Data communication method and device and vehicle

By using preset keys and session salt values ​​to generate keys in vehicle data communication, the packets are encrypted and decrypted, and the problem of insufficient confidentiality and security of the packets in the prior art is solved, efficient data transmission is achieved and insufficient computing power is avoided.

CN119995839APending Publication Date: 2025-05-13CONTEMPORARY AMPEREX INTELLIGENCE TECHNOLOGY (SHANGHAI) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311508646.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-13
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to effectively ensure the confidentiality and security of messages in vehicle data communication, and the large amount of data processing may lead to insufficient computing power, crash or lag.

Method used

By using preset keys and session salt values ​​in the data sender and receiver, and using these keys to encrypt and decrypt the packets, combining the session counter and counter update mechanisms, the encryption transmission and decryption of packets are achieved.

Benefits of technology

It effectively ensures the confidentiality and security of the message, reduces the data processing volume, and avoids the problem of crashes or lags caused by insufficient computing power.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995839A_ABST
    Figure CN119995839A_ABST
Patent Text Reader

Abstract

The invention discloses a data communication method and device and a vehicle, and the method comprises the steps: generating a first session salt value through employing a count value of a first session counter after a to-be-sent message and a first preset key are obtained, and the first session counter comprises at least one of a first synchronous counter and a first reset counter; and generating a first secret key by using the first preset secret key and the first session salt value, encrypting the message by using the first secret key to obtain an encrypted message, and sending the encrypted message. The data sender generates the first secret key by using the first preset secret key and the first session salt value, and encrypts the message by using the first secret key, so that encrypted transmission of the message is realized, and confidentiality and security of the message are effectively ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data communication technology, and in particular to a data communication method and device, and a vehicle. Background Art

[0002] The vehicle may include a data sender and a data receiver, and the data sender may send a message to the data receiver via a controller area network with flexible data rate (CAN FD) between domains. Summary of the invention

[0003] In view of the above problems, the present invention proposes a data communication method, device, and vehicle, wherein the data sender obtains a message to be sent and a first preset key, and after using the count value of a first session counter to generate a first session salt value, uses the first preset key and the first session salt value to generate a first key, and uses the first key to encrypt the message and send the encrypted message. Thus, encrypted transmission of the message is achieved, and the confidentiality and security of the message are effectively guaranteed.

[0004] In a first aspect, the present invention provides a data communication method, comprising: obtaining a message to be sent and a first preset key, and using a count value of a first session counter to generate a first session salt value, the first session counter including at least one of a first synchronization counter and a first reset counter; using the first preset key and the first session salt value to generate a first key, and using the first key to encrypt the message to obtain an encrypted message; and sending the encrypted message.

[0005] Since the data sender uses the first preset key and the first session salt value to generate the first key, and uses the first key to encrypt the message, encrypted transmission of the message is achieved, thereby effectively ensuring the confidentiality and security of the message.

[0006] Moreover, since the data sender uses a small number of counter count values ​​to generate the first session salt value, the amount of data that the data sender needs to process can be reduced, effectively avoiding the impact on the data sender's computing power, thereby avoiding problems such as freezing and freezing of the data sender.

[0007] In some embodiments of the present invention, the first session counter includes: a first synchronization counter and a first reset counter, and using the count value of the first session counter to generate the first session salt value includes: using the count value of the first synchronization counter and the count value of the first reset counter to generate the first session salt value.

[0008] In some embodiments of the present invention, the method further includes: updating the first session salt value at preset time intervals.

[0009] Thus, the update frequency of the first session salt value can be guaranteed, thereby ensuring the confidentiality of the first session salt value.

[0010] In some embodiments of the present invention, the first session salt value is updated at preset time intervals, including: updating the count value of the first synchronization counter and the count value of the first reset counter respectively at preset time intervals; using the count value after the update of the first synchronization counter and the count value after the update of the first reset counter to combine and generate the first session salt value.

[0011] In some embodiments of the present invention, the method also includes: using the message identifier of the message as additional authentication data; using the count value of the first message counter corresponding to the additional authentication data to generate an initial vector; using the message, additional authentication data, the initial vector and the first key to generate an authentication identifier; sending the authentication identifier, the additional authentication data and the initial vector.

[0012] By using the message identifier of the message as additional authentication data and using the count value of the first message counter corresponding to the message identifier of the message to generate an initial vector, authenticity protection of the message identifier and protection against replay attacks can be achieved.

[0013] In some embodiments of the present invention, the first message counter includes: a first message counter and a second reset counter; using the count value of the first message counter corresponding to the additional authentication data to generate an initial vector, including: determining the first message counter corresponding to the additional authentication data, and controlling the count value of the first message counter to increase by a preset value; combining the low bits of the count value of the first message counter and the count value of the second reset counter to generate an initial vector.

[0014] Since the data sender generates the initial vector by using the count value of the first message counter of the first message counter corresponding to the additional authentication data and the low-order combination of the count value of the second reset counter, the authenticity protection of the message identification and the protection against replay attacks can be achieved.

[0015] In a second aspect, the present invention provides another data communication method, the method comprising: obtaining a second preset key, and using the count value of a second session counter to generate a second session salt value, the second session counter comprising at least one of a second synchronization counter and a third reset counter; using the second preset key and the second session salt value to generate a second key, and using the second key to decrypt the received encrypted message.

[0016] Since the data receiving party uses the second preset key and the second session salt value to generate the second key, and uses the second key to decrypt the message, the message can be successfully decrypted. Since the data receiving party uses a small number of counter count values ​​to generate the second session salt value, the amount of data that the data receiving party needs to process can be reduced, effectively avoiding the impact on the computing power of the data receiving party, thereby avoiding the data receiving party from freezing, freezing and other problems.

