System, method, device and equipment for authenticating communication security of Internet of Vehicles, and storage medium

Through the hardware security module and service discovery module, the random key factor is generated and distributed in the Internet of Vehicles environment, the problem of man-in-the-middle attack in the Internet of Vehicles communication is solved and data security and integrity is achieved.

CN119995841APending Publication Date: 2025-05-13智行盒子(河南)科技有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411905891.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

In the Internet of Vehicles environment, the prior art is difficult to effectively protect against man-in-the-middle attacks, which affects the confidentiality and integrity of data during Internet of Vehicles communication.

Method used

Through the combination of the hardware security module and the service discovery module, random key factors are generated and distributed, and multiple vehicle electronic control units generate session keys based on the key factors, and encrypt the plaintext data during the Internet of Vehicles communication process.

Benefits of technology

The security and integrity of data during the Internet of Vehicles communication process is achieved, the risk of man-in-the-middle attacks is avoided, and the confidentiality and integrity of data is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995841A_ABST
    Figure CN119995841A_ABST
Patent Text Reader

Abstract

The invention provides a system, a method, a device and equipment for authenticating the communication security of the Internet of Vehicles, and a storage medium, and the system comprises a hardware security module, a service discovery module and a plurality of vehicle electronic control units. The hardware security module is used for generating a random key factor based on the current Internet of Vehicles communication scene; the service discovery module is used for distributing the random secret key factor to each vehicle electronic control unit; and the plurality of vehicle electronic control units are used for generating a session key according to the random key factor, and encrypting plaintext data in the communication process of the Internet of Vehicles through the session key. According to the method, the effect of ensuring the safety and completeness of data in the communication process of the Internet of Vehicles can be achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data encryption, and more specifically, to a system, method, apparatus, device and storage medium for authenticating the security of vehicle network communications. Background Art

[0002] In the Internet of Vehicles environment, the service discovery protocol is used for service discovery and communication, but it may also introduce some information security risks, such as man-in-the-middle attacks. In order to protect the message data in the serial communication protocol and Ethernet protocol, there must be a secure mechanism to generate and distribute session keys. In the existing technical solution, a pre-shared key or other key exchange protocol is used to generate session keys, and the service discovery protocol is used for service discovery and communication.

[0003] The above methods are usually not dynamic and flexible, and may not effectively protect against man-in-the-middle attacks. After the introduction of the service discovery protocol, the communication process may be subject to man-in-the-middle attacks, affecting the confidentiality and integrity of the data.

[0004] Therefore, how to ensure the security and integrity of data during Internet of Vehicles communications is a technical problem that needs to be solved. Summary of the invention

[0005] The purpose of the embodiments of the present application is to provide a system for authenticating the security of vehicle network communications. The technical solutions of the embodiments of the present application can ensure the security and integrity of data during vehicle network communications.

[0006] In a first aspect, an embodiment of the present application provides a system for authenticating the security of Internet of Vehicles communications, including a hardware security module, a service discovery module and multiple vehicle electronic control units; the hardware security module is used to generate a random key factor based on the current Internet of Vehicles communication scenario; the service discovery module is used to distribute the random key factor to each vehicle electronic control unit; multiple vehicle electronic control units are used to generate a session key based on the random key factor, and encrypt plaintext data in the Internet of Vehicles communication process through the session key.

[0007] In the above-mentioned embodiments of the present application, the generation and distribution of secret key factors are realized through the combination of the hardware security module and the service discovery module. Finally, multiple vehicle electronic control units encrypt the data generated during the Internet of Vehicles communication process through the received secret key factors, thereby ensuring the security and integrity of the data during the Internet of Vehicles communication process.

[0008] In some embodiments, the hardware security module is specifically used to:

[0009] Analyze the communication objects and communication environment in the current Internet of Vehicles communication scenario, where the communication objects include: vehicles, mobile terminals or cloud; match the random key factors corresponding to the communication objects and communication environments.

[0010] In the above embodiments of the present application, the corresponding random key factor can be matched according to the communication object and communication environment in the current Internet of Vehicles communication scenario, and different encryption methods can be implemented according to different scenarios, which is more flexible.

[0011] In some embodiments, the service discovery module is specifically used to:

[0012] The random key factor is distributed to each vehicle electronic control unit through hash verification.

[0013] In the above embodiments of the present application, the integrity of the secret key factor when it is issued to the vehicle electronic control unit can be ensured by means of hash verification.

