A vehicle privacy data security encryption method, upload method and viewing method
Through periodically updated keys and desensitization processing, combined with quantum communication, the problem of vehicle privacy data leaking in the Internet of Vehicles is solved, the secure storage and efficient viewing of data are realized, and the security and privacy protection of vehicle services are improved.
Patent Information
- Application Number
- CN202510199655.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-02-24
AI Technical Summary
Vehicle privacy data is easily leaked in the Internet of Vehicles, resulting in the infringement of the privacy and legitimate rights and interests of car owners and others, reducing the safety of vehicle services.
The vehicle privacy data security encryption method is adopted to encrypt and desensitize the privacy data through periodically updated second key and desensitization key, and authenticate and store data after the vehicle is powered on. Quantum communication is used to synchronize registration information to ensure the security and privacy of the data in the cloud.
Effectively prevent vehicle privacy data leakage, reduce storage resource usage, improve vehicle services security and privacy protection, ensure that viewers can only see authorized data, reduce performance requirements, and enhance universality and security.
Smart Images

Figure CN119995883B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of vehicle networking, and in particular relates to a method for securely encrypting, uploading and viewing vehicle privacy data. Background Art
[0002] With the continuous development of Internet of Vehicles technology, various vehicle services not only provide people with a comfortable driving experience, but also ensure the safety of the vehicle. However, these vehicle services must be based on vehicle privacy data.
[0003] Furthermore, the implementation process will generate a lot of new vehicle privacy data. Private data generated on the vehicle or recorded by the vehicle is vehicle privacy data, such as vehicle location information, in-cabin images, in-cabin call logs, driving records, and sentry mode recordings.
[0004] Once private vehicle data is viewed by someone other than the person for whom it was recorded, it can lead to a data leak. For example, if the vehicle's location information is recorded for the vehicle owner, leaking it could expose the owner's whereabouts and home address, potentially threatening the owner's personal safety while using route planning services. Alternatively, if a driving record is recorded for the vehicle owner, pedestrians, the vehicle involved in the accident, and the vehicle owner, leaking the recording could result in the unauthorized dissemination of images of the pedestrians and the vehicle owner online, infringing on their portrait rights. Alternatively, if a vehicle owner parks their vehicle in a residential area and Sentry Mode captures footage from inside a resident's home, the Sentry Mode recording would be recorded for the resident. The vehicle owner's subsequent use of the Sentry Mode recording to view footage of the resident would constitute a data leak and a violation of the resident's privacy. Therefore, the leakage of private vehicle data not only infringes on the privacy and legal rights of the vehicle owner and / or others, but also compromises the security of vehicle services.
[0005] Therefore, how to ensure that vehicle privacy data is not leaked and improve the security of vehicle services has become an urgent problem to be solved in the field of Internet of Vehicles. Summary of the Invention
[0006] The purpose of the present invention is to overcome the deficiencies of the above-mentioned prior art and provide a method for securely encrypting vehicle privacy data, which can ensure the security of vehicle privacy data stored on the vehicle, prevent vehicle privacy data from being leaked, and improve the security of vehicle services.
[0007] To achieve the above object, the present invention adopts the following technical solutions:
[0008] A method for securely encrypting vehicle privacy data includes the following steps:
[0009] S1: After the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle. One cycle is from the time the vehicle is powered on to the time it is powered off.
[0010] S2: When the vehicle generates Class I private data, it encrypts the Class I private data using the second key of the current cycle. When the vehicle generates Class II private data, it first desensitizes the Class II private data using the desensitizing key of the current cycle, and then encrypts the desensitized Class II private data using the second key of the current cycle.
[0011] S3: The vehicle is powered off and then powered on again, entering the next cycle and returning to S1.
[0012] Preferably, before S1, it also includes S0: S0, after the vehicle completes registration in the first cloud, the first cloud stores the registration information; the registered vehicle V stores the first key K1 charged by the first cloud TSP1; the registration information of the vehicle V includes the first key K1 and the vehicle identification code ID that are bound together V .