[0017] In some embodiments of the present invention, the second session counter includes: a second synchronization counter and a third reset counter; using the count value of the second session counter to generate the second session salt value includes: using the count value of the second synchronization counter and the count value of the third reset counter to generate the second session salt value.

[0018] In some embodiments of the present invention, the method further includes: updating the second session salt value at preset time intervals.

[0019] In some embodiments of the present invention, the second session salt value is updated at preset time intervals, including: updating the count value of the second synchronization counter and the count value of the third reset counter respectively at preset time intervals; using the updated count value of the second synchronization counter and the updated count value of the third reset counter to combine and generate the second session salt value.

[0020] In some embodiments of the present invention, the method further includes: receiving additional authentication data, an initial vector, and an authentication identifier; generating a vector check value using a count value of a second message counter corresponding to the additional authentication data; decrypting the received encrypted message using a second key, including: if the vector check value is the same as the initial vector, decrypting the received encrypted message using the second key;

[0021] The method also includes: if the encrypted message is successfully decrypted using the second key, then using the decrypted message, additional authentication data, vector check value and the second key to generate an identification check value; if the identification check value is the same as the authentication identifier, then outputting the decrypted message.

[0022] In some embodiments of the present invention, the second message counter includes: a second message counter and a fourth reset counter; the count value of the second message counter corresponding to the additional authentication data is used to generate a vector check value, including: determining the second message counter corresponding to the additional authentication data, and controlling the count value of the second message counter to increase by a preset value; and combining the low bits of the count value of the second message counter and the count value of the fourth reset counter to generate a vector check value.

[0023] In a third aspect, the present invention provides a computer-readable storage medium having a data communication program stored thereon, which implements the above-mentioned data communication method when executed by a processor.

[0024] In a fourth aspect, the present invention provides a data sender, comprising: a memory, a processor, and a data communication program stored in the memory and executable on the processor, wherein when the processor executes the data communication program, the above-mentioned data communication method is implemented.

[0025] In a fifth aspect, the present invention provides a data receiver, comprising: a memory, a processor, and a data communication program stored in the memory and executable on the processor, wherein when the processor executes the data communication program, the above-mentioned data communication method is implemented.

[0026] In a sixth aspect, the present invention provides a data communication device, comprising: an acquisition module, used to acquire a message to be sent and a first preset key; a determination module, used to generate a first session salt value using the count value of a first session counter, and to generate a first key using the first preset key and the first session salt value, the first session counter comprising at least one of a first synchronization counter and a first reset counter; an encryption module, used to encrypt the message using the first key to obtain an encrypted message; and a sending module, used to send the encrypted message.

[0027] Since the data sender uses the first preset key and the first session salt value to generate the first key, and uses the first key to encrypt the message, encrypted transmission of the message is achieved, thereby effectively ensuring the confidentiality of the message.

[0028] In the seventh aspect, the present invention provides another data communication device, which includes: a second acquisition module, used to obtain a second preset key; a second determination module, used to generate a second session salt value using the count value of a second session counter, and use the second preset key and the second session salt value to generate a second key, the second session counter including at least one of a second synchronization counter and a third reset counter; a decryption module, used to decrypt the received encrypted message using the second key.

[0029] Since the data receiving party uses the second preset key and the second session salt value to generate the second key, and uses the second key to decrypt the message, decryption of the message is achieved.

[0030] In an eighth aspect, the present invention provides a vehicle, comprising the above-mentioned data sender and data receiver.

[0031] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1is a flow chart of a data communication method provided by an embodiment of the present invention;

[0033] Figure 2 is a flow chart of another data communication method provided by an embodiment of the present invention;

[0034] Figure 3 is a schematic diagram of an encryption algorithm provided by an embodiment of the present invention;

[0035] Figure 4 is a flow chart of another data communication method provided by an embodiment of the present invention;

[0036] Figure 5 is a flow chart of another data communication method provided by an embodiment of the present invention;

[0037] Figure 6 is a schematic diagram of a decryption algorithm provided by an embodiment of the present invention;

[0038] Figure 7 is a structural diagram of a data sender provided by an embodiment of the present invention;

[0039] Figure 8 is a structural diagram of a data receiver provided by an embodiment of the present invention;

[0040] Fig. 9 is a block diagram of a data communication device provided by an embodiment of the present invention;

[0041] Fig.10 It is a block diagram of another data communication device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0042] The following embodiments of the technical solution of the present invention are described in detail in conjunction with the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, and are therefore only used as examples, and cannot be used to limit the protection scope of the present invention.

[0043] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by technicians in the technical field to which the present invention belongs; the terms used herein are only for the purpose of describing specific embodiments and are not intended to limit the present invention; the terms "including" and "having" in the specification and claims of the present invention and the above-mentioned figure descriptions and any variations thereof are intended to cover non-exclusive inclusions.

[0044] In the description of the embodiments of the present invention, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present invention, the meaning of "multiple" is more than two, unless otherwise clearly and specifically defined.

[0045] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0046] In the description of the embodiments of the present invention, the term "multiple" refers to more than two (including two). Similarly, "multiple groups" refers to more than two groups (including two groups), and "multiple pieces" refers to more than two pieces (including two pieces).

[0047] In the description of the embodiments of the present invention, unless otherwise clearly specified and limited, technical terms such as "installed", "connected", "connected", "fixed" and the like should be understood in a broad sense, for example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, it can be the internal connection of two elements or the interaction relationship between two elements. For ordinary technicians in this field, the specific meanings of the above terms in the embodiments of the present invention can be understood according to specific circumstances.

