Vehicle privacy data security encryption method, vehicle privacy data uploading method and vehicle privacy data viewing method
By encrypting and desensitizing private data using periodic keys and desensitizing keys on vehicles, the problem of vehicle privacy data leakage is solved, the secure storage and transmission of data is realized, and the security of vehicle services is improved.
Patent Information
- Application Number
- CN202510199655.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-24
AI Technical Summary
Vehicle privacy data is easily leaked during transmission and storage, resulting in the privacy of car owners and others being violated and the security of vehicle services is reduced.
A vehicle privacy data security encryption method is adopted to ensure the security of data during storage and transmission by encrypting and desensitizing private data using periodic keys and desensitizing keys on the vehicle.
Effectively prevent vehicle privacy data leakage, improve vehicle services security, reduce the use of vehicle storage resources, and improve the security of data transmission.
Smart Images

Figure CN119995883A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicle networking, and in particular relates to a vehicle privacy data security encryption method, an upload method and a viewing method. Background Art
[0002] With the continuous development of Internet of Vehicles technology, various vehicle services not only provide people with a comfortable driving experience, but also ensure the safety of the vehicle. However, these vehicle services can only be realized based on vehicle privacy data. In addition, a lot of new vehicle privacy data will be generated in the process of implementation. The privacy data generated on the vehicle or recorded by the vehicle is the vehicle privacy data, such as vehicle location information, in-cabin images, in-cabin call records, driving records, sentry mode recordings, etc.
[0003] Once the vehicle privacy data is seen by people other than the object of vehicle privacy data recording, the vehicle privacy data will be leaked. For example, the object of vehicle location information recording is the vehicle owner, and the leakage of vehicle location information will expose the whereabouts and home address of the vehicle owner, causing the vehicle owner to be followed by criminals while using the route planning vehicle service, posing a threat to the personal safety of the vehicle owner; for another example, the objects of driving records are the vehicle owner, pedestrians, the vehicle causing the accident and the owner of the vehicle causing the accident, then the leakage of driving records will cause the images of pedestrians and the owner of the vehicle causing the accident to be spread on the Internet at will, infringing the portrait rights of pedestrians and the owner of the vehicle causing the accident; for another example, the vehicle owner parks the vehicle in a residential area, and the sentinel mode video records some images inside the residents' houses, then the object of the sentinel mode video recording is the residents, and the subsequent behavior of the vehicle owner to look through the images of the residents through the sentinel mode video recording has caused the leakage of vehicle privacy data and violated the privacy of the residents. Therefore, the leakage of vehicle privacy data will not only violate the privacy and legal rights of the vehicle owner and / or others, but also reduce the security of vehicle services.
[0004] Therefore, how to ensure that vehicle privacy data is not leaked and improve the security of vehicle services has become an urgent problem to be solved in the field of Internet of Vehicles. Summary of the invention
[0005] The purpose of the present invention is to overcome the deficiencies of the above-mentioned prior art and provide a method for securely encrypting vehicle privacy data, which can ensure the security of vehicle privacy data stored on the vehicle, prevent the vehicle privacy data from being leaked, and improve the security of vehicle services.
[0006] To achieve the above object, the present invention adopts the following technical solutions: A method for securely encrypting vehicle privacy data comprises the following steps: S1, after the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle; one cycle is from the power on to the power off of the vehicle; S2, when the vehicle generates Class I privacy data, the vehicle uses the second key of the current period to encrypt the Class I privacy data; when the vehicle generates Class II privacy data, the vehicle first uses the desensitizing key of the current period to desensitize the Class II privacy data, and then uses the second key of the current period to encrypt the desensitized Class II privacy data; S3, the vehicle is powered on again after being powered off, enters the next cycle, and returns to S1.
[0007] Preferably, before S1, it also includes S0: S0, after the vehicle completes registration at the first cloud, the first cloud stores the registration information; the registered vehicle V stores the first key K1 charged by the first cloud TSP1; the registration information of the vehicle V includes the first key K1 and the vehicle identification code ID bound together V .
[0008] Preferably, S1 also includes the following sub-steps: S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1: A1={ID V ||X1||V X1},V X1 =P X1 [K1]; Among them, || represents a connector; X1 represents the first eigenvalue; V X1 Represents the first authentication entity; P X1 represents the first feature segment selected from the first key K1 using the first feature value X1; X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption; S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first eigenvalue first copy X1 1 and the first copy of the first authentication entity V X1 1 Then, extract the first copy ID of the vehicle identification code from the registration information V 1 The first copy of the bound first key K1 1 ; Then use the first copy of the first eigenvalue X1 1 From the first copy of the first key K1 1 Select the first copy of the first feature fragment P X1 1, calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ]; Among them, P X1 1 [·] indicates using the first copy of the first feature segment P X1 1 Symmetric encryption; If V X1 2 =V X1 1 , then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V 1 =ID V And P X1 1 =P X1 ; If the first copy of the vehicle identification code ID does not exist in the registration information V 1 , or V X1 2 ≠V X1 1 , then the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1; S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitized key K3 and time code TC of the current period, and then binds the second key K2, desensitized key K3 and time code TC of the current period one by one with the vehicle identification code ID V The periodic key information of the vehicle V is bound; at the same time, the first cloud TSP1 sends a key update information M1 to the vehicle V: M1=K1[K2||K3||TC]; wherein K1[·] indicates symmetric encryption using the first key K1; S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current period 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 and store it; In S3: When the vehicle V is powered off, the current first copy of the second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 .
[0009] Preferably, the first characteristic value X1 is used to select the first characteristic segment from the first key K1, which specifically includes the following contents: let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, take the first key K1 from the left X1th to the (X1+dth) as the first characteristic segment P X1 ; When (X1+d)>L, the first key K1 from the X1th to the Lth bit from the left is used as the first feature segment P X1 .