[0013] Preferably, S1 further includes the following sub-steps:
[0014] S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1:
[0015] A1={ID V ||X1||V X1}, V X1 =P X1 [K1];
[0016] Among them, || represents a connector; X1 represents the first eigenvalue; V X1 Represents the first authentication entity; P X1 represents the first feature segment selected from the first key K1 using the first feature value X1; X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption;
[0017] S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first copy of the first eigenvalue X1 1 and the first copy of the first authentication entity V X1 1 Then, extract the first copy ID of the vehicle identification code from the registration information V 1 The first copy of the bound first key K1 1 ; Then use the first copy of the first eigenvalue X11 From the first copy of the first key K1 1 Select the first copy of the first feature segment P X1 1 , calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ];
[0018] Among them, P X1 1 [·] indicates the use of the first copy of the first feature segment P X1 1 Symmetric encryption;
[0019] If V X1 2 =V X1 1 , then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V 1 =ID V And P X1 1 =P X1 ;
[0020] If the first copy of the vehicle identification code does not exist in the registration information V 1 , or V X1 2 ≠V X1 1 , then the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1;
[0021] S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitization key K3 and time code TC of the current cycle, and then binds the second key K2, desensitization key K3 and time code TC of the current cycle one by one with the vehicle identification code ID V Bind to the periodic key information of vehicle V; at the same time, the first cloud TSP1 sends key update information M1 to vehicle V: M1=K1[K2||K3||TC]; where K1[·] represents symmetric encryption using the first key K1;
[0022] S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current cycle 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1and store it;
[0023] In S3: When the vehicle V is powered off, the first copy of the current second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 .
[0024] Preferably, the first characteristic value X1 is used to select the first characteristic segment from the first key K1, specifically including the following: let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, use the first key K1 from the left X1 to the (X1+d) as the first characteristic segment P X1 When (X1+d)>L, the first key K1 from the left X1 to the L position is used as the first feature segment P X1 .
[0025] Preferably, S2 also includes the following contents:
[0026] When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then type I encrypted data ED Ⅰ With the first copy of time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cabin audio, vehicle cabin video; when vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then type II encrypted data ED Ⅱ With the first copy of time code TC 1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
[0027] Preferably, vehicle V has Class II privacy data PD Ⅱ After desensitization, desensitized data MD is generated, which specifically includes the following sub-steps:
[0028] S201, vehicle V identifies Class II privacy data PD Ⅱ The non-owner's face image and the non-vehicle V's license plate image in each frame are recorded as sensitive images; the vehicle V identifies the Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio;
[0029] S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption and desensitization of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
[0030] The present invention also provides a method for securely uploading vehicle privacy data, comprising the following steps:
[0031] S1´, the first cloud TSP synchronizes the registration information to the second cloud TSP2 in real time through quantum communication;
[0032] S2', vehicle V selects the Class I data packet P to be uploaded Ⅰ and / or Class II data packets P Ⅱ , send data upload message M2 to the second cloud TSP2: M2={ID V ||X2||G X2}, G X2 =P X2 [K1||P];
[0033] Among them, X2 represents the second eigenvalue; G X2 Represents the second data body; P X2 represents the second feature segment selected from the first key K1 using the second feature value X2; X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption; P represents a data packet, including type I data packet P Ⅰ and / or Class II data packets P Ⅱ ;
[0034] Class I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by using a vehicle privacy data security encryption method as described above;
[0035] S3', the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 And the first copy of the second data body G X2 1After that, take out the second copy of the vehicle identification code ID in the registration information V 2 The second copy of the bound first key K1 2 ; Then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy P of the second feature segment X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body G X2 1 Get the third copy of the first key K1 3 and the first copy of the data packet P 1 If K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plaintext message of "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data;
[0036] If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
[0037] The present invention also provides a method for securely viewing private data in a vehicle, wherein a viewer views private data in a vehicle, comprising the following steps:
[0038] Step 1: After the car owner completes registration on the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle;
[0039] Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric verification and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED that is expected to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ; Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ Obtained by using a vehicle privacy data security encryption method as described above;
[0040] Step 3: After the car owner authorizes, the first cloud sends the Class I encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED ⅡThe corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the Class I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for viewing by viewers.