[0014] In some embodiments, a plurality of vehicle electronic control units are specifically used to:

[0015] The random key factor is analyzed using the in-card distributed key and distributed algorithm to generate the session key. The session key is then used to encrypt the plaintext data in the IoV communication process.

[0016] In the above-mentioned embodiments of the present application, the random key factor is analyzed by using the dispersed key in the card and the dispersed algorithm, so that the session key can be generated effectively and quickly, and the encryption of the data in the vehicle network communication process can be realized.

[0017] In some embodiments, it also includes:

[0018] A security gateway is used to verify the identity of each vehicle electronic control unit and decrypt encrypted plaintext data through a session key.

[0019] In the above embodiments of the present application, identity authentication and data decryption of the vehicle electronic control unit can be achieved through the security gateway.

[0020] On the second aspect, an embodiment of the present application provides a method for authenticating the security of vehicle network communication, including: generating a random key factor based on the current vehicle network communication scenario; distributing the random key factor to each vehicle electronic control unit of the vehicle; encapsulating the random key factor into a session key through each vehicle electronic control unit; and encrypting plaintext data in the vehicle network communication process through the session key.

[0021] In the above embodiments of the present application, through the generation and distribution of secret key factors, multiple vehicle electronic control units encrypt the data generated during the vehicle networking communication process through the received secret key factors, which can ensure the security and integrity of the data during the vehicle networking communication process.

[0022] In some embodiments, based on the current Internet of Vehicles communication scenario, a random key factor is generated, including: analyzing the communication object and communication environment in the current Internet of Vehicles communication scenario, where the communication object includes: a vehicle, a mobile terminal or the cloud; matching the random key factor corresponding to the communication object and the communication environment.

[0023] In the above embodiments of the present application, the corresponding random key factor can be matched according to the communication object and communication environment in the current Internet of Vehicles communication scenario, and different encryption methods can be implemented according to different scenarios, which is more flexible.

[0024] In a third aspect, an embodiment of the present application provides a device for authenticating the security of vehicle network communication, including:

[0025] A generation module, used to generate a random secret key factor based on the current Internet of Vehicles communication scenario;

[0026] A distribution module, for distributing the random key factor to each vehicle electronic control unit of the vehicle;

[0027] A packaging module, used for packaging the random key factors into session keys through each vehicle electronic control unit;

[0028] The encryption module is used to encrypt the plaintext data in the Internet of Vehicles communication process through the session key.

[0029] Optionally, the generation module is specifically used to:

[0030] Analyze the communication objects and communication environment in the current vehicle networking communication scenario, where the communication objects include: vehicles, mobile terminals or cloud;

[0031] A random key factor that matches the communication object and the communication environment.

[0032] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method provided in the first aspect are executed.

[0033] In a fifth aspect, an embodiment of the present application provides a readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the method provided in the first aspect are executed.

[0034] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or be understood by practicing the embodiments of the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0036] Figure 1 A schematic block diagram of a system for authenticating vehicle network communication security provided in an embodiment of the present application;

[0037] Figure 2 A flowchart of a method for authenticating vehicle network communication security provided in an embodiment of the present application;

[0038] Figure 3 A schematic block diagram of a device for authenticating vehicle network communication security provided in an embodiment of the present application;

[0039] Figure 4 A schematic diagram of the structure of a device for authenticating the security of Internet of Vehicles communications provided in an embodiment of the present application. DETAILED DESCRIPTION

[0040] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and shown in the drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0041] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.

[0042] First, some terms involved in the embodiments of the present application are explained to facilitate understanding by those skilled in the art.

[0043] Hash checksum is an important method for computer data integrity check. It processes the complete content of a file or a piece of information through a computer using a specific algorithm to obtain a small, fixed-length digital sequence, which is used as the unique "summary" or "fingerprint" corresponding to the file or information. By comparing the calculated hash value with the previously saved hash value, it can be determined whether the file or information has been tampered with during storage or transmission.

[0044] A hardware security module (HSM) is a computer hardware device used to protect and manage the keys used by strong authentication systems and provide related cryptographic operations. A hardware security module is usually directly connected to a computer or network server in the form of an expansion card or external device.

[0045] SomeIP-SD (Service Discovery) is a service discovery protocol used to discover available services in a local area network or a wide area network. The protocol allows service providers to broadcast their presence to the network and allows service consumers to query services with specific functions on demand.