[0048] The vehicle may include a data sender and a data receiver, and the data sender may send a message to the data receiver via an inter-domain variable rate controller area network CAN FD.

[0049] The present invention proposes a data communication method, device and vehicle. In the method, a data sender uses a first preset key and a first session salt value to generate a first key, and uses the first key to encrypt a message, thereby realizing encrypted transmission of the message. Compared with plain text transmission of the message, the confidentiality and security of the message are effectively guaranteed.

[0050] Figure 1 FIG. 1 is a flow chart of a data communication method provided by an embodiment of the present invention, and the method is applied to the data sender of a vehicle. Figure 1 As shown, the method includes:

[0051] Step 101: Obtain a message to be sent and a first preset key, and use the count value of a first session counter to generate a first session salt value.

[0052] The data sender may obtain the message to be sent and the first preset key, and use the count value of the first session counter to generate the first session salt value. The first session counter may include at least one of a first synchronization counter and a first reset counter. The data sender may store the first preset key in advance. For example, when the vehicle is produced and rolled off the production line, the first preset key may be uniformly set in the storage area of ​​the data sender.

[0053] Compared with using the count values ​​of multiple counters (for example, four counters) to generate the first session salt value, the method provided in the embodiment of the present invention can reduce the amount of data that the data sender needs to process, effectively avoid affecting the computing power of the data sender, and further avoid problems such as freezing or freezing of the data sender, because the data sender uses the count values ​​of a small number of counters (such as at least one of the first synchronization counter and the first reset counter) to generate the first session salt value.

[0054] Step 102: Generate a first key using a first preset key and a first session salt value, and encrypt the message using the first key to obtain an encrypted message.

[0055] After obtaining the message to be sent, the first preset key and the first session salt value, the data sender can use the first preset key and the first session salt value to generate a first key, and use the first key to encrypt the message to obtain an encrypted message.

[0056] Step 103: Send the encrypted message.

[0057] After the data sender encrypts the message using the first key, the encrypted message can be sent.

[0058] In summary, the present invention provides a data communication method, in which a data sender obtains a message to be sent and a first preset key, and uses the count value of a first session counter to generate a first session salt value. Then, the first preset key and the first session salt value can be used to generate a first key, and the first key can be used to encrypt the message and send the encrypted message.

[0059] Since the data sender uses the first preset key and the first session salt value to generate the first key, and uses the first key to encrypt the message, the encrypted transmission of the message is realized, and the confidentiality and security of the message are effectively guaranteed. And since the data sender uses a small number of counter count values ​​to generate the first session salt value, the amount of data that the data sender needs to process can be reduced, effectively avoiding the impact on the computing power of the data sender, and thus avoiding the data sender from freezing or freezing.

[0060] Figure 2FIG. 1 is a flow chart of another data communication method provided by an embodiment of the present invention, and the method is applied to a data sender. Figure 2 As shown, the method may include:

[0061] Step 201: Obtain a message to be sent and a first preset key.

[0062] The data sender obtains the message to be sent and the first preset key, wherein the data sender can pre-store the first preset key. For example, when the vehicle is produced off the production line, the first preset key can be uniformly set in the storage area of ​​the data sender.

[0063] Step 202: Generate a first session salt value using the count value of the first session counter.

[0064] After obtaining the message to be sent and the first preset key, the data sender may use the count value of the first session counter to generate a first session salt value.

[0065] The first session counter may include at least one of a first synchronization counter and a first reset counter. Optionally, the first session counter may include a first synchronization counter and a first reset counter. The data sender may generate the first session salt value by combining the count value of the first synchronization counter and the count value of the first reset counter.

[0066] Compared with using the count values ​​of multiple counters (for example, four counters) to generate the first session salt value, the method provided in the embodiment of the present invention can reduce the amount of data that the data sender needs to process, effectively avoid affecting the computing power of the data sender, and further avoid problems such as freezing or freezing of the data sender, because the data sender uses a small number of counters (such as at least one of the first synchronization counter and the first reset counter) to combine the count values ​​to generate the first session salt value.

[0067] Step 203: Generate a first key using the first preset key and the first session salt value.

[0068] After the data sender uses the count value of the first session counter to generate the first session salt value, it can use the first preset key and the first session salt value to generate the first key.

[0069] Optionally, the data sender may use a key derivation function (KDF) algorithm to process the first preset key and the first session salt value to generate the first key.

[0070] In the embodiment of the present invention, the data sender may update the first session salt value at preset time intervals.

[0071] Optionally, the data sender may update the count value of the first synchronization counter and the count value of the first reset counter at preset time intervals, and use the updated count value of the first synchronization counter and the updated count value of the first reset counter to combine and generate the first session salt value, thereby achieving periodic update of the first session salt value.

[0072] Among them, the preset duration can be set according to actual needs and pre-stored in the data sender. For example, the preset duration can be 30 seconds. The data sender can update the count value of the first synchronization counter and the count value of the first reset counter every 30 seconds, thereby updating the first session salt value.

[0073] The data sender updates the first session salt value at a preset time interval, which can effectively reduce the risk of the first key being cracked during repeated use, ensure the security of data communication, and reduce the update frequency of the first key, reducing the dependence on chip performance. At the same time, the data sender uses the first preset key and the first session salt value to generate the first key as the key used for message encryption, ensuring the confidentiality and secure storage of the first preset key.

[0074] Step 204: Use the message identifier of the message as additional authentication data, and use the count value of the first message counter corresponding to the additional authentication data to generate an initial vector.

