Data transmission method and apparatus, data transmission system
Patent Information
- Application Number
- CN202510111963.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2045-01-23
AI Technical Summary
[0004]但是,现有的量子密钥技术中的组网和密钥传输方式对传统系统的改造幅度较大,经济成本较高;而传统的加密方式所适用的组网和密钥传输方式已不再适用量子密钥技术,且传输安全风险较高
[0032] The data transmission method provided in this application embodiment uses the same sequence number as the service key for both the vehicle and the ground, and the sequence number is a truly random number. This enables secure distribution of quantum keys in vehicle-to-ground communication applications, improving the security of vehicle-to-ground transmission. Furthermore, based on the applicable networking schemes, this method reduces the extent of modifications to existing systems and minimizes unnecessary overhead.
Smart Images

Figure CN119945786B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, specifically to a data transmission method and apparatus, and a data transmission system. Background Technology
[0002] With the continuous improvement of informatization and intelligence, rail vehicles have increasingly higher requirements for communication security, and traditional encryption methods are no longer able to meet the growing security needs.
[0003] Quantum key distribution (QKD) technology, based on the fundamental principles of quantum mechanics, leverages the uncertainty and no-cloning properties of quantum states to achieve unconditionally secure key transmission, thus providing a revolutionary security guarantee for rail vehicle communication. In rail vehicle communication networks, QKD effectively prevents security threats such as hacker attacks, information leaks, and malicious tampering, ensuring the stability and reliability of train control systems, passenger service systems, and emergency rescue communications. Furthermore, with the rapid development of my country's rail transit industry, the requirements for rail vehicle communication security are becoming increasingly stringent. The application of QKD will help improve the overall security level of my country's rail transit system, laying a solid foundation for its continued development.
[0004] However, existing quantum key distribution technologies require significant modifications to traditional systems in terms of networking and key transmission, resulting in high economic costs. Furthermore, the networking and key transmission methods used in traditional encryption are no longer suitable for quantum key distribution technologies and pose high transmission security risks. Therefore, a networking and key transmission method is needed that can effectively prevent potential transmission security risks and achieve system security upgrades at a lower cost. Summary of the Invention
[0005] To address one of the aforementioned technical deficiencies, this application provides a data transmission method, apparatus, and system.
[0006] According to a first aspect of the embodiments of this application, a data transmission method is provided, applied to a terrestrial terminal device; the method includes:
[0007] A true random number is generated as the first key sequence number and sent to the vehicle terminal device. The ground terminal device and the vehicle terminal device are configured with the same preset key, and the key corresponding to the first key sequence number in the preset key is used as the first key.
[0008] Generate a random digital tag encrypted with the first key and send it to the vehicle terminal device;
[0009] After receiving the decryption and loading feedback of the random digital tag from the vehicle terminal device, a true random number is generated as the second key sequence number and sent to the vehicle terminal device. The key corresponding to the second key sequence number in the preset key is used as the second key, and the second key is used to perform encrypted communication with the vehicle terminal device.
[0010] In an optional embodiment of this application, after receiving the decryption loading feedback of the random digital tag from the vehicle-mounted terminal device, a truly random number is generated as the second key sequence number and sent to the vehicle-mounted terminal device. The step of using the key corresponding to the second key sequence number in the preset key as the second key and using the second key to perform encrypted communication with the vehicle-mounted terminal device further includes:
[0011] The decryption and loading feedback includes the vehicle terminal device's identity information and the hash algorithm calculation value of the random digital tag. The vehicle terminal device's identity information is verified. If the verification is successful, a second key is generated and used to conduct encrypted communication with the vehicle terminal device.
[0012] In an optional embodiment of this application, it further includes:
[0013] Upon receiving a key charging request from the vehicle-mounted terminal device, the key is wirelessly charged to the vehicle-mounted terminal device.
[0014] According to a second aspect of the embodiments of this application, a data transmission method is provided, applied to an in-vehicle terminal device, the method comprising:
[0015] The vehicle-mounted terminal equipment receives the first key sequence number sent by the ground terminal equipment. The vehicle-mounted terminal equipment and the ground terminal equipment are configured with the same preset key. The key corresponding to the first key sequence number in the preset key is used as the first key.