[0010] Preferably, S2 also includes the following contents: When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then the type I encrypted data ED Ⅰ With the first copy of the time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cockpit audio, vehicle cockpit video; when vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate number image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then the type II encrypted data ED Ⅱ With the first copy of the time code TC 1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
[0011] Preferably, vehicle V has class II privacy data PD Ⅱ After desensitization, desensitized data MD is formed, which specifically includes the following sub-steps: S201, vehicle V identifies Class II privacy data PD Ⅱ The non-owner's face image and the non-vehicle V's license plate number image in each frame are recorded as sensitive images; the vehicle V recognizes the Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio; S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
[0012] The present invention also provides a method for securely uploading vehicle privacy data, comprising the following steps: S1´, the first cloud TSP synchronizes the registration information to the second cloud TSP2 in real time through quantum communication; S2', vehicle V selects the type I data packet P to be uploaded Ⅰ and / or Class II data packet P Ⅱ , send data upload message M2 to the second cloud TSP2: M2={ID V ||X2||G X2}, G X2 =P X2 [K1||P]; Where X2 represents the second eigenvalue; G X2 Represents the second data body; P X2 represents the second feature segment selected from the first key K1 using the second feature value X2; X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption; P represents a data packet, including type I data packet P Ⅰ and / or Class II data packets P Ⅱ ; Type I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by adopting a vehicle privacy data security encryption method as described above; S3´, the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 and the first copy of the second data body G X2 1 After that, take out the second copy ID of the vehicle identification code in the registration information V 2 The second copy of the bound first key K1 2 ; Then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy of the second feature segment P X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body GX2 1 Get the third copy of the first key K1 3 and the first copy of the packet P 1 ; If K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plain text message of "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data; If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
[0013] The present invention also provides a method for safely viewing private data of a vehicle, wherein a viewer views private data on a vehicle, comprising the following steps: Step 1: After the car owner completes registration at the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle; Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric verification and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED that is expected to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ; Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ Obtained by using a vehicle privacy data security encryption method as described above; Step 3: After the car owner authorizes, the first cloud sends the encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED Ⅱ The corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the desensitized data MD is provided for the viewer to view.
[0014] Preferably, step 3 includes the following sub-steps: Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3={ID V ||TC 1}; Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 then generates the key distribution information M3 and sends it to the vehicle V: M3=Y[K2], Y=K 2* [K 3* ]; Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Perform symmetric encryption; Y represents the encryption key of the current cycle; Y[·] represents symmetric encryption using encryption key Y; Step 33, vehicle V calculates the first copy of the encryption key Y of the current cycle 1 =K 2* 1 [K 3* 1 ], then use Y 1 After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second key second copy K2 2 ; Step 34, vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the masked data MD is provided for VR viewing by the viewer.
[0015] The present invention also provides a method for securely viewing vehicle private data, wherein a viewer views private data on a second cloud, comprising the following steps: Step 1´, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 ; The data packet P stored in the second cloud is obtained by using a vehicle privacy data secure uploading method as described above; Step 2', the first cloud sends the second key and the desensitized key corresponding to the data packet P to the second cloud; Step 3´, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰand / or Category II privacy data PD Ⅱ and check it out.
[0016] The beneficial effects of the present invention are: (1) The security of vehicle privacy data stored in the vehicle can prevent the leakage of vehicle privacy data.
[0017] (2) In a vehicle privacy data security encryption method of the present invention, the vehicle only needs to store its own first key and the second key and desensitization key of the current cycle, without occupying additional storage resources to store a large number of keys; and there is no need to set up a quantum random number generator for generating random numbers on the vehicle, which further reduces the occupation of vehicle storage resources. Therefore, the storage resources on the vehicle are mainly used for class I data packets P Ⅰ and Class II packets P Ⅱ For storage, the vehicle can store more data packets.
[0018] (3) In the vehicle privacy data security encryption method, the storage of Class I data packets P Ⅰ and Class II packets P Ⅱ In addition to occupying vehicle storage resources, the present invention occupies less storage resources during implementation and has lower performance requirements for the vehicle, making the present invention more versatile.
[0019] (4) In a method for securely encrypting vehicle privacy data of the present invention, if there is a viewer who wishes to view the vehicle privacy data, the vehicle privacy data that the viewer wishes to view must be of a historical period. However, at the end of each period, the vehicle automatically clears the second key and desensitizing key of the current period. The encrypted vehicle privacy data cannot be viewed using the second key and desensitizing key of the current period. In other words, the viewer cannot directly view the vehicle privacy data without the vehicle communicating with the first cloud. Therefore, the present invention can well ensure the security of vehicle privacy data stored on the vehicle.
[0020] (5) In a method for securely encrypting vehicle privacy data of the present invention, the authentication process uses a randomly generated first characteristic value to select a first characteristic fragment from a first key, so the first characteristic fragment of each cycle is different; and the first authentication body is obtained by symmetrically encrypting the first key that remains unchanged using the first characteristic fragment, so the first authentication body of each cycle is also different; that is, the first characteristic value of the authentication request in each cycle of the present invention is random, and the corresponding first authentication body is also different, and the first authentication body is generated by symmetric encryption, and the computational overhead is smaller than that of asymmetric encryption, so the entire authentication process in a method for securely encrypting vehicle privacy data of the present invention is more concise and efficient, and has extremely high security.
[0021] (6) In a method for securely uploading private vehicle data of the present invention, the vehicle can select part of the Class I data packets and / or Class II data packets to upload to the second cloud, which greatly reduces the storage burden of the vehicle; and the vehicle has extremely high security in the process of uploading the Class I data packets and / or Class II data packets to the second cloud.