[0046] SomeIP is an extensible IP-based middleware for service communication in automotive electronic systems. It supports service discovery, request / response, one-way request, notification events and attributes, and handles data structures through serialization and deserialization. SomeIP defines the message format, including header and data segments, for error handling and service addressing.

[0047] CAN protocol is a serial communication protocol, the full name is Controller Area Network. The main purpose is to reduce the number of wiring harnesses and communicate large amounts of data at high speed through multiple LANs.

[0048] ECU is the abbreviation of Electronic Control Unit, also known as vehicle electronic control unit or on-board computer. It is one of the core electronic components of a car, equivalent to the "brain" of the car, responsible for controlling the driving status of the car and realizing various functions.

[0049] AES algorithm (Advanced Encryption Standard) is a symmetric encryption algorithm.

[0050] Public Key Infrastructure (PKI) is a key management platform that follows established standards and can provide cryptographic services such as encryption and digital signatures as well as the necessary key and certificate management system for all network applications.

[0051] Transport Layer Security (TLS) is a security protocol used to provide confidentiality, data integrity, and authenticity between two communicating applications. The protocol consists of the TLS Record Protocol and the TLS Handshake Protocol, and is designed to ensure the security and data integrity of Internet communications.

[0052] This application is applied to the scenario of data encryption in the process of Internet of Vehicles communication. The specific scenario is a communication security authentication method and system based on HSM (hardware security module) and SomeIP-SD (service discovery protocol). The dynamic negotiation of session keys is realized through the secure distribution of key factors. The final negotiated session key can be used to protect the message security of CAN protocol and Ethernet protocol. At the same time, it solves the information security risks such as man-in-the-middle attacks that may occur after the introduction of SomeIP protocol.

[0053] In the Internet of Vehicles environment, the service discovery protocol is used for service discovery and communication, but it may also introduce some information security risks, such as man-in-the-middle attacks. In order to protect the message data in the serial communication protocol and the Ethernet protocol, there must be a secure mechanism to generate and distribute session keys. In the existing technical solution, a pre-shared key or other key exchange protocol is used to generate session keys, and the service discovery protocol is used for service discovery and communication. The above methods are usually not dynamic and flexible, and may not be able to effectively protect against man-in-the-middle attacks. After the introduction of the service discovery protocol, the communication process may be subject to man-in-the-middle attacks, affecting the confidentiality and integrity of the data.

[0054] To this end, the present application provides a system for authenticating the security of Internet of Vehicles communications, including a hardware security module, a service discovery module, and multiple vehicle electronic control units; the hardware security module is used to generate a random secret key factor based on the current Internet of Vehicles communication scenario; the service discovery module is used to distribute the random secret key factor to each vehicle electronic control unit; multiple vehicle electronic control units are used to generate a session key based on the random secret key factor, and encrypt the plaintext data in the Internet of Vehicles communication process through the session key. The generation and distribution of the secret key factor is achieved through the combination of the hardware security module and the service discovery module. Finally, multiple vehicle electronic control units encrypt the data generated in the Internet of Vehicles communication process through the received secret key factor, which can ensure the security and integrity of the data in the Internet of Vehicles communication process.

[0055] In an embodiment of the present application, the execution entity may be an authenticated Internet of Vehicles communication safety device in an authenticated Internet of Vehicles communication safety system. In actual applications, the authenticated Internet of Vehicles communication safety device may be electronic devices such as terminal devices and servers, which are not limited here.

[0056] Combine the following Figure 1 The system for authenticating the security of Internet of Vehicles communications in an embodiment of the present application is described in detail.

[0057] Please see Figure 1 , Figure 1 A schematic block diagram of a system 100 for authenticating vehicle network communication security provided in an embodiment of the present application, such as Figure 1 The system for certifying the security of vehicle-to-vehicle communication shown includes:

[0058] A hardware security module 110, a service discovery module 120 and multiple vehicle electronic control units 130; the hardware security module 110 is used to generate a random key factor based on the current Internet of Vehicles communication scenario; the service discovery module 120 is used to distribute the random key factor to each vehicle electronic control unit; multiple vehicle electronic control units 130 are used to generate a session key based on the random key factor, and encrypt the plaintext data in the Internet of Vehicles communication process through the session key.

[0059] The plaintext data includes message data in the CAN protocol and the Ethernet protocol.