[0041] Preferably, step 3 includes the following sub-steps:
[0042] Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3={ID V ||TC 1};
[0043] Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 generates the key distribution information M3 and sends it to the vehicle V: M3=Y[K2], Y=K 2* [K 3* ];
[0044] Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Perform symmetric encryption; Y represents the encryption key of the current cycle; Y[·] represents symmetric encryption using encryption key Y;
[0045] Step 33: Vehicle V calculates the first copy of the encryption key Y for the current cycle. 1 =K 2* 1 [K 3* 1 ], then use Y 1 After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second copy of the second key K2 2 ;
[0046] Step 34: Vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for VR viewing by viewers.
[0047] The present invention also provides a method for securely viewing vehicle private data, wherein a viewer views private data on a second cloud, comprising the following steps:
[0048] Step 1´, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 The data packet P stored in the second cloud is obtained by using a vehicle privacy data secure upload method as described above;
[0049] Step 2', the first cloud sends the second key and the desensitization key corresponding to the data packet P to the second cloud;
[0050] Step 3´, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ and check it out.
[0051] The beneficial effects of the present invention are:
[0052] (1) The security of vehicle privacy data stored in the vehicle prevents the leakage of vehicle privacy data.
[0053] (2) In the vehicle privacy data security encryption method of the present invention, the vehicle only needs to store its own first key and the second key and desensitization key of the current cycle, without occupying additional storage resources to store a large number of keys; and there is no need to set up a quantum random number generator to generate random numbers on the vehicle, which further reduces the occupation of vehicle storage resources. Therefore, the storage resources on the vehicle are mainly used for Class I data packets P Ⅰ and Class II data packets P Ⅱ For storage, the vehicle can store more data packets.
[0054] (3) In the vehicle privacy data security encryption method, the storage of Class I data packets P is excluded. Ⅰ and Class II data packets P Ⅱ In addition to occupying vehicle storage resources, the present invention occupies less storage resources during implementation and has lower performance requirements for the vehicle, making the present invention more versatile.
[0055] (4) In a vehicle privacy data security encryption method of the present invention, if there is a viewer who wants to view the vehicle privacy data, the vehicle privacy data that the viewer wants to view must be from a historical period. However, at the end of each period, the vehicle automatically clears the second key and desensitizing key of the current period. The encrypted vehicle privacy data cannot be viewed using the second key and desensitizing key of the current period. In other words, the viewer cannot directly view the vehicle privacy data without the vehicle communicating with the first cloud. Therefore, the present invention can well ensure the security of vehicle privacy data stored on the vehicle.
[0056] (5) In the vehicle privacy data security encryption method of the present invention, the authentication process uses a randomly generated first characteristic value to select a first characteristic fragment from the first key, so the first characteristic fragment of each cycle is different; and the first authentication body is obtained by symmetric encryption of the first key that remains unchanged using the first characteristic fragment, so the first authentication body of each cycle is also different; that is, the first characteristic value of the authentication request in each cycle of the present invention is random, and the corresponding first authentication body is also different, and the first authentication body is generated by symmetric encryption, and the computational overhead is smaller than that of asymmetric encryption, so the entire authentication process in the vehicle privacy data security encryption method of the present invention is more concise and efficient, and has extremely high security.
[0057] (6) In a method for securely uploading private vehicle data of the present invention, a vehicle can select part of the Class I data packets and / or Class II data packets to upload to the second cloud, thereby greatly reducing the storage burden of the vehicle; and the process of the vehicle uploading the Class I data packets and / or Class II data packets to the second cloud is extremely secure.
[0058] (7) In a method for securely viewing private data on a vehicle according to the present invention, whether a viewer has the right to view private data on the vehicle is decided by the vehicle owner. At the same time, the viewer on the vehicle can only see Class I private data and / or desensitized data, but cannot see Class II private data. In addition, viewers approved by the vehicle owner cannot see the information of non-vehicle owners. This ensures that the viewer can efficiently view private data and that the private data of non-vehicle owners will not be leaked.