[0022] (7) In a method for securely viewing private data of a vehicle of the present invention, whether a viewer has the right to view private data on the vehicle is decided by the vehicle owner. At the same time, the viewer on the vehicle can only see Class I private data and / or desensitized data, but cannot see Class II private data. In addition, the viewer approved by the vehicle owner cannot see the information of non-vehicle owners. This ensures that the viewer can efficiently view private data and that the private data of non-vehicle owners will not be leaked.
[0023] (8) A method for securely viewing private data of a vehicle according to the present invention enables a viewer other than the vehicle owner to quickly and conveniently view Class I private data and / or desensitized data on the vehicle even when the viewer is not with the vehicle owner.
[0024] (9) The method for safely viewing vehicle privacy data of the present invention allows viewers to view Class II privacy data only in the second cloud, and viewers who are allowed by the vehicle owner can only view Class I privacy data and / or desensitized data in the vehicle, which not only meets the needs of viewers to conveniently and quickly view vehicle privacy data, but also ensures that viewers cannot see / hear Class II privacy data containing non-vehicle owner privacy in the absence of supervision. The specific viewing method of the viewer ensures that the viewing process of the viewer will not leak vehicle privacy data, nor will it leak Class II privacy data containing non-vehicle owner privacy, and will not infringe on the privacy and legal rights of the vehicle owner and / or others. Further, it also improves the security of vehicle services based on vehicle privacy data. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 The present invention is a flow chart of a vehicle privacy data encryption method. DETAILED DESCRIPTION
[0026] In order to make the technical solution of the present invention clearer and more specific, the present invention is clearly and completely described below in conjunction with the accompanying drawings. Any equivalent replacement of the technical features of the technical solution of the present invention and any solution derived by conventional reasoning by ordinary technicians in the field without making any creative work shall fall within the protection scope of the present invention.
[0027] Example 1 like Figure 1 As shown, a method for securely encrypting vehicle privacy data in this embodiment includes the following steps: S0, after the vehicle completes registration at the first cloud, the first cloud stores the registration information.
[0028] S1, after the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle; one cycle is from the power on to the power off of the vehicle; S2: When the vehicle generates Class I privacy data, the vehicle uses the second key of the current period to encrypt the Class I privacy data; when the vehicle generates Class II privacy data, the vehicle first uses the desensitizing key of the current period to desensitize the Class II privacy data, and then uses the second key of the current period to encrypt the desensitized Class II privacy data.
[0029] S3, the vehicle is powered on again after being powered off, enters the next cycle, and returns to S1.
[0030] In S0, the following are included: Vehicle V is registered with the first cloud TSP1 through an offline secure channel, and the unique vehicle identification code ID V Upload to the first cloud TSP1, the first cloud TSP1 will receive the vehicle identification code ID V Compare with the vehicle identification code in all registration information in the first cloud TSP1. If the current vehicle identification code ID V If the current vehicle identification code ID does not exist in the registration information, the first cloud TSP1 sends a duplicate registration message to the vehicle V. V , after the first cloud TSP1 generates the first key K1, it injects the first key K1 into the secure medium on the vehicle V, and the vehicle V completes the registration at the first cloud TSP1. At the same time, the first cloud TSP1 combines the first key K1 with the vehicle identification code ID V The registration information of vehicle V is bound and stored.
[0031] The first cloud TSP1 has a built-in quantum random number generator, and the first key K1 is a quantum key generated by the quantum random number generator.
[0032] The identity of the vehicle V that has completed registration at the first cloud TSP1 is legal.
[0033] In S1, the following sub-steps are also included: S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1: A1={ID V ||X1||V X1},V X1 =P X1 [K1], Among them, || represents a connector, X1 represents the first eigenvalue, VX1 represents the first authenticator, P X1 represents the first feature segment selected from the first key K1 using the first feature value X1, P X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption.
[0034] The first characteristic value X1 is randomly determined by the vehicle during the process of generating the authentication request A1.
[0035] Selecting a first characteristic fragment from the first key K1 using the first characteristic value X1 specifically includes the following contents: Let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, take the first key K1 from the left X1th to the (X1+dth) as the first feature segment P X1 ; When (X1+d)>L, the first key K1 from the X1th to the Lth bit from the left is used as the first feature segment P X1 .
[0036] S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first eigenvalue first copy X1 1 and the first copy of the first authentication entity V X1 1 After that, extract the first copy ID of the vehicle identification code from your own registration information V 1 The first copy of the bound first key K1 1 , and then use the first copy of the first eigenvalue X1 1 From the first copy of the first key K1 1 Select the first copy of the first feature fragment P X1 1 , calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ], where P X1 1 [·] indicates using the first copy of the first feature segment P X1 1 Symmetric encryption; If V X1 2 =V X1 1 Then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V1 =ID V And P X1 1 =P X1 ; If the first copy of the vehicle identification code ID does not exist in the registration information V 1 , or V X1 2 ≠V X1 1 , then the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1.
[0037] S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitized key K3 and time code TC of the current period, binds the second key K2, desensitized key K3 and time code TC of the current period one by one, and then binds them to the vehicle identification code ID V The periodic key information of vehicle V is bound to the first cloud TSP1, and the first cloud TSP1 sends key update information M1 to vehicle V: M1=K1[K2||K3||TC], where K1[·] indicates symmetric encryption using the first key K1.
[0038] The second key K2, the desensitized key K3 and the time code TC are all generated by the first cloud TSP1 using a quantum random number generator.
[0039] S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current period 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 and store it.
[0040] If the key update information M1 is not tampered with during the process of being sent from the first cloud TSP1 to the vehicle V, then K2 1 =K2 and K3 1 =K3 and TC 1 =TC.