[0060] Alternatively, Figure 1 The hardware security module 110 and service discovery module 120 in the system shown can use public key infrastructure (PKI) for key management and distribution, adopt symmetric encryption algorithm for key exchange, and provide key protection and distribution functions. Multiple vehicle electronic control units 130 can use transport layer security (TLS) protocol for encrypted communication to protect messages in CAN and Ethernet protocols.

[0061] In some embodiments of the present application, the hardware security module 110 is specifically used for:

[0062] Analyze the communication objects and communication environment in the current Internet of Vehicles communication scenario, where the communication objects include: vehicles, mobile terminals or cloud; match the random key factors corresponding to the communication objects and communication environments.

[0063] In the above embodiments of the present application, the corresponding random key factor can be matched according to the communication object and communication environment in the current Internet of Vehicles communication scenario, and different encryption methods can be implemented according to different scenarios, which is more flexible.

[0064] The communication environment includes in-vehicle network, inter-vehicle network and in-vehicle mobile Internet, etc. The communication object and communication environment correspond to different random key factors, and different combinations of communication objects and communication environments also correspond to different random key factors. The specific corresponding method can be determined according to the preset rules.

[0065] In some embodiments of the present application, the service discovery module 120 is specifically used to:

[0066] The random key factor is distributed to each vehicle electronic control unit through hash verification.

[0067] In the above embodiments of the present application, the integrity of the secret key factor when it is issued to the vehicle electronic control unit can be ensured by means of hash verification.

[0068] Specifically, the security gateway distributes the key factor to the ECU slave node that subscribes to this service through the SomeIP-SD message, and the secure transmission of the key factor can be ensured through hash verification.

[0069] For example, the security gateway generates a random key factor based on the current Internet of Vehicles communication scenario through the hardware security module 110, and distributes the random key factor to each ECU slave node through the service discovery module 120. Each ECU slave node decrypts the security gateway identity, receives the random key factor, uses the card's decentralized key and decentralized algorithm to analyze the random key factor, and generates a session key; and uses the session key to encrypt the plaintext data in the Internet of Vehicles communication process. The security gateway verifies the identity of each vehicle electronic control unit and decrypts the encrypted plaintext data through the session key.

[0070] Optionally, the data is encrypted using the AES strong encryption algorithm during distribution to each vehicle electronic control unit by means of hash verification, which can ensure data security during the session key negotiation process.

[0071] In some embodiments of the present application, the plurality of vehicle electronic control units 130 are specifically used for:

[0072] The random key factor is analyzed using the in-card distributed key and distributed algorithm to generate the session key. The session key is then used to encrypt the plaintext data in the IoV communication process.

[0073] In the above-mentioned embodiments of the present application, the random key factor is analyzed by using the dispersed key in the card and the dispersed algorithm, so that the session key can be generated effectively and quickly, and the encryption of the data in the vehicle network communication process can be realized.

[0074] In some embodiments of the present application, Figure 1 The system shown also includes:

[0075] A security gateway is used to verify the identity of each vehicle electronic control unit and decrypt encrypted plaintext data through a session key.

[0076] In the above embodiments of the present application, identity authentication and data decryption of the vehicle electronic control unit can be achieved through the security gateway.

[0077] Among them, the security gateway can also be used as the main node in the communication process of the Internet of Vehicles. The concept of a security gateway as a main node or server is not necessarily limited to a gateway, but can also be an ECU; for example, Tbox, the ECU slave node encrypts the key factor through the session key and returns the confidential content to the key factor distribution master node. The master node verifies the ciphertext. If the correct key factor can be obtained, it indicates that the session key has been negotiated in agreement. The master node sends an ACK response message to inform the slave node; the final generated session key is used to protect the message security in the CAN protocol and Ethernet protocol.

[0078] In the above Figure 1 In the process shown, the present application provides a system for authenticating the security of Internet of Vehicles communications, including a hardware security module 110, a service discovery module 120, and multiple vehicle electronic control units 130; the hardware security module 110 is used to generate a random key factor based on the current Internet of Vehicles communication scenario; the service discovery module 120 is used to distribute the random key factor to each vehicle electronic control unit; multiple vehicle electronic control units 130 are used to generate a session key based on the random key factor, and encrypt the plaintext data in the Internet of Vehicles communication process through the session key. The generation and distribution of the key factor is achieved through the combination of the hardware security module 110 and the service discovery module 120, and finally the multiple vehicle electronic control units 130 encrypt the data generated in the Internet of Vehicles communication process through the received key factor, which can ensure the security and integrity of the data in the Internet of Vehicles communication process.