[0075] After the data sender generates the first key using the first preset key and the first session salt value, it can obtain the message identifier of the message, use the message identifier as additional authentication data, and use the count value of the first message counter corresponding to the additional authentication data to generate an initial vector.

[0076] The first message counter may include a first message counter and a second reset counter, and the second reset counter and the first reset counter may be the same counter or different counters. There may be multiple first message counters, and the multiple first message counters correspond one-to-one to multiple identifiers, and the identifier may be an identifier of the message.

[0077] The data sender may determine a first message counter corresponding to the additional authentication data, control the count value of the first message counter to increase by a preset value, and combine the low bits of the count value of the first message counter and the count value of the second reset counter to generate an initial vector. The data sender may pre-store the preset value, for example, the preset value may be 1.

[0078] In an embodiment of the present invention, each time the data sender sends a message, it can control the count value of the first message counter corresponding to the message identifier (i.e., additional authentication data) of the message to increase by a preset value based on the current count value, and combine the updated count value of the first message counter and the low-order count value of the second reset counter to generate an initial vector.

[0079] In the case that the second reset counter and the first reset counter are the same counter, the count value of the second reset counter is updated once every preset time period.

[0080] When the second reset counter and the first reset counter are different counters and the second reset counter is one, the data sender may update the count value of the second reset counter every target duration. The data sender may pre-store the target duration, which is different from the preset duration.

[0081] Since each identifier corresponds to a first message counter, and the data sender updates the initialization vector after the count value of the first message counter is updated, each identifier also corresponds to an initialization vector. When sending a message identified as a message identifier, the data sender updates the count value of the first message counter to update the initialization vector corresponding to the message identifier when sending the message.

[0082] In an embodiment of the present invention, the message identifier of the message is used as additional authentication data, and the count value of the first message counter corresponding to the message identifier and the low-order combination of the count value of the second reset counter are used to generate an initial vector, which can achieve authenticity protection of the message identifier and protection against replay attacks.

[0083] In the case where the second reset counter and the first reset counter are different counters and there are multiple second reset counters, the multiple second reset counters correspond one to one with the multiple identifiers. The data sender can also determine the second reset counter corresponding to the additional authentication data, and control the count value of the second reset counter to increase by a target value. Then the data sender can generate an initial vector by combining the low bits of the updated count value of the first message counter and the updated count value of the second reset counter. The target value can be the same as or different from the preset value.

[0084] Since each identifier corresponds to a first message counter and a second reset counter, and the data sender updates the initial vector after updating the count value of the first message counter and the count value of the second reset counter, each identifier also corresponds to an initial vector. When sending a message identified as a message identifier, the data sender updates the count value of the first message counter and the count value of the second reset counter to update the initial vector corresponding to the message identifier when sending the message.

[0085] In an embodiment of the present invention, the message identifier of the message is used as additional authentication data, and the count value of the first message counter corresponding to the message identifier and the low-order combination of the count value of the second reset counter corresponding to the message identifier are used to generate an initial vector, which can achieve authenticity protection of the message identifier and protection against replay attacks.

[0086] Step 205: Use the first key to encrypt the message, and use the message, additional authentication data, the initial vector and the first key to generate an authentication identifier.

[0087] After the data sender generates an initial vector using the count value of the first message counter corresponding to the additional authentication data, it can use the first key to encrypt the message to obtain an encrypted message, and use the message, additional authentication data, the initial vector and the first key to generate an authentication identifier.

[0088] refer to Figure 3 The data sender can input the first key K1, the message P, the initial vector IV1 and the additional authentication data ADD into the encryption algorithm E1 to obtain the encrypted message C and the authentication identifier T1 output by the encryption algorithm E1. Optionally, the encryption algorithm E1 can be an AES-GCM encryption algorithm.

[0089] By inputting various input values ​​(first key, message, initial vector and additional authentication data) into the encryption algorithm, the encrypted message and authentication identifier output by the encryption algorithm are obtained, thereby effectively ensuring the authenticity, integrity and timeliness of the encrypted message while achieving encryption.

[0090] Step 206: Send the encrypted message, authentication identifier, additional authentication data and initialization vector.

[0091] After the data sender generates an encrypted message using the encrypted message, additional authentication data and initial vector combination, it can send the encrypted message, authentication identifier, additional authentication data and initial vector to the data receiver via CAN FD.

[0092] In summary, the present invention provides a data communication method, in which a data sender obtains a message to be sent and a first preset key, and uses the count value of a first session counter to generate a first session salt value, then uses the first preset key and the first session salt value to generate a first key, and uses the first key to encrypt the message and send the encrypted message.

[0093] Since the data sender uses the first preset key and the first session salt value to generate the first key, and uses the first key to encrypt the message, encrypted transmission of the message is achieved, thereby effectively ensuring the confidentiality and security of the message.

[0094] Figure 4FIG. 1 is a flow chart of another data communication method provided by an embodiment of the present invention, and the method is applied to a data receiving party of a vehicle. Figure 4 As shown, the method may include:

[0095] Step 401: Obtain a second preset key, and use the count value of a second session counter to generate a second session salt value.

[0096] The data receiver may obtain the second preset key and generate the second session salt value using the count value of the second session counter. The second session counter may include at least one of a second synchronization counter and a third reset counter. The data receiver may store the second preset key in advance. For example, when the vehicle is produced and rolled off the production line, the second preset key may be uniformly set in the storage area of ​​the data receiver.