[0041] During the authentication process of S1, a randomly generated first characteristic value is used to select a first characteristic fragment from the first key, so the first characteristic fragment of each period is different; and the first authentication body is obtained by symmetric encryption of the first key that has always remained unchanged using the first characteristic fragment, so the first authentication body of each period is also different.
[0042] In the prior art cloud-based vehicle authentication, a pair of unchanging public and private keys is often used to encrypt and decrypt an unchanging root key to determine whether the vehicle has been authenticated. However, because the public and private keys and the root key remain unchanged, their security gradually decreases with the increase in usage time, and the probability of being cracked continues to increase. In this embodiment, the first characteristic value of the authentication request A1 in each cycle is random, and the corresponding first authentication body is also different. Moreover, the first authentication body is generated by symmetric encryption, and the computational overhead is relatively small compared to asymmetric encryption. Therefore, the entire authentication process in this embodiment is more concise and efficient, and has extremely high security.
[0043] Optionally, after the vehicle V sends the authentication request A1 to the first cloud TSP1, if the vehicle V does not receive the key update information M1 for a period greater than the set first time threshold Δt1, S11 is automatically re-executed so that the vehicle V with a legitimate identity can obtain the first copy K2 of the second key of the current cycle as soon as possible. 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 This avoids the problem that a legitimate vehicle V does not receive the key update information M1 and has to wait for a long time due to network packet loss. In this embodiment, the first time threshold Δt1 is set to 30 seconds.
[0044] In S2, the following are also included: When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then the type I encrypted data ED Ⅰ With the first copy of the time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cabin audio, and vehicle cabin video.
[0045] When vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate number image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then the type II encrypted data ED Ⅱ With the first copy of the time code TC1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
[0046] Vehicle V to Class II Privacy Data PD Ⅱ After desensitization, desensitized data MD is formed, which specifically includes the following sub-steps: S201, vehicle V identifies Class II privacy data PD Ⅱ The non-owner's face image and the non-vehicle V's license plate number image in each frame are recorded as sensitive images; the vehicle V recognizes the Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio; S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
[0047] Privacy Data PD Ⅱ Each sensitive image frame contains several pixels, which are desensitized using the first copy of the desensitizing key K3. 1 After symmetric encryption, it can be reversibly converted into a color different from the original pixel, which makes the sensitive image unrecognizable after desensitization, and this color conversion is controlled by the first copy of the desensitization key K3 1 Even if the pixels are the same color, as long as the first copy of the desensitization key K3 1 If the desensitization key is different, the pixel color after desensitization is also different. That is to say, even if it is the same sensitive picture, as long as the first copy of the desensitization key K3 1 If the data is different, the desensitized images will also be different. Ⅱ The sensitive audio in contains several audio frames, which are desensitized using the first copy of the desensitizing key K3 1 After symmetric encryption, it is reversibly converted into an audio frame that is completely different from the original audio data. This makes the sensitive audio unrecognizable after desensitization (the timbre is unrecognizable and the audio semantics is incomprehensible). Even if it is the same sensitive audio, as long as the first copy of the desensitization key K3 1 If the audio is different, the audio after desensitization will also be different.
[0048] The following are also included in S3: S31, when the vehicle V is powered off, the first copy of the current second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 ; S32, the vehicle V is powered on again, enters the next cycle, and returns to S1.
[0049] In a vehicle privacy data security encryption method of this embodiment, the vehicle only needs to store its own first key and the second key and desensitization key of the current cycle, without occupying additional storage resources to store a large number of keys; and there is no need to set a quantum random number generator to generate random numbers on the vehicle, which further reduces the occupation of vehicle storage resources, so the storage resources on the vehicle are mainly used for Class I data packets P Ⅰ and Class II packets P Ⅱ For storage, the vehicle can store more data packets.
[0050] Remove the storage of Class I packets P Ⅰ and Class II packets P Ⅱ In addition to the occupation of vehicle storage resources, the storage resources occupied during the implementation of this embodiment are relatively small, and the performance requirements of the vehicle are lower, making this embodiment more versatile.
[0051] The entire implementation process of the vehicle privacy data security encryption method of this embodiment is extremely secure, which is mainly reflected in the following two aspects: ① In each cycle, the vehicle generates an authentication request by randomly using the first key fragment to encrypt the first key and then authenticates on the first cloud. Therefore, the authentication request sent by the vehicle to the first cloud in each cycle is different. Even if a hacker attempts to use the authentication request of the previous cycle for a replay attack, it will not be able to successfully authenticate on the first cloud in the current cycle.
[0052] ② In the communication process between the vehicle and the first cloud, the first key is never directly used as the encrypted object, and the plain text of the first key and the first key fragment does not exist in all messages. Therefore, even if a hacker intercepts the communication messages between the vehicle and the first cloud, he cannot obtain the first key, and it is even more impossible to restore the first key by piecing together the first key fragments. The transmitted second key and desensitized key will not exist in the vehicle at the end of the current cycle. Therefore, in this embodiment, even if the first key of the vehicle remains unchanged for a long time, it can still be guaranteed that the vehicle can safely obtain the second key and desensitized key of the current cycle.
[0053] A vehicle privacy data security encryption method of the present embodiment encrypts the vehicle privacy data in different levels. The encrypted vehicle privacy data is stored on the vehicle, and the vehicle privacy data cannot be directly viewed. If there is a viewer who wants to view the vehicle privacy data, the vehicle privacy data that the viewer wants to view must be from a historical period. However, the second key and desensitizing key of the current period are automatically cleared at the end of each period of the vehicle. The encrypted vehicle privacy data cannot be viewed using the second key and desensitizing key of the current period. In other words, the viewer cannot directly view the vehicle privacy data without the vehicle communicating with the first cloud. Therefore, the present embodiment can well ensure the security of the vehicle privacy data stored on the vehicle and avoid the leakage of the vehicle privacy data.
