High-safety vehicle-road interconnection information transmission method and system based on encryption algorithm
By managing RSU and OBU devices in the issuing center system and using a signature verification mechanism, the security and resource limitation problems of vehicle-road interconnected information transmission under high-speed motion in the prior art are solved, and high-security communication under low bandwidth is achieved.
Patent Information
- Application Number
- CN202411842505.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-13
- Publication Date
- 2025-05-09
AI Technical Summary
In the prior art, the certificate authentication scheme based on public key cryptography technology has problems such as large amount of data, many interactions, and many computing steps in communication scenarios under high-speed vehicle movement, making it difficult to achieve high-safe vehicle-road interconnection information transmission.
By managing RSU and OBU devices in the issuing center system, the device public-private key pair and the issuing center public-private key pair are used to sign and verify, and the devices exchange device credentials, the second signature value, and the public key in the device public-private key pair as the basis for communication mutual trust.
The interactive traffic volume is reduced, high-security communication under low bandwidth resources is realized, and the resource limitation problem exists in communication between RSU and OBU devices.
Smart Images

Figure CN119966611A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of vehicle-road interconnection information transmission technology, and in particular to a high-security vehicle-road interconnection information transmission method and system based on an encryption algorithm. Background Art
[0002] Traffic Catcher is a technical solution based on the ETC system to improve the safety of vehicle-road collaboration and intelligent service solutions. It can realize functions such as safety warning, operation management and customized information push on demand. The Traffic Catcher system is equivalent to a talking ETC vehicle-mounted device that can realize the dialogue between the car and the road.
[0003] Figure 2 The figure is a schematic diagram of the system structure of a traffic watcher in the prior art.
[0004] The "Traffic Watcher" system consists of an information release center, road side equipment (Road Side Unit, RSU) and on-board equipment (On-Board Unit, OBU). The road test equipment can include RSU antennas, communication modules and safety modules. When releasing information, the information release center sends information to the road side equipment in the specified area. When a vehicle passes by, the road side equipment communicates wirelessly with the vehicle's on-board equipment through the road side equipment and releases the information to the passing vehicle. After the vehicle receives the information, the on-board equipment broadcasts it.
[0005] The certificate authentication scheme based on public key cryptography proposed in the prior art specifically includes: when the roadside equipment and the vehicle-mounted equipment leave the factory, they will apply for a digital certificate (Certificate Authority, CA) from the certificate authentication center. The certificate authentication center will verify the identity of the applicant and issue a digital certificate containing public key information to it. The certificate is stored in a secure storage area. During communication, before the roadside equipment and the vehicle-mounted equipment establish communication, the two parties will exchange their respective digital certificates. After receiving the other party's certificate, the communicating parties will use the CA's public key to verify the certificate. After the identity authentication is successful, the RSU and OBU can use the other party's public key to encrypt the communication data to ensure the confidentiality of the data. At the same time, both parties can also use their own private keys to sign the communication data to ensure the integrity and non-repudiation of the data.
[0006] However, although the above certificate authentication scheme based on public key cryptography technology is widely used in network communications, due to the large size of certificate files, the authentication used in ETC communication will cause problems such as large communication data volume, high number of interactions, and many calculation steps, and is not suitable for communication scenarios where vehicles are moving at high speed.
[0007] Therefore, how to provide a high-security vehicle-road interconnection information transmission method suitable for communication scenarios under high-speed vehicle movement is a technical problem that needs to be solved urgently. Summary of the invention
[0008] In view of this, an embodiment of the present invention provides a high-security vehicle-road interconnection information transmission method and system based on an encryption algorithm to eliminate or improve one or more defects existing in the prior art.
[0009] One aspect of the present invention provides a high-security vehicle-road interconnection information transmission method based on an encryption algorithm, wherein each roadside unit RSU or on-board unit OBU device has a device public-private key pair, and an issuing center has an issuing center public-private key pair, and the method comprises: the issuing center receives a device certificate generated by the RSU or OBU and a first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate includes device information and a public key in the device public-private key pair; the issuing center verifies the legitimacy of the first signature value using the received device certificate; after the verification is passed, the device information of the corresponding RSU or OBU device is recorded in the issuing center, and the issuing center signs the device certificate using the private key in the issuing center public-private key pair to generate a second signature value, which is sent back to the corresponding RSU or OBU device; wherein, during the communication process between the RSU and the OBU, the devices use the exchange of device certificates, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
[0010] In some embodiments of the present invention, when the second signature value is sent back to the corresponding RSU or OBU, the method also includes: the corresponding RSU or OBU uses the public key in the public-private key pair of the issuing center to verify the legitimacy of the second signature value, and records the second signature value in the corresponding RSU or OBU after the verification is passed; the step in which the issuing center uses the received device certificate to verify the legitimacy of the first signature value includes: the issuing center uses the public key in the device public-private key pair contained in the device certificate to verify the legitimacy of the first signature value.