[0097] Since the data receiver uses the count values ​​of a small number of counters (at least one of the second synchronization counter and the third reset counter) to generate the second session salt value, the amount of data that the data receiver needs to process can be reduced, effectively avoiding the impact on the computing power of the data receiver, thereby avoiding problems such as freezing or freezing of the data receiver.

[0098] Step 402: Generate a second key using the second preset key and the second session salt value, and use the second key to decrypt the received encrypted message.

[0099] After the data receiver obtains the second preset key and generates a second session salt value using the count value of the second session counter, it can generate a second key using the second preset key and the second session salt value, and use the second key to decrypt the received encrypted message.

[0100] In summary, the present invention provides a data communication method, in which a data receiving party obtains a second preset key, generates a second session salt value using the count value of a second session counter, generates a second key using the second preset key and the second session salt value, and decrypts a message using the second key. Since the data receiving party generates the second key using the second preset key and the second session salt value, and decrypts the message using the second key, the message is successfully decrypted.

[0101] Figure 5 FIG. 1 is a flow chart of another data communication method provided by an embodiment of the present invention, and the method is applied to a data receiving party of a vehicle. Figure 5 As shown, the method may include:

[0102] Step 501: Receive an encrypted message, an authentication identifier, additional authentication data and an initialization vector.

[0103] The data receiver can receive the encrypted message, authentication identifier, additional authentication data and initialization vector sent by the data sender.

[0104] Step 502: Generate a vector check value using the count value of the second message counter corresponding to the additional authentication data.

[0105] After receiving the encrypted message, authentication identifier, additional authentication data and initial vector sent by the data sender, the data receiver may use the count value of the second message counter corresponding to the additional authentication data to generate a vector check value.

[0106] The second message counter may include a second message counter and a fourth reset counter. When the first reset counter and the second reset counter are the same counter, the fourth reset counter and the third reset counter included in the second session counter are also the same counter, and the first reset counter and the third reset counter are kept synchronized. When the first reset counter and the second reset counter are different counters, the fourth reset counter and the third reset counter are also different counters, and the first reset counter and the third reset counter are kept synchronized, and the second reset counter and the fourth reset counter are kept synchronized.

[0107] In the embodiment of the present invention, there may be multiple second message counters, and the multiple second message counters correspond to the multiple identifiers one by one. The second message counter corresponding to the same identifier is synchronized with the first message counter, that is, the identifier corresponding to the second message counter is the same as the identifier corresponding to the first message counter.

[0108] The data receiver may obtain the second message counter corresponding to the additional authentication data, and control the count value of the second message counter to increase by a preset value. Optionally, the data receiver may pre-store the preset value, for example, the preset value may be 1. The data receiver combines the count value of the second message counter and the low bits of the count value of the fourth reset counter to generate a vector check value.

[0109] In an embodiment of the present invention, each time the data recipient receives an encrypted message, it can control the count value of the second message counter corresponding to the message identifier (i.e., additional authentication data) of the encrypted message to increase by a preset value based on the current count value, and combine the updated count value of the second message counter and the low-order bits of the count value of the fourth reset counter to generate a vector check value.

[0110] In the case that the fourth reset counter and the third reset counter are the same counter, the count value of the fourth reset counter is updated once every preset time period.

[0111] In the case where the fourth reset counter and the third reset counter are different counters and the fourth reset counter is one, if the data sender updates the count value of the second reset counter every target duration, the data receiver also updates the count value of the fourth reset counter every target duration. The target duration may be pre-stored in the data receiver.

[0112] Since each identifier corresponds to a second message counter, and the data receiving party updates the vector check value after the count value of the second message counter is updated, each identifier also corresponds to a vector check value. When the data receiving party receives an encrypted message identified as a message identifier, the data receiving party updates the count value of the second message counter to update the vector check value corresponding to the message identifier when receiving the encrypted message.

[0113] When the fourth reset counter and the third reset counter are different counters and there are multiple second reset counters, the multiple second reset counters correspond one-to-one to the multiple identifiers, and there are also multiple fourth reset counters, which correspond one-to-one to the multiple identifiers.

[0114] Correspondingly, if the data sender controls the count value of the second reset counter corresponding to the additional authentication data to increase by the target value, and combines the low bits of the count value after the first message counter is updated and the count value after the second reset counter is updated to generate the initial vector, then the data receiver can also determine the fourth reset counter corresponding to the additional authentication data, and control the count value of the fourth reset counter to increase by the target value. Then the data receiver can combine the low bits of the count value after the second message counter is updated and the count value after the fourth reset counter is updated to generate the vector check value.

[0115] Since each identifier corresponds to a second message counter and a fourth reset counter, and the data receiving party updates the vector check value after updating the count value of the second message counter and the count value of the fourth reset counter, each identifier also corresponds to a vector check value. When receiving an encrypted message identified as a message identifier, the data receiving party updates the count value of the second message counter and the count value of the fourth reset counter to update the vector check value corresponding to the message identifier when receiving the encrypted message.

[0116] Step 503: Verify whether the vector check value is the same as the initial vector.

[0117] After the data receiver generates the vector check value using the count value of the second message counter corresponding to the additional authentication data, it can verify whether the vector check value is the same as the initial vector. If the vector check value is the same as the initial vector, it can be determined that the initial vector verification is passed, so step 504 is executed. If the vector check value is different from the initial vector, it can be determined that the initial vector verification fails, so step 510 is executed.

[0118] The data receiver can effectively verify whether the timeliness of the transmitted encrypted message is correct by using the vector check value to verify the initial vector. If correct, step 504 is executed to continue decrypting the encrypted message.

[0119] Step 504: Obtain a second preset key, and use the count value of the second session counter to generate a second session salt value.

