UDM module, an authentication token and a random number are generated according to the first preset generation rule;
[0041] Compare the first key and the second key. If the first key and the second key match, obtain the access policy corresponding to SUPI, registration type, vehicle terminal capability information, and slice parameters, including:
[0042] Using a dedicated AMF module, the first key and the second key are compared. If the first key and the second key are consistent, the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters is obtained from the dedicated UDM module.
[0043] In one possible implementation, the dedicated network device further includes a Dedicated Authentication Service Function (AUSF) module;
[0044] If the registration request includes SUPI, obtain the authentication data corresponding to SUPI, including:
[0045] If the registration request includes SUPI when the dedicated AMF module is used, the authentication data corresponding to SUPI is obtained using the dedicated AMF module and the dedicated UDM module.
[0046] Generate the authentication token and the first key corresponding to the random number according to the second preset generation rule, including:
[0047] Using a dedicated AUSF module, an authentication token and a first key corresponding to a random number are generated according to the second preset generation rule.
[0048] In one possible implementation, the dedicated network device further includes a dedicated unified data warehouse (UDR) module;
[0049] If the registration request includes SUPI, the authentication data corresponding to SUPI is obtained using the dedicated AMF module and the dedicated UDM module, including:
[0050] If the registration request includes SUPI when the dedicated AMF module is used, the authentication data corresponding to SUPI is obtained from the dedicated UDR module using the dedicated AMF module and the dedicated UDM module.
[0051] In one possible implementation, after obtaining the access policy corresponding to SUPI, registration type, vehicle terminal capability information, and slice parameters, provided that the first key and the second key are consistent, the method further includes:
[0052] Generate the target user identifier corresponding to SUPI;
[0053] Send the target user identifier to the vehicle terminal;
[0054] Connecting the vehicle terminal and dedicated network equipment according to the access policy includes:
[0055] Upon receiving a response from the vehicle-mounted terminal, the vehicle-mounted terminal and the dedicated network equipment are connected according to the access policy.
[0056] In one possible implementation, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0057] Generate the target user identifier corresponding to SUPI, including:
[0058] Using a dedicated AMF module, the target user identifier corresponding to SUPI is generated;
[0059] Send the target user identifier to the vehicle terminal, including:
[0060] Using a dedicated base station, the target user identifier is sent to the vehicle-mounted terminal;
[0061] Upon receiving a response from the vehicle-mounted terminal, the vehicle-mounted terminal and the dedicated network equipment are connected according to the access policy, including:
[0062] When the response information sent by the vehicle terminal is received using the dedicated AMF module, the vehicle terminal and the dedicated network equipment are connected using the dedicated AMF module according to the access policy.
[0063] In one possible implementation, the registration request includes the target user identifier of the vehicle terminal; before generating the authentication token and random number corresponding to the authentication data according to the first preset generation rule, the method further includes:
[0064] If no SUPI is detected in the registration request, an identity request is sent to the vehicle terminal.
[0065] Receive identity response information sent by the vehicle terminal, the identity response information including SUPI;
[0066] Obtain the authentication data corresponding to SUPI.
[0067] In one possible implementation, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0068] If no SUPI is detected in the registration request, send identity request information to the vehicle terminal, including:
[0069] If the dedicated AMF module does not detect that the registration request includes SUPI, the dedicated base station is used to send identity request information to the vehicle terminal.
[0070] Receive identity response information sent by the vehicle terminal, including:
[0071] Using a dedicated base station and a dedicated AMF module, the system receives identity response information sent by the vehicle-mounted terminal.
[0072] In one possible implementation, the registration request includes the initial user identifier of the vehicle terminal; after obtaining the access policy corresponding to SUPI, registration type, vehicle terminal capability information, and slice parameters, provided that the first key and the second key are consistent, the method further includes:
[0073] Generate the target user identifier corresponding to SUPI;
[0074] Send the target user identifier to the vehicle terminal so that the vehicle terminal can update the initial user identifier to the target user identifier;
[0075] Connecting the vehicle terminal and dedicated network equipment according to the access policy includes:
[0076] Upon receiving a response from the vehicle-mounted terminal, the vehicle-mounted terminal and the dedicated network equipment are connected according to the access policy.
[0077] Secondly, embodiments of this application provide a data transmission method applied to an in-vehicle terminal, comprising:
[0078] The system receives data processing instructions sent by a dedicated network device. The data processing instructions are sent by the dedicated network device when it receives a selection input for the target user identifier. The dedicated network device only provides services to the preset vehicle terminal corresponding to the preset user identifier. The preset user identifier includes the target user identifier.
[0079] In response to data processing instructions, obtain authentication information;
[0080] Send a first authentication request to a dedicated network device. The first authentication request includes authentication information and is used to instruct the dedicated network device to verify the authentication information. If the authentication information meets the first preset conditions, send software data to the vehicle terminal.
[0081] Receive software data sent by dedicated network devices.
[0082] In one possible implementation, data processing instructions are sent by a dedicated network device using a dedicated AMF module and a dedicated base station; software data is sent by a dedicated network device using a dedicated UPF module and a dedicated base station.
[0083] Send a first authentication request to the dedicated network device, including:
[0084] Using a dedicated base station and a dedicated UPF module of a dedicated network device, a first authentication request is sent to the server of the dedicated network device. The dedicated network device responds to the first authentication request and uses the server to verify the authentication information. If the authentication information meets the first preset conditions, the dedicated UPF module and the dedicated base station send software data to the vehicle terminal.
[0085] In one possible implementation, the authentication information includes authentication token information; prior to receiving data processing instructions sent by the dedicated network device, the method further includes:
[0086] Obtain identity information;
[0087] Send a second authentication request to the dedicated network device. The second authentication request includes identity information and is used to instruct the dedicated network device to verify the identity information in the second authentication request. If the identity information meets the second preset conditions, generate authentication token information according to the authentication token generation rules.
[0088] Receive authentication token information sent by dedicated network devices.
[0089] In one possible implementation, before receiving data processing instructions sent by the dedicated network device, the method further includes:
[0090] Send a registration request to the dedicated network device. The registration request includes at least the registration type, the capability information of the vehicle terminal, and the slice parameters. It is used to instruct the dedicated network device to obtain the authentication data corresponding to the SUPI when it detects that the registration request includes SUPI. It generates the authentication token and random number corresponding to the authentication data according to the first preset generation rule, and generates the first key corresponding to the authentication token and random number according to the second preset generation rule.
[0091] Receive authentication tokens and random numbers sent by dedicated network devices;
[0092] Generate the authentication token and the second key corresponding to the random number according to the second preset generation rule;
[0093] A second key is sent to the dedicated network device for comparison with the first and second keys. If the first and second keys match, the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters is obtained, and the vehicle terminal and the dedicated network device are connected according to the access policy.
[0094] In one possible implementation, the authentication token and random number are generated by a dedicated network device using a dedicated UDM module and sent using a dedicated AUSF module, a dedicated AMF module, and a dedicated base station.
[0095] Send a registration request to the dedicated network device, including:
[0096] Using a dedicated base station of a dedicated network device, a registration request is sent to the dedicated AMF module of the dedicated network device. When the dedicated AMF module detects that the registration request includes SUPI, the dedicated AUSF module and the dedicated UDM module are used to obtain the authentication data corresponding to SUPI. The dedicated UDM module generates the authentication token and random number corresponding to the authentication data according to the first preset generation rule. The dedicated AUSF module generates the first key corresponding to the authentication token and random number according to the second preset generation rule.
[0097] Send a second key to a dedicated network device, including:
[0098] Using a dedicated base station of a dedicated network device, a second key is sent to the dedicated AMF module of the dedicated network device. The dedicated network device uses the dedicated AMF module to compare the first key and the second key. If the first key and the second key are consistent, the dedicated UDM module obtains the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters.
[0099] In one possible implementation, after sending the second key to the dedicated network device, the method further includes:
[0100] Receive the target user identifier sent by the dedicated network device;
[0101] A response message is sent to the dedicated network device so that, upon receiving the response message from the vehicle terminal, the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy.
[0102] In one possible implementation, the target user identifier is sent by a dedicated network device using a dedicated base station; sending response information to the dedicated network device includes:
[0103] Using a dedicated base station of a dedicated network device, a response message is sent to the dedicated AMF module of the dedicated network device, so that the dedicated network device can use the dedicated AMF module to connect the vehicle terminal and the dedicated network device according to the access policy.
[0104] In one possible implementation, the vehicle-mounted terminal includes a target user identifier, and the registration request includes the target user identifier; before generating a second key corresponding to the authentication token and the random number according to a second preset generation rule upon receiving an authentication token and a random number sent by a dedicated network device, the method further includes:
[0105] Receive identity request information sent by dedicated network devices;
[0106] Send an identity response message, including a SUPI, to the dedicated network device so that the dedicated network device can obtain the authentication data corresponding to the SUPI.
[0107] In one possible implementation, the identity request information is sent by a dedicated network device using a dedicated base station; sending identity response information to the dedicated network device includes:
[0108] Using a dedicated base station of a dedicated network device, identity response information is sent to a dedicated AMF module of the dedicated network device.
[0109] In one possible implementation, the vehicle terminal includes an initial user identifier, and the registration request includes the initial user identifier; after sending the second key to the dedicated network device, the method further includes:
[0110] Receive the target user identifier sent by the dedicated network device;
[0111] Update the initial user identifier in the vehicle terminal to the target user identifier;
[0112] A response message is sent to the dedicated network device so that, upon receiving the response message from the vehicle terminal, the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy.