[0011] In some embodiments of the present invention, the information release center has an information release center public-private key pair, and the method also includes: at the beginning of the communication between the RSU and the OBU, the RSU and the OBU exchange device credentials, the second signature value and the public key in the device public-private key pair; at the end of the communication, the RSU and the OBU use the public key in the public-private key pair of the issuing center, the public key in the public-private key pair of the information release center, and the public key in the device public-private key pair to verify the legitimacy of the data received from the other party.
[0012] In some embodiments of the present invention, during the communication process between the RSU and the OBU, the method also includes: the RSU receives the spliced information from the information release center; in the online stage, the RSU uses the public key in the OBU's equipment public-private key pair to encrypt and send the spliced information to the OBU; in the offline stage, the OBU uses the public key in the issuance center's public-private key pair, the private key in the OBU's equipment public-private key pair, and the public key in the information release center's public-private key pair to verify the legitimacy of the received spliced information, and extracts the information to be released from it; when the legitimacy check passes, the OBU releases the information to be released; wherein, the spliced information includes the information to be released and a third signature value obtained by signing the information to be released based on the private key in the public-private key pair of the information release center.
[0013] In some embodiments of the present invention, the step of verifying the legitimacy of the received splicing information by the OBU using the public key in the issuing center's public-private key pair, the private key in the OBU's equipment public-private key pair, and the public key in the information release center's public-private key pair includes: the OBU uses the pre-stored public key in the issuing center's public-private key pair to verify the legitimacy of the RSU's equipment certificate and the RSU's second signature value; the OBU uses the private key in the OBU's equipment public-private key pair to decrypt the encrypted splicing information from the RSU; and uses the public key in the RSU's equipment public-private key pair to verify the third signature value.
[0014] In some embodiments of the present invention, before the step of the RSU using the public key in the OBU's equipment public-private key pair to encrypt and send the splicing information to the OBU, the method also includes: a step in which the RSU verifies the OBU identity, the RSU uses the acquired public key in the OBU's equipment public-private key pair to verify the OBU's equipment certificate and the second signature value, and after the verification is passed, the corresponding OBU is counted as a legal OBU.
[0015] In some embodiments of the present invention, the method is based on a security chip preset by the RSU based on the SM series national commercial cryptographic algorithm, and the communication protocol between the main control chip and the security chip preset by the OBU adopts the 7816 protocol.
[0016] Corresponding to the above method, the present invention also provides a high-security vehicle-road interconnection information transmission system based on an encryption algorithm, the system comprising: an issuing center, the issuing center having a public-private key pair of the issuing center, for receiving a device certificate generated by an RSU or OBU and a first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate comprises device information and a public key in the device public-private key pair; and is also used to verify the legitimacy of the first signature value using the received device certificate; after the verification is passed, the issuing center is also used to record the device information of the corresponding RSU or OBU device, and use the private key in the public-private key pair of the issuing center to sign the device certificate to generate a second signature value, and the second signature value is sent back to the corresponding RSU or OBU device; wherein, in the communication process between the RSU and the OBU, the devices use the exchange of device certificates, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
[0017] In some embodiments of the present invention, the system further includes an RSU and an OBU; wherein, at the beginning stage of communication between the RSU and the OBU, the RSU and the OBU exchange device credentials, a second signature value, and a public key in a device public-private key pair; at the end stage of communication, the RSU and the OBU use the public key in a public-private key pair of a distribution center, the public key in a public-private key pair of an information release center, and the public key in a device public-private key pair to verify the legitimacy of the data received from the other party.
[0018] In some embodiments of the present invention, the system further includes an information publishing center, which is used to send spliced information to the RSU, wherein the spliced information includes information to be published and a third signature value obtained by signing the information to be published based on a private key in the public-private key pair of the information publishing center.