[0120] If the data receiver determines that the vector check value is the same as the initial vector, it can be determined that the initial vector is verified successfully, so the second preset key can be obtained, and the count value of the second session counter can be used to generate a second session salt value.

[0121] The data receiver may store the second preset key in advance. For example, when the vehicle is produced off the production line, the second preset key may be uniformly set in the storage area of ​​the data sender.

[0122] The second session counter may include at least one of a second synchronization counter and a third reset counter. Optionally, the second session counter may include a second synchronization counter and a third reset counter.

[0123] The data receiver may generate a second session salt value by combining the count value of the second synchronization counter and the count value of the third reset counter.

[0124] Since the data receiver uses a small number of counter count values ​​to generate the second session salt value, the amount of data that the data receiver needs to process can be reduced, effectively avoiding the impact on the computing power of the data receiver, thereby avoiding problems such as freezing or freezing of the data receiver.

[0125] It should be noted that the second synchronous counter is synchronized with the first synchronous counter.

[0126] Step 505: Generate a second key using the second preset key and the second session salt value.

[0127] After the data receiver obtains the second preset key and uses the count value of the second session counter to generate the second session salt value, the second preset key and the second session salt value may be used to generate the second key.

[0128] Optionally, the data recipient may use a KDF algorithm to process the second preset key and the second session salt value to generate a second key.

[0129] In the embodiment of the present invention, the data receiver may update the second session salt value at preset time intervals.

[0130] Optionally, the data receiving party may update the count value of the second synchronization counter and the count value of the third reset counter respectively at preset time intervals, and use the count value updated by the second synchronization counter and the count value updated by the third reset counter to generate the second session salt value in combination, thereby periodically updating the second session salt value. The preset time duration may be set according to actual needs and pre-stored in the data receiving party.

[0131] The data receiver updates the second session salt value at a preset time interval, which can effectively reduce the risk of the second key being cracked during repeated use, ensure the security of data communication, and reduce the update frequency of the second key, reducing the dependence on chip performance. At the same time, the data receiver uses the second preset key and the second session salt value to generate the second key as the key used for decrypting encrypted messages, ensuring the confidentiality and secure storage of the second preset key.

[0132] Step 506: Verify whether the encrypted message is successfully decrypted using the second key.

[0133] After the data receiving party generates the second key using the second preset key and the second session salt value, it can verify whether the encrypted message is successfully decrypted using the second key. If the encrypted message is successfully decrypted using the second key, step 507 can be executed. If the encrypted message is not decrypted using the second key, step 510 can be executed.

[0134] refer to Figure 6 The data recipient can input the encrypted message C and the second key K2 into the decryption algorithm E2, so that the decryption algorithm E2 processes the second key K2 and the encrypted message C to achieve decryption of the encrypted message C.

[0135] The decryption algorithm used by the data receiver must be the same as the encryption algorithm used by the data sender. For example, if the data sender uses the AES-GCM encryption algorithm to encrypt the message, the data receiver uses the AES-GCM decryption algorithm to decrypt the encrypted message.

[0136] Step 507: Generate an identification check value using the decrypted message, the additional authentication data, the vector check value and the second key.

[0137] After the data receiver successfully decrypts the encrypted message using the second key, it can use the decrypted message, additional authentication data, vector check value and the second key to generate an identification check value.

[0138] refer to Figure 6 The data recipient can also input the additional authentication data ADD and the vector check value IV2 into the decryption algorithm E2. After the data recipient uses the decryption algorithm E2 to process the second key K2 and the encrypted message C and successfully decrypts the encrypted message C, the decryption algorithm E2 can be used to process the decrypted message P, the additional authentication data ADD, the vector check value IV2 and the second key K2 to generate an identification check value.

[0139] Step 508: Verify whether the identification check value is the same as the authentication identification.

[0140] After the data receiving party generates the identification verification value using the decrypted message, the additional authentication data, the vector verification value and the second key, it can verify whether the identification verification value is the same as the authentication identification. If the identification verification value is the same as the authentication identification, step 509 can be executed. If the identification verification value is different from the authentication identification, step 510 can be executed.

[0141] refer to Figure 6 The data recipient may also input the authentication identifier T1 into the decryption algorithm E2. After the data recipient uses the decryption algorithm E2 to generate an identifier verification value, the decryption algorithm E2 may be used to verify whether the identifier verification value is the same as the authentication identifier T1.

[0142] Step 509: Output the decrypted message.

[0143] After the data receiver verifies that the identifier check value is the same as the authentication identifier, it can output the decrypted message.

[0144] refer to Figure 6 If the data receiver uses the decryption algorithm E2 to verify that the identifier check value is the same as the authentication identifier T1, the decrypted message P output by the decryption algorithm E2 can be obtained.

[0145] Step 510: discard the encrypted message.

[0146] If the verification vector check value is different from the initial vector, or the encrypted message fails to be decrypted using the second key, or the verification identifier check value is different from the authentication identifier, the data receiver may discard the encrypted message.

[0147] In summary, the present invention provides a data communication method, in which a data receiver obtains a second preset key, uses the count value of a second session counter to generate a second session salt value, then uses the second preset key and the second session salt value to generate a second key, and uses the second key to decrypt the message to obtain a decrypted message.

[0148] The embodiment of the present invention provides a computer-readable storage medium on which a data communication program is stored. When the data communication program is executed by a processor, the data communication method shown in the above embodiment is implemented. For example, Figure 1 , Figure 2 , Figure 4 or Figure 5 The data communication method shown.