[0113] Thirdly, embodiments of this application provide a data transmission device applied to a dedicated network device, which only provides services to a preset vehicle terminal corresponding to a preset user identifier. The method includes:
[0114] The sending module is used to send a data processing instruction to the vehicle terminal corresponding to the target user identifier when a selection input for the target user identifier is received, so that the vehicle terminal can respond to the data processing instruction and obtain authentication information. The preset user identifier includes the target user identifier.
[0115] The receiving module is used to receive the first authentication request sent by the vehicle terminal, the first authentication request including authentication information;
[0116] The verification module is used to verify the authentication information in response to the first authentication request, and send software data to the vehicle terminal if the authentication information meets the first preset conditions.
[0117] Fourthly, embodiments of this application provide a data transmission device applied to an in-vehicle terminal, comprising:
[0118] The receiving module is used to receive data processing instructions sent by the dedicated network device. The data processing instructions are sent by the dedicated network device when it receives the selection input of the target user identifier. The dedicated network device only provides services to the preset vehicle terminal corresponding to the preset user identifier. The preset user identifier includes the target user identifier.
[0119] The acquisition module is used to obtain authentication information in response to data processing instructions;
[0120] The sending module is used to send a first authentication request to a dedicated network device. The first authentication request includes authentication information and is used to instruct the dedicated network device to verify the authentication information. If the authentication information meets the first preset conditions, the module sends software data to the vehicle terminal.
[0121] The receiving module is also used to receive software data sent by dedicated network devices.
[0122] Fifthly, embodiments of this application provide an electronic device, the device comprising:
[0123] Processor and memory storing computer program instructions;
[0124] A method for transmitting data that enables any of the above-mentioned features when a processor executes computer program instructions.
[0125] Sixthly, embodiments of this application provide a computer storage medium on which computer program instructions are stored, and a method for transmitting data that implements any of the above-mentioned methods when the computer program instructions are executed by a processor.
[0126] In a seventh aspect, embodiments of this application provide a computer program product, characterized in that, when the instructions in the computer program product are executed by the processor of an electronic device, the electronic device is able to execute any of the above-mentioned data transmission methods.
[0127] This application discloses a data transmission method, apparatus, device, medium, and product. The method is applied to a dedicated network device that provides services only to a preset vehicle-mounted terminal corresponding to a preset user identifier. The method includes: upon receiving a selection input for a target user identifier, sending a data processing instruction to the vehicle-mounted terminal corresponding to the target user identifier, so that the vehicle-mounted terminal can obtain authentication information in response to the data processing instruction. The preset user identifier includes the target user identifier. The method also includes receiving a first authentication request sent by the vehicle-mounted terminal, the first authentication request including authentication information; and in response to the first authentication request, verifying the authentication information. If the authentication information meets a first preset condition, software data is sent to the vehicle-mounted terminal. Thus, when the dedicated network device receives a selection input for a target user identifier from the preset user identifiers, the dedicated network device sends a data processing instruction to the vehicle-mounted terminal corresponding to the target user identifier. If the authentication information sent by the vehicle-mounted terminal passes verification, the dedicated network device sends software data to the vehicle-mounted terminal. Based on the dedicated network device transmitting software data to the vehicle-mounted terminal, only the vehicle-mounted terminal to be transmitted needs to be selected, and the software data can be transmitted after the vehicle-mounted terminal passes verification, thus improving transmission efficiency. Attached Figure Description
[0128] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0129] Figure 1 This is a schematic flowchart of a data transmission method provided in one embodiment of this application;
[0130] Figure 2 This is a flowchart illustrating a data transmission method provided in another embodiment of this application;
[0131] Figure 3 This is a schematic flowchart of a data transmission method provided in another embodiment of this application;
[0132] Figure 4 This is a schematic flowchart of a data transmission method provided in another embodiment of this application;
[0133] Figure 5 This is a schematic flowchart of a data transmission method provided in another embodiment of this application;
[0134] Figure 6 This is a schematic flowchart of a data transmission method provided in another embodiment of this application;
[0135] Figure 7 This is an architecture diagram of a dedicated network device provided in another embodiment of this application;
[0136] Figure 8 This is a schematic diagram of the structure of a data transmission device applied to a dedicated network device according to another embodiment of this application;
[0137] Figure 9 This is a schematic diagram of the structure of a data transmission device applied to an in-vehicle terminal provided in another embodiment of this application;
[0138] Figure 10 This is a schematic diagram of the structure of an electronic device provided in another embodiment of this application. Detailed Implementation
[0139] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0140] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes said element.
[0141] With the accelerated integration of automotive technologies with energy, transportation, and information and communication technologies, electrification, connectivity, and intelligence have become the development trends of the automotive industry. Against this backdrop, the methods of software data processing in vehicles are also changing, shifting from manual connection and processing to automated processing.
[0142] Automated processing includes deployment, upgrades, and maintenance based on Over-The-Air (OTA) technology, Bluetooth, or wireless networks. Taking OTA upgrades as an example, OTA is a technology for remote software upgrades via wireless networks. This technology allows device manufacturers or service providers to remotely send software data over the network, enabling software deployment, updates, and upgrades without requiring users to physically connect their devices to computers or other devices. In the automotive field, OTA upgrades can be used to deploy, update, and upgrade various systems in in-vehicle terminals, such as human-machine interface systems, autonomous driving systems, powertrain systems, and battery systems. Through OTA technology, automakers can quickly fix system defects, improve performance, add new features, and optimize the product experience. The OTA upgrade process includes online detection of the vehicle's current software version, matching the latest software version, downloading new code to the local machine, and performing installation and verification procedures. Compared to traditional recalls and on-site upgrades, OTA upgrades have significant advantages. They not only save time and costs but also improve efficiency and convenience.
[0143] However, OTA (Over-The-Air) updates primarily require the vehicle's built-in connected car SIM card to be registered and activated after the vehicle is sold, enabling automatic software processing. Therefore, it's clear that currently, OTA software processing is only supported after the vehicle has been sold.
[0144] Currently, for vehicles not yet manufactured, the vehicle-to-everything (V2X) SIM cards built into the vehicles are not registered or activated. Software data is typically transmitted to the in-vehicle terminal via Bluetooth or a wireless network, where it is then deployed, upgraded, and maintained. However, transmitting software data via Bluetooth or a wireless network is limited by its coverage area, requiring manual intervention to transfer the data to the vehicle's in-vehicle terminal, resulting in low transmission efficiency.
[0145] To address the problems of existing technologies, embodiments of this application provide a data transmission method, apparatus, device, medium, and product. The data transmission method provided in this application involves a dedicated network device receiving a selection input for a target user identifier from a preset user identifier. The dedicated network device then sends a data processing instruction to the vehicle-mounted terminal corresponding to the target user identifier. If the authentication information sent by the vehicle-mounted terminal passes verification, the dedicated network device sends software data to the vehicle-mounted terminal. By transmitting software data from the dedicated network device to the vehicle-mounted terminal, only the vehicle-mounted terminal to be transmitted needs to be selected; once the vehicle-mounted terminal passes verification, software data transmission can proceed, thus improving transmission efficiency.
[0146] Dedicated network equipment provides network access, essentially offering in-vehicle terminals a private network (like a 5G network) through which they access software data. The main difference between dedicated network equipment and public networks lies in their closed nature and security. Public networks are open to the public and have relatively low security, while dedicated network equipment offers higher security and privacy protection. Furthermore, dedicated network equipment typically requires encryption measures to protect data transmitted over the public internet. Dedicated network equipment is a network designed for a specific user or organization, offering high security and control, and is suitable for applications requiring strict data protection and privacy.
[0147] The data transmission method provided in the embodiments of this application is described below. Figure 1 A schematic flowchart of a data transmission method provided in one embodiment of this application is shown.
[0148] like Figure 1 As shown, the data transmission method provided in this application embodiment includes the following steps.
[0149] S110: Upon receiving a selection input for the target user identifier, the dedicated network device sends a data processing instruction to the vehicle terminal corresponding to the target user identifier.
[0150] Here, the dedicated network equipment only provides services to the preset vehicle-mounted terminal corresponding to the preset user identifier, which includes the target user identifier. The selection input can be the user choosing the target user identifier from multiple preset user identifiers. The preset user identifier includes a 5G-Globally Unique Temporary Identifier (5G-GUTI). The 5G-GUTI is a temporary identifier used to uniquely identify user equipment in the 5G system. Its main purpose is to provide a clear identifier in the 5G network that does not reveal the user's permanent identity, thereby improving communication security and privacy. The target user identifier includes at least one user identifier.
[0151] In some embodiments, data processing instructions include instructions for deploying, upgrading, and maintaining software data.
[0152] In some embodiments, before the dedicated network device sends data processing instructions to the vehicle terminal corresponding to the target user identifier, the dedicated network device compiles the software code into an executable software package, ensuring that the software package has the correct version number and meets the vehicle's hardware and operating system requirements. The software package is then signed and encrypted to ensure its integrity and security, using digital signature and encryption technologies to protect it from unauthorized modification or tampering. Here, the software package includes software data.
[0153] S120, in response to the data processing command, the vehicle terminal obtains authentication information.
[0154] Specifically, authentication information refers to credentials used for authentication, which can be a username (or vehicle identifier) and password, or authentication token information. It is understood that the username (or vehicle identifier) and password serve as identity information.