[0059] (8) The method for securely viewing private vehicle data of the present invention enables a viewer who is not the vehicle owner to quickly and conveniently view Class I private data and / or desensitized data on the vehicle even when the viewer is not with the vehicle owner.
[0060] (9) The present invention provides a method for securely viewing vehicle private data, which allows viewers to view Class II private data only in the second cloud. Viewers who have been permitted by the vehicle owner can only view Class I private data and / or desensitized data in the vehicle. This not only satisfies the viewer's need to conveniently and quickly access vehicle private data, but also ensures that the viewer cannot see / hear Class II private data containing the private information of non-vehicle owners without supervision. The viewer's specific viewing method ensures that the viewer's viewing process will not leak vehicle private data, nor will it leak Class II private data containing the private information of non-vehicle owners, and will not infringe upon the privacy and legal rights of the vehicle owner and / or others. Furthermore, it also improves the security of vehicle services based on vehicle private data. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 The figure is a flow chart of a vehicle privacy data encryption method of the present invention. DETAILED DESCRIPTION
[0062] In order to make the technical solution of the present invention clearer and more specific, the present invention is clearly and completely described below with reference to the accompanying drawings. Any equivalent replacement of the technical features of the technical solution of the present invention and any solution derived by conventional reasoning by ordinary technicians in this field without making any creative work shall fall within the scope of protection of the present invention.
[0063] Example 1
[0064] like Figure 1 As shown in FIG. 1 , a method for securely encrypting vehicle private data according to this embodiment includes the following steps:
[0065] S0: After the vehicle completes registration at the first cloud, the first cloud stores the registration information.
[0066] S1: After the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle. One cycle is from the time the vehicle is powered on to the time it is powered off.
[0067] S2: When the vehicle generates Class I privacy data, the vehicle uses the second key of the current period to encrypt the Class I privacy data; when the vehicle generates Class II privacy data, the vehicle first uses the desensitizing key of the current period to desensitize the Class II privacy data, and then uses the second key of the current period to encrypt the desensitized Class II privacy data.
[0068] S3: The vehicle is powered off and then powered on again, entering the next cycle and returning to S1.
[0069] In S0, the following are included:
[0070] Vehicle V is registered at the first cloud TSP1 through an offline secure channel, and the unique vehicle identification code ID V Upload to the first cloud TSP1, the first cloud TSP1 will receive the vehicle identification code ID V Compare the current vehicle identification code with all the registration information in the first cloud TSP1. V If the vehicle identification code ID does not exist in the registration information, the first cloud TSP1 sends a duplicate registration message to the vehicle V. V , the first cloud TSP1 generates the first key K1 and injects the first key K1 into the secure medium on the vehicle V. The vehicle V completes the registration at the first cloud TSP1. At the same time, the first cloud TSP1 combines the first key K1 with the vehicle identification code ID V The registration information of vehicle V is bound and stored.
[0071] The first cloud TSP1 has a built-in quantum random number generator, and the first key K1 is a quantum key generated by the quantum random number generator.
[0072] The identity of the vehicle V that has completed registration at the first cloud TSP1 is legal.
[0073] In S1, the following sub-steps are also included:
[0074] S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1:
[0075] A1={ID V ||X1||V X1}, V X1 =P X1 [K1],
[0076] Among them, || represents a connector, X1 represents the first eigenvalue, V X1 Represents the first authenticator, P X1 represents the first feature segment selected from the first key K1 using the first feature value X1, P X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption.
[0077] The first characteristic value X1 is randomly determined by the vehicle during the process of generating the authentication request A1.
[0078] The first characteristic value X1 is used to select the first characteristic segment from the first key K1, specifically including the following contents:
[0079] Let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, take the first key K1 from the left X1 to the (X1+d) as the first feature segment P X1 When (X1+d)>L, the first key K1 from the left X1 to the L position is used as the first feature segment P X1 .
