Road traffic terminal identification method and related device
By generating and managing road traffic terminal identification codes on terminal devices and using proxy nodes for identification resolution, the complexity of identification management caused by limited resources of terminal devices is solved, and efficient and safe identification resolution is achieved.
Patent Information
- Application Number
- CN202510334207.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-20
AI Technical Summary
In the prior art, terminal equipment is difficult to support complex identification generation, registration and analysis operations due to limited resources, and the identification resolution system has shortcomings in terms of security, analysis efficiency and real-timeness.
A road traffic terminal identification method is proposed, by collecting information on the terminal equipment, generating a symmetric key, generating a terminal identification code based on hardware information and timestamps, and ensuring the security of the identification through encryption and signature mechanisms. This method uses proxy nodes to perform identification resolution to reduce the computing and storage burden of terminal devices.
It effectively reduces the computing and storage pressure of terminal equipment, improves the efficient execution of identification management tasks, improves the overall security of the system, and significantly improves the efficiency and real-timeness of identification resolution.
Smart Images

Figure CN119853910B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the technical field of intelligent transportation, and particularly to a road traffic terminal identification method and related devices. Background Art
[0002] This section aims to provide background or context for the embodiments of the present disclosure described in the claims. The description herein is not admitted to be prior art merely by virtue of its inclusion in this section.
[0003] With the rapid development of intelligent transportation systems, the number and types of road traffic terminal devices have been increasing continuously. These devices include traffic lights, electronic police, vehicle-mounted terminals, sensor nodes, etc. They play an important role in traffic management, vehicle monitoring, environmental monitoring, etc.
[0004] However, in the related art, due to limited resources, terminal devices are difficult to support complex identification generation, registration, and parsing operations. At the same time, there are also obvious deficiencies in the security, parsing efficiency, and real-time performance of the identification parsing system. Summary of the Invention
[0005] In view of this, an object of the present disclosure is to propose a road traffic terminal identification method and related devices, which can at least solve one of the technical problems in the related art to a certain extent.
[0006] Based on the above object, a first aspect of an exemplary embodiment of the present disclosure provides a road traffic terminal identification method, which is applied to a client. The method includes:
[0007] Collect information of road traffic terminal devices to obtain hardware information and a timestamp; generate a symmetric key, and based on the hardware information and the timestamp, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code;
[0008] Receive a proxy public key transmitted by a proxy node; encrypt the symmetric key through the proxy public key to obtain an encrypted symmetric key;
[0009] Generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature;
[0010] Transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification parsing result, and receive the terminal identification parsing result generated by the proxy node.
[0011] Based on the same inventive concept, a second aspect of the exemplary embodiments of the present disclosure provides a road traffic terminal identification method, which is applied to a proxy node. The method includes:
[0012] Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client. Receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client. Verify the terminal identification signature based on the client public key to obtain a signature verification result;
[0013] Decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code;
[0014] Verify the terminal identification code to obtain a terminal identification code verification result;
[0015] Determine the authentication information of the terminal identification code, and based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature, obtain the parsing request information;
[0016] Perform format conversion on the parsing request information to obtain an adapted parsing request information; transmit the adapted parsing request information to the identification parsing system; receive the terminal identification parsing result transmitted by the identification parsing system, and transmit the terminal identification parsing result to the client; wherein, the terminal identification parsing result is obtained by the identification parsing system parsing the adapted parsing request information.
[0017] Based on the same inventive concept, a third aspect of the exemplary embodiments of the present disclosure provides a road traffic terminal active identification device, which is applied to a client and includes:
[0018] An encrypted identification code determination module, configured to collect information of a road traffic terminal device to obtain hardware information and a timestamp; generate a symmetric key, and based on the hardware information and the timestamp, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code;
[0019] An encrypted key determination module, configured to receive the proxy public key transmitted by the proxy node; encrypt the symmetric key through the proxy public key to obtain an encrypted symmetric key;
[0020] An identification signature determination module, configured to generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature;
[0021] The parsing result receiving module is configured to transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification parsing result, and receive the terminal identification parsing result generated by the proxy node.
[0022] Based on the same inventive concept, a fourth aspect of the exemplary embodiments of the present disclosure provides a road traffic terminal active identification device, which is applied to a proxy node and includes:
[0023] The signature verification result determination module is configured to generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, and receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client; verify the terminal identification signature based on the client public key to obtain a signature verification result;
[0024] The terminal identification code determination module is configured to decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain a terminal identification code;
[0025] The identification code verification result determination module is configured to verify the terminal identification code to obtain a terminal identification code verification result;
[0026] The request information determination module is configured to determine the authentication information of the terminal identification code, and obtain a parsing request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature;
[0027] The parsing result transmission module is configured to perform format conversion on the parsing request information to obtain an adapted parsing request information; transmit the adapted parsing request information to the identification parsing system; receive the terminal identification parsing result transmitted by the identification parsing system, where the terminal identification parsing result is obtained by the identification parsing system parsing the adapted parsing request information.
[0028] Based on the same inventive concept, a fifth aspect of the exemplary embodiments of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the method described in the first aspect is implemented.
[0029] Based on the same inventive concept, a sixth aspect of the exemplary embodiments of the present disclosure provides a non-transitory computer-readable storage medium, where the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method described in the first aspect.
[0030] Based on the same inventive concept, a seventh aspect of the exemplary embodiments of the present disclosure provides a computer program product, including computer program instructions which, when running on a computer, cause the computer to execute the method described in the first aspect.