[0155] In some embodiments, the vehicle identifier includes the vehicle's chassis number, and the password is a pre-set password for the vehicle. The authentication token information can be pre-configured. For example, the authentication token information is distributed by a dedicated network device to the in-vehicle terminal.
[0156] S130, the vehicle terminal sends a first authentication request to the dedicated network device, the first authentication request including authentication information.
[0157] In some embodiments, the vehicle terminal and the dedicated network equipment have established a communication connection in advance.
[0158] S140. The dedicated network device responds to the first authentication request, verifies the authentication information, and sends software data to the vehicle terminal if the authentication information meets the first preset conditions.
[0159] Here, the first preset condition is set in advance. The first preset condition can verify the authentication information, including the verification of identity information and authentication token information.
[0160] In some embodiments, if the authentication information does not meet the first preset condition, the dedicated network device sends a prompt message to the vehicle terminal to notify the user to retry authentication or provide the correct credentials.
[0161] In some embodiments, upon receiving software data, the vehicle terminal decrypts the software data according to pre-agreed decryption rules with the dedicated network device and installs the software corresponding to the decrypted data. After the vehicle terminal completes the software installation and restarts the vehicle system, the dedicated network device and the vehicle system synchronize and record update status and logs upon successful confirmation. Here, the vehicle terminal can either install the software directly after receiving the decrypted software data, or it can begin installation after user confirmation.
[0162] In some embodiments, the software data includes a version number.
[0163] In this way, when the dedicated network device receives the input of selecting the target user identifier from the preset user identifiers, the dedicated network device sends a data processing instruction to the vehicle terminal corresponding to the target user identifier. If the authentication information sent by the vehicle terminal passes the verification, the dedicated network device sends software data to the vehicle terminal. Based on the dedicated network device transmitting software data to the vehicle terminal, it is only necessary to select the vehicle terminal to be transmitted. After the vehicle terminal passes the verification, the software data can be transmitted, which improves the transmission efficiency.
[0164] Accordingly, in some embodiments, the dedicated network device includes a dedicated access and mobility management function (AMF) module, a dedicated base station, a dedicated user plane network function (UPF) module, and a server;
[0165] Specifically, S110 may include: when the dedicated network device receives a selection input for the target user identifier from the server, it uses a dedicated AMF module and a dedicated base station to send a data processing instruction to the vehicle terminal corresponding to the target user identifier.
[0166] Specifically, S130 may include: the vehicle terminal using the dedicated base station and dedicated UPF module of the dedicated network equipment to send a first authentication request to the server of the dedicated network equipment;
[0167] Specifically, S140 may include: in response to the first authentication request, the dedicated network device verifies the authentication information using a server, and if the authentication information meets the first preset conditions, sends software data to the vehicle terminal using a dedicated UPF module and a dedicated base station.
[0168] Here, the server includes the vehicle software processing server. The server is deployed in dedicated network equipment. The dedicated base station is a dedicated wireless base station.
[0169] In some embodiments, the dedicated network device uses a server to issue data processing instructions, page a dedicated AMF module, and uses the dedicated AMF module and a dedicated base station to send data processing instructions to the vehicle terminal corresponding to the target user identifier.
[0170] By deploying the server in a dedicated network device, communication between the server and the vehicle terminal can be achieved through a dedicated AMF module, a dedicated UPF module, and a dedicated base station, enabling secure transmission of software data and improving transmission efficiency and security.
[0171] Therefore, in some embodiments, the authentication information includes authentication token information; such as Figure 2 As shown, prior to S110 above, the method may further include:
[0172] S101. The vehicle-mounted terminal obtains identity information;
[0173] S102. The vehicle terminal sends a second authentication request to the dedicated network device. The second authentication request includes identity information.
[0174] S103. The dedicated network device responds to the second authentication request, verifies the identity information in the second authentication request, and generates authentication token information according to the authentication token generation rules if the identity information meets the second preset conditions.
[0175] S104. The dedicated network device sends authentication token information to the vehicle terminal.
[0176] Here, the identity information includes the vehicle identifier and password; the vehicle identifier includes the vehicle identification number (VIN). The second preset condition is pre-set.
[0177] In some embodiments, after receiving the second authentication request, the dedicated network device verifies the vehicle identifier and password. The dedicated network device then generates an authentication token for the verified user—that is, a user whose identity information meets the second preset conditions. The authentication token can be an encrypted string that may include identity information and authorization information. This authentication token can be used as authentication credentials in authentication requests, eliminating the need to re-enter the username and password each time.
[0178] In some embodiments, if the identity information meets the second preset condition, the dedicated network device sends a successful verification response to the vehicle terminal, the response including authentication token information. If the identity information does not meet the second preset condition, the dedicated network device sends a prompt to the vehicle terminal to notify the user to retry authentication or provide correct credentials.
[0179] It should be noted that the second preset condition can verify identity information, and the first preset condition can include the second preset condition.
[0180] Specifically, the dedicated network device uses a server to verify the identity information in the second authentication request. If the identity information meets the second preset conditions, the dedicated network device uses the server to generate authentication token information according to the authentication token generation rules. The vehicle terminal can carry this authentication token information as a credential for identity authentication in subsequent authentication requests. Each request must include this authentication token information in the request header or request parameters. After receiving the authentication request, the server verifies the validity of the authentication token information and decides whether to authorize the authentication request based on the information in the authentication token information. Verification may include timeliness and the vehicle's VIN, etc., which are not specifically limited here.
[0181] In this way, the authentication token information sent through the dedicated network device can be carried in the authentication request sent by the vehicle terminal, eliminating the need to carry the vehicle identification and password every time, thus avoiding the leakage of the vehicle identification and password and improving security.
[0182] In some embodiments, after registering with the dedicated network device, the vehicle terminal can access the dedicated network device. When the vehicle terminal connects to the dedicated network device, verification is required first. Only after successful verification can the vehicle terminal and the dedicated network device be connected to transmit software data and enable operations such as deployment, upgrades, and maintenance of vehicle software.
[0183] Based on this, in some embodiments, such as Figure 3 As shown, prior to S110 above, the method may further include:
[0184] S210. The vehicle-mounted terminal sends a registration request to the dedicated network equipment. The registration request includes at least the registration type, the vehicle-mounted terminal's capability information, and the slice parameters.
[0185] S220: When a private network device detects that a registration request includes a SubscriptionPermanent Identifier (SUPI), it obtains the authentication data corresponding to the SUPI.
[0186] S230. The dedicated network device generates the authentication token and random number corresponding to the authentication data according to the first preset generation rule.
[0187] S240. The dedicated network device generates an authentication token and a first key corresponding to a random number according to the second preset generation rule;
[0188] S250, a dedicated network device, sends an authentication token and a random number to the vehicle terminal;
[0189] S260. The vehicle terminal generates an authentication token and a second key corresponding to a random number according to the second preset generation rule.
[0190] S270, The vehicle-mounted terminal sends the second key to the dedicated network equipment;
[0191] S280: The dedicated network device compares the first key and the second key. If the first key and the second key are consistent, it obtains the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters, and connects the vehicle terminal and the dedicated network device according to the access policy.
[0192] Here, the registration request also includes a user identifier or SUPI. The user identifier can be an initial user identifier or a target user identifier.
[0193] In some embodiments, when the registration request includes a SUPI but not a user identifier, the dedicated network device can detect the SUPI in the registration request. Upon detecting that the registration request includes a SUPI, the dedicated network device obtains the authentication data corresponding to the SUPI, generates an authentication token (AUTN) and a random number RAND (RAND typically refers to a function used in programming to generate pseudo-random numbers) corresponding to the authentication data according to a first preset generation rule, and generates a first key corresponding to the authentication token and the random number according to a second preset generation rule. The first and second preset generation rules are pre-defined and are not specifically limited here. The first key is used to verify the vehicle terminal.
[0194] Next, the dedicated network device sends an authentication token and a random number to the vehicle-mounted terminal. The vehicle-mounted terminal then generates a second key corresponding to the authentication token and the random number according to a second preset generation rule. It is understood that the vehicle-mounted terminal includes the second preset generation rule. If the vehicle-mounted terminal does not include the second preset generation rule, it cannot generate the second key, and the vehicle-mounted terminal will fail verification and cannot connect to the dedicated network device. After generating the second key corresponding to the authentication token and the random number according to the second preset generation rule, the vehicle-mounted terminal sends the second key to the dedicated network device. The dedicated network device compares the first key and the second key. If the first key and the second key match, it obtains the access policy corresponding to the SUPI, registration type, vehicle-mounted terminal capability information, and slice parameters, and connects the vehicle-mounted terminal and the dedicated network device according to the access policy.
[0195] It should be noted that AUTN is a type of authentication data used in mobile communication networks. It is generated by the network and sent to user equipment for user equipment to authenticate the network.
[0196] In some embodiments, the access policy needs to meet preset rules. Based on these preset rules, a customized access policy for the vehicle terminal is pre-set; that is, the access policy is pre-defined and corresponds to SUPI, registration type, vehicle terminal capability information, and slicing parameters. The preset rules are shown in Table 1. The access policy includes access information and subscription information, etc.
[0197] Table 1
[0198]
[0199]
[0200] It should be noted that the preset rules in Table 1 are only illustrative examples, and the preset rules that the access policy needs to meet are not limited to those shown in Table 1.