[0080] S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first copy of the first eigenvalue X1 1 and the first copy of the first authentication entity V X1 1 Then, extract the first copy ID of the vehicle identification code from your own registration information V 1 The first copy of the bound first key K1 1 , then use the first copy of the first eigenvalue X1 1 From the first copy of the first key K1 1 Select the first copy of the first feature segment P X1 1 , calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ], where P X1 1 [·] indicates the use of the first copy of the first feature segment P X1 1 Symmetric encryption;
[0081] If V X1 2 =V X1 1 Then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V 1 =ID V And P X1 1 =P X1 ;
[0082] If the first copy of the vehicle identification code does not exist in the registration information V 1 , or V X1 2 ≠V X1 1, the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1.
[0083] S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitized key K3 and time code TC of the current cycle, binds the second key K2, desensitized key K3 and time code TC of the current cycle one by one, and then binds them to the vehicle identification code ID V The key is bound to the periodic key information of vehicle V. At the same time, the first cloud TSP1 sends the key update information M1 to vehicle V:
[0084] M1=K1[K2||K3||TC], where K1[·] indicates symmetric encryption using the first key K1.
[0085] The second key K2, the desensitized key K3 and the time code TC are all generated by the first cloud TSP1 using a quantum random number generator.
[0086] S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current cycle 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 and store it.
[0087] If the key update information M1 is not tampered with during the process of being sent from the first cloud TSP1 to the vehicle V, then K2 1 =K2 and K3 1 =K3 and TC 1 =TC.
[0088] During the authentication process of S1, a randomly generated first characteristic value is used to select a first characteristic fragment from the first key, so the first characteristic fragment of each cycle is different; and the first authentication body is obtained by symmetrically encrypting the first key that has always remained unchanged using the first characteristic fragment, so the first authentication body of each cycle is also different.
[0089] In existing cloud-based vehicle authentication, authentication is often determined by using a pair of unchanging public and private keys to encrypt and decrypt an unchanging root key. However, because these keys and root keys remain unchanged, their security decreases over time, and the probability of being cracked increases. In contrast, in this embodiment, the first characteristic value of the authentication request A1 is random within each cycle, and the corresponding first authentication entity is also different. Furthermore, the first authentication entity is generated using symmetric encryption, resulting in a lower computational overhead than asymmetric encryption. Therefore, the entire authentication process in this embodiment is more concise, efficient, and highly secure.
[0090] Optionally, after the vehicle V sends the authentication request A1 to the first cloud TSP1, if it does not receive the key update information M1 for a period greater than the set first time threshold Δt1, S11 will be automatically re-executed so that the legitimate vehicle V can obtain the first copy K2 of the second key of the current cycle as soon as possible. 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 This avoids the problem of a legitimate vehicle V having to wait for a long time due to not receiving the key update information M1 due to network packet loss. In this embodiment, the first time threshold Δt1 is set to 30 seconds.
[0091] In S2, the following are also included:
[0092] When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then type I encrypted data ED Ⅰ With the first copy of time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cabin audio, and vehicle cabin video.
[0093] When vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then type II encrypted data ED Ⅱ With the first copy of time code TC 1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
[0094] Vehicle V to Class II Privacy Data PD Ⅱ After desensitization, desensitized data MD is generated, which specifically includes the following sub-steps:
[0095] S201, vehicle V identifies Class II privacy data PD ⅡThe non-owner's face image and the non-vehicle V's license plate image in each frame are recorded as sensitive images; the vehicle V identifies the Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio;
[0096] S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption and desensitization of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
[0097] Privacy Data PD Ⅱ Each sensitive image frame contains several pixels, which are desensitized using the first copy of the desensitizing key K3. 1 After symmetric encryption, it is reversibly converted into a color different from the original pixel, which makes the sensitive image unrecognizable after desensitization, and this color conversion is controlled by the first copy of the desensitization key K3 1 Even if the pixels are the same color, as long as the first copy of the desensitization key K3 1 Different, then the color of the pixel after desensitization is also different. That is to say, even if it is the same sensitive picture, as long as the first copy of the desensitization key K3 1 If the data is different, then the desensitized images will also be different. Ⅱ The sensitive audio in contains several audio frames, which are desensitized using the first copy of the desensitizing key K3 1 After symmetric encryption, it is reversibly converted into an audio frame that is completely different from the original audio data. This makes the sensitive audio unrecognizable after desensitization (the timbre is unrecognizable and the audio semantics are incomprehensible). Even if it is the same sensitive audio, as long as the first copy of the desensitization key K3 1 If the audio is different, then the audio after desensitization processing will also be different.