[0016] Receive a random digital tag encrypted with a first key sent by a ground terminal device, decrypt the random digital tag, load and store it in a static random access memory, and send decryption and loading feedback to the ground terminal device;
[0017] The system receives the second key sequence number sent by the ground terminal equipment, uses the key corresponding to the second key sequence number in the preset key as the second key, and uses the second key to conduct encrypted communication with the ground terminal equipment.
[0018] In an optional embodiment of this application, the steps of receiving a random digital tag encrypted with a first key sent by the vehicle-mounted terminal device, decrypting the random digital tag and loading it, and sending decryption and loading feedback to the ground terminal device further include:
[0019] The vehicle-mounted terminal device's identity information and a random digital tag are hashed together, and the hash value is encrypted with a first key and then sent to the ground terminal device.
[0020] In an optional embodiment of this application, it further includes:
[0021] When the number of preset keys is lower than the set number, a key refill request is sent to the ground terminal equipment;
[0022] Receive the key sent by the ground terminal equipment in accordance with the key filling request.
[0023] According to a third aspect of the embodiments of this application, a data transmission apparatus is provided, including a processor and a memory storing program instructions, wherein the processor is configured to execute a data transmission method as described in any one of the first and second aspects of the embodiments of this application when executing the program instructions.
[0024] According to a fourth aspect of the embodiments of this application, a data transmission system is provided, comprising:
[0025] Ground terminal equipment includes a ground data center, a quantum key management platform, and a communication encryption module;
[0026] Vehicle-mounted terminal equipment, communicating with ground terminal equipment; and,
[0027] The data transmission apparatus of the third aspect of the present application is installed on ground terminal equipment and vehicle-mounted terminal equipment.
[0028] In an optional embodiment of this application, it further includes:
[0029] The quantum key distribution center stores the identity information of the vehicle-mounted terminal equipment and communicates with the ground terminal equipment. It is used to verify the identity information of the vehicle-mounted terminal equipment received by the ground terminal equipment according to the request sent by the ground terminal equipment. It also stores keys, which are used to fill the keys of the vehicle-mounted terminal equipment through the ground terminal equipment according to the request sent by the ground terminal equipment.
[0030] In an optional embodiment of this application, it further includes:
[0031] The quantum encryption device production terminal communicates with the quantum key service center to produce keys and, upon receiving a request from the quantum key service center, sends the key to the quantum key service center.
[0032] The data transmission method provided in this application embodiment uses the same sequence number as the service key for both the vehicle and the ground, and the sequence number is a truly random number. This enables secure distribution of quantum keys in vehicle-to-ground communication applications, improving the security of vehicle-to-ground transmission. Furthermore, based on the applicable networking schemes, this method reduces the extent of modifications to existing systems and minimizes unnecessary overhead. Attached Figure Description
[0033] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0034] Figure 1 This is a schematic diagram of a data transmission system provided in an embodiment of this application;
[0035] Figure 2 This is a schematic diagram of a data transmission method provided in an embodiment of this application;
[0036] Figure 3 This is a schematic diagram of another data transmission method provided in an embodiment of this application;
[0037] Figure 4 This is a schematic diagram of a data transmission device provided in an embodiment of this application. Detailed Implementation
[0038] To make the technical solutions and advantages of the embodiments of this application clearer, the exemplary embodiments of this application will be described in further detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not an exhaustive list of all embodiments. It should be noted that, unless otherwise specified, the embodiments and features in the embodiments of this application can be combined with each other.
[0039] This application proposes a data transmission system, comprising:
[0040] The system comprises ground terminal equipment, vehicle-mounted terminal equipment communicating with the ground terminal equipment, and processors installed in both the vehicle-mounted and ground terminal equipment. The ground terminal equipment includes a ground data center, a quantum key management platform, and a communication encryption module.
[0041] In some embodiments of this application, a quantum key service center is also included, which stores the identity information and keys of the vehicle-mounted terminal equipment and is connected to the ground terminal equipment; a quantum encryption device production terminal is connected to the quantum key service center and is used to produce keys.