[0031] As can be seen from the above, a road traffic terminal identification method provided by the embodiments of the present disclosure is applied to a client, and the method includes:
[0032] Collect information of road traffic terminal devices to obtain hardware information and timestamps; generate a symmetric key, and based on the hardware information and timestamps, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code; receive the proxy public key transmitted by the proxy node; encrypt the symmetric key through the proxy public key to obtain an encrypted symmetric key; generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature; transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification parsing result, and receive the terminal identification parsing result generated by the proxy node.
[0033] A road traffic terminal identification method is applied to a proxy node, and the method includes:
[0034] Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, and receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client; verify the terminal identification signature based on the client public key to obtain a signature verification result; decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain a terminal identification code; verify the terminal identification code to obtain a terminal identification code verification result; determine the authentication information of the terminal identification code, and based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature, obtain a parsing request information; perform format conversion on the parsing request information to obtain an adapted parsing request information; transmit the adapted parsing request information to the identification parsing system; receive the terminal identification parsing result transmitted by the identification parsing system, and transmit the terminal identification parsing result to the client; wherein, the terminal identification parsing result is obtained by the identification parsing system parsing the adapted parsing request information. The present disclosure effectively reduces the pressure on the terminal device in terms of computing and storage, and at the same time realizes the efficient execution of the identification management task, significantly improves the overall security of the system, and greatly improves the efficiency and real-time performance of the identification parsing. Description of the Drawings
[0035] To more clearly illustrate the technical solutions in the present disclosure or related technologies, the following will briefly introduce the drawings required for use in the embodiments or the description of related technologies. Obviously, the drawings in the following description are only embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0036] Figure 1 A schematic diagram of an application scenario of the road traffic terminal identification method provided by an exemplary embodiment of the present disclosure;
[0037] Figure 2 A schematic flowchart of the road traffic terminal identification method provided by an exemplary embodiment of the present disclosure when applied to a client;
[0038] Figure 3 A schematic diagram of the system architecture of the road traffic terminal identification method provided by an exemplary embodiment of the present disclosure;
[0039] Figure 4 A schematic flowchart of the road traffic terminal identification method provided by an exemplary embodiment of the present disclosure when applied to an agent node;
[0040] Figure 5 A schematic diagram of the structure of the road traffic terminal identification device provided by an exemplary embodiment of the present disclosure when applied to a client;
[0041] Figure 6 A schematic diagram of the structure of the road traffic terminal identification device provided by an exemplary embodiment of the present disclosure when applied to an agent node;
[0042] Figure 7 A schematic diagram of the hardware structure of an electronic device provided by an exemplary embodiment of the present disclosure. Detailed implementation manners
[0043] It can be understood that before using the technical solutions disclosed in the embodiments of the present application, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present application should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0044] For example, when responding to a user's active request, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that executes the operations of the technical solutions of the present application according to the prompt message.
[0045] As an optional but non-limiting implementation, in response to receiving an active request from a user, the way to send a prompt message to the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0046] It can be understood that the above notification and the process of obtaining user authorization are only illustrative and do not limit the implementation of the present application. Other ways that comply with relevant laws and regulations can also be applied to the implementation of the present application.
[0047] It can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of corresponding laws, regulations and related provisions.
[0048] To make the purpose, technical solution and advantages of the present disclosure clearer and more understandable, the principles and spirit of the present disclosure will be described below with reference to several exemplary embodiments. It should be understood that these embodiments are only provided to enable those skilled in the art to better understand and then implement the present disclosure, rather than limiting the scope of the present disclosure in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to be able to convey the scope of the present disclosure completely to those skilled in the art.
[0049] In this article, it should be understood that any number of elements in the drawings is for illustration rather than limitation, and any naming is only for distinction and does not have any limiting meaning.
[0050] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meaning understood by those of ordinary skill in the art belonging to the field of the present disclosure. The "first", "second" and similar terms used in the embodiments of the present disclosure do not indicate any order, quantity or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right" are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly. The article "a" or "an" before an element does not exclude the existence of multiple such elements.
[0051] Next, the principles and spirit of the present disclosure will be elaborated in detail with reference to several representative embodiments of the present disclosure.
[0052] As described in the background art, in the related art, due to limited resources, terminal devices are difficult to support complex identifier generation, registration, and resolution operations. At the same time, there are obvious deficiencies in the identifier resolution system in terms of security, resolution efficiency, and real-time performance. Specifically, in actual applications, the existing identifier resolution systems, especially for road traffic terminal devices, face many challenges and limitations. First of all, these systems usually require terminal devices to have certain software and hardware capabilities to support the functions of identifier generation, registration, and resolution. This means that the terminal devices need to be correspondingly modified or upgraded, such as increasing the storage capacity, improving the processor performance, or optimizing the communication module, etc. However, in the road traffic scenario, there are various types of terminal devices, including traffic lights, electronic police, in-vehicle terminals, sensor nodes, etc. These devices often have limited resources and are difficult to meet the high requirements of the identifier resolution system for computing and storage capabilities. For example, many old traffic light devices may only have basic signal control functions and lack sufficient storage space and processing power to support complex identifier management tasks.