[0201] In this way, by connecting the vehicle-mounted terminal with a dedicated network device, software data transmission is achieved, thus improving transmission efficiency.
[0202] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0203] Specifically, S210 may include:
[0204] The vehicle-mounted terminal uses a dedicated base station to send a registration request to the dedicated AMF module of the dedicated network equipment;
[0205] Specifically, S250 mentioned above may include:
[0206] Dedicated network equipment uses dedicated AMF modules and dedicated base stations to send authentication tokens and random numbers to vehicle terminals;
[0207] Specifically, S270 mentioned above may include:
[0208] The vehicle-mounted terminal uses a dedicated base station and a dedicated AMF module to send a second key to a dedicated network device;
[0209] In the above S280, connecting the vehicle terminal and the dedicated network equipment according to the access policy includes:
[0210] Dedicated network equipment uses a dedicated AMF module to connect the vehicle terminal and the dedicated network equipment according to the access policy.
[0211] In this way, through dedicated base stations and dedicated AMF modules, interaction between dedicated network equipment and vehicle terminals can be achieved, thereby connecting dedicated network equipment and vehicle terminals, realizing the transmission of software data, and improving transmission efficiency.
[0212] Accordingly, in some embodiments, the dedicated network device also includes a Dedicated Unified Data Management (UDM) module;
[0213] Specifically, S230 mentioned above may include:
[0214] The dedicated network device uses a dedicated UDM module to generate an authentication token and a random number corresponding to the authentication data according to the first preset generation rule;
[0215] In S280 above, the dedicated network device compares the first key and the second key. If the first key and the second key are consistent, it obtains the access policy corresponding to the SUPI, registration type, vehicle terminal capability information, and slice parameters, including:
[0216] The dedicated network device uses a dedicated AMF module to compare the first key and the second key. If the first key and the second key are consistent, the device obtains the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters from the dedicated UDM module.
[0217] In some embodiments, prior to S210 above, the dedicated network device inputs vehicle user information and access policies into the dedicated UDM module through the Operations Administration and Maintenance (OAM) system for use in various 5G signaling processes. OAM refers to Operations, Administration, and Maintenance in network management. It is a set of network management functions that provide information and specific details to manage a system or network, such as performance information, network fault indication, and data diagnostic functions.
[0218] In this way, the dedicated UDM module can store authentication data and access policies, providing data for the authentication and connection of the vehicle terminal, thereby connecting the dedicated network equipment and the vehicle terminal, realizing the transmission of software data and improving transmission efficiency.
[0219] Accordingly, in some embodiments, the dedicated network device further includes a dedicated Authentication Server Function (AUSF) module;
[0220] Specifically, S220 mentioned above may include:
[0221] When a dedicated network device detects that a registration request includes a SUPI using a dedicated AMF module, it uses a dedicated AMF module and a dedicated UDM module to obtain the authentication data corresponding to the SUPI.
[0222] Specifically, S240 mentioned above may include:
[0223] Using a dedicated AUSF module, an authentication token and a first key corresponding to a random number are generated according to the second preset generation rule.
[0224] Specifically, when the dedicated network device detects that the registration request includes a SUPI using the dedicated AMF module, it initiates a user authentication request to the dedicated AUSF module using the dedicated AMF module. The dedicated AUSF module processes the authentication request, obtains the SUPI from the authentication request, and sends an authentication information data request to the dedicated UDM module. The dedicated UDM module processes the authentication information data request from the dedicated AUSF module and obtains the SUPI from the authentication information data request. The dedicated UDM module then obtains the authentication data corresponding to the SUPI. Using the dedicated UDM module, the dedicated network device generates an authentication token and a random number corresponding to the authentication data according to a first preset generation rule, and sends the authentication token and random number to the dedicated AUSF module. Using the dedicated AUSF module, it generates a first key corresponding to the authentication token and random number according to a second preset generation rule, and sends the first key to the dedicated AMF module. When the dedicated network device receives the second key sent by the vehicle terminal using the dedicated base station and the dedicated AMF module, it compares the first key and the second key using the dedicated AMF module. If the first key and the second key match, it obtains the access policy corresponding to the SUPI, registration type, vehicle terminal capability information, and slice parameters from the dedicated UDM module. Dedicated network equipment uses a dedicated AMF module to connect the vehicle terminal and the dedicated network equipment according to the access policy.
[0225] After generating a first key corresponding to an authentication token and a random number using a dedicated AMF module according to a second preset generation rule, and sending the first key to the dedicated AMF module, the dedicated network device uses the dedicated AMF module and the dedicated base station to send an authentication request to the vehicle terminal. The authentication request includes an authentication token and a random number. The vehicle terminal generates a second key corresponding to the authentication token and the random number according to the second preset generation rule.
[0226] In this way, the vehicle terminal can be verified through a dedicated AUSF module, thereby connecting the dedicated network equipment and the vehicle terminal, realizing the transmission of software data and improving transmission efficiency.
[0227] Accordingly, in some embodiments, the dedicated network device also includes a dedicated unified data repository (UDR) module;
[0228] If the registration request includes SUPI, the authentication data corresponding to SUPI is obtained using the dedicated AMF module and the dedicated UDM module, including:
[0229] If the registration request includes SUPI when the dedicated AMF module is used, the authentication data corresponding to SUPI is obtained from the dedicated UDR module using the dedicated AMF module and the dedicated UDM module.
[0230] In some embodiments, the dedicated UDR module pre-stores the authentication data corresponding to SUPI.
[0231] In this way, by using a dedicated UDR module to store the authentication data corresponding to SUPI, and using a dedicated AUSF module to verify the vehicle terminal based on the authentication data, the dedicated network equipment and the vehicle terminal can be connected, realizing the transmission of software data and improving transmission efficiency.
[0232] Based on this, in some embodiments, such as Figure 4 As shown, in S280, after obtaining the access policy corresponding to SUPI, registration type, vehicle terminal capability information, and slice parameters, assuming the first and second keys are consistent, the method may further include:
[0233] S281. The dedicated network device generates the target user identifier corresponding to SUPI;
[0234] S282. Dedicated network equipment sends the target user identifier to the vehicle terminal;
[0235] In S280, the vehicle-mounted terminal and dedicated network equipment are connected according to the access policy, which may specifically include:
[0236] S283. Upon receiving the response information sent by the vehicle terminal, the dedicated network device connects the vehicle terminal and the dedicated network device according to the access policy.
[0237] In some embodiments, when the first key and the second key are consistent, after obtaining the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters, the dedicated network device assigns a target user identifier to the vehicle terminal, the vehicle terminal sends a response information to the dedicated network device, and the dedicated network device connects the vehicle terminal and the dedicated network device according to the access policy upon receiving the response information sent by the vehicle terminal.
[0238] In this way, by assigning a target user identifier to the vehicle terminal and transmitting data through the target user identifier instead of SUPI, the security of the vehicle terminal is improved.
[0239] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0240] Specifically, S281 mentioned above may include:
[0241] Dedicated network devices utilize dedicated AMF modules to generate target user identifiers corresponding to SUPI;
[0242] Specifically, S282 mentioned above may include:
[0243] Dedicated network equipment uses dedicated base stations to send target user identifiers to vehicle-mounted terminals;
[0244] Specifically, S283 mentioned above may include:
[0245] When the dedicated network device receives the response information sent by the vehicle terminal using the dedicated AMF module, it connects the vehicle terminal and the dedicated network device according to the access policy using the dedicated AMF module.
[0246] In this way, by assigning target user identifiers to vehicle terminals through dedicated base stations and dedicated AMF modules, and transmitting data through target user identifiers instead of SUPI, the security of vehicle terminals is improved.
[0247] Based on this, in some embodiments, the vehicle terminal includes a target user identifier, and the registration request includes the target user identifier of the vehicle terminal; such as Figure 5 As shown, corresponding to S220 above, before S230 above, the method may further include:
[0248] S221. The dedicated network device sends an identity request to the vehicle terminal if it does not detect that the registration request includes SUPI.
[0249] S222. The dedicated network device receives the identity response information sent by the vehicle terminal, and the identity response information includes SUPI.
[0250] S223. Dedicated network devices obtain authentication data corresponding to SUPI.
[0251] Here, the target user identifier can also be pre-defined, and the vehicle terminal includes the target user identifier. The vehicle terminal carries the target user identifier in the registration request and sends it to the dedicated network device for transmitting software data.
[0252] It should be noted that SUPI can also be encrypted, i.e., SUCI. SUCI (Subscription Concealed Identifier) is an identifier used in 5G networks to protect user privacy. It contains a hidden SUPI (Subscription Permanent Identifier) used to protect the user's permanent identity information when transmitted between the user device and the network.
[0253] In this way, SUPI is used for authentication, ensuring the security of software data. If authentication is successful, a dedicated network device and an in-vehicle terminal are connected. After the connection is established, the target user identifier is used to transmit data, ensuring the security of the in-vehicle terminal.
[0254] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0255] Specifically, S221 mentioned above may include:
[0256] If the dedicated AMF module does not detect that the registration request includes SUPI, the dedicated base station is used to send identity request information to the vehicle terminal.
[0257] Specifically, S222 mentioned above may include:
[0258] Using a dedicated base station and a dedicated AMF module, the system receives identity response information sent by the vehicle-mounted terminal.