[0019] The high-security vehicle-road interconnection information transmission method and system based on encryption algorithm proposed in the present invention can use the newly established distribution center to manage RSU and OBU devices, so that in the communication process between RSU and OBU, the devices use the exchange of device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust, thereby reducing the amount of interactive communication and achieving high-security communication under low bandwidth resources.
[0020] Additional advantages, purposes, and features of the present invention will be described in part in the following description, and will become apparent to those skilled in the art after studying the following, or may be learned from the practice of the present invention. The purposes and other advantages of the present invention may be achieved and obtained by the structures specifically indicated in the specification and the accompanying drawings.
[0021] Those skilled in the art will appreciate that the objectives and advantages that can be achieved with the present invention are not limited to the above specific description, and the above and other objectives that can be achieved by the present invention will be more clearly understood from the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The drawings described herein are used to provide a further understanding of the present invention, constitute a part of the present application, and do not constitute a limitation of the present invention. In the drawings:
[0023] Figure 1 This is a flow chart of a high-security vehicle-road interconnection information transmission method based on an encryption algorithm in one embodiment of the present invention.
[0024] Figure 2 The figure is a schematic diagram of the system structure of a traffic watcher in the prior art.
[0025] Figure 3 Schematic diagram of the issuance steps of the device to be issued in one embodiment of the present invention.
[0026] Figure 4 The figure is a flow chart of secure communication between RSU and OBU in the online stage in one embodiment of the present invention. DETAILED DESCRIPTION
[0027] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments and the accompanying drawings. Here, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0028] It should also be noted that, in order to avoid obscuring the present invention due to unnecessary details, only structures and / or processing steps closely related to the solutions according to the present invention are shown in the accompanying drawings, while other details that are not closely related to the present invention are omitted.
[0029] It should be emphasized that the term “include / comprises” when used herein refers to the presence of features, elements, steps or components, but does not exclude the presence or addition of one or more other features, elements, steps or components.
[0030] It should also be noted that, unless otherwise specified, the term “connection” herein may refer not only to a direct connection but also to an indirect connection involving an intermediate.
[0031] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. In the accompanying drawings, the same reference numerals represent the same or similar components, or the same or similar steps.
[0032] The present invention proposes a highly secure vehicle-road interconnection information transmission method and system based on an encryption algorithm to solve the problem that RSU and OBU have great limitations in computing and bandwidth resources under the premise of using the original RSU and OBU facilities. The technical problem to be solved by the present invention is to design a highly secure vehicle-road interconnection information transmission solution under the condition of limited resources.
[0033] Figure 1 This is a flow chart of a high-security vehicle-road interconnection information transmission method based on an encryption algorithm in one embodiment of the present invention. Each roadside unit RSU or on-board unit OBU device has a device public-private key pair, and the issuing center has an issuing center public-private key pair. The method includes:
[0034] Step S110: The issuing center receives the device certificate generated by the RSU or OBU and the first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate includes device information and the public key in the device public-private key pair.
[0035] Step S120: The issuing center uses the received device credentials to verify the legitimacy of the first signature value.
[0036] Step S130: After the verification is passed, the device information of the corresponding RSU or OBU device is recorded in the issuing center. The issuing center uses the private key in the public-private key pair of the issuing center to sign the device certificate to generate a second signature value, which is sent back to the corresponding RSU or OBU device.
[0037] Among them, in the communication process between the RSU and the OBU, the devices exchange device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
[0038] The core innovation of this solution is: adding a distribution center system to sign each device, and the devices use the public key of the distribution center system to verify the signature value to confirm whether the other party's public key is legitimate. The execution participants of the solution include OBU, RSU, distribution center and information release center.
[0039] The high-security vehicle-road interconnection information transmission method and system based on encryption algorithm proposed in the present invention can use the newly established distribution center to manage RSU and OBU devices, so that in the communication process between RSU and OBU, the devices use the exchange of device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust, thereby reducing the amount of interactive communication and achieving high-security communication under low bandwidth resources.
[0040] In some embodiments of the present invention, when the second signature value is sent back to the corresponding RSU or OBU, the method also includes: the corresponding RSU or OBU uses the public key in the public-private key pair of the issuing center to verify the legitimacy of the second signature value, and after the verification is passed, the second signature value is recorded in the corresponding RSU or OBU.