[0053] In the road traffic scenario, terminal devices not only have to process massive amounts of data but also face the problems of high-concurrency access and coexistence of multiple protocols. Such a complex working environment poses higher requirements on the identifier resolution system. The existing identifier resolution systems often require terminal devices to have high computing and storage capabilities to cope with these challenges. However, the hardware configurations of many terminal devices are relatively low and are difficult to support complex identifier management functions. For example, some small sensor nodes may only be equipped with low-power processors and limited memory and are unable to efficiently process the complex algorithms and data storage tasks required for identifier generation, registration, and resolution. This dependence on the software and hardware structure of the terminal makes the existing identifier resolution systems face high costs and complexities in actual deployment. The modification or upgrade of terminal devices not only requires a large amount of capital investment but also consumes a large amount of time and manpower for system integration and debugging.
[0054] In addition, the existing identifier resolution systems lack an efficient proxy mechanism in terms of identifier registration, resolution, and service interaction. Usually, terminal devices need to directly interact with the identifier resolution system, which may lead to performance bottlenecks on resource-constrained terminal devices. For example, terminal devices may need to frequently communicate with the identifier resolution server to complete the operations of identifier registration and resolution, which not only increases the burden on terminal devices but also may cause network latency and data transmission errors. Many terminal devices are unable to efficiently complete these operations due to limited resources or poor network conditions, thus affecting the operating efficiency of the entire system.
[0055] Finally, the existing identification and resolution system has limitations in cross-system data sharing. In the road traffic scenario, terminal devices often belong to different systems, such as the signal light system of the traffic management department and the in-vehicle terminal system of vehicle manufacturers. Seamless data interaction needs to be achieved between these systems to support applications such as traffic flow monitoring and vehicle dispatching. However, it is difficult for the existing identification and resolution system to achieve seamless data interaction between different systems. The efficiency is low in terms of identification registration, resolution, and service interaction, making it difficult to meet the actual needs of road traffic terminals. For example, when an in-vehicle terminal needs to interact with a roadside unit, the existing identification and resolution system may not be able to complete the identification resolution quickly and accurately, thus affecting the real-time navigation of vehicles and the dynamic adjustment of traffic signals.
[0056] To solve the above problems, the present disclosure provides a method for identifying road traffic terminals and related device solutions, specifically including:
[0057] A method for identifying road traffic terminals, applied to a client, the method includes:
[0058] Collect information of road traffic terminal devices to obtain hardware information and a timestamp; generate a symmetric key, and based on the hardware information and the timestamp, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code; receive a proxy public key transmitted by a proxy node; encrypt the symmetric key through the proxy public key to obtain an encrypted symmetric key; generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature; transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification resolution result, and receive the terminal identification resolution result generated by the proxy node.
[0059] A method for identifying road traffic terminals, applied to a proxy node, the method includes:
[0060] Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client. Receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client. Verify the terminal identification signature based on the client public key to obtain a signature verification result. Decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code. Verify the terminal identification code to obtain a terminal identification code verification result. Determine the authentication information of the terminal identification code, and based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature, obtain a parsing request information. Perform format conversion on the parsing request information to obtain an adapted parsing request information. Transmit the adapted parsing request information to the identification parsing system. Receive the terminal identification parsing result transmitted by the identification parsing system, and transmit the terminal identification parsing result to the client. Wherein, the terminal identification parsing result is obtained by the identification parsing system parsing the adapted parsing request information. The present disclosure generates and obtains the terminal identification based on the protocol parsing mechanism by adding a client security module, without the need to modify or upgrade the software and hardware structure of the terminal device. This method significantly reduces the computing and storage burden of the terminal device, and thus can efficiently complete the identification management task without increasing the hardware cost.
[0061] The present disclosure also ensures the security of the terminal device during the processes of identification generation, registration, and parsing through a lightweight security protocol and an encryption mechanism. At the same time, based on the proxy mechanism, the terminal device does not need to directly interact with the identification parsing system, further reducing the security risk. This design effectively prevents security threats such as forged identification and data tampering, and improves the overall security of the system.
[0062] Finally, the present disclosure provides a method for identification registration, parsing, and service interaction based on the proxy mechanism. Through the efficient processing ability of the proxy node, the terminal device does not need to directly participate in complex identification management operations, thus significantly improving the efficiency and real-time performance of identification parsing.
[0063] After introducing the basic principle of the present disclosure, the following specifically introduces various non-limiting implementation manners of the present disclosure.
[0064] Refer to Figure 1 , which is a schematic diagram of an application scenario of the road traffic terminal identification method provided by an exemplary embodiment of the present disclosure.
[0065] In this application scenario, it includes a client 101, a proxy node 102, and an identification parsing system 103. Among them, the client 101, the proxy node 102, and the identification parsing system 103 can all be connected through a wired or wireless communication network to achieve data interaction.
[0066] The client 101 can be an electronic device near the user side with data transmission, multimedia input / output functions, including but not limited to desktop computers, mobile phones, mobile computers, tablet computers, media players, smart wearable devices, personal digital assistants (PDAs), or other electronic devices capable of implementing the above functions. The electronic device may include a processor and a display screen with touch input function, the display screen is used to present a graphical user interface, the graphical user interface can display an application interface, and the processor is used to process application data, generate a graphical user interface, and control the display of the graphical user interface on the display screen.
[0067] Both the proxy node 102 and the identity resolution system 103 can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms.
[0068] In some exemplary embodiments, the road traffic terminal identification method can run on the client 101 or the proxy node 102.
[0069] When the road traffic terminal identification method runs on the proxy node 102, the proxy node 102 is used to provide the road traffic terminal identification service to the user of the client 101.
[0070] The client 101 collects information on the road traffic terminal device to obtain hardware information and a timestamp; the client 101 generates a symmetric key, and the client 101 obtains a terminal identification code based on the hardware information and the timestamp; the client 101 encrypts the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code.