[0259] In this way, SUPI is obtained using a dedicated base station and a dedicated AMF module. SUPI is used for authentication, which ensures the security of software data. If authentication is successful, a dedicated network device and vehicle terminal are connected. After connection, the target user identifier is used to transmit data, which ensures the security of the vehicle terminal.
[0260] Based on this, in some embodiments, the vehicle terminal includes an initial user identifier, and the registration request includes the initial user identifier of the vehicle terminal; such as Figure 6 As shown, in S280, after obtaining the access policy corresponding to SUPI, registration type, vehicle terminal capability information, and slice parameters, assuming the first and second keys are consistent, the method may further include:
[0261] S290, Dedicated network equipment generates the target user identifier corresponding to SUPI;
[0262] S291. Dedicated network equipment sends the target user identifier to the vehicle terminal;
[0263] S292. The vehicle terminal updates the initial user identifier to the target user identifier;
[0264] In S280, the vehicle-mounted terminal and dedicated network equipment are connected according to the access policy, which may specifically include:
[0265] S293. Upon receiving the response information sent by the vehicle terminal, the dedicated network device connects the vehicle terminal and the dedicated network device according to the access policy.
[0266] In some embodiments, after the vehicle terminal passes verification, the dedicated network device generates a target user identifier corresponding to the SUPI, and the vehicle terminal updates its initial user identifier to the target user identifier. The newly assigned target user identifier can replace the original initial user identifier of the vehicle terminal.
[0267] This improves the security of the vehicle terminal and software data by updating the user identifier of the vehicle terminal upon connection.
[0268] Since vehicle network access requires real-name authentication, it is difficult to implement real-name authentication on the operator's network for tens of thousands of vehicles that have not yet left the factory. To address this issue, a dedicated mobile communication network is used, where both the wireless network and the core network are deployed on the user side. In the embodiments provided in this application, such as... Figure 7 As shown, the architecture of the dedicated network equipment includes a dedicated base station 310, a dedicated AMF module 320, a dedicated AUSF module 330, a dedicated UDM module 340, a dedicated UPF module 350, and a dedicated UDR module 360, as well as a server 370. The dedicated AMF module 320, dedicated AUSF module 330, dedicated UDM module 340, dedicated UPF module 350, and dedicated UDR module 360 are deployed via Software Defined Network (SDN). The dedicated base station 310 provides dedicated 5G access for vehicle-mounted terminals. The dedicated UPF module 350 is configured with an internal network entry point, through which vehicle-mounted terminals can access the server. User identifiers, access policies, and authentication data are stored in the dedicated UDM module 340 and dedicated UDR module 360. When a vehicle-mounted terminal accesses the network, authentication is performed through the dedicated AUSF module 330.
[0269] For 5G private network registration of users who are not yet connected to the Internet of Vehicles (IoV), the customized design is as follows: User registration is achieved through the interaction of the IoV's onboard terminal, dedicated base station, dedicated AMF module, dedicated AUSF module, dedicated UDM module, dedicated UPF module, and dedicated UDR module, thereby enabling the onboard terminal to access the dedicated network equipment for software processing.
[0270] The system comprises several modules: a dedicated server for vehicle software deployment, upgrades, and maintenance; a dedicated network device for connecting vehicles to the server for automated software processing; a dedicated UDM module (User Data Management module) for managing and storing user-related data and providing authentication, authorization, and user configuration functions for the private network; a dedicated AMF module for authentication services, receiving authentication requests from the dedicated AMF module, requesting authentication data from the dedicated UDM module, generating authentication tokens and random numbers, and forwarding these to both the dedicated AMF and AMF modules for authentication processing; a dedicated AMF module for control plane network functions, transmitting signaling between terminals, base stations, and other core network elements; and a dedicated UPF module for user plane network functions, transmitting service traffic between the vehicle terminal and the server, such as authentication information and software data.
[0271] In the embodiments provided in this application, to better support software upgrades and development, based on the principle of "network following industry and network construction on demand," a 5G private network mode is launched. Multiple 5G private network capabilities, including edge computing, super uplink, and network services, are released to help users quickly build secure, reliable, stable, and service-visible customized private network equipment. This meets users' diverse needs for communication networks and enables different operational scenarios. Within the private network equipment, vehicles are registered using their identification, such as vehicle identification number (VIN), and can use the private network normally for server connections used for deployment, upgrades, and maintenance, thereby achieving automated software processing functions.
[0272] The embodiments provided in this application solve the following technical problems: First, providing customized dedicated network equipment for vehicle software processing; Second, realizing the use of dedicated network equipment based on the activation of the vehicle terminal through processes such as registration and authentication of dedicated network equipment; Third, realizing automated software processing for the deployment, upgrading, and maintenance of vehicle software based on dedicated network equipment, which can greatly improve software processing efficiency.
[0273] Since vehicle terminal authentication is performed within a dedicated network device, and this device does not access external networks, thus having no impact on the public network, vehicle authentication information can be pre-configured within it. When the vehicle terminal accesses the network, registration and authentication processes can proceed normally. By pre-setting the target user identifier in the vehicle and registering on a dedicated 5G network, vehicles can utilize dedicated network devices, significantly improving the efficiency of vehicle software deployment, upgrades, and maintenance, while reducing labor costs.
[0274] Based on the data transmission method provided in the above embodiments, this application also provides specific implementations of the data transmission apparatus. Please refer to the following embodiments.
[0275] See Figure 8 The data transmission device 400 provided in this application embodiment is applied to a dedicated network device, which only provides services to a preset vehicle terminal corresponding to a preset user identifier. The method includes:
[0276] The sending module 410 is used to send a data processing instruction to the vehicle terminal corresponding to the target user identifier when receiving the selection input for the target user identifier, so that the vehicle terminal can respond to the data processing instruction to obtain authentication information. The preset user identifier includes the target user identifier.
[0277] The receiving module 420 is used to receive a first authentication request sent by the vehicle terminal, the first authentication request including authentication information;
[0278] The verification module 430 is used to verify the authentication information in response to the first authentication request, and send software data to the vehicle terminal if the authentication information meets the first preset conditions.
[0279] Based on this, in some embodiments, the dedicated network device includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server;
[0280] The sending module 410 can be specifically used for:
[0281] When the server receives a selection input for the target user identifier, it uses a dedicated AMF module and a dedicated base station to send data processing instructions to the vehicle terminal corresponding to the target user identifier.
[0282] The receiver module 420 can be specifically used for:
[0283] The server receives the first authentication request sent by the vehicle terminal using a dedicated base station and a dedicated UPF module.
[0284] The verification module 430 can be specifically used for:
[0285] In response to the first authentication request, the server verifies the authentication information. If the authentication information meets the first preset conditions, the software data is sent to the vehicle terminal using a dedicated UPF module and a dedicated base station.
[0286] Based on this, in some embodiments, the authentication information includes authentication token information; the device 400 may further include:
[0287] The receiving module 420 is also configured to receive a second authentication request sent by the vehicle terminal before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier when receiving a selection input for the target user identifier;
[0288] The verification module 420 is also used to verify the identity information in the second authentication request in response to the second authentication request;
[0289] The generation module is used to generate authentication token information according to the authentication token generation rules when the identity information meets the second preset conditions.
[0290] The sending module 410 is also used to send authentication token information to the vehicle terminal.
[0291] Based on this, in some embodiments, the device 400 may further include:
[0292] The receiving module is used to receive a registration request sent by the vehicle terminal before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier when a selection input for the target user identifier is received. The registration request includes at least the registration type, the capability information of the vehicle terminal, and the slice parameters.
[0293] The acquisition module is used to acquire the authentication data corresponding to SUPI when the registration request includes the subscription permanent identifier SUPI.
[0294] The generation module is used to generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule;
[0295] The generation module is also used to generate the first key corresponding to the authentication token and the random number according to the second preset generation rule;
[0296] The sending module 410 is also used to send an authentication token and a random number to the vehicle terminal, so that the vehicle terminal can generate a second key corresponding to the authentication token and the random number according to the second preset generation rule;
[0297] The receiving module 420 is also used to receive the second key sent by the vehicle terminal;
[0298] The acquisition module is also used to compare the first key and the second key. If the first key and the second key are consistent, the module acquires the access strategy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters.
[0299] The connection module is used to connect the vehicle terminal and the dedicated network equipment according to the access policy.
[0300] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0301] The receiving module can be specifically used for:
[0302] Using a dedicated base station and a dedicated AMF module, it receives registration requests sent by the vehicle-mounted terminal;
[0303] The sending module 410 can be specifically used for:
[0304] Using a dedicated AMF module and a dedicated base station, an authentication token and a random number are sent to the vehicle terminal;
[0305] The receiver module 420 can be specifically used for:
[0306] The second key sent by the vehicle terminal is received using a dedicated base station and a dedicated AMF module;
[0307] The connection module can be specifically used for:
[0308] Using a dedicated AMF module, the vehicle terminal and dedicated network equipment are connected according to the access policy.
[0309] Accordingly, in some embodiments, the dedicated network device also includes a dedicated unified data management function (UDM) module;
[0310] The generation module can be specifically used for:
[0311] Using a dedicated UDM module, an authentication token and a random number are generated according to the first preset generation rule;
[0312] The acquisition module can be specifically used for:
[0313] Using a dedicated AMF module, the first key and the second key are compared. If the first key and the second key are consistent, the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters is obtained from the dedicated UDM module.