[0042] In some embodiments of this application, the ground terminal equipment is an operations ground center, and the vehicle-mounted terminal equipment is a vehicle-mounted encrypted terminal.
[0043] Figure 1 For a schematic diagram of a data transmission system provided in an embodiment of this application, please refer to [link / reference]. Figure 1 :
[0044] Quantum key service centers include:
[0045] Authentication module: Enables identity authentication between the quantum key service center and the vehicle-mounted encryption terminal.
[0046] The central and branch center modules enable data exchange between the quantum key service center and the branch centers at the operation end, ensuring the synchronization of information between the two ends.
[0047] Data storage module: Stores key data and vehicle identification information for all vehicle depots.
[0048] Server security modules include perimeter protection, security auditing, zero-trust management, and disaster recovery, which strengthen the security of server systems.
[0049] Quantum key distribution and management module: Manages keys for all rail vehicles, including generating quantum keys through QRNG (Quantum Random Number Generator), wirelessly recharging keys using quantum-resistant algorithms, emergency operations to stop or destroy quantum keys in special circumstances, and monitoring the number, cycle, and time period of wireless recharging for vehicles to detect potential problems in advance.
[0050] Algorithm engine module: Wireless key filling provides symmetric national cryptographic encryption algorithms, and provides symmetric encryption and hash algorithms for identity authentication of vehicle-mounted devices.
[0051] Communication encryption module: Employing QKD (quantum key distribution) encryption or quantum IPsec (Internet Protocol Security) gateway encryption, the generated quantum keys are securely sent to the branch center at the operations end, where vehicle keys are refilled and managed. Simultaneously, it communicates securely with the production end of the in-vehicle encryption device to refill the pre-filled keys and digital tags into the in-vehicle device, and collects the UID (User Identification) and fingerprint information of the in-vehicle device into the central service.
[0052] Operations ground centers include:
[0053] Ground-based data centers: For large railways (high-speed trains, bullet trains, and regular trains), vehicle data is stored via a unified public 4G / 5G network. For urban rail transit vehicles, data logic is handled through either the public network or a dedicated LET network. The ground-based data center uses a quantum-secure gateway to decrypt encrypted wireless vehicle data. The quantum-secure gateway obtains quantum keys from a quantum key service sub-center.
[0054] The quantum key management platform (branch center) consists of quantum key distribution, quantum key emergency management, and data synchronization between the central and branch centers. It assists the quantum key service center in wirelessly charging quantum keys to vehicle-mounted terminals using quantum-resistant algorithms, while also securely distributing them to quantum gateways in ground data centers. This achieves secure key distribution.
[0055] Security Protection Module: Provides network security hardening for the operation ground center system.
[0056] Communication encryption module: Enables data communication with the quantum key service center through QKD encryption or quantum IPsec gateway encryption.
[0057] The production end of quantum encryption devices includes:
[0058] Secure filling machine: Obtains quantum keys from the quantum key service center via a QKD encrypted channel. The key management platform fills the pre-set keys into the encryption devices that are about to leave the factory through the filling machine, and at the same time reads the UID and fingerprint information of the encryption devices back to the key management platform.
[0059] Central and Production Ends: The central end and the production end exchange business data through a secure communication channel.
[0060] The security and monitoring module provides video surveillance and access control functions. To enhance environmental security, the pre-charging key process for encryption devices is subject to video surveillance and access control.
[0061] Communication encryption module: Enables data communication with the quantum key service center through QKD encryption or quantum IPsec gateway encryption.
[0062] The vehicle-mounted encryption terminal includes:
[0063] The in-vehicle application security module includes security boundary protection, which functions as a firewall, capable of blocking and protecting against malicious attacks through policy formulation. The module also includes an authentication handshake function, which is the protocol for the authentication process between the in-vehicle encrypted terminal and the key management center.
[0064] Device fingerprint: Device fingerprint refers to the unique identifier of a gateway generated by combining hardware characteristics such as ARM processor model, unique hardware ID, network card MAC address, operating system version and security patches, network configuration, installed encryption algorithm or security module, runtime encryption protocol, clock synchronization information, and power status (the device fingerprint is used to obtain a unique hardware digital number for the vehicle encryption terminal through a hash algorithm or other digest algorithm).