[0071] The client 101 receives the proxy public key transmitted by the proxy node 102; the client 101 encrypts the symmetric key through the proxy public key to obtain an encrypted symmetric key.
[0072] The client 101 generates a client public key and a client private key, and the client 101 signs the terminal identification code based on the client private key to obtain a terminal identification signature.
[0073] The client 101 transmits the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node 102, so that the proxy node 102 generates a terminal identification resolution result, and the client 101 receives the terminal identification resolution result generated by the proxy node 102;
[0074] The proxy node 102 generates a proxy public key and a proxy private key. The proxy node 102 transmits the proxy public key to the client 101. The proxy node 102 receives the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client 101. The proxy node 102 verifies the terminal identification signature based on the client 101 public key to obtain a signature verification result;
[0075] The proxy node 102 decrypts the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code;
[0076] The proxy node 102 verifies the terminal identification code to obtain a terminal identification code verification result;
[0077] The proxy node 102 determines the authentication information of the terminal identification code. The proxy node 102 obtains a parsing request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature;
[0078] The proxy node 102 performs format conversion on the parsing request information to obtain an adapted parsing request information. The proxy node 102 transmits the adapted parsing request information to the identification resolution system 103. The proxy node 102 receives the terminal identification resolution result transmitted by the identification resolution system 103, and the proxy node 102 transmits the terminal identification resolution result to the client 101; wherein, the terminal identification resolution result is obtained by the identification resolution system 103 parsing the adapted parsing request information.
[0079] It should be noted that the above application scenarios are only shown for the convenience of understanding the spirit and principle of the present disclosure, and the embodiments of the present disclosure are not limited in this regard. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.
[0080] Reference Figure 2 , a road traffic terminal identification method, which is applied to a client, and the method includes the following steps:
[0081] Step S210: Collect information from road traffic terminal devices to obtain hardware information and timestamps; generate a symmetric key, and based on the hardware information and timestamps, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code.
[0082] Specifically, when implementing, the method for collecting information from road traffic terminal devices to obtain hardware information and timestamps is as follows:
[0083] Reference Figure 3 , in order to collect necessary data from road traffic terminal devices, the road traffic terminal identification system constructs a perception layer. The perception layer can collect data from the vehicle side and the road side. The active identification carriers on the vehicle side can actively send identification information to communicate with other devices. For example, the OBU (On-Board Unit) active identification body can actively broadcast vehicle ID, current location, etc. information through communication technologies such as Wi-Fi and Bluetooth. The T-BOX (Telematics BOX) active identification body integrates multiple communication and positioning functions, can connect to external systems through the mobile network, and transmit vehicle data to the cloud platform or roadside devices by monitoring the vehicle status. The various active identification carriers on the road side actively emit signals based on their own perception capabilities for other devices to identify. For example, the RSU (Road Side Unit) active identification body actively exchanges information with vehicle-mounted devices through wireless communication protocols. The traffic light controller and traffic signal system actively send traffic management information through sensors and communication devices, and transmit relevant information to other devices through sensors. The perception layer contains a large number of heterogeneous road traffic devices, and these road traffic devices actively transmit device information through their respective software.
[0084] The upper layer of the perception layer is the platform layer. The platform layer includes a client, a proxy node, and an identification resolution platform, where the client contains a client security module. The client security module collects the device information obtained from the perception layer and generates a unique identifier for the device locally and encrypts it for transmission to the proxy node on the premise of ensuring the data security and light weight of road traffic devices. The proxy node forwards the identification registration request to the identification resolution system for identification registration through the proxy mechanism. The identification resolution system adopts the Handle identification resolution system. After receiving the identification registration request, the identification resolution platform performs identification registration and returns a registration confirmation. Similarly, when performing identification resolution, the client security module initiates a resolution request and forwards the resolution request to the identification resolution platform through the proxy node, and the platform returns the resolution result.
[0085] Among them, the perception layer will collect vehicle information and road side information through active identification carriers to obtain device-related information and then obtain hardware information and timestamps .
[0086] In the above exemplary embodiments, the methods for obtaining hardware information and timestamps are introduced. Next, the method for obtaining the terminal identification code will be introduced:
[0087] In this exemplary embodiment, based on the hardware information and the timestamp, obtaining the terminal identification code includes:
[0088] Concatenate the hardware information and the timestamp to obtain the original identification data;
[0089] Calculate the original identification data based on the hash algorithm to obtain the terminal identification code.
[0090] During specific implementation, the method of concatenating the hardware information and the timestamp to obtain the original identification data, and calculating the original identification data based on the hash algorithm to obtain the terminal identification code:
[0091] Refer to Figure 3 , the client security module concatenates the unique hardware information of the device and the timestamp together to obtain the original identification data, and then uses the hash algorithm SHA-256 to calculate and generate the unique identifier i.e., the terminal identification code.
[0092] .
[0093] In the above exemplary embodiments, the method for obtaining the terminal identification code is introduced. Next, the method for obtaining the encrypted terminal identification code will be introduced:
[0094] In this exemplary embodiment, based on the symmetric key, encrypting the terminal identification code to obtain the encrypted terminal identification code includes:
[0095] Encrypt the symmetric key based on the asymmetric encryption algorithm to obtain the symmetric encryption key;
[0096] Encrypt the terminal identification code with the symmetric encryption key to obtain the encrypted terminal identification code.