[0079] Combine the following Figure 2 The method for authenticating the security of vehicle network communication in the embodiment of the present application is described in detail. Figure 1 The system shown is executed.

[0080] Please see Figure 2 , Figure 2 A flowchart of a method for authenticating vehicle network communication security provided in an embodiment of the present application, such as Figure 2 The method for authenticating the security of vehicle network communication shown includes:

[0081] Step 210: Generate a random secret key factor based on the current Internet of Vehicles communication scenario.

[0082] Specifically, the random key factor can be generated by a hardware security module in the Internet of Vehicles communication security system.

[0083] In some embodiments of the present application, a random key factor is generated based on the current Internet of Vehicles communication scenario, including: analyzing the communication object and communication environment in the current Internet of Vehicles communication scenario, wherein the communication object includes: a vehicle, a mobile terminal or the cloud; and matching the random key factor corresponding to the communication object and the communication environment.

[0084] In the above process, the present application can match the corresponding random key factor according to the communication object and communication environment in the current Internet of Vehicles communication scenario, and implement different encryption methods according to different scenarios, which is more flexible.

[0085] Step 220: Distribute the random key factor to each vehicle electronic control unit of the vehicle.

[0086] Specifically, the random key factor can be distributed to each vehicle electronic control unit through the service discovery module in the vehicle network communication security system.

[0087] Step 230: Encapsulate the random key factor into a session key through each vehicle electronic control unit.

[0088] Specifically, the random key factor can be encapsulated into a session key by the vehicle electronic control unit in the vehicle network communication security system.

[0089] Step 240: Encrypt the plaintext data in the Internet of Vehicles communication process using the session key.

[0090] Specifically, the plaintext data in the vehicle networking communication process can be encrypted by the vehicle electronic control unit in the vehicle networking communication security system.

[0091] also, Figure 2 The specific methods and steps shown can be found in Figure 1 The system shown will not be described in detail here.

[0092] The previous article uses the figure Figure 2 Describes the method of authenticating the security of vehicle network communication. Figure 3-Figure 4 Describes a device for authenticating the security of vehicle-to-vehicle communications.

[0093] Please refer to Figure 3 , is a schematic block diagram of a device 300 for authenticating vehicle network communication security provided in an embodiment of the present application. The device 300 may be a module, program segment or code on an electronic device. The device 300 is similar to the above Figure 1 The method embodiment corresponds to and can be executed Figure 1 The various steps involved in the method embodiment and the specific functions of the device 300 can be found in the description below. To avoid repetition, the detailed description is appropriately omitted here.

[0094] Optionally, the device 300 includes:

[0095] A generating module 310, configured to generate a random secret key factor based on the current Internet of Vehicles communication scenario;

[0096] A distribution module 320, for distributing the random key factor to each vehicle electronic control unit of the vehicle;

[0097] The packaging module 330 is used to package the random key factor into a session key through each vehicle electronic control unit;

[0098] The encryption module 340 is used to encrypt the plaintext data in the vehicle network communication process by using the session key.

[0099] Optionally, the generating module 310 is specifically used for:

[0100] Analyze the communication objects and communication environment in the current Internet of Vehicles communication scenario, where the communication objects include: vehicles, mobile terminals or cloud; match the random key factors corresponding to the communication objects and communication environments.

[0101] Please refer to Figure 4 The structure schematic block diagram of a device for authenticating the communication security of a vehicle network provided in an embodiment of the present application, the device may include a memory 410 and a processor 420. Optionally, the device may also include: a communication interface 430 and a communication bus 440. The device is similar to the above Figure 2 The method embodiment corresponds to and can be executed Figure 2 The various steps involved in the method embodiment and the specific functions of the device can be found in the description below.

[0102] Specifically, the memory 410 is used to store computer-readable instructions.

[0103] Processor 420 is used to process the readable instructions stored in the memory and can execute Figure 2 The steps in the method.

[0104] The communication interface 430 is used for signaling or data communication with other node devices, for example, for communication with a server or a terminal, or for communication with other device nodes, but the embodiments of the present application are not limited thereto.

[0105] The communication bus 440 is used to realize direct connection and communication among the above components.