[0065] UID Number: A serial number of the vehicle-mounted encryption terminal, stored in the encryption chip, and it remains unchanged.
[0066] The security encryption module consists of a quantum-resistant algorithm, a QRNG chip, secure storage, an encryption engine, fingerprint generation, and a main processor. The quantum-resistant encryption algorithm is used for secure wireless key injection, ensuring that the key cannot be cracked by supercomputers or quantum computers during the injection process. The QRNG quantum true random number generator is used to generate truly random numbers, primarily for the quantum-resistant algorithm. Secure storage mainly stores the encrypted key, which can be read and decrypted using the main processor's decryption protocol. The fingerprint generation function creates a unique fingerprint for the module's hardware and firmware information and provides it to the next-level application security module. The encryption engine implements hash algorithms and symmetric encryption SM4 / DES. The main processor is used to implement the quantum-resistant encryption algorithm and key derivation algorithms PBKDF2 and scrypt.
[0067] Thus, based on security risk assessment, implementation costs, and application scenario boundaries, this application embodiment is divided into four units: quantum key service center, ground operation center, vehicle-mounted encryption terminal, and quantum encryption equipment production terminal. By integrating QKD technology with optical fiber medium, quantum random number IPsecVPN technology, and anti-quantum key injection technology based on Shannon's perfect theorem, it realizes secure distribution of quantum keys in vehicle-to-ground communication application scenarios and improves the security of vehicle-to-ground transmission.
[0068] In this embodiment, the quantum encryption device is manufactured using a dedicated key filling device for rail vehicles. This device communicates with the quantum encryption service center via QKD encryption, enabling it to fill the onboard encryption device with keys and digital tags online, while also reading the device's UID and fingerprint information. The key filling link is: quantum key service center—QKD encryption channel—dedicated key filling device—onboard encryption device, resulting in a high overall security level.
[0069] In this embodiment, the digital link for the wireless key refilling process of the vehicle-mounted quantum encryption device is: quantum key service center—quantum VPN gateway—ground operation and maintenance center—wireless channel—vehicle-mounted encryption device. The entire wireless refilling process employs a quantum-resistant algorithm, improving the overall data link security and reliability.
[0070] Figures 2 to 3 This is a schematic diagram of the data transmission method provided in an embodiment of this application. Any of the following methods can be executed in the data transmission system, or in a server or terminal device communicatively connected to the data transmission system. In this embodiment, the solution is described using the vehicle-mounted terminal device and the ground terminal device of the data transmission system as the execution entities.
[0071] Based on the above-mentioned data transmission system structure, such as Figure 2 As shown in the figure, this application provides a data transmission method, including:
[0072] S21: Generate a true random number as the first key sequence number and send it to the vehicle terminal device. The ground terminal device and the vehicle terminal device are configured with the same preset key, and the key corresponding to the first key sequence number in the preset key is used as the first key.
[0073] S22: Generate a random digital tag encrypted with the first key and send it to the vehicle terminal device.
[0074] S23: After receiving the decryption and loading feedback of the random digital tag from the vehicle terminal device, generate a true random number as the second key sequence number and send it to the vehicle terminal device. Use the key corresponding to the second key sequence number in the preset key as the second key and use the second key to perform encrypted communication with the vehicle terminal device.
[0075] In this embodiment, during the production of the vehicle-mounted quantum encryption device, a pre-set key is injected into the device using a dedicated injection device and method based on QKD secure communication. Simultaneously, the device's UID and fingerprint information are acquired and uploaded to the quantum key service platform. After the vehicle-mounted quantum encryption device is installed in the vehicle, it needs to be registered and activated by entering the device's UID number on the operation ground center or a manual platform within the quantum key service upon first use. When the device is powered on, it will conduct a handshake process and identity verification with the quantum key service center via the wireless channel of the operation ground center.