[0054] Example 2 The present invention also provides a method for securely uploading vehicle privacy data, comprising the following steps: S1´, the first cloud TSP1 synchronizes the registration information to the second cloud TSP2 in real time through quantum communication; S2', vehicle V selects the type I data packet P to be uploaded Ⅰ and / or Class II data packets P Ⅱ , send data upload message M2 to the second cloud TSP2: M2={ID V ||X2||G X2}, G X2 =P X2 [K1||P], Among them, X2 represents the second eigenvalue, G X2 Represents the second data body, P X2 represents the second feature segment selected from the first key K1 using the second feature value X2, P X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption, P represents data packets, including type I data packets P Ⅰ and / or Class II data packets P Ⅱ .
[0055] The method of selecting the second characteristic segment from the first key K1 using the second characteristic value X2 is the same as the method of selecting the first characteristic segment from the first key K1 using the first characteristic value X1 in Embodiment 1, and will not be described again here.
[0056] Type I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by adopting the vehicle privacy data security encryption method described in Example 1.
[0057] The second characteristic value X2 is randomly determined by the vehicle when generating the data upload message M2.
[0058] S3´, the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 and the first copy of the second data body G X2 1 After that, take out the second copy ID of the vehicle identification code from your own registration information V 2 The second copy of the bound first key K1 2 , and then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy of the second feature segment P X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body G X2 1 Get the third copy of the first key K1 3 and the first copy of the packet P 1 , if K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plaintext message of "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data.
[0059] If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
[0060] Optionally, if the vehicle V receives a plain text message of "upload failure", or if the vehicle V does not receive a plain text reply message from the second cloud TSP2 after sending a data upload message M2 to the second cloud TSP2 for more than the set second time threshold Δt2, the process returns to S2´.
[0061] In this embodiment, the second time threshold Δt2 is set to 45 seconds.
[0062] Optionally, the same data packet P is only saved once in the second cloud TSP2.
[0063] The first cloud TSP1 does not store the Class I data packets P uploaded by the vehicle. Ⅰ and / or Class II data packets P ⅡThe second cloud TSP2 has a large amount of storage space for storing the Class I data packets P uploaded by vehicles. Ⅰ and / or Class II data packets P Ⅱ , and the second cloud TSP2 can be multiple. For example, cars of the same brand upload their privacy data to the same second cloud TSP2. The second cloud TSP2 is supervised by a third party and is an absolutely safe storage space. The brand of the vehicle cannot retrieve the Class I data packet P from the second cloud TSP2 at will. Ⅰ and / or Class II data packets P Ⅱ .
[0064] Vehicle V sends a class I data packet P Ⅰ and / or Class II data packets P Ⅱ The process of uploading to the second cloud TSP2 is extremely secure, which is reflected in the following aspects: ① Data packet P itself is ciphertext, and the vehicle clears the first copy of the second key K2 in the current cycle at the end of each cycle 1 and the first copy of the desensitized key K3 1 Therefore, when a vehicle uploads a data packet P, there is generally no key corresponding to the decryption of the uploaded data packet in the vehicle, so the data upload message M2 does not contain any key for decryption, and the data packet P itself has extremely high security.
[0065] ② During the process of uploading data packet P via wireless communication, the second feature fragment randomly extracted is encrypted again into a second data body, and the data upload message M2 is not encrypted using the first key K1, nor does it contain any first key K1 fragment. Therefore, even if a hacker intercepts the data upload message M2, he cannot crack the data packet P, let alone obtain the plaintext privacy data.
[0066] ③ The recipient of the data packet P uploaded by the vehicle is the second cloud, not the first cloud. The second cloud only contains registration information, but does not have the key (second key and desensitizing key) corresponding to the decrypted uploaded data packet. Therefore, after the second cloud stores the data packet P, it is unable to obtain the plaintext privacy data.
[0067] ④ The second cloud will authenticate the vehicle V based on the data upload message M2. The data packet P will only be stored if the authentication is passed. Therefore, even if a hacker intercepts and tampers with the data upload message M2 and resends it to the second cloud in an attempt to perform malicious operations in the second cloud, it will not pass the authentication of the second cloud, making it impossible to perform malicious operations.
[0068] Therefore, in a method for securely uploading private vehicle data of this embodiment, the vehicle can select part of the Class I data packets P by itself. Ⅰ and / or Class II data packets P ⅡSafely upload to the second cloud TSP2, greatly reducing the vehicle storage burden.
[0069] Example 3 The present invention also provides a method for safely viewing vehicle privacy data: When a viewer views private data on a vehicle, the following steps are included: 1 to 4: Step 1: After the car owner completes registration at the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle; Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric authentication and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ; Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ It is obtained by adopting the vehicle privacy data security encryption method described in Example 1.
[0070] Step 3: After the car owner authorizes, the first cloud sends the encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED Ⅱ The corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the desensitized data MD is provided for the viewer to view.
[0071] Optionally, when the viewer views the private data on the second cloud, the following steps 1´ to 3´ are included: Step 1´, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 ; The data packet P stored in the second cloud is obtained by using the vehicle privacy data secure uploading method described in Example 2.
[0072] Step 2', the first cloud sends the second key and the desensitized key corresponding to the data packet P to the second cloud; Step 3´, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PDⅠ and / or Category II privacy data PD Ⅱ and check it out.
[0073] Because in the method for securely viewing vehicle private data of this embodiment, the viewer must either view it in the vehicle or in the second cloud. The premise for viewing it in the vehicle is that the vehicle is powered on and the viewer enters the vehicle. Once the vehicle is powered on, it enters the current cycle, and the private data being viewed must belong to a historical cycle that has ended. The second key for the current cycle generated by the first cloud is recorded as K 2* , the current period desensitization key generated by the first cloud is recorded as K 3* , the first copy of the second key of the current period obtained by the vehicle from the first cloud is recorded as K 2* 1 , the first copy of the current period desensitized key obtained by the vehicle from the first cloud is recorded as K 3* 1 .