[0314] Accordingly, in some embodiments, the dedicated network device further includes a dedicated authentication service function (AUSF) module;
[0315] The acquisition module can be specifically used for:
[0316] If the registration request includes SUPI when the dedicated AMF module is used, the authentication data corresponding to SUPI is obtained using the dedicated AMF module and the dedicated UDM module.
[0317] The generation module can be specifically used for:
[0318] Using a dedicated AUSF module, an authentication token and a first key corresponding to a random number are generated according to the second preset generation rule.
[0319] Accordingly, in some embodiments, the dedicated network device also includes a dedicated unified data warehouse (UDR) module;
[0320] The acquisition module can be specifically used for:
[0321] If the registration request includes SUPI when the dedicated AMF module is used, the authentication data corresponding to SUPI is obtained from the dedicated UDR module using the dedicated AMF module and the dedicated UDM module.
[0322] Based on this, in some embodiments, the device 400 may further include:
[0323] The generation module is also used to generate the target user identifier corresponding to the SUPI after obtaining the access policy corresponding to the SUPI, registration type, vehicle terminal capability information and slice parameters when the first key and the second key are consistent.
[0324] The sending module 410 is also used to send the target user identifier to the vehicle terminal;
[0325] The connection module can be specifically used for:
[0326] Upon receiving a response from the vehicle-mounted terminal, the vehicle-mounted terminal and the dedicated network equipment are connected according to the access policy.
[0327] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0328] The generation module can be specifically used for:
[0329] Using a dedicated AMF module, the target user identifier corresponding to SUPI is generated;
[0330] The sending module 410 can be specifically used for:
[0331] Using a dedicated base station, the target user identifier is sent to the vehicle-mounted terminal;
[0332] The connection module can be specifically used for:
[0333] When the response information sent by the vehicle terminal is received using the dedicated AMF module, the vehicle terminal and the dedicated network equipment are connected using the dedicated AMF module according to the access policy.
[0334] Based on this, in some embodiments, the registration request includes the target user identifier of the vehicle terminal; the device 400 may further include:
[0335] The sending module 410 is also used to send identity request information to the vehicle terminal before generating the authentication token and random number corresponding to the authentication data according to the first preset generation rule, in the absence of detecting that the registration request includes SUPI;
[0336] The receiving module is used to receive identity response information sent by the vehicle terminal, which includes SUPI;
[0337] The acquisition module is also used to acquire the authentication data corresponding to SUPI.
[0338] Accordingly, in some embodiments, the dedicated network device includes a dedicated base station and a dedicated AMF module;
[0339] The sending module 410 can be specifically used for:
[0340] If the dedicated AMF module does not detect that the registration request includes SUPI, the dedicated base station is used to send identity request information to the vehicle terminal.
[0341] The receiving module can be specifically used for:
[0342] Using a dedicated base station and a dedicated AMF module, the system receives identity response information sent by the vehicle-mounted terminal.
[0343] Based on this, in some embodiments, the registration request includes the initial user identifier of the vehicle terminal; the device 400 may further include:
[0344] The generation module is also used to generate the target user identifier corresponding to the SUPI after obtaining the access policy corresponding to the SUPI, registration type, vehicle terminal capability information and slice parameters when the first key and the second key are consistent.
[0345] The sending module 410 is also used to send the target user identifier to the vehicle terminal so that the vehicle terminal can update the initial user identifier to the target user identifier.
[0346] The connection module can be specifically used for:
[0347] Upon receiving a response from the vehicle-mounted terminal, the vehicle-mounted terminal and the dedicated network equipment are connected according to the access policy.
[0348] See Figure 9 The data transmission device 500 provided in this application embodiment is applied to an in-vehicle terminal and includes:
[0349] The receiving module 510 is used to receive data processing instructions sent by the dedicated network device. The data processing instructions are sent by the dedicated network device when it receives the selection input of the target user identifier. The dedicated network device only provides services to the preset vehicle terminal corresponding to the preset user identifier. The preset user identifier includes the target user identifier.
[0350] The acquisition module 520 is used to acquire authentication information in response to data processing instructions;
[0351] The sending module 530 is used to send a first authentication request to a dedicated network device. The first authentication request includes authentication information and is used to instruct the dedicated network device to verify the authentication information. If the authentication information meets the first preset conditions, the module sends software data to the vehicle terminal.
[0352] The receiving module 510 is also used to receive software data sent by a dedicated network device.
[0353] Based on this, in some embodiments, data processing instructions are sent by a dedicated network device using a dedicated AMF module and a dedicated base station; software data is sent by a dedicated network device using a dedicated UPF module and a dedicated base station.
[0354] The sending module 530 can be specifically used for:
[0355] Using a dedicated base station and a dedicated UPF module of a dedicated network device, a first authentication request is sent to the server of the dedicated network device. The dedicated network device responds to the first authentication request and uses the server to verify the authentication information. If the authentication information meets the first preset conditions, the dedicated UPF module and the dedicated base station send software data to the vehicle terminal.
[0356] Based on this, in some embodiments, the authentication information includes authentication token information; the device 500 may further include:
[0357] The acquisition module 520 is also used to acquire identity information before receiving data processing instructions sent by the dedicated network device;
[0358] The sending module 530 is also used to send a second authentication request to the dedicated network device. The second authentication request includes identity information and is used to instruct the dedicated network device to verify the identity information in the second authentication request. If the identity information meets the second preset conditions, authentication token information is generated according to the authentication token generation rules.
[0359] The receiving module 510 is also used to receive authentication token information sent by a dedicated network device.
[0360] Based on this, in some embodiments, the device 500 may further include:
[0361] The sending module 530 is also used to send a registration request to the dedicated network device before receiving the data processing instruction sent by the dedicated network device. The registration request includes at least the registration type, the capability information of the vehicle terminal and the slice parameters. It is used to instruct the dedicated network device to obtain the authentication data corresponding to the SUPI when it detects that the registration request includes SUPI, generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule, and generate the first key corresponding to the authentication token and random number according to the second preset generation rule.
[0362] The receiving module 510 is also used to receive authentication tokens and random numbers sent by dedicated network devices;
[0363] The generation module is used to generate the authentication token and the second key corresponding to the random number according to the second preset generation rule;
[0364] The sending module 530 is also used to send a second key to the dedicated network device, so that the dedicated network device can compare the first key and the second key. If the first key and the second key are consistent, the dedicated network device can obtain the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters, and connect the vehicle terminal and the dedicated network device according to the access policy.
[0365] Based on this, in some embodiments, the authentication token and the random number are generated by a dedicated network device using a dedicated UDM module and sent using a dedicated AUSF module, a dedicated AMF module and a dedicated base station;
[0366] The sending module 530 can be specifically used for:
[0367] Using a dedicated base station of a dedicated network device, a registration request is sent to the dedicated AMF module of the dedicated network device. When the dedicated AMF module detects that the registration request includes SUPI, the dedicated AUSF module and the dedicated UDM module are used to obtain the authentication data corresponding to SUPI. The dedicated UDM module generates the authentication token and random number corresponding to the authentication data according to the first preset generation rule. The dedicated AUSF module generates the first key corresponding to the authentication token and random number according to the second preset generation rule.
[0368] The sending module 530 can be specifically used for:
[0369] Using a dedicated base station of a dedicated network device, a second key is sent to the dedicated AMF module of the dedicated network device. The dedicated network device uses the dedicated AMF module to compare the first key and the second key. If the first key and the second key are consistent, the dedicated UDM module obtains the access policy corresponding to SUPI, registration type, vehicle terminal capability information and slice parameters.
[0370] Based on this, in some embodiments, the device 500 may further include:
[0371] The receiving module 510 is also used to receive the target user identifier sent by the dedicated network device;
[0372] The sending module 530 is also configured to send a response message to the dedicated network device after sending the second key, so that the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy upon receiving the response message sent by the vehicle terminal.
[0373] Based on this, in some embodiments, the target user identifier is sent by a dedicated network device using a dedicated base station; the sending module 530 can specifically be used for:
[0374] Using a dedicated base station of a dedicated network device, a response message is sent to the dedicated AMF module of the dedicated network device, so that the dedicated network device can use the dedicated AMF module to connect the vehicle terminal and the dedicated network device according to the access policy.
[0375] Based on this, in some embodiments, the vehicle terminal includes a target user identifier, and the registration request includes the target user identifier; the device 500 may further include:
[0376] The sending module 530 is further configured to, upon receiving the authentication token and random number sent by the dedicated network device, before generating the second key corresponding to the authentication token and random number according to the second preset generation rule, send identity response information to the dedicated network device upon receiving the identity request information sent by the dedicated network device. The identity response information includes SUPI, which is used by the dedicated network device to obtain the authentication data corresponding to SUPI.
[0377] Based on this, in some embodiments, the identity request information is sent by a dedicated network device using a dedicated base station; the sending module 530 can specifically be used for:
[0378] Using a dedicated base station of a dedicated network device, identity response information is sent to a dedicated AMF module of the dedicated network device.
[0379] Based on this, in some embodiments, the vehicle terminal includes an initial user identifier, and the registration request includes the initial user identifier; the device 500 may further include:
[0380] The update module is used to update the initial user identifier in the vehicle terminal to the target user identifier after sending the second key to the dedicated network device and receiving the target user identifier sent by the dedicated network device.
[0381] The sending module 530 is also used to send response information to the dedicated network device, so that the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy when it receives the response information sent by the vehicle terminal.