[0076] In this embodiment, after the vehicle-mounted encryption device and the ground operation center complete the handshake and authentication, the ground center generates a random number using a quantum random number generator. Specifically, the random number will not exceed the number of pre-set keys in the vehicle. The key with the random number as its sequence number is selected from the pre-set keys as the encryption key K1 for the business data, i.e., the first key. This random number is then wirelessly transmitted to the vehicle-mounted encryption device. The vehicle-mounted encryption device also uses the key with the same sequence number from the pre-set keys as the business encryption key K1. Since the key pools of the service center and the vehicle are the same, the keys with the same sequence number are identical at both ends.
[0077] In this embodiment, the ground center generates a random digital tag using QRNG, encrypts it with key K1, and sends it to the vehicle-mounted encryption device. Optionally, the encryption algorithm can be symmetric encryption from the encryption engine. The vehicle-mounted encryption device decrypts the digital tag and stores it in SRAM (Static Random-Access Memory) as a digital tag to prevent tampering. When the device board is removed, the SRAM is de-energized, the digital tag disappears, equivalent to the tag being torn off. After the tag is torn off, the encryption device becomes inactive and requires a reactivation process.
[0078] In this embodiment of the application, the decryption loading feedback in step S23 includes the vehicle terminal device identity information and the hash algorithm calculation value of the random digital tag. The vehicle terminal device identity information is verified. If the verification is successful, a second key is generated and used to conduct encrypted communication with the vehicle terminal device.
[0079] In this way, during the authentication process, under the condition that manual activation is required by the ground platform, the vehicle terminal first sends the UID, and the server sends the key serial number. Both parties use the same serial number as the business key. The vehicle terminal performs a hash algorithm on the device fingerprint and digital tag, encrypts the hash algorithm value with the business key, and sends it to the service center. The service center uses the same business key to decrypt it to obtain the encrypted device fingerprint of the vehicle, and checks it against the device fingerprint in the database. If they match, the identity authentication is passed, which greatly improves the security and efficiency of key transmission.
[0080] Once the vehicle-mounted encryption device reports that the digital tag has been loaded, the ground center uses the same method to replace the business encryption key K2, i.e., the second key, and uses symmetric encryption for encrypted communication of business data.
[0081] In this embodiment of the application, when a key charging request is received from the vehicle terminal device, a key is wirelessly charged to the vehicle terminal device.
[0082] In this way, when the preset key of the vehicle encryption device is insufficient, the key is replenished through a secure quantum-resistant wireless communication method to ensure that the vehicle encryption device has enough keys to use.
[0083] In this embodiment of the application, when an abnormal situation occurs, the communication emergency mode can be activated in the operation ground center or quantum key service, and the encryption mode can be converted to plaintext mode.
[0084] In this embodiment of the application, the quantum key service center is responsible for the key management of all vehicles and also assigns management authority over the keys of the vehicles to the operation ground center. The key database of all vehicles is stored in the quantum key service center.
[0085] In this embodiment, the ground operations center and the quantum key service center communicate encryptedly through a QKD or quantum VPN gateway. The ground operations center has the functions of emergency management, monitoring and refilling of keys for its vehicles.
[0086] In this embodiment, the ground operations center securely distributes the quantum key obtained from the quantum key service center to the quantum security gateway and vehicle encryption device to achieve encryption and decryption functions for data communication between the vehicle and the ground. Vehicle data needs to be encrypted by the onboard encryption device, and then the ciphertext is sent to the quantum security gateway for decryption. The gateway then sends the decrypted data to the ground operations center.
[0087] Based on the above-mentioned data transmission system structure, such as Figure 3 As shown in the figure, this application provides a data transmission method, including:
[0088] S31: Receive the first key sequence number sent by the ground terminal equipment. The vehicle terminal equipment and the ground terminal equipment are configured with the same preset key. The key corresponding to the first key sequence number in the preset key is used as the first key.
[0089] S32: Receive a random digital tag encrypted with the first key sent by the ground terminal equipment, decrypt the random digital tag, load and store it in the static random access memory, and send decryption and loading feedback to the ground terminal equipment.
[0090] S33: Receive the second key sequence number sent by the ground terminal equipment, use the key corresponding to the second key sequence number in the preset key as the second key, and use the second key to perform encrypted communication with the ground terminal equipment.
[0091] S34: The ground terminal equipment uses a random salt to regenerate the first key to obtain the second key, and updates the preset key using the second key.