[0097] During specific implementation, the method of encrypting the symmetric key based on the asymmetric encryption algorithm to obtain the symmetric encryption key, and encrypting the terminal identification code with the symmetric encryption key to obtain the encrypted terminal identification code:
[0098] Refer to Figure 3 , the client will generate a symmetric key, where is used to represent the symmetric key generated for the client, and then encrypt the symmetric key, where It is used to represent the symmetric encryption key for client use. To ensure the security and integrity of the generated identifier during transmission, the client security module encrypts the data using the AES symmetric encryption algorithm and protects the key using an asymmetric encryption algorithm (such as RSA).
[0099]
[0100] Among them, It is used to represent the encrypted terminal identification code.
[0101] Step S220: Receive the proxy public key transmitted by the proxy node; encrypt the symmetric key with the proxy public key to obtain the encrypted symmetric key.
[0102] In specific implementation, the method of receiving the proxy public key transmitted by the proxy node:[[]]
[0103] Refer to Figure 3 , the client receives the proxy public key generated by the proxy node transmitted by the proxy node, where It is used to represent the proxy public key,
[0104] In specific implementation, the method of encrypting the symmetric key with the proxy public key to obtain the encrypted symmetric key:[[]]
[0105] Refer to Figure 3 , when communicating between the client and the proxy node, use the RSA asymmetric encryption algorithm to exchange encryption keys.
[0106]
[0107] Among them, It is used to represent the encrypted symmetric key.
[0108] The client encrypts the asymmetric key with RSA and sends it to the proxy node. The proxy node decrypts it with its private key and obtains the symmetric key. Subsequently, both parties can use this symmetric key for secure communication.
[0109] Step S230: Generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain the terminal identification signature.
[0110] In specific implementation, the method of generating a client public key and a client private key, and signing the terminal identification code based on the client private key to obtain the terminal identification signature:[[]]
[0111] Refer to Figure 3, To ensure the integrity of data and the authenticity of the source, the client security module uses digital signatures to authenticate the sent identification information. The digital signature is signed with the client's private key, and the receiving end verifies it with the public key. The client security module signs the generated identification with the client's private key.
[0112]
[0113] Among them, is used to represent signing the terminal identification, is used to represent the client's private key.
[0114] Step S240: Transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification resolution result, and receive the terminal identification resolution result generated by the proxy node.
[0115] Specifically, when implementing, the way to transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification resolution result, and receive the terminal identification resolution result generated by the proxy node:
[0116] Refer to Figure 3 , The client transmits the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification resolution result, and finally the client will receive the terminal identification resolution result sent by the proxy node.
[0117] Refer to Figure 4 , A road traffic terminal identification method, applied to a proxy node, the method includes the following steps:
[0118] Step S410: Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client; verify the terminal identification signature based on the client public key to obtain a signature verification result.
[0119] Specifically, when implementing, the way to generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client:
[0120] Refer to Figure 3, when the proxy node interacts with the client, the proxy node first generates a proxy public key and a paired proxy private key. Subsequently, the proxy node transmits the proxy public key to the client for encrypting the symmetric key of the client and retains the proxy private key, and then receives the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client.
[0121] Specifically, when implementing, the method for verifying the terminal identification signature based on the client public key to obtain a signature verification result:
[0122] The receiving end, i.e., the proxy node, uses the public key of the client for signature verification to ensure that the identification data has not been tampered with.
[0123] 。
[0124] Among them, is used to represent the signature verification result. After the signature verification result passes, the proxy node can perform subsequent operations.
[0125] Step S420, decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code.
[0126] In this exemplary embodiment, decrypting the encrypted terminal identification code based on the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code includes:
[0127] Decrypt the encrypted symmetric key based on the signature verification result and the proxy private key to obtain the symmetric key;
[0128] Decrypt the encrypted terminal identification code based on the symmetric key to obtain the terminal identification code.
[0129] Specifically, when implementing, decrypt the encrypted symmetric key based on the signature verification result and the proxy private key to obtain the symmetric key; the method for decrypting the encrypted terminal identification code based on the symmetric key to obtain the terminal identification code:
[0130] Refer to Figure 3 , after the proxy node receives the identification registration request sent by the client , since the registration request includes encrypted identification data, device information, and a digital signature, decrypt the request data using the public key of the client.
[0131]
[0132] Among them Represents the plaintext data obtained after the proxy node decrypts, which contains the original information in the encryption transmission process, including the terminal identification code ; Used to represent the proxy private key.
[0133] Step S430: Verify the terminal identification code to obtain the verification result of the terminal identification code.
[0134] In specific implementation, the method for verifying the terminal identification code to obtain the verification result of the terminal identification code:
[0135] Refer to Figure 3 , the proxy node verifies the digital signature generated by the client private key to ensure the integrity and legality of the data. If the verification is successful, subsequent operations are performed.
[0136]
[0137] Among them, Is a status identifier used to indicate whether the data, request, or identification is legal, valid, or verified, that is, the verification result of the terminal identification code.
[0138] Step S440: Determine the authentication information of the terminal identification code, and obtain the parsing request information based on the authentication information, the verification result of the terminal identification code, the terminal identification code, and the terminal identification signature.
[0139] Refer to Figure 3 , after the proxy node verifies the request, it will forward the registration request to the identity resolution platform for identity registration. The proxy node prepares to forward other necessary authentication information after decryption To the identity resolution platform together.
[0140]
[0141] Among them Used to represent the parsing request information.
[0142] The proxy node prepares to transfer this information to the resolution platform through an appropriate protocol according to the requirements of the identity resolution platform.