[0041] By adopting the embodiment of the invention, the public key in the public-private key pair of the issuing center can be used to verify the identity of the RSU or OBU, thereby efficiently verifying the legitimacy of the identity of the OBU and the RSU.
[0042] In some embodiments of the present invention, the step of the issuing center using the received device credential to verify the legitimacy of the first signature value includes: the issuing center using the public key in the device public-private key pair contained in the device credential to verify the legitimacy of the first signature value.
[0043] By adopting the embodiment of the invention, the legitimacy of the first signature value of the device can be verified efficiently using the public key in the public-private key pair of the device.
[0044] In some embodiments of the present invention, the execution entity further includes RSU and OBU, and the information release center has an information release center public-private key pair. The method also includes: (1) at the beginning of the communication between the RSU and the OBU, the RSU and the OBU exchange device credentials, the second signature value and the public key in the device public-private key pair; (2) on the other hand, at the end of the communication, the RSU and the OBU use the public key in the public-private key pair of the issuing center, the public key in the public-private key pair of the information release center, and the public key in the device public-private key pair to verify the legitimacy of the data received from the other party.
[0045] By adopting this embodiment of the invention, during the communication process between the RSU and the OBU, the second signature value issued by the issuing center and the verified device certificate can be used to perform communication preparation for the information to be published sent by the information publishing center before publishing.
[0046] In some embodiments of the present invention, during the communication process between the RSU and the OBU, the method further includes: (1) the RSU receives the spliced information from the information release center; (2) in the online stage, the RSU uses the public key in the public-private key pair of the OBU device to encrypt and send the spliced information to the OBU; (3) in the offline stage, the OBU uses the public key in the public-private key pair of the issuing center, the private key in the public-private key pair of the OBU device and the public key in the public-private key pair of the information release center to verify the legitimacy of the received spliced information, and extract the information to be released from it; (4) when the legitimacy check passes, the OBU releases the information to be released. Wherein, the spliced information includes the information to be released and the third signature value obtained by signing the information to be released based on the private key in the public-private key pair of the information release center.
[0047] By adopting the embodiment of the invention, secure communication between the RSU and the OBU can be achieved.
[0048] In some embodiments of the present invention, the step of verifying the legitimacy of the received splicing information by the OBU using the public key in the issuing center's public-private key pair, the private key in the OBU's equipment public-private key pair, and the public key in the information publishing center's public-private key pair includes: (1) the OBU uses the pre-stored public key in the issuing center's public-private key pair to verify the legitimacy of the RSU's equipment certificate and the RSU's second signature value; (2) the OBU uses the private key in the OBU's equipment public-private key pair to decrypt the encrypted splicing information from the RSU; and (3) the public key in the RSU's equipment public-private key pair is used to verify the third signature value.
[0049] In other embodiments of the present invention, before the step of the RSU using the public key in the OBU's equipment public-private key pair to encrypt and send the splicing information to the OBU, the method also includes: a step in which the RSU verifies the OBU identity, the RSU uses the acquired public key in the OBU's equipment public-private key pair to verify the OBU's equipment certificate and the second signature value, and after the verification is passed, the corresponding OBU is counted as a legal OBU.
[0050] In some embodiments of the present invention, the security chip preset by the RSU can be based on the SM series national commercial cryptographic algorithm, and the communication protocol of the master chip and the security chip preset by the OBU adopts the 7816 protocol. The method can be designed based on the domestic commercial cryptographic algorithm SM2, SM3 or SM4, and the secondary security chip of the commercial cryptographic product is used to ensure the security of the key and algorithm at runtime. Among them, the national commercial cryptographic algorithm is the cryptographic algorithm standard and its application specification recognized and announced by the State Cryptography Administration, for example, the asymmetric encryption algorithm SM2, the cryptographic hash algorithm SM3, the block encryption algorithm SM4, etc. included in the SM series cryptography.
[0051] The high-security vehicle-road interconnection information transmission method based on encryption algorithm proposed in the present invention can be achieved by adding a distribution center system, which signs each device (including RSU and OBU). The devices verify the signature value by using the public key of the distribution center system to confirm whether the other party's public key is legal.
[0052] The entire plan can be divided into three stages: the issuance stage, the pre-communication stage, and the communication end stage.