[0074] If the first copy of the second key of the current period and the first copy of the desensitized key obtained by the vehicle from the first cloud are both tamper-free, then K 2* 1 =K 2* And K 3* 1 =K 3* .
[0075] Also include the following in step 1: The car owner registers at the first cloud TSP1 through an offline secure channel and enters the car owner's account number AC, car owner's account password PW, and car owner's biometric information BI AC and vehicle identification number ID V Upload to the first cloud TSP1, the first cloud TSP1 will store the car owner's account number AC, car owner's account password PW, car owner's biometric information BI AC After binding to the car owner's account information, the car owner's account information and the vehicle identification code ID V The corresponding registration information and periodic key information are bound; the viewer VR enters his own biometric information on the vehicle V; the viewer VR can be the owner's family, the owner's friend, the owner himself, the vehicle maintenance personnel, etc.
[0076] Biometric information includes fingerprint information, facial image information, etc.
[0077] One car owner's account information can be bound to the registration information and periodic key information of multiple vehicles. In reality, one car owner owns multiple private cars.
[0078] Also include the following in step 2: After the vehicle V is powered on, the viewer VR successfully performs biometric authentication on the vehicle V, and then the viewer VR sends a first viewing request A2 to the vehicle owner account AC through the vehicle V: A2={ID V ||N VR ||TC 1}, where N VR Indicates the viewer VR name.
[0079] It can be seen from steps 1 to 2 that only viewers who have entered their own biometric information on the vehicle can send the first viewing request to the owner's account through the corresponding vehicle; and because the personnel included in the viewers change greatly (for example, for safety reasons, the owner will enter the corresponding vehicle maintenance personnel's biometric information into the vehicle every time the vehicle is sent to the 4S shop for maintenance, and delete the maintenance personnel's biometric information in the vehicle after each maintenance), so in this embodiment, the viewer does not need to register on the first cloud, but the owner decides who should enter the biometric information on the vehicle. This not only gives the right to become a viewer to the owner, but also compared to registering on the first cloud TSP1, entering biometric information on the vehicle is obviously more flexible and convenient.
[0080] Step 3 also includes the following sub-steps: Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3={ID V ||TC 1}; Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 then generates the key distribution information M3 and sends it to the vehicle V: M3=Y[K2], Y=K 2* [K 3* ]; Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Symmetric encryption is performed; Y represents the encryption key of the current cycle; Y[·] represents the use of encryption key Y for symmetric encryption.
[0081] If the periodic key information of the first cloud platform TSP1 does not contain the first copy of the vehicle V and the time code TC 1 Corresponding to the second key K2, the first cloud platform TSP1 feeds back a plain text message of "information error" to the car owner account AC.
[0082] Optionally, when the vehicle owner account AC receives the "information error" message fed back by the first cloud platform TSP1 for f consecutive times, an alarm is issued to the vehicle manufacturer. In this case, it may be because the hacker intercepted the first viewing request A2 and / or the key request information A3 and / or the key update information M1 and tampered with it. The vehicle manufacturer needs to encrypt or replace the wireless communication channel of the first viewing request A2 and / or the key request information A3 and / or the key update information M1.
[0083] When the hacker intercepts the first viewing request A2 and tampered with it and then resent it to the vehicle V, it will cause the vehicle V to obtain the first copy of the second key K2 in the same cycle. 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 Different from the second key K2, desensitized key K3 and time code TC generated by the first cloud platform TSP1. When a hacker intercepts the key request information A3 and tamper with it and resend it to the first cloud platform TSP1, if there is a one in a billion probability that the corresponding second key exists in the periodic key information of the first cloud platform TSP1, then the vehicle cannot decrypt the correct vehicle privacy data using this second key, ensuring that the vehicle privacy data will not be leaked. When a hacker intercepts the key update information M1 and tamper with it and resend it to the vehicle V, the vehicle cannot decrypt the correct vehicle privacy data using the encryption key of the current period, ensuring that the vehicle privacy data will not be leaked.
[0084] In this embodiment, f=5.
[0085] Step 33, vehicle V calculates the first copy of the encryption key Y of the current cycle 1 =K 2* 1 [K 3* 1 ], then use Y 1 After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second key second copy K2 2 .
[0086] Step 34, vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the masked data MD is provided for VR viewing by the viewer.
[0087] If the messages in each step of the method for securely encrypting private vehicle data in Example 1 and the messages in each step of the method for securely viewing private vehicle data in this embodiment have not been tampered with by hackers, then K2 2 =K2, vehicle V can also decrypt the correct Class I privacy data PD Ⅰ And / or desensitized data MD, otherwise the viewer can only see a bunch of garbled data.
[0088] Optional, Class I privacy data PD Ⅰ And / or the time during which the desensitized data MD is provided for viewing by the viewer VR is a third time threshold Δt3. In this embodiment, Δt3=15 min.
[0089] The method for safely viewing private data of a vehicle in this embodiment allows the vehicle owner to decide whether the viewer has the right to view private data on the vehicle, while allowing the viewer on the vehicle to only see Class I private data PD. Ⅰ and / or desensitized data MD, but cannot see Class II privacy data PD Ⅱ , so that viewers approved by the car owner cannot see the information of non-car owners. This not only ensures that viewers can efficiently view private data, but also ensures that the private data of non-car owners will not be leaked.