[0143] Step S450: Perform format conversion on the parsing request information to obtain the adapted parsing request information; transmit the adapted parsing request information to the identity resolution system; receive the terminal identity resolution result transmitted by the identity resolution system, and transmit the terminal identity resolution result to the client; among them, the terminal identity resolution result is obtained by the identity resolution system parsing the adapted parsing request information.
[0144] In this exemplary embodiment, format conversion is performed on the parsing request information to obtain the adapted parsing request information, including:
[0145] Based on the protocol adaptation function, format conversion is performed on the parsing request information to obtain the adapted parsing request information.
[0146] Specifically, when implemented, the method of performing format conversion on the parsing request information based on the protocol adaptation function to obtain the adapted parsing request information:
[0147] Refer to Figure 3 , after the proxy node receives the parsing request from the client, protocol adaptation and forwarding operations are performed. The proxy node forwards the parsing request to the identity resolution platform.
[0148]
[0149] Where is the decrypted identity resolution request, is the protocol adaptation function, which converts the parsing request into a format supported by the identity resolution platform, is used to represent the adapted parsing request information.
[0150] Specifically, when implemented, the terminal identity resolution result transmitted by the identity resolution system is received, and the terminal identity resolution result is transmitted to the client; wherein, the terminal identity resolution result is obtained by the identity resolution system parsing the adapted parsing request information.
[0151] Refer to Figure 3 , after the identity resolution system finishes parsing the adapted parsing request information, a terminal identity resolution result will be generated; the terminal identity resolution result will be returned to the proxy node, and finally the proxy node will return the terminal identity resolution result to the client.
[0152] It should be noted that the method of this embodiment of the present disclosure can be executed by a single device, such as a computer or a server, etc. The method of this embodiment can also be applied to a distributed scenario, and multiple devices cooperate with each other to complete it. In this case of a distributed scenario, one of the multiple devices can only execute one or more steps of the method of this embodiment of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0153] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0154] Based on the same inventive concept, corresponding to any of the above-described method embodiments, the present disclosure also provides a road traffic terminal active identification device.
[0155] Referring to Figure 5 , the road traffic terminal active identification device, which is applied to a client, includes:
[0156] An encrypted identification code determination module 510, configured to collect information of a road traffic terminal device to obtain hardware information and a timestamp; generate a symmetric key, and based on the hardware information and the timestamp, obtain a terminal identification code; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code;
[0157] An encrypted key determination module 520, configured to receive a proxy public key transmitted by a proxy node; encrypt the symmetric key through the proxy public key to obtain an encrypted symmetric key;
[0158] An identification signature determination module 530, configured to generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature;
[0159] A parsing result receiving module 540, configured to transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification parsing result, and receive the terminal identification parsing result generated by the proxy node.
[0160] In this exemplary embodiment, the encrypted identification code determination module 510 is specifically configured to:
[0161] Collect information of a road traffic terminal device to obtain hardware information and a timestamp; generate a symmetric key, splice the hardware information and the timestamp to obtain original identification data; calculate the original identification data based on a hash algorithm to obtain the terminal identification code; encrypt the symmetric key based on an asymmetric encryption algorithm to obtain a symmetric encryption key; encrypt the terminal identification code through the symmetric encryption key to obtain the encrypted terminal identification code.
[0162] In this exemplary embodiment, the encryption key determination module 520 is specifically configured to:
[0163] Receive the proxy public key transmitted by the proxy node; encrypt the symmetric key with the proxy public key to obtain the encrypted symmetric key.
[0164] In this exemplary embodiment, the identification signature determination module 530 is specifically configured to:
[0165] Generate a client public key and a client private key, and sign the terminal identification code with the client private key to obtain the terminal identification signature.
[0166] In this exemplary embodiment, the parsing result receiving module 540 is specifically configured to:
[0167] Transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature to the proxy node, so that the proxy node generates a terminal identification parsing result, and receive the terminal identification parsing result generated by the proxy node.
[0168] Reference Figure 6 , the active identification device for road traffic terminals, which is applied to the proxy node, includes:
[0169] The signature verification result determination module 610 is configured to generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, and receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identification signature transmitted by the client; verify the terminal identification signature with the client public key to obtain a signature verification result;
[0170] The terminal identification code determination module 620 is configured to decrypt the encrypted terminal identification code with the proxy private key, the signature verification result, and the encrypted symmetric key to obtain the terminal identification code;
[0171] The identification code verification result determination module 630 is configured to verify the terminal identification code to obtain a terminal identification code verification result;
[0172] The request information determination module 640 is configured to determine the authentication information of the terminal identification code, and obtain a parsing request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature;
[0173] The parsing result transmission module 650 is configured to perform format conversion on the parsing request information to obtain the adapted parsing request information; transmit the adapted parsing request information to the identity resolution system; and receive the terminal identity resolution result transmitted by the identity resolution system, where the terminal identity resolution result is obtained by the identity resolution system parsing the adapted parsing request information.
[0174] In this exemplary embodiment, the signature verification result determination module 610 is specifically configured to:
[0175] Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, and receive the client public key, the encrypted terminal identification code, the encrypted symmetric key, and the terminal identity signature transmitted by the client; verify the terminal identity signature based on the client public key to obtain the signature verification result.
[0176] In this exemplary embodiment, the terminal identification code determination module 620 is specifically configured to:
[0177] Decrypt the encrypted symmetric key based on the signature verification result and the proxy private key to obtain the symmetric key; decrypt the encrypted terminal identification code based on the symmetric key to obtain the terminal identification code.