[0149] Figure 7 is a structural diagram of a data sender provided by an embodiment of the present invention, such as Figure 7 As shown, the computer device 70 may include a memory 701, a processor 702, and a data communication program stored in the memory 701 and executable on the processor 702. When the processor 702 executes the data communication program, the data communication method shown in the above embodiment is implemented. Figure 1 or Figure 2 The data communication method shown.

[0150] Figure 8 is a structural diagram of a data receiver provided by an embodiment of the present invention, such as Figure 8 As shown, the computer device 80 may include a memory 801, a processor 802, and a data communication program stored in the memory 801 and executable on the processor 802. When the processor 802 executes the data communication program, the data communication method shown in the above embodiment is implemented. Figure 4 or Figure 5 The data communication method shown.

[0151] Fig. 9 is a block diagram of a data communication device provided by an embodiment of the present invention, such as Fig. 9 As shown, the device comprises:

[0152] An acquisition module 901 is used to acquire a message to be sent and a first preset key;

[0153] A determination module 902 is configured to generate a first session salt value using a count value of a first session counter, and to generate a first key using a first preset key and the first session salt value, wherein the first session counter includes at least one of a first synchronization counter and a first reset counter;

[0154] The encryption module 903 is used to encrypt the message using the first key to obtain an encrypted message;

[0155] The sending module 904 is used to send the encrypted message.

[0156] Optionally, the first session counter includes: a first synchronization counter and a first reset counter, and the determination module 902 is configured to generate a first session salt value by combining a count value of the first synchronization counter and a count value of the first reset counter.

[0157] Optional, reference Fig. 9 , the device further comprises:

[0158] The updating module 905 is configured to update the first session salt value at a preset time interval.

[0159] Optionally, an updating module 905 is configured to update the count value of the first synchronization counter and the count value of the first reset counter at preset time intervals;

[0160] The determination module 902 is configured to generate a first session salt value by combining the updated count value of the first synchronization counter and the updated count value of the first reset counter.

[0161] Optional, reference Fig. 9 , the device further comprises:

[0162] The vector generation module 906 is used to use the message identifier of the message as the additional authentication data; and to generate an initial vector using the count value of the first message counter corresponding to the additional authentication data;

[0163] An identification generation module 907, used to generate an authentication identification using a message, additional authentication data, an initialization vector and a first key;

[0164] The sending module 904 is used to send the authentication identifier, additional authentication data and the initial vector.

[0165] Optionally, the first message counter includes: a first message counter and a second reset counter; a vector generation module 906, configured to:

[0166] Determine a first message counter corresponding to the additional authentication data, and control the count value of the first message counter to automatically increase by a preset value;

[0167] The count value of the first message counter and the lower bits of the count value of the second reset counter are combined to generate an initial vector.

[0168] In summary, the present invention provides a data communication device, in which a data sender obtains a message to be sent and a first preset key, and uses the count value of a first session counter to generate a first session salt value, then uses the first preset key and the first session salt value to generate a first key, and uses the first key to encrypt the message and send the encrypted message.

[0169] Since the data sender uses the first preset key and the first session salt value to generate the first key, and uses the first key to encrypt the message, encrypted transmission of the message is achieved, thereby effectively ensuring the confidentiality and security of the message.

[0170] Fig.10is a block diagram of another data communication device provided by an embodiment of the present invention, such as Fig.10 As shown, the device comprises:

[0171] The second acquisition module 1001 is used to acquire a second preset key;

[0172] A second determination module 1002 is configured to generate a second session salt value by using a count value of a second session counter, and to generate a second key by using a second preset key and a second session salt value, wherein the second session counter includes at least one of a second synchronization counter and a third reset counter;

[0173] The decryption module 1003 is used to decrypt the received encrypted message using the second key.

[0174] Optionally, the second session counter includes: a second synchronization counter and a third reset counter; and a second determination module 1002, configured to:

[0175] The second session salt value is generated by combining the count value of the second synchronization counter and the count value of the third reset counter.

[0176] Optionally, the device further comprises:

[0177] The second updating module 1004 is configured to update the second session salt value at a preset time interval.

[0178] Optionally, the second updating module 1004 is used to:

[0179] At preset time intervals, respectively updating the count value of the second synchronization counter and the count value of the third reset counter;

[0180] The second determining module 1002 is configured to generate a second session salt value by combining the updated count value of the second synchronization counter and the updated count value of the third reset counter.

[0181] Optionally, the device further comprises:

[0182] Receiving module 1005, used to receive additional authentication data, an initialization vector and an authentication identifier;

[0183] A second vector generating module 1006, configured to generate a vector check value using a count value of a second message counter corresponding to the additional authentication data;

[0184] The decryption module 1003 is used to:

[0185] If the vector check value is the same as the initial vector, the received encrypted message is decrypted using the second key;

[0186] The device also includes:

[0187] The identification verification module 1007 is used to generate an identification verification value using the decrypted message, the additional authentication data, the vector verification value and the second key if the encrypted message is successfully decrypted using the second key;

[0188] If the identifier check value is the same as the authentication identifier, the decrypted message is output.

[0189] Optionally, the second message counter includes: a second message counter and a fourth reset counter; a second vector generating module 1006, configured to:

[0190] Determine a second message counter corresponding to the additional authentication data, and control the count value of the second message counter to automatically increase by a preset value;

[0191] The count value of the second message counter and the lower bits of the count value of the fourth reset counter are combined to generate a vector check value.

[0192] In summary, the present invention provides a data communication device, in which a data receiver obtains a second preset key, uses the count value of a second session counter to generate a second session salt value, then uses the second preset key and the second session salt value to generate a second key, and uses the second key to decrypt the message, thereby achieving decryption of the message.