[0092] In this embodiment, the identity information of the vehicle terminal device and the random digital tag are hashed using a hash algorithm, and the hash value is encrypted with a first key and then sent to the ground terminal device.
[0093] In this way, during the authentication process, under the condition that manual activation is required by the ground platform, the vehicle terminal first sends the UID, and the server sends the key serial number. Both parties use the same serial number as the business key. The vehicle terminal performs a hash algorithm on the device fingerprint and digital tag, encrypts the hash algorithm value with the business key, and sends it to the service center. The service center uses the same business key to decrypt it to obtain the encrypted device fingerprint of the vehicle, and checks it against the device fingerprint in the database. If they match, the identity authentication is passed, which greatly improves the security and efficiency of key transmission.
[0094] In this embodiment of the application, when the number of preset keys is lower than a set number, a key filling request is sent to the ground terminal device; and the key sent by the ground terminal device according to the key filling request is received.
[0095] In this way, when the preset key of the vehicle encryption device is insufficient, the key is replenished through a secure quantum-resistant wireless communication method to ensure that the vehicle encryption device has enough keys to use.
[0096] Furthermore, such as Figure 4As shown, this application embodiment provides a data transmission device 800, including a processor 801 and a memory 802. Optionally, the device may further include a communication interface 803 and a bus 804. The processor 801, communication interface 803, and memory 802 can communicate with each other via the bus 804. The communication interface 803 can be used for information transmission. The processor 801 can call logical instructions in the memory 802 to execute the data transmission method of the above embodiment.
[0097] Furthermore, the logic instructions in the aforementioned memory 802 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium.
[0098] The memory 802, as a computer-readable storage medium, can be used to store software programs and computer-executable programs, such as program instructions / modules corresponding to the methods in the embodiments of this application. The processor executes the program instructions / modules stored in the memory 802 to perform functional applications and data processing, thereby implementing the data transmission method described in the above embodiments.
[0099] The memory 802 may include a program storage area and a data storage area. The program storage area may store the operating system and application programs required for at least one function; the data storage area may store data created based on the use of the terminal device. Furthermore, the memory 802 may include high-speed random access memory and may also include non-volatile memory.
[0100] This application provides a data transmission system, including a data transmission system body and the aforementioned data transmission device 800. The data transmission device is installed in the data transmission system body. The installation relationship described herein is not limited to placement within the data transmission system, but also includes installation connections with other components of the data transmission system, including but not limited to physical connections, electrical connections, or signal transmission connections. Those skilled in the art will understand that the data transmission device can be adapted to any feasible data transmission system body to achieve other feasible embodiments.
[0101] This application provides a computer-readable storage medium storing computer-executable instructions configured to perform the above-described data transmission method.
[0102] The technical solutions of this application embodiment can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes one or more instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in this application embodiment. The aforementioned storage medium can be a non-transitory storage medium, including: USB flash drive, portable hard drive, read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk, and other media capable of storing program code.
[0103] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.
[0104] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. A data transmission method, characterized by, Applied to ground terminal equipment; the method includes: A true random number is generated as the first key sequence number and sent to the vehicle terminal device. The ground terminal device and the vehicle terminal device are configured with the same preset key, and the key corresponding to the first key sequence number in the preset key is used as the first key. A random digital tag encrypted with the first key is generated and sent to the vehicle terminal device; the random digital tag is decrypted by the vehicle terminal device and placed in the static random access memory as a digital tag for anti-tampering purposes, and when the device board is removed, the static random access memory stops being powered, the digital tag disappears, and the vehicle terminal device becomes inactive. After receiving the decryption loading feedback of the random digital tag from the vehicle terminal device, a true random number is generated as the second key sequence number and sent to the vehicle terminal device. The key corresponding to the second key sequence number in the preset key is used as the second key, and the second key is used to perform encrypted communication with the vehicle terminal device. The decryption loading feedback includes the vehicle terminal device identity information and the hash algorithm calculation value of the random digital tag. The vehicle terminal device identity information is verified. If the verification is successful, the second key is generated and used to conduct encrypted communication with the vehicle terminal device. The vehicle terminal device identity information is a device fingerprint generated by combining hardware characteristics such as ARM processor model, unique hardware ID, network card MAC address, operating system version and security patches, network configuration, installed encryption algorithm or security module, runtime encryption protocol, clock synchronization information, and power status. Furthermore, when the vehicle-mounted terminal device is used for the first time, it is registered and activated on the ground terminal device or the artificial platform of the quantum key service center that is connected to the ground terminal device, based on the input device UID number of the vehicle-mounted terminal device, and the device fingerprint of the vehicle-mounted terminal device is stored in the quantum key service center.