[0053] (1) Issuance phase: The device (including RSU and OBU) needs to be issued before use. The device itself generates a public-private key pair, concatenates the device information INFO and the public key into a device certificate, and sends the device certificate and the signature value of the device certificate to the issuance center system. The issuance center system uses the received device certificate to verify the signature. If it passes, it uses the private key of the issuance center system to sign the device certificate and return it.
[0054] (2) Before the start of communication: At the beginning of the communication, the RSU and OBU first exchange device credentials and the signature value of the device credentials. The RSU sends its own device credentials and signature value to the OBU. The OBU sends its own device credentials and signature value to the RSU, and the RSU then uses the public key of the issuing center system to verify the signature value of the OBU. After the verification is successful, the RSU uses the public key of the OBU to encrypt the information to be transmitted, and sends it to the OBU in two packets. After receiving it, the OBU returns a random number and ACK respectively. After receiving the ACK, the RSU calculates a signature value based on the RSU public key, the OBU public key, the transmission data, and the random number and sends it to the OBU. The OBU calculates a signature value based on the RSU public key, the OBU public key, and the time and sends it to the RSU.
[0055] (3) Communication end stage: After the communication ends, the RSU and OBU need to verify the legitimacy of the data. The OBU uses the public key of the issuing center system to verify the legitimacy of the RSU's device credentials and signature value, uses its own private key to decrypt the encrypted information, uses the RSU's public key to verify the signature value calculated by the RSU based on the RSU public key, OBU public key, transmission data, and random number, and uses the public key of the information publishing center to verify the signature value in the decrypted information. At this point, after all verifications are passed, the OBU will broadcast the information. The RSU uses the OBU's public key to verify the signature value calculated by the OBU based on the RSU public key, OBU public key, and time. If the verification is passed, the RSU will perform statistics.
[0056] Figure 3 The schematic diagram of the issuing steps of the device to be issued in one embodiment of the present invention is as follows. The device issuing stage includes two stages: burning and issuing.
[0057] During the burning phase, device A burns the code, and the code is pre-set with the issuing center SM2 signature public key P R , information release center public key P C .
[0058] The issuance phase includes the following steps: (1) Device A generates a public-private key pair (P A ,D A ); (2) Device A calculates C A =INFO A ||P A , where INFO A 4-byte device information, P A It is the compressed form of the public key of device SM2, with a length of 33 bytes. A The total length is 37 bytes; (3) A uses the device private key D A C A Signature calculation signature value And C A and Sent to issuing device R; (4) issuing device R verifies C A and signature If it is legal, then record the device information of A and use the issuing device private key D R C A Sign and generate signature value and will Send back to device A; (5) Device A uses P R Verify the signature value Legality, legal records Completed issuance.
[0059] Figure 4 This is a flowchart of secure communication between RSU and OBU in the online phase of an embodiment of the present invention. This solution is mainly applicable to communication between RSU and OBU in the operational phase after deployment. In the prior art, the information release center and RSU already have the ability to securely communicate. After the release of RSU and OBU, both have as well as This is the basis for the subsequent secure communication between the two. The information publishing center uses its private key D C Sign the information msg to be published and generate a signature value Splicing information Then M is securely sent to the corresponding RSU, which stores M and completes the security protocol with the OBU device when the vehicle passes by to publish the information M.
[0060] The operation phase after deployment can be divided into two parts: online phase and offline phase. In the online phase, RSU and OBU communicate over the air interface to achieve protocol-related data interaction; in the offline phase, the roadside unit and on-board unit perform offline calculations to achieve subsequent functions. The air interface refers to the air interface, that is, the interface for communication between mobile terminals (such as mobile phones) and base stations.
[0061] In the online phase, the communication between RSU and OBU includes the following steps: (1) RSU sends C RSU , To OBU, the frame sends data with a length of 37+64=101 bytes; (2) OBU responds with C OBU , To RSU, the frame sends data with a length of 37+64=101 bytes; (3) RSU uses the pre-stored issuing center public key P R Verification C OBU , Legality; (4) RSU in C OBU Extract the OBU public key P OBU , and use P OBU Encrypt information M to generate ciphertext The length of M is 64+64=128 bytes. After SM2 encryption, It is expressed as C1||C3||C2. C1 is compressed in SM2 format and has a length of 33 bytes. C3 has a length of 32 bytes. The length of C2 is the same as M, which is 128 bytes. The total length is 193 bytes. This information exceeds the maximum length of a frame and needs to be disassembled into and Send; (5) RSU sends The length of the data sent in this frame is 100 bytes; (6) OBU generates and responds to the random number Rand, and the length of the data response in this frame is 32 bytes; (7) RSU sends The length of the data sent in this frame is 93 bytes; (8) OBU responds with an empty message, the length of this frame is 4 bytes; (9) RSU uses its private key D RSU Calculate C RSU ||C OBU ||M||Rand's signature value (10) RSU sending To OBU, the frame sends data of 64 bytes in length; (11) OBU uses the private key D during steps 1-10 OBU Calculate C RSU ||C OBU ||The signature value of Time In this step, respond The frame response data length is 64 bytes.