[0090] For example, the car owner did not close the window after parking the car last night, and the car owner found that he could not find his wallet the next day. The car owner did not know whether the wallet was left in the car last night and was taken away directly from the car by someone through the open window. So the car owner came to the car to check the sentry mode video after parking last night, and found in the sentry mode video that someone did take the wallet directly from the car through the open window, so the car owner called the police; but the face image in the sentry mode video was desensitized, and the car owner did not know who it was, so the car owner was prevented from spreading the appearance of the target person who took the wallet on the Internet, so as not to infringe the portrait rights of the target person. Furthermore, if the target person just took the wallet and handed it in, the harm of the car owner spreading the appearance of the target person who took the wallet on the Internet will be further expanded. If the car owner did not find anyone approaching the vehicle in the sentry mode video, and the car owner did not find the wallet in the vehicle, the car owner thought that the wallet should still be left at home, so he went back home to look for it.
[0091] A method for securely viewing vehicle privacy data in this embodiment enables a viewer who is not a vehicle owner to quickly and conveniently view Class I privacy data and / or desensitized data on the vehicle when the viewer is not with the vehicle owner.
[0092] For example, vehicle maintenance personnel need to check the driving records to quickly determine what problems the vehicle still has. At this time, the owner is not in the vehicle. The vehicle maintenance personnel at the 4S shop can also conveniently view the corresponding privacy data with the owner's consent, which is convenient for the vehicle maintenance personnel to perform corresponding inspections and maintenance on the vehicle.
[0093] In step 31, the owner enters the owner's account number AC, the owner's account password PW and the owner's biometric information BI AC , log in to the car owner account AC on different mobile devices, including mobile phones, tablets, etc.
[0094] Include the following in step 2´: The first cloud TSP1 extracts the vehicle identification code ID from its own periodic key according to the second check request. V And the first copy of the time code TC 1 After the corresponding second key K2 and desensitized key K3 are obtained, a key transfer message M4 is generated and sent to the second cloud TSP2: M4={X3||KD},KD=P X3 [K2||K3], Among them, X3 represents the third eigenvalue, KD represents the key body, P X3 represents the third feature segment selected from the first key K1 of the vehicle V using the third feature value X3, P X3 [·] indicates the use of P X3 Perform symmetric encryption.
[0095] The method of selecting the third characteristic segment from the first key K1 using the third characteristic value X3 is the same as the method of selecting the first characteristic segment from the first key K1 using the first characteristic value X1 in Embodiment 1, and will not be repeated here.
[0096] In step 3´ include the following: The second cloud TSP2 obtains the first copy X3 of the third characteristic value from the key transfer message M4 1 and the first copy of the key body KD 1 After that, take out the vehicle identification code ID from your own registration information V The bound first key K1, and then use the first copy of the third characteristic value X3 1 Select the first copy P of the third feature segment from the first key K1 X3 1 Then, use the first copy of the third feature fragment P X3 1 The first copy of the symmetric decryption key KD 1 Get the third copy of the second key K2 3 and the second copy of the desensitized key K2 2; The second cloud TSP2 uses the third copy of the second key K2 3 and the second copy of the desensitized key K2 2 Symmetrically decrypt the encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ For viewers to view in VR.
[0097] Because the second cloud TSP2 is supervised by a third party, the viewer VR cannot view the Class I privacy data PD at the second cloud TSP2 at will. Ⅰ and / or Category II privacy data PD Ⅱ Only viewers permitted by the third party can view the Class I privacy data PD in the second cloud TSP2 Ⅰ and / or Category II privacy data PD Ⅱ At this time, the viewer VR will not disclose the privacy of others who are not the car owner.
[0098] For example, the car owner came to the car to check the sentry mode video after parking last night, and found in the sentry mode video that someone did take the wallet in the car directly through the open window, so the car owner called the police; but the face image in the sentry mode video was desensitized, and the car owner did not know who it was; subsequently, under the supervision of a third party, the car owner checked the Class II privacy data PD at the second cloud TSP2 Ⅱ , and found that it was the child at home who took out the wallet.
[0099] A method for securely viewing vehicle private data in this embodiment enables the viewer to view the Class II private data PD only in the second cloud TSP2. Ⅱ , viewers who have been allowed by the owner can only view Class I privacy data PD on the vehicle Ⅰ and / or desensitized data MD, which not only meets the need of viewers to conveniently and quickly access vehicle privacy data, but also ensures that viewers cannot see / hear Class II privacy data PD containing non-owner privacy without supervision Ⅱ .
[0100] In this embodiment, a method for securely viewing vehicle private data is provided. The specific viewing method of the viewer ensures that the viewing process of the viewer will not leak the vehicle private data, and thus will not leak the Class II private data PD containing the privacy of non-vehicle owners. Ⅱ , and will not infringe upon the privacy and legal rights of the vehicle owner and / or others. Further, it also improves the security of vehicle services based on vehicle privacy data.
[0101] The techniques, shapes, and structural parts not described in detail in the present invention are all well-known techniques.
[0102] It should also be pointed out that the above are only preferred embodiments of the present invention and are not intended to limit the present invention. The components or steps in the embodiments of the present invention can be decomposed and / or recombined, and these decompositions and / or recombinations should be regarded as equivalent schemes of the present application and should fall within the protection scope of the present invention.
Claims
1. A vehicle privacy data security encryption method, characterized in that: The following steps are involved: S1, after the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle; One cycle is from vehicle power on to power off; S2, when the vehicle generates Class I privacy data, the vehicle uses the second key of the current period to encrypt the Class I privacy data; when the vehicle generates Class II privacy data, the vehicle first uses the desensitizing key of the current period to desensitize the Class II privacy data, and then uses the second key of the current period to encrypt the desensitized Class II privacy data; S3, the vehicle is powered on again after being powered off, enters the next cycle, and returns to S1.
2. A vehicle privacy data security encryption method according to claim 1, characterized in that: Before S1, it also includes S0: S0, after the vehicle completes registration at the first cloud, the first cloud stores the registration information; the registered vehicle V stores the first key K1 charged by the first cloud TSP1; the registration information of the vehicle V includes the first key K1 and the vehicle identification code ID bound together V .