[0106] The communication interface 430 of the device in the embodiment of the present application is used to communicate signals or data with other node devices. The memory 410 can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The memory 410 can also be at least one storage device located away from the aforementioned processor. The memory 410 stores computer-readable instructions. When the computer-readable instructions are executed by the processor 420, the electronic device executes the aforementioned Figure 2The method process shown. The processor 420 can be used on the device 300 and is used to perform the functions in the present application. Exemplarily, the above-mentioned processor 420 can be a general-purpose processor, a digital signal processor (Digital Signal Processor, DSP), an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), a field programmable gate array (Field Programmable Gate Array, FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the embodiments of the present application are not limited thereto.

[0107] The embodiment of the present application also provides a readable storage medium, when the computer program is executed by a processor, Figure 2 The method process in the method embodiment shown is executed by the electronic device.

[0108] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.

[0109] In summary, the embodiments of the present application provide a system, method, device, equipment and storage medium for authenticating the security of Internet of Vehicles communication, the system comprising a hardware security module, a service discovery module and multiple vehicle electronic control units; the hardware security module is used to generate a random key factor based on the current Internet of Vehicles communication scenario; the service discovery module is used to distribute the random key factor to each vehicle electronic control unit; multiple vehicle electronic control units are used to generate a session key based on the random key factor, and encrypt the plaintext data in the Internet of Vehicles communication process through the session key. This method can achieve the effect of ensuring the security and integrity of data in the Internet of Vehicles communication process.

[0110] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.

[0111] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.

[0112] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0113] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.

[0114] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

[0115] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

Claims

1. A system for authenticating the security of vehicle network communication, characterized in that: include: Hardware security modules, service discovery modules, and multiple vehicle electronic control units; The hardware security module is used to generate a random secret key factor based on the current Internet of Vehicles communication scenario; The service discovery module is used to distribute the random key factor to each vehicle electronic control unit; The multiple vehicle electronic control units are used to generate a session key based on the random key factor, and encrypt plaintext data in the vehicle network communication process through the session key.

2. The system according to claim 1, characterized in that The hardware security module is specifically used for: Analyze the communication object and communication environment in the current Internet of Vehicles communication scenario, wherein the communication object includes: a vehicle, a mobile terminal or a cloud; Match the random key factor corresponding to the communication object and the communication environment.

3. The system according to claim 1 or 2, characterized in that: The service discovery module is specifically used for: The random key factor is distributed to each vehicle electronic control unit by means of hash verification.

4. The system according to claim 1 or 2, characterized in that: The multiple vehicle electronic control units are specifically used for: The random key factor is analyzed using the card's decentralized key and decentralized algorithm to generate a session key; The session key is used to encrypt the plaintext data during the Internet of Vehicles communication process.

5. The system according to claim 1 or 2, characterized in that: Also includes: A security gateway, wherein the security gateway is used to verify the identity of each vehicle electronic control unit and decrypt encrypted plaintext data through the session key.

6. A method for authenticating the security of vehicle network communication, characterized in that: include: Generate a random secret key factor based on the current Internet of Vehicles communication scenario; Distributing the random key factor to each vehicle electronic control unit of the vehicle; Encapsulating the random key factor into a session key through each of the vehicle electronic control units; The plaintext data in the vehicle network communication process is encrypted by the session key.

7. The method according to claim 6, characterized in that The generating of a random secret key factor based on the current Internet of Vehicles communication scenario includes: Analyze the communication object and communication environment in the current Internet of Vehicles communication scenario, wherein the communication object includes: a vehicle, a mobile terminal or a cloud; Match the random key factor corresponding to the communication object and the communication environment.

8. A device for authenticating the security of vehicle network communication, characterized in that: include: A generation module, used to generate a random secret key factor based on the current Internet of Vehicles communication scenario; A distribution module, used to distribute the random key factor to each vehicle electronic control unit of the vehicle; A packaging module, used for packaging the random key factor into a session key through each vehicle electronic control unit; The encryption module is used to encrypt the plaintext data in the vehicle network communication process through the session key.

9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, the steps in the method according to any one of claims 6 to 7 are executed.

10. A computer-readable storage medium, characterized in that: include: A computer program, when the computer program is run on a computer, causes the computer to execute the method according to any one of claims 6 to 7.

Citation Information

Cited By

  • Lightweight Internet of Vehicles communication method based on dynamic pseudo-random encryption

    CN120416841A