[0098] The following are also included in S3:
[0099] S31, when the vehicle V is powered off, the first copy of the current second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 ;
[0100] S32, the vehicle V is powered on again, enters the next cycle, and returns to S1.
[0101] In a vehicle privacy data security encryption method of this embodiment, the vehicle only needs to store its own first key and the second key and desensitization key of the current cycle, without occupying additional storage resources to store a large number of keys; and there is no need to set up a quantum random number generator to generate random numbers on the vehicle, which further reduces the occupation of vehicle storage resources. Therefore, the storage resources on the vehicle are mainly used for Class I data packets P Ⅰ and Class II data packets P Ⅱ For storage, the vehicle can store more data packets.
[0102] Remove the storage of Class I data packets P Ⅰ and Class II data packets P Ⅱ In addition to occupying vehicle storage resources, the implementation of this embodiment occupies less storage resources and has lower performance requirements for the vehicle, making this embodiment more versatile.
[0103] The entire implementation process of the vehicle privacy data security encryption method of this embodiment is extremely secure, which is mainly reflected in the following two aspects:
[0104] ① In each cycle, the vehicle generates an authentication request by randomly using the first key fragment to encrypt the first key and then authenticates on the first cloud. Therefore, the authentication request sent by the vehicle to the first cloud in each cycle is different. Even if a hacker attempts to use the authentication request of the previous cycle to perform a replay attack, it will not be able to successfully authenticate on the first cloud in the current cycle.
[0105] ② In the communication process between the vehicle and the first cloud, the first key is never directly used as the object to be encrypted, and the plain text of the first key and the first key fragment does not exist in all messages. Therefore, even if a hacker intercepts the communication messages between the vehicle and the first cloud, he cannot obtain the first key, and it is even more impossible to restore the first key by piecing together the first key fragments. The transmitted second key and desensitized key will not exist in the vehicle at the end of the current cycle. Therefore, in this embodiment, even if the first key of the vehicle remains unchanged for a long time, it can still be guaranteed that the vehicle can safely obtain the second key and desensitized key of the current cycle.
[0106] A vehicle privacy data security encryption method of this embodiment encrypts vehicle privacy data in different levels. The encrypted vehicle privacy data is stored on the vehicle and cannot be viewed directly. If there is a viewer who wants to view the vehicle privacy data, the vehicle privacy data that the viewer wants to view must be from a historical period. However, at the end of each period, the vehicle automatically clears the second key and desensitizing key of the current period. The encrypted vehicle privacy data cannot be viewed using the second key and desensitizing key of the current period. In other words, the viewer cannot directly view the vehicle privacy data without the vehicle communicating with the first cloud. Therefore, this embodiment can well ensure the security of vehicle privacy data stored on the vehicle and avoid the leakage of vehicle privacy data.
[0107] Example 2
[0108] The present invention also provides a method for securely uploading vehicle privacy data, comprising the following steps:
[0109] S1´, the first cloud TSP1 synchronizes the registration information to the second cloud TSP2 in real time through quantum communication;
[0110] S2', vehicle V selects the Class I data packet P to be uploaded Ⅰ and / or Class II data packets P Ⅱ , send data upload message M2 to the second cloud TSP2: M2={ID V ||X2||G X2}, G X2 =P X2 [K1||P],
[0111] Among them, X2 represents the second eigenvalue, G X2 Represents the second data body, P X2 represents the second feature segment selected from the first key K1 using the second feature value X2, P X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption, P represents the data packet, including type I data packet P Ⅰ and / or Class II data packets P Ⅱ .