[0382] Each module of the data transmission device provided in this application embodiment can realize the functions of each step of the data transmission method provided above, and can achieve its corresponding technical effects. For the sake of brevity, it will not be described in detail here.
[0383] Based on the same inventive concept, embodiments of this application also provide an electronic device.
[0384] Figure 10 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0385] An electronic device may include a processor 601 and a memory 602 storing computer program instructions.
[0386] Specifically, the processor 601 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0387] Memory 602 may include mass storage for data or instructions. For example, and not limitingly, memory 602 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 602 may include removable or non-removable (or fixed) media. Where appropriate, memory 602 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 602 is non-volatile solid-state memory.
[0388] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.
[0389] The processor 601 reads and executes computer program instructions stored in the memory 602 to implement any of the data transmission methods in the above embodiments.
[0390] In one example, the electronic device may also include a communication interface 603 and a bus 610. For example, Figure 10 As shown, the processor 601, memory 602, and communication interface 603 are connected through bus 610 and complete communication with each other.
[0391] The communication interface 603 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0392] Bus 610 includes hardware, software, or both, that couples components of an electronic device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Linear Predictive Coding (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (Peripheral Component Interconnect-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VESA Local Bus, VLB) bus, or other suitable buses, or a combination of two or more of these. Where appropriate, bus 610 may include one or more buses. Although specific buses are described and illustrated in the embodiments of this application, this application contemplates any suitable bus or interconnection. The electronic device can perform the data transmission method described in the embodiments of the present invention, thereby realizing the data transmission method described above.
[0393] Furthermore, in conjunction with the data transmission methods in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the data transmission methods in the above embodiments.
[0394] This application also provides a computer program product, wherein the instructions in the computer program product, when executed by the processor of an electronic device, cause the electronic device to perform various processes implementing any of the above-described data transmission method embodiments.
[0395] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0396] The functional blocks shown in the above-described block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0397] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0398] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0399] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.
Claims
1. A data transmission method, characterized in that, Applied to dedicated network equipment, wherein the dedicated network equipment only provides services to a preset vehicle-mounted terminal corresponding to a preset user identifier, the method includes: Upon receiving a selection input for a target user identifier, a data processing instruction is sent to the vehicle terminal corresponding to the target user identifier, so that the vehicle terminal can respond to the data processing instruction and obtain authentication information. The preset user identifier includes the target user identifier. The vehicle corresponding to the preset vehicle terminal is an un-manufactured vehicle. The vehicle network card corresponding to the preset vehicle terminal is not activated. The wireless network and core network of the dedicated mobile communication network corresponding to the dedicated network device are both deployed on the user side. Receive a first authentication request sent by the vehicle terminal, wherein the first authentication request includes the authentication information; In response to the first authentication request, the authentication information is verified, and if the authentication information meets the first preset conditions, software data is sent to the vehicle terminal. The dedicated network equipment includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server; the step of sending data processing instructions to the vehicle terminal corresponding to the target user identifier upon receiving a selection input for the target user identifier includes: When the server receives a selection input for the target user identifier, the AMF module and the dedicated base station are used to send a data processing instruction to the vehicle terminal corresponding to the target user identifier. The receiving of the first authentication request sent by the vehicle terminal includes: Using the server, the first authentication request sent by the vehicle terminal using the dedicated base station and UPF module is received; The step of responding to the first authentication request by verifying the authentication information and sending software data to the vehicle terminal when the authentication information meets a first preset condition includes: In response to the first authentication request, the server is used to verify the authentication information. If the authentication information meets the first preset conditions, software data is sent to the vehicle terminal using the UPF module and the dedicated base station.
2. The data transmission method according to claim 1, characterized in that, The authentication information includes authentication token information; before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier upon receiving a selection input for the target user identifier, the method further includes: Receive the second authentication request sent by the vehicle terminal; In response to the second authentication request, the identity information in the second authentication request is verified; If the identity information meets the second preset condition, the authentication token information is generated according to the authentication token generation rule; The authentication token information is sent to the vehicle terminal.
3. The data transmission method according to claim 1, characterized in that, Upon receiving a selection input for a target user identifier, before sending a data processing instruction to the vehicle terminal corresponding to the target user identifier, the method further includes: Receive a registration request sent by the vehicle terminal, the registration request including at least the registration type, the capability information of the vehicle terminal, and the slice parameters; If the registration request includes a subscription permanent identifier SUPI, obtain the authentication data corresponding to the SUPI; Generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule; Generate the authentication token and the first key corresponding to the random number according to the second preset generation rule; The authentication token and the random number are sent to the vehicle terminal so that the vehicle terminal can generate a second key corresponding to the authentication token and the random number according to the second preset generation rule; Receive the second key sent by the vehicle terminal; Compare the first key and the second key. If the first key and the second key are consistent, obtain the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal, and the slice parameters. The vehicle terminal and the dedicated network device are connected according to the access strategy.
4. The data transmission method according to claim 3, characterized in that, Receiving the registration request sent by the vehicle terminal includes: Using the dedicated base station and AMF module, the registration request sent by the vehicle terminal is received; Sending the authentication token and the random number to the vehicle terminal includes: Using the AMF module and the dedicated base station, the authentication token and the random number are sent to the vehicle terminal; Receiving the second key sent by the vehicle terminal includes: The second key sent by the vehicle terminal is received using the dedicated base station and AMF module; The step of connecting the vehicle terminal and the dedicated network device according to the access policy includes: Using the AMF module, the vehicle terminal and the dedicated network device are connected according to the access strategy.
5. The data transmission method according to claim 4, characterized in that, The dedicated network device also includes a dedicated unified data management (UDM) module; The step of generating the authentication token and random number corresponding to the authentication data according to the first preset generation rule includes: Using the UDM module, an authentication token and a random number corresponding to the authentication data are generated according to the first preset generation rule; The step of comparing the first key and the second key, and obtaining the access policy corresponding to the SUPI, the registration type, the vehicle terminal's capability information, and the slice parameters if the first key and the second key match, includes: Using the AMF module, the first key and the second key are compared. If the first key and the second key are consistent, the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal, and the slice parameters is obtained from the UDM module.
6. The data transmission method according to claim 5, characterized in that, The dedicated network equipment also includes a dedicated authentication service (AUSF) module. The step of obtaining the authentication data corresponding to the SUPI when the registration request is detected to include: If the AMF module detects that the registration request includes SUPI, the AMF module and UDM module are used to obtain the authentication data corresponding to the SUPI. The step of generating the authentication token and the first key corresponding to the random number according to the second preset generation rule includes: Using the AUSF module, the authentication token and the first key corresponding to the random number are generated according to the second preset generation rule.
7. The data transmission method according to claim 6, characterized in that, The dedicated network equipment also includes a dedicated unified data warehouse (UDR) module; When the AMF module detects that the registration request includes SUPI, the authentication data corresponding to the SUPI is obtained using the AMF and UDM modules, including: If the AMF module detects that the registration request includes SUPI, the authentication data corresponding to the SUPI is obtained from the UDR module using the AMF and UDM modules.
8. The data transmission method according to claim 3, characterized in that, If the first key and the second key are consistent, after obtaining the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal, and the slice parameters, the method further includes: Generate the target user identifier corresponding to the SUPI; Send the target user identifier to the vehicle terminal; The step of connecting the vehicle terminal and the dedicated network device according to the access policy includes: Upon receiving the response information sent by the vehicle terminal, the vehicle terminal and the dedicated network device are connected according to the access strategy.
9. The data transmission method according to claim 8, characterized in that, The generation of the target user identifier corresponding to the SUPI includes: The target user identifier corresponding to the SUPI is generated using the AMF module; Sending the target user identifier to the vehicle terminal includes: The target user identifier is sent to the vehicle terminal using the dedicated base station. Upon receiving the response information sent by the vehicle-mounted terminal, connecting the vehicle-mounted terminal and the dedicated network device according to the access policy includes: Upon receiving the response information sent by the vehicle terminal using the AMF module, the vehicle terminal and the dedicated network device are connected using the AMF module according to the access strategy.
10. The data transmission method according to claim 3, characterized in that, The registration request includes the target user identifier of the vehicle terminal; Before generating the authentication token and random number corresponding to the authentication data according to the first preset generation rule, the method further includes: If the SUPI is not detected in the registration request, an identity request is sent to the vehicle terminal. Receive identity response information sent by the vehicle terminal, wherein the identity response information includes the SUPI; Obtain the authentication data corresponding to the SUPI.
11. The data transmission method according to claim 10, characterized in that, The step of sending identity request information to the vehicle terminal when the registration request does not detect the inclusion of the SUPI includes: If the AMF module does not detect that the registration request includes the SUPI, the dedicated base station is used to send identity request information to the vehicle terminal. The receipt of the identity response information sent by the vehicle terminal includes: The system utilizes the dedicated base station and AMF module to receive identity response information sent by the vehicle-mounted terminal.
12. The data transmission method according to claim 3, characterized in that, The registration request includes the initial user identifier of the vehicle terminal; if the first key and the second key are consistent, after obtaining the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal, and the slice parameters, the method further includes: Generate the target user identifier corresponding to the SUPI; The target user identifier is sent to the vehicle terminal so that the vehicle terminal can update the initial user identifier to the target user identifier; The step of connecting the vehicle terminal and the dedicated network device according to the access policy includes: Upon receiving the response information sent by the vehicle terminal, the vehicle terminal and the dedicated network device are connected according to the access strategy.