[0062] The offline phase includes OBU calculation and broadcasting, and RSU verification of OBU legitimacy. RSU needs to count the legal OBU communications. After the online phase, RSU cannot determine the legitimacy of OBU, so RSU needs to verify the legitimacy of OBU.
[0063] OBU calculation and broadcasting include: (1) using the pre-stored issuing center public key P R Verification C RSU The legitimacy of (2) using the private key D OBU Decryption Get information (3) In C RSU Extract the RSU public key P RSU , and use P OBU Information C RSU ||C OBU ||M||Rand's signature Verify; (4) Use the pre-stored information publishing center public key P C , verify the signature of msg (5) If steps 1-4 are all passed, the OBU broadcasts the msg.
[0064] The RSU's verification of the OBU's legitimacy includes: (1) The RSU uses the obtained P OBU Verification C RSU ||C OBU ||The signature value of Time Legality; (2) If step (1) is passed, statistics will be performed.
[0065] In some embodiments of the present invention, the scheme has bandwidth resource limitations, including: (1) the downlink communication rate from RSU to OBU is 256Kb / s, and the uplink communication rate from OBU to RSU is 512Kb / s; (2) RSU and OBU communicate in a "question-and-answer" mode, with RSU actively initiating and OBU responding; (3) RSU and OBU communicate in a data frame mode, and except for the communication packet header, the data payload of each frame is 100 bytes; (4) Due to the vehicle speed and spatial signal transmission interference, data frames need to be retransmitted to achieve stable communication transmission, and 2-3 retransmissions can ensure stable data frame transmission; (5) When the vehicle speed is fast, the online communication duration needs to be less than 50ms; Based on the data frame size, transmission speed and retransmission requirements, it can be roughly calculated that it takes about 8ms for RSU to send a frame of data to OBU, and about 4ms for OBU to send a frame of data to RSU.
[0066] In some embodiments of the present invention, the scheme has limited computing resources. Unlike RSU which can use high-speed cryptographic equipment, OBU is limited by form and power consumption. The cryptographic engineering implementation is limited as follows: (1) A single SM2 operation (encryption, decryption, signing, and verification) of the OBU side security chip takes about 20ms; (2) The OBU main control chip and the security chip can communicate using the 7816 protocol with a communication rate of 1Mb / s.
[0067] Among them, due to bandwidth and computing resource limitations, RSU and OBU cannot use the PKI system to implement security protocols by exchanging certificates (the amount of data and computing required for the certificate exchange process is too large). This solution is based on the SM2 public key for cryptographic scheme design, and the overall solution includes two parts: equipment issuance and deployment operation.
[0068] Correspondingly, on the other hand, the present invention proposes a high-security vehicle-road interconnection information transmission system based on an encryption algorithm, the system comprising: an issuing center, the issuing center having a public-private key pair of the issuing center, for receiving a device certificate generated by an RSU or OBU and a first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate comprises device information and a public key in the device public-private key pair; and is also used to verify the legitimacy of the first signature value using the received device certificate; after the verification is passed, the issuing center is also used to record the device information of the corresponding RSU or OBU device, and use the private key in the public-private key pair of the issuing center to sign the device certificate to generate a second signature value, and the second signature value is sent back to the corresponding RSU or OBU device; wherein, during the communication process between the RSU and the OBU, the devices use the exchange of device certificates, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
[0069] In some embodiments of the present invention, the system further includes an RSU and an OBU; wherein, at the beginning stage of communication between the RSU and the OBU, the RSU and the OBU exchange device credentials, a second signature value, and a public key in a device public-private key pair; at the end stage of communication, the RSU and the OBU use the public key in a public-private key pair of a distribution center, the public key in a public-private key pair of an information release center, and the public key in a device public-private key pair to verify the legitimacy of the data received from the other party.