[0178] In this exemplary embodiment, the identification code verification result determination module 630 is specifically configured to:
[0179] Verify the terminal identification code to obtain the terminal identification code verification result.
[0180] In this exemplary embodiment, the request information determination module 640 is specifically configured to:
[0181] Determine the authentication information of the terminal identification code, and obtain the parsing request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identity signature.
[0182] In this exemplary embodiment, the parsing result transmission module 650 is specifically configured to:
[0183] Perform format conversion on the parsing request information based on the protocol adaptation function to obtain the adapted parsing request information; transmit the adapted parsing request information to the identity resolution system; receive the terminal identity resolution result transmitted by the identity resolution system, and transmit the terminal identity resolution result to the client; where the terminal identity resolution result is obtained by the identity resolution system parsing the adapted parsing request information.
[0184] For the convenience of description, when describing the above device, it is divided into various modules according to functions for separate description. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0185] The device of the above embodiment is used to implement the corresponding road traffic terminal identification method in any one of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0186] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the road traffic terminal identification method described in any one of the above embodiments.
[0187] Figure 7 FIG. shows a more specific schematic diagram of the hardware structure of the electronic device provided in this embodiment. The device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.
[0188] The processor 1010 can be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0189] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1020 and called and executed by the processor 1010.
[0190] The input / output interface 1030 is used to connect to the input / output module to achieve information input and output. The input / output module can be configured as a component in the device (not shown in the figure), or can be externally connected to the device to provide corresponding functions. Among them, the input devices can include keyboards, mice, touchscreens, microphones, various sensors, etc., and the output devices can include displays, speakers, vibrators, indicator lights, etc.
[0191] The communication interface 1040 is used to connect to the communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module can achieve communication through wired means (such as USB, network cable, etc.), or can also achieve communication through wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0192] The bus 1050 includes a path to transmit information between various components of the device (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).
[0193] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, this device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0194] The electronic device of the above embodiment is used to implement the corresponding road traffic terminal identification method in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0195] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides a non-transitory computer-readable storage medium, and the non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause the computer to execute the road traffic terminal identification method as described in any of the foregoing embodiments.
[0196] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0197] The above non-transitory computer-readable storage medium can be any available medium or data storage device accessible by a computer, including but not limited to magnetic memory (such as floppy disks, hard disks, magnetic tapes, magneto-optical discs (MO), etc.), optical memory (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memory (such as ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drives (SSD)), etc.
[0198] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the road traffic terminal identification method described in any one of the above exemplary method embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0199] Based on the same inventive concept, corresponding to the road traffic terminal identification method described in any of the above embodiments, the present disclosure also provides a computer program product, which includes computer program instructions. In some embodiments, the computer program instructions can be executed by one or more processors of the computer to cause the computer and / or the processor to execute the road traffic terminal identification method. Corresponding to the execution subjects corresponding to the steps in each embodiment of the road traffic terminal identification method, the processor executing the corresponding steps can belong to the corresponding execution subject.
[0200] The computer program product of the above embodiment is used to cause the computer and / or the processor to execute the road traffic terminal identification method described in any of the above embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0201] As is known to those skilled in the art, the embodiments of the present disclosure can be implemented as a system, a method, or a computer program product. Therefore, the present disclosure can be specifically implemented in the following forms, namely: all hardware, all software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as "circuit", "module", or "system". In addition, in some embodiments, the present disclosure can also be implemented in the form of a computer program product in one or more computer-readable media, which contain computer-readable program code.
[0202] Any combination of one or more computer-readable media can be adopted. The computer-readable media can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive) of the computer-readable storage medium can include, for example: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0203] The computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0204] The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to wireless, wire, optical cable, RF, etc., or any suitable combination of the above.
[0205] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0206] It should be understood that each block of the flowchart and / or block diagram, and combinations of blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine. These computer program instructions, when executed by a computer or other programmable data processing device, produce a means for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.
[0207] These computer program instructions can also be stored in a computer-readable medium that can cause a computer or other programmable data processing device to work in a particular manner. In this way, the instructions stored in the computer-readable medium produce a product that includes an instruction means for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.
[0208] The computer program instructions can also be loaded onto a computer, other programmable data processing device, or other device, such that a series of operation steps are performed on the computer, other programmable data processing device, or other device to produce a computer-implemented process. Thus, the instructions executed on the computer or other programmable device can provide a process for implementing the functions / operations specified in the blocks of the flowchart and / or block diagram.
[0209] In addition, although the operations of the method of this disclosure are described in a specific order in the drawings, this does not require or imply that the operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart can be changed in the order of execution. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution.
[0210] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code, and the above-mentioned module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0211] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of the two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0212] Those of ordinary skill in the art should understand that: the discussion of any of the above embodiments is only exemplary and is not intended to imply that the scope of the present application (including the claims) is limited to these examples; under the concept of the present application, the technical features between the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and they are not provided in detail for the sake of brevity.
[0213] In addition, for the sake of simplicity of description and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. In addition, the device may be shown in the form of a block diagram in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (that is, these details should be completely within the understanding of those skilled in the art). In the case where specific details (such as circuits) are set forth to describe the exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0214] Although the present application has been described in connection with specific embodiments thereof, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art in light of the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0215] Embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Accordingly, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the embodiments of the present application shall be included within the protection scope of the present application.