13. A data transmission method, characterized in that, Applications in vehicle-mounted terminals include: The system receives data processing instructions sent by a dedicated network device. These instructions are sent by the dedicated network device upon receiving a selection input for a target user identifier. The dedicated network device provides services only to a preset vehicle terminal corresponding to a preset user identifier. The preset user identifier includes the target user identifier. The vehicle corresponding to the vehicle terminal is an un-manufactured vehicle. The vehicle network card corresponding to the vehicle terminal is not activated. The wireless network and core network of the dedicated mobile communication network corresponding to the dedicated network device are both deployed on the user side. In response to the data processing instruction, obtain authentication information; Send a first authentication request to the dedicated network device, the first authentication request including the authentication information, for instructing the dedicated network device to verify the authentication information, and send software data to the vehicle terminal if the authentication information meets a first preset condition; Receive the software data sent by the dedicated network device; The dedicated network equipment includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server; the data processing instructions are sent by the dedicated network equipment using the AMF module and the dedicated base station; the software data is sent by the dedicated network equipment using the UPF module and the dedicated base station. Sending the first authentication request to the dedicated network device includes: Using the dedicated base station and UPF module of the dedicated network device, a first authentication request is sent to the server of the dedicated network device. In response to the first authentication request, the dedicated network device verifies the authentication information using the server. If the authentication information meets the first preset condition, the dedicated network device sends software data to the vehicle terminal using the UPF module and the dedicated base station.
14. The data transmission method according to claim 13, characterized in that, The authentication information includes authentication token information; Before receiving data processing instructions sent by a dedicated network device, the method further includes: Obtain identity information; Send a second authentication request to the dedicated network device. The second authentication request includes the identity information. It is used to instruct the dedicated network device to verify the identity information in the second authentication request. If the identity information meets the second preset condition, generate the authentication token information according to the authentication token generation rule. Receive the authentication token information sent by the dedicated network device.
15. The data transmission method according to claim 13, characterized in that, Before receiving data processing instructions sent by a dedicated network device, the method further includes: Send a registration request to the dedicated network device. The registration request includes at least the registration type, the capability information of the vehicle terminal, and the slice parameters. This is used to instruct the dedicated network device to obtain the authentication data corresponding to the SUPI when it detects that the registration request includes SUPI. Then, it generates an authentication token and a random number corresponding to the authentication data according to a first preset generation rule, and generates a first key corresponding to the authentication token and the random number according to a second preset generation rule. Receive the authentication token and the random number sent by the dedicated network device; Generate the authentication token and the second key corresponding to the random number according to the second preset generation rule; A second key is sent to the dedicated network device for the dedicated network device to compare the first key and the second key. If the first key and the second key are consistent, the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal and the slice parameters is obtained, and the vehicle terminal and the dedicated network device are connected according to the access policy.
16. The data transmission method according to claim 15, characterized in that, The authentication token and the random number are generated by the dedicated network device using the UDM module and sent using the AUSF module, AMF module and dedicated base station; Sending a registration request to the dedicated network device includes: Using the dedicated base station of the dedicated network device, a registration request is sent to the AMF module of the dedicated network device. When the dedicated network device detects that the registration request includes SUPI using the AMF module, it uses the AUSF module and UDM module to obtain the authentication data corresponding to the SUPI, uses the UDM module to generate the authentication token and random number corresponding to the authentication data according to the first preset generation rule, and uses the AUSF module to generate the first key corresponding to the authentication token and the random number according to the second preset generation rule. Sending the second key to the dedicated network device includes: Using the dedicated base station of the dedicated network device, a second key is sent to the AMF module of the dedicated network device. The dedicated network device uses the AMF module to compare the first key and the second key. If the first key and the second key are consistent, the dedicated network device obtains the access policy corresponding to the SUPI, the registration type, the capability information of the vehicle terminal and the slice parameters from the UDM module.
17. The data transmission method according to claim 15, characterized in that, After sending the second key to the dedicated network device, the method further includes: Receive the target user identifier sent by the dedicated network device; A response message is sent to the dedicated network device so that, upon receiving the response message sent by the vehicle terminal, the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy.
18. The data transmission method according to claim 17, characterized in that, The target user identifier is sent by the dedicated network device using a dedicated base station; sending response information to the dedicated network device includes: The dedicated base station of the dedicated network device sends a response message to the AMF module of the dedicated network device, so that the dedicated network device can use the AMF module to connect the vehicle terminal and the dedicated network device according to the access policy.
19. The data transmission method according to claim 15, characterized in that, The vehicle-mounted terminal includes the target user identifier, and the registration request includes the target user identifier; before generating the second key corresponding to the authentication token and the random number according to the second preset generation rule after receiving the authentication token and the random number sent by the dedicated network device, the method further includes: Receive the identity request information sent by the dedicated network device; The dedicated network device sends an identity response information, which includes the SUPI, to the dedicated network device to obtain the authentication data corresponding to the SUPI.
20. The data transmission method according to claim 19, characterized in that, The identity request information is sent by the dedicated network device using a dedicated base station; sending the identity response information to the dedicated network device includes: Using the dedicated base station of the dedicated network device, identity response information is sent to the AMF module of the dedicated network device.
21. The data transmission method according to claim 15, characterized in that, The vehicle-mounted terminal includes an initial user identifier, and the registration request includes the initial user identifier; after sending the second key to the dedicated network device, the method further includes: Receive the target user identifier sent by the dedicated network device; Update the initial user identifier in the vehicle terminal to the target user identifier; A response message is sent to the dedicated network device so that, upon receiving the response message sent by the vehicle terminal, the dedicated network device can connect the vehicle terminal and the dedicated network device according to the access policy.
22. A data transmission device, characterized in that, Applied to dedicated network equipment, which only provides services to a preset vehicle-mounted terminal corresponding to a preset user identifier, the device includes: The sending module is used to send a data processing instruction to the vehicle terminal corresponding to the target user identifier when a selection input for the target user identifier is received, so that the vehicle terminal can respond to the data processing instruction and obtain authentication information. The preset user identifier includes the target user identifier. The vehicle corresponding to the preset vehicle terminal is an un-manufactured vehicle. The vehicle network card corresponding to the preset vehicle terminal is not activated. The wireless network and core network of the dedicated mobile communication network corresponding to the dedicated network equipment are both deployed on the user side. The receiving module is configured to receive a first authentication request sent by the vehicle terminal, wherein the first authentication request includes the authentication information; The verification module is used to verify the authentication information in response to the first authentication request, and send software data to the vehicle terminal when the authentication information meets the first preset conditions. The dedicated network equipment includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server; the transmitting module is specifically used for: When the server receives a selection input for the target user identifier, the AMF module and the dedicated base station are used to send a data processing instruction to the vehicle terminal corresponding to the target user identifier. The receiving module is specifically used for: Using the server, the first authentication request sent by the vehicle terminal using the dedicated base station and UPF module is received; The verification module is specifically used for: In response to the first authentication request, the server is used to verify the authentication information. If the authentication information meets the first preset conditions, software data is sent to the vehicle terminal using the UPF module and the dedicated base station.
23. A data transmission device, characterized in that, Applications in vehicle-mounted terminals include: The receiving module is used to receive data processing instructions sent by the dedicated network device. The data processing instructions are sent by the dedicated network device when it receives the selection input of the target user identifier. The dedicated network device only provides services to the preset vehicle terminal corresponding to the preset user identifier. The preset user identifier includes the target user identifier. The vehicle corresponding to the vehicle terminal is a non-factory vehicle. The vehicle network card corresponding to the vehicle terminal is not activated. The wireless network and core network of the dedicated mobile communication network corresponding to the dedicated network device are both deployed on the user side. The acquisition module is used to acquire authentication information in response to the data processing instruction; The sending module is configured to send a first authentication request to the dedicated network device, the first authentication request including the authentication information, and to instruct the dedicated network device to verify the authentication information. If the authentication information meets a first preset condition, the module sends software data to the vehicle terminal. The receiving module is also used to receive the software data sent by the dedicated network device; The dedicated network equipment includes a Dedicated Access and Mobility Management Function (AMF) module, a dedicated base station, a Dedicated User Plane Network Function (UPF) module, and a server; the data processing instructions are sent by the dedicated network equipment using the AMF module and the dedicated base station; the software data is sent by the dedicated network equipment using the UPF module and the dedicated base station. The sending module is specifically used for: Using the dedicated base station and UPF module of the dedicated network device, a first authentication request is sent to the server of the dedicated network device. In response to the first authentication request, the dedicated network device verifies the authentication information using the server. If the authentication information meets the first preset condition, the dedicated network device sends software data to the vehicle terminal using the UPF module and the dedicated base station.
24. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; When the processor executes the computer program instructions, it implements the data transmission method as described in any one of claims 1-12, or the data transmission method as described in any one of claims 13-21.
25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement the data transmission method as described in any one of claims 1-12, or the data transmission method as described in any one of claims 13-21.
26. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device is able to perform the data transmission method as described in any one of claims 1-12, or the data transmission method as described in any one of claims 13-21.
Citation Information
Patent Citations
Terminal access method and device and authentication service function network element
CN116471590A
Vehicle OTA upgrading method and system, electronic equipment and storage medium
CN116506840A
Registration method and device of user equipment, computer readable medium and electronic equipment
CN117098111A
Data security verification method, device and equipment, vehicle and storage medium
CN118734290A