[0193] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be included in the scope of the claims and specification of the present invention. In particular, as long as there is no structural conflict, the various technical features mentioned in each embodiment can be combined in any way. The present invention is not limited to the specific embodiments disclosed herein, but includes all technical solutions that fall within the scope of the claims.

Claims

1. A data communication method, characterized in that: The method comprises: Acquire a message to be sent and a first preset key, and generate a first session salt value using a count value of a first session counter, where the first session counter includes at least one of a first synchronization counter and a first reset counter; Generate a first key using the first preset key and the first session salt value, and encrypt the message using the first key to obtain an encrypted message; Send the encrypted message.

2. The data communication method according to claim 1, characterized in that: The first session counter includes the first synchronization counter and the first reset counter; Generating a first session salt value using the count value of the first session counter includes: The first session salt value is generated by combining the count value of the first synchronization counter and the count value of the first reset counter.

3. The data communication method according to claim 2, characterized in that: The method further comprises: The first session salt value is updated every preset time period.

4. The data communication method according to claim 3, characterized in that: Updating the first session salt value at a preset time interval includes: At every preset time period, respectively update the count value of the first synchronization counter and the count value of the first reset counter; The first session salt value is generated by combining the updated count value of the first synchronization counter and the updated count value of the first reset counter.

5. The data communication method according to any one of claims 1 to 4, characterized in that: The method further comprises: Using the message identifier of the message as additional authentication data; Generate an initial vector using a count value of a first message counter corresponding to the additional authentication data; Generate an authentication identifier using the message, the additional authentication data, the initial vector and the first key; The authentication identifier, the additional authentication data, and the initialization vector are sent.

6. The data communication method according to claim 5, characterized in that: The first message counter includes: a first message counter and a second reset counter; using the count value of the first message counter corresponding to the additional authentication data to generate an initial vector includes: Determine a first message counter corresponding to the additional authentication data, and control the count value of the first message counter to automatically increase by a preset value; The count value of the first message counter and the lower bits of the count value of the second reset counter are combined to generate an initial vector.

7. A data communication method, characterized in that: The method comprises: Obtain a second preset key, and generate a second session salt value using a count value of a second session counter, where the second session counter includes at least one of a second synchronization counter and a third reset counter; The second preset key and the second session salt value are used to generate a second key, and the second key is used to decrypt the received encrypted message.

8. The data communication method according to claim 7, characterized in that: The second session counter includes: the second synchronization counter and the third reset counter; and using the count value of the second session counter to generate a second session salt value includes: The second session salt value is generated by combining the count value of the second synchronization counter and the count value of the third reset counter.

9. The data communication method according to claim 8, characterized in that: The method further comprises: The second session salt value is updated every preset time period.

10. The data communication method according to claim 9, characterized in that: Updating the second session salt value at a preset time interval includes: At every preset time period, respectively updating the count value of the second synchronization counter and the count value of the third reset counter; The updated count value of the second synchronization counter and the updated count value of the third reset counter are used to generate the second session salt value in combination.

11. The data communication method according to any one of claims 7 to 10, characterized in that: The method further comprises: receiving additional authentication data, an initialization vector, and an authentication identifier; Generate a vector check value using a count value of a second message counter corresponding to the additional authentication data; Decrypting the received encrypted message using the second key includes: If the vector check value is the same as the initial vector, decrypting the received encrypted message using the second key; The method further comprises: If the encrypted message is successfully decrypted using the second key, generating an identification check value using the decrypted message, the additional authentication data, the vector check value and the second key; If the identification verification value is the same as the authentication identification, the decrypted message is output.

12. The data communication method according to claim 11, characterized in that: The second message counter includes: a second message counter and a fourth reset counter; using the count value of the second message counter corresponding to the additional authentication data to generate a vector check value includes: Determine a second message counter corresponding to the additional authentication data, and control the count value of the second message counter to automatically increase by a preset value; The vector check value is generated by combining the count value of the second message counter and the lower bits of the count value of the fourth reset counter.

13. A computer-readable storage medium, characterized in that: A data communication program is stored thereon, and when the data communication program is executed by a processor, the data communication method according to any one of claims 1 to 12 is implemented.

14. A data sender, characterized in that: include: A memory, a processor, and a data communication program stored in the memory and executable on the processor, wherein when the processor executes the data communication program, the data communication method according to any one of claims 1 to 6 is implemented.

15. A data receiver, characterized in that: include: A memory, a processor, and a data communication program stored in the memory and executable on the processor, wherein when the processor executes the data communication program, the data communication method according to any one of claims 7 to 12 is implemented.

16. A data communication device, characterized in that: The device comprises: An acquisition module, used for acquiring a message to be sent and a first preset key; a determination module, configured to generate a first session salt value by using a count value of a first session counter, and to generate a first key by using the first preset key and the first session salt value, wherein the first session counter includes at least one of a first synchronization counter and a first reset counter; An encryption module, used to encrypt the message using the first key to obtain an encrypted message; A sending module is used to send the encrypted message.

17. A data communication device, characterized in that: The device comprises: A second obtaining module, used to obtain a second preset key; a second determining module, configured to generate a second session salt value by using a count value of a second session counter, and to generate a second key by using the second preset key and the second session salt value, wherein the second session counter includes at least one of a second synchronization counter and a third reset counter; A decryption module is used to decrypt the received encrypted message using the second key.

18. A vehicle, characterized in that: It includes the data sender as described in claim 14 and the data receiver as described in claim 15.