[0070] In some other embodiments of the present invention, the system further includes an information publishing center, which is used to send spliced information to the RSU, wherein the spliced information includes the information to be published and a third signature value obtained by signing the information to be published based on the private key in the public-private key pair of the information publishing center.
[0071] The high-security vehicle-road interconnection information transmission method and system based on encryption algorithm proposed in the present invention can manage RSU and OBU devices by using the newly established distribution center, so that in the communication process between RSU and OBU, the devices exchange device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust, thereby reducing the amount of interactive communication and achieving high-security communication under low-bandwidth resources. This solution solves the problem that when RSU and OBU devices have large restrictions on communication, RSU and OBU can still communicate securely, and the confidentiality, integrity and authentication of RSU and OBU communication are carried out, so that OBU supports anti-replay.
[0072] The scheme proposed in the present invention can realize the communication between RSU and OBU and increase identity authentication and transmission encryption, prevent RSU that is not under control from operating or damaging OBU equipment, protect the security of the system, and meet the following security requirements: (1) Confidentiality: The air interface communication between RSU and OBU needs to be confidentiality protected to avoid eavesdropping; (2) Integrity and authentication: After the OBU receives the broadcast information, it needs to determine that the information comes from a legitimate publishing center, and at the same time, the RSU communicating with it is a legitimate device (to avoid cross-regional information transmission); the RSU needs to verify that the OBU communicating with it is a legitimate device and make statistical records. (3) Anti-replay: After the OBU receives the broadcast information, it needs to determine that the information is not replayed by an illegal device. (4) High-security communication: OBU and RSU devices perform high-security communication under the premise that computing and bandwidth resources are greatly restricted.
[0073] The key technical points of this solution include: (1) During the release phase, the RSU and OBU are issued by the issuing center in a secure environment, and the issuing center SM2 signature public key and the information release center public key are pre-made. (2) 4-byte device information and compressed public key are used as device credentials to replace PKI certificates, which reduces the amount of interactive communication and achieves high-security communication under low-bandwidth resources. (3) RSU and OBU exchange credentials and signature values before business communication for each other to verify the legitimacy of their identities. (4) Business data is encrypted and transmitted by the public key in the legitimate credentials. (5) Parallel operation logic is designed, and OBU receives C RSU After that, you can The calculation is performed while the interaction is in progress, and the calculation is completed within 38ms before the fourth round of interaction reply. The entire interaction time is controlled within about 50ms, achieving high-security communication with limited computing resources.
[0074] It should be understood by those skilled in the art that the exemplary components, systems and methods described in conjunction with the embodiments disclosed herein can be implemented in hardware, software or a combination of the two. Whether it is performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention. When implemented in hardware, it can be, for example, an electronic circuit, an application specific integrated circuit (ASIC), appropriate firmware, a plug-in, a function card, etc. When implemented in software, the elements of the present invention are programs or code segments used to perform the required tasks. The program or code segment can be stored in a machine-readable medium, or transmitted on a transmission medium or a communication link via a data signal carried in a carrier.
[0075] It should be clear that the present invention is not limited to the specific configuration and processing described above and shown in the figures. For the sake of simplicity, a detailed description of the known method is omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications and additions, or change the order between the steps after understanding the spirit of the present invention.
[0076] In the present invention, features described and / or illustrated for one embodiment may be used in the same or similar manner in one or more other embodiments, and / or combined with features of other embodiments or replace features of other embodiments.
[0077] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the embodiments of the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A highly secure vehicle-road interconnection information transmission method based on an encryption algorithm, characterized in that: Each roadside unit RSU or on-board unit OBU device has a device public-private key pair, and the issuing center has an issuing center public-private key pair, and the method includes: The issuing center receives the device certificate generated by the RSU or OBU and the first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate includes the device information and the public key in the device public-private key pair; The issuing center verifies the legitimacy of the first signature value using the received device credential; After the verification is passed, the device information of the corresponding RSU or OBU device is recorded in the issuing center, and the issuing center signs the device certificate using the private key in the issuing center's public-private key pair to generate a second signature value, which is sent back to the corresponding RSU or OBU device; Among them, in the communication process between the RSU and the OBU, the devices exchange device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
2. The high-security vehicle-road interconnection information transmission method according to claim 1 is characterized in that: When the second signature value is sent back to the corresponding RSU or OBU, the method further includes: the corresponding RSU or OBU uses the public key in the public-private key pair of the issuing center to verify the legitimacy of the second signature value, and after the verification is passed, the second signature value is recorded in the corresponding RSU or OBU; The step of the issuing center using the received device certificate to verify the legitimacy of the first signature value includes: the issuing center uses the public key in the device public-private key pair included in the device certificate to verify the legitimacy of the first signature value.