2. The data transmission method of claim 1, wherein, Also includes: Upon receiving a key charging request from the vehicle-mounted terminal device, the system wirelessly charges the key to the vehicle-mounted terminal device.
3. A data transmission method, characterized by, Applied to in-vehicle terminal equipment; the method includes: The vehicle-mounted terminal device receives a first key sequence number sent by the ground terminal device. The vehicle-mounted terminal device and the ground terminal device are configured with the same preset key. The key corresponding to the first key sequence number in the preset key is used as the first key. The system receives a random digital tag encrypted with the first key from a ground terminal device, decrypts the random digital tag, loads and stores it in a static random access memory (SRAM), and sends decryption and loading feedback to the ground terminal device. The random digital tag is decrypted, loaded, and stored in the SRAM as a digital tag for tamper protection. When the device board is removed, the SRAM stops receiving power, the digital tag disappears, and the vehicle-mounted terminal device becomes inactive, requiring a reactivation process. Furthermore, the vehicle-mounted terminal device identity information and the random digital tag are hashed using a hash algorithm, and the hash value is encrypted using the first key and sent to the ground terminal device. The decryption loading feedback includes the hash value calculated by the vehicle-mounted terminal device identity information and the random digital tag. The vehicle-mounted terminal device identity information is a device fingerprint generated by combining hardware characteristics such as ARM processor model, unique hardware ID, network card MAC address, operating system version and security patches, network configuration, installed encryption algorithm or security module, runtime encryption protocol, clock synchronization information, and power status. Receive the second key sequence number sent by the ground terminal equipment, use the key corresponding to the second key sequence number in the preset key as the second key, and use the second key to perform encrypted communication with the ground terminal equipment; Furthermore, when the vehicle-mounted terminal device is used for the first time, it is registered and activated on the ground terminal device or the artificial platform of the quantum key service center that is connected to the ground terminal device, based on the input device UID number of the vehicle-mounted terminal device, and the device fingerprint of the vehicle-mounted terminal device is stored in the quantum key service center.
4. The data transmission method of claim 3, wherein, Also includes: When the number of preset keys is lower than the set number, a key replenishment request is sent to the ground terminal device; Receive the key sent by the ground terminal device in accordance with the key filling request.
5. A data transmission apparatus comprising a processor and a memory having stored therein program instructions, the apparatus being characterized by: The processor is configured to execute the data transfer method as described in any one of claims 1 to 4 when running the program instructions.
6. A data transmission system, characterized by include: Ground terminal equipment includes a ground data center, a quantum key management platform, and a communication encryption module; The vehicle-mounted terminal equipment is communicatively connected to the ground terminal equipment; and, The data transmission device as described in claim 5 is installed on the ground terminal equipment and the vehicle-mounted terminal equipment.
7. The data transmission system of claim 6, wherein, Also includes: The quantum key service center stores the identity information of the vehicle-mounted terminal device and communicates with the ground terminal device. It is used to verify the identity information of the vehicle-mounted terminal device received by the ground terminal device according to the request sent by the ground terminal device. It also stores a key, which is used to fill the key of the vehicle-mounted terminal device through the ground terminal device according to the request sent by the ground terminal device.
8. The data transmission system of claim 6, wherein, Also includes: The quantum encryption device production terminal is communicatively connected to the quantum key service center, used to produce keys, and to send keys to the quantum key service center according to the requests received from the quantum key service center.
Citation Information
Patent Citations
Handshaking method for network safety, apparatus for initiating and responding handshake
CN101409882A
Quantum encryption communication method and corresponding communication system
CN114726515A