[0216] Although the spirit and principles of the present disclosure have been described with reference to several specific embodiments, it should be understood that the present disclosure is not limited to the specific embodiments disclosed, and the division of each aspect does not mean that the features in these aspects cannot be combined for benefit. This division is only for convenience of expression. The present disclosure is intended to cover various modifications and equivalent arrangements included within the spirit and scope of the appended claims. The scope of the appended claims is to be accorded the broadest interpretation so as to encompass all such modifications and equivalent structures and functions.
Claims
1. A road traffic terminal identification method, characterized in that: Applied to the client, including: Collecting information from road traffic terminal equipment to obtain hardware information and a timestamp; generating a symmetric key to obtain a terminal identification code based on the hardware information and the timestamp; encrypting the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code; Receiving a proxy public key transmitted by a proxy node; encrypting the symmetric key by using the proxy public key to obtain an encrypted symmetric key; Generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature; The client public key, the encrypted terminal identification code, the encrypted symmetric key and the terminal identification signature are transmitted to the proxy node so that the proxy node generates a terminal identification resolution result, and the terminal identification resolution result generated by the proxy node is received.
2. The method according to claim 1, characterized in that The obtaining of the terminal identification code based on the hardware information and the timestamp includes: Concatenating the hardware information and the timestamp to obtain original identification data; The original identification data is calculated based on a hash algorithm to obtain the terminal identification code.
3. The method according to claim 1, characterized in that The step of encrypting the terminal identification code based on the symmetric key to obtain the encrypted terminal identification code includes: Encrypting the symmetric key based on an asymmetric encryption algorithm to obtain a symmetric encryption key; The terminal identification code is encrypted using the symmetric encryption key to obtain the encrypted terminal identification code.
4. A road traffic terminal identification method, characterized in that: Applicable to proxy nodes, including: Generate a proxy public key and a proxy private key, and transmit the proxy public key to the client, receive the client public key, the encrypted terminal identification code, the encrypted symmetric key and the terminal identification signature transmitted by the client; verify the terminal identification signature based on the client public key to obtain a signature verification result; Decrypting the encrypted terminal identification code based on the proxy private key, the signature verification result and the encrypted symmetric key to obtain the terminal identification code; Verifying the terminal identification code to obtain a terminal identification code verification result; Determine authentication information of the terminal identification code, and obtain resolution request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature; Performing format conversion on the resolution request information to obtain adapted resolution request information; transmitting the adapted resolution request information to an identification resolution system; receiving a terminal identification resolution result transmitted by the identification resolution system, and transmitting the terminal identification resolution result to a client; wherein the terminal identification resolution result is obtained by the identification resolution system parsing the adapted resolution request information.
5. The method according to claim 4, characterized in that The decrypting the encrypted terminal identification code based on the proxy private key, the signature verification result and the encrypted symmetric key to obtain the terminal identification code includes: Decrypting the encrypted symmetric key based on the signature verification result and the proxy private key to obtain a symmetric key; The encrypted terminal identification code is decrypted based on the symmetric key to obtain the terminal identification code.
6. The method according to claim 4, characterized in that The format conversion of the resolution request information to obtain adapted resolution request information includes: The format of the resolution request information is converted based on the protocol adaptation function to obtain the adapted resolution request information.
7. A road traffic terminal active identification device, characterized in that: Applied to the client, including: The encryption identification code determination module is configured to collect information from the road traffic terminal equipment to obtain hardware information and a timestamp; generate a symmetric key to obtain a terminal identification code based on the hardware information and the timestamp; encrypt the terminal identification code based on the symmetric key to obtain an encrypted terminal identification code; The encryption key determination module is configured to receive the proxy public key transmitted by the proxy node; encrypt the symmetric key by using the proxy public key to obtain the encrypted symmetric key; An identification signature determination module is configured to generate a client public key and a client private key, and sign the terminal identification code based on the client private key to obtain a terminal identification signature; The resolution result receiving module is configured to transmit the client public key, the encrypted terminal identification code, the encrypted symmetric key and the terminal identification signature to the proxy node so that the proxy node generates a terminal identification resolution result, and receive the terminal identification resolution result generated by the proxy node.
8. A road traffic terminal active identification device, characterized in that: Applicable to proxy nodes, including: The signature verification result determination module is configured to generate a proxy public key and a proxy private key, transmit the proxy public key to the client, receive the client public key, the encrypted terminal identification code, the encrypted symmetric key and the terminal identification signature transmitted by the client; verify the terminal identification signature based on the client public key to obtain a signature verification result; a terminal identification code determination module, configured to decrypt the encrypted terminal identification code based on the proxy private key, the signature verification result and the encrypted symmetric key to obtain the terminal identification code; an identification code verification result determination module, configured to verify the terminal identification code to obtain a terminal identification code verification result; a request information determination module configured to determine authentication information of the terminal identification code, and obtain resolution request information based on the authentication information, the terminal identification code verification result, the terminal identification code, and the terminal identification signature; The resolution result transmission module is configured to perform format conversion on the resolution request information to obtain adapted resolution request information; transmit the adapted resolution request information to the identity resolution system; and receive the terminal identity resolution result transmitted by the identity resolution system, wherein the terminal identity resolution result is obtained by the identity resolution system parsing the adapted resolution request information.
9. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 6 is implemented.
10. A non-transitory computer-readable storage medium, characterized in that: The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Dynamic encryption method and device based on random key and symmetric encryption, and medium
CN114866242A
Federal learning method based on identity-based homomorphic signature and related equipment
CN118133355A