3. The method according to claim 1, characterized in that The information release center has a public and private key pair of the information release center, and the method further includes: At the beginning of the communication between the RSU and the OBU, the RSU and the OBU exchange the device certificate, the second signature value, and the public key in the device public-private key pair; At the end of the communication, the RSU and OBU use the public key in the issuing center's public-private key pair, the public key in the information publishing center's public-private key pair, and the public key in the device's public-private key pair to verify the legitimacy of the data received from each other.
4. The method according to claim 3, characterized in that During the communication process between the RSU and the OBU, the method further comprises: RSU receives splicing information from the information release center; In the online stage, the RSU uses the public key in the public-private key pair of the OBU device to encrypt and send the splicing information to the OBU; In the offline stage, the OBU uses the public key in the public-private key pair of the issuing center, the private key in the public-private key pair of the OBU device, and the public key in the public-private key pair of the information publishing center to verify the legitimacy of the received spliced information, and extract the information to be published therefrom; When the legality check is passed, OBU publishes the information to be published; The spliced information includes the information to be released and a third signature value obtained by signing the information to be released with a private key in the public-private key pair of the information release center.
5. The method according to claim 4, characterized in that The step of the OBU using the public key in the public-private key pair of the issuing center, the private key in the public-private key pair of the equipment of the OBU and the public key in the public-private key pair of the information issuing center to verify the legitimacy of the received splicing information comprises: The OBU uses the public key in the pre-stored public-private key pair of the issuing center to verify the legitimacy of the RSU's device certificate and the RSU's second signature value; The OBU decrypts the encrypted splicing information from the RSU using the private key in the device public-private key pair of the OBU; The third signature value is verified using the public key in the RSU's device public-private key pair.
6. The method according to claim 4, characterized in that Before the RSU uses the public key in the OBU's equipment public-private key pair to encrypt and send the splicing information to the OBU, the method also includes: the RSU verifies the OBU identity, the RSU uses the acquired public key in the OBU's equipment public-private key pair to verify the OBU's equipment certificate and the second signature value, and after the verification is passed, the corresponding OBU is counted as a legal OBU.
7. The method according to claim 3, characterized in that The method is based on the RSU preset security chip based on the SM series national commercial cryptographic algorithm, and the communication protocol between the OBU preset main control chip and the security chip adopts the 7816 protocol.
8. A highly secure vehicle-road interconnection information transmission system based on encryption algorithm, characterized in that: The system comprises: The issuing center has a public-private key pair of the issuing center, and is used to receive the device certificate generated by the RSU or OBU and the first signature value obtained by signing the device certificate based on the private key in the device public-private key pair; wherein the device certificate includes device information and the public key in the device public-private key pair; and is also used to verify the legitimacy of the first signature value using the received device certificate; After the verification is passed, the issuing center is also used to record the device information of the corresponding RSU or OBU device, and use the private key in the public-private key pair of the issuing center to sign the device certificate to generate a second signature value, and the second signature value is sent back to the corresponding RSU or OBU device; Among them, in the communication process between the RSU and the OBU, the devices exchange device credentials, the second signature value and the public key in the device public-private key pair as the basis for communication and mutual trust.
9. The high-security vehicle-road interconnection information transmission system according to claim 8 is characterized in that: The system also includes an RSU and an OBU; wherein, at the beginning stage of communication between the RSU and the OBU, the RSU and the OBU mutually exchange device credentials, a second signature value, and a public key in a device public-private key pair; at the end stage of communication, the RSU and the OBU use the public key in a public-private key pair of an issuing center, the public key in a public-private key pair of an information publishing center, and the public key in a device public-private key pair to verify the legitimacy of the data received from the other party.
10. The high-security vehicle-road interconnection information transmission system according to claim 8, characterized in that: The system further includes an information publishing center, which is used to send spliced information to the RSU, wherein the spliced information includes information to be published and a third signature value obtained by signing the information to be published based on a private key in the public-private key pair of the information publishing center.