3. A vehicle privacy data security encryption method according to claim 2, characterized in that: S1 also includes the following sub-steps: S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1: A1={ID V ||X1||V X1 },V X1 =P X1 [K1]; Among them, || represents a connector; X1 represents the first eigenvalue; V X1 Represents the first authentication entity; P X1 represents the first feature segment selected from the first key K1 using the first feature value X1; X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption; S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first eigenvalue first copy X1 1 and the first copy of the first authentication entity V X1 1 Then, extract the first copy ID of the vehicle identification code from the registration information V 1 The first copy of the first key K1 1 ; Then use the first copy of the first eigenvalue X1 1 From the first copy of the first key K1 1 Select the first copy of the first feature fragment P X1 1 , calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ]; Among them, P X1 1 [·] indicates using the first copy of the first feature segment P X1 1 Symmetric encryption; If V X1 2 =V X1 1 , then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V 1 =ID V And P X1 1 =P X1 ; If the first copy of the vehicle identification code ID does not exist in the registration information V 1 , or V X1 2 ≠V X1 1 , then the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1; S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitized key K3 and time code TC of the current period, and then binds the second key K2, desensitized key K3 and time code TC of the current period one by one with the vehicle identification code ID V The periodic key information of the vehicle V is bound; at the same time, the first cloud TSP1 sends a key update information M1 to the vehicle V: M1=K1[K2||K3||TC]; wherein K1[·] indicates symmetric encryption using the first key K1; S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current period 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 and store it; In S3: When the vehicle V is powered off, the current first copy of the second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 .
4. A vehicle privacy data security encryption method according to claim 3, characterized in that: Selecting a first characteristic fragment from the first key K1 using the first characteristic value X1 specifically includes the following contents: Let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, take the first key K1 from the left X1th to the (X1+dth) as the first feature segment P X1 ; When (X1+d)>L, the first key K1 from the X1th to the Lth bit from the left is used as the first feature segment P X1 .
5. A vehicle privacy data security encryption method according to claim 3, characterized in that: S2 also includes the following: When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then the type I encrypted data ED Ⅰ With the first copy of the time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cabin audio, and vehicle cabin video; When vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate number image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then the type II encrypted data ED Ⅱ With the first copy of the time code TC 1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
6. A vehicle privacy data security encryption method according to claim 5, characterized in that: Vehicle V to Class II Privacy Data PD Ⅱ After desensitization, desensitized data MD is formed, which specifically includes the following sub-steps: S201, vehicle V identifies Class II privacy data PD Ⅱ The non-owner's face image and the non-vehicle V's license plate number image in each frame are recorded as sensitive images; Vehicle V identifies Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio; S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
7. A method for securely uploading vehicle privacy data, characterized in that: The following steps are involved: S1´, the first cloud TSP synchronizes the registration information to the second cloud TSP2 in real time through quantum communication; S2', vehicle V selects the type I data packet P to be uploaded Ⅰ and / or Class II data packets P Ⅱ , send data upload message M2 to the second cloud TSP2: M2={ID V ||X2||G X2 }, G X2 =P X2 [K1||P]; Where X2 represents the second eigenvalue; G X2 Represents the second data body; P X2 represents the second feature segment selected from the first key K1 using the second feature value X2; X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption; P represents a data packet, including type I data packet P Ⅰ and / or Class II data packets P Ⅱ ; Type I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by adopting a vehicle privacy data security encryption method as claimed in claim 5 or 6; S3´, the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 and the first copy of the second data body G X2 1 After that, take out the second copy ID of the vehicle identification code from the registration information V 2 The second copy of the bound first key K1 2 ; Then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy of the second feature fragment P X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body G X2 1 Get the third copy of the first key K1 3 and the first copy of the packet P 1 ; If K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plain text message of "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data; If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
8. A method for securely viewing vehicle privacy data, characterized in that: The viewer views the private data on the vehicle, including the following steps: Step 1: After the car owner completes registration at the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle; Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric verification and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED that is expected to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ; Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ Obtained by using a vehicle privacy data security encryption method as claimed in claim 5 or 6; Step 3: After the car owner authorizes, the first cloud sends the encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED Ⅱ The corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the desensitized data MD is provided for the viewer to view.
9. A method for securely viewing vehicle private data according to claim 8, characterized in that: Step 3 includes the following sub-steps: Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3={ID V ||TC 1 }; Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 then generates the key distribution information M3 and sends it to the vehicle V: M3=Y[K2], Y=K 2* [K 3* ]; Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Perform symmetric encryption; Y represents the encryption key of the current cycle; Y[·] represents symmetric encryption using encryption key Y; Step 33, vehicle V calculates the first copy of the encryption key Y of the current cycle 1 =K 2* 1 [K 3* 1 ], then use Y 1 After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second key second copy K2 2 ; Step 34, vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ And / or the masked data MD is provided for VR viewing by the viewer.
10. A method for securely viewing vehicle privacy data, characterized in that: The viewer views private data in the second cloud, including the following steps: Step 1´, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 ; The data packet P stored in the second cloud is obtained by using a method for securely uploading vehicle privacy data as described in claim 7; Step 2', the first cloud sends the second key and the desensitized key corresponding to the data packet P to the second cloud; Step 3´, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get the Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ and check it out.
Citation Information
Patent Citations
Private data protection method and device of cloud platform, equipment and storage medium
CN115481434A
Vehicle privacy data processing method
CN115982751A
Data encryption system for mobile phone terminal
CN117768093A
Vehicle sentry mode data supervision method and supervision system
CN117812582A
Vehicle cloud communication method and communication system in multi-cloud environment
CN117812585A