[0112] The method of selecting the second characteristic segment from the first key K1 using the second characteristic value X2 is the same as the method of selecting the first characteristic segment from the first key K1 using the first characteristic value X1 in Example 1, and will not be repeated here.
[0113] Class I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by adopting the vehicle privacy data security encryption method described in Example 1.
[0114] The second characteristic value X2 is randomly determined by the vehicle when generating the data upload message M2.
[0115] S3', the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 And the first copy of the second data body G X2 1 Then, take out the second copy ID of the vehicle identification code from your own registration information V 2 The second copy of the bound first key K1 2 , and then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy P of the second feature segment X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body G X2 1 Get the third copy of the first key K1 3 and the first copy of the data packet P 1 , if K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plaintext message of "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data.
[0116] If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
[0117] Optionally, if the vehicle V receives a plaintext message of "upload failed", or if the vehicle V does not receive a plaintext reply message from the second cloud TSP2 after sending the data upload message M2 to the second cloud TSP2 for more than the set second time threshold Δt2, the process returns to S2'.
[0118] In this embodiment, the second time threshold Δt2 is set to 45 seconds.
[0119] Optionally, the same data packet P is only saved once in the second cloud TSP2.
[0120] The first cloud TSP1 does not store the Class I data packets P uploaded by the vehicle.Ⅰ and / or Class II data packets P Ⅱ The second cloud TSP2 has a large amount of storage space for storing the Class I data packets P uploaded by vehicles. Ⅰ and / or Class II data packets P Ⅱ , and the second cloud TSP2 can be multiple. For example, cars of the same brand upload their privacy data to the same second cloud TSP2. The second cloud TSP2 is supervised by a third party and is an absolutely safe storage space. The brand of the vehicle cannot retrieve the Class I data packet P from the second cloud TSP2 at will. Ⅰ and / or Class II data packets P Ⅱ .
[0121] Vehicle V sends the Class I data packet P Ⅰ and / or Class II data packets P Ⅱ The process of uploading to the second cloud TSP2 is extremely secure, as shown in the following aspects:
[0122] ① Data packet P itself is ciphertext, and the vehicle clears the first copy of the second key K2 in the current cycle at the end of each cycle 1 and the first copy of the desensitized key K3 1 Therefore, when a vehicle uploads a data packet P, there is generally no key in the vehicle to decrypt the uploaded data packet. Therefore, the data upload message M2 does not contain any key for decryption, and the data packet P itself has extremely high security.
[0123] ② During the wireless communication upload process, the data packet P is encrypted again into a second data body using the second feature fragment randomly extracted. The data upload message M2 is not encrypted using the first key K1, nor does it contain any first key K1 fragment. Therefore, even if a hacker intercepts the data upload message M2, he or she will not be able to crack the data packet P, let alone obtain the plaintext private data.
[0124] ③ The recipient of the vehicle-uploaded data packet P is the second cloud, not the first cloud. The second cloud only contains registration information, but does not have the keys (second key and desensitizing key) corresponding to the decryption of the uploaded data packet. Therefore, after the second cloud stores data packet P, it cannot obtain the plaintext private data.
[0125] ④ The second cloud will authenticate the vehicle V based on the data upload message M2. The data packet P will be stored only after the authentication is passed. Therefore, even if a hacker intercepts and tampers with the data upload message M2 and resends it to the second cloud in an attempt to perform malicious operations in the second cloud, the second cloud will not pass the authentication, making the malicious operation impossible.
[0126] Therefore, in a method for securely uploading private vehicle data of this embodiment, the vehicle can select some Class I data packets P by itself. Ⅰ and / or Class II data packets P Ⅱ Safely upload to the second cloud TSP2, greatly reducing the vehicle storage burden.
[0127] Example 3
[0128] The present invention also provides a method for securely viewing vehicle privacy data:
[0129] When a viewer views private data on a vehicle, the following steps are included: 1 to 4:
[0130] Step 1: After the car owner completes registration on the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle;
[0131] Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric authentication and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED that is expected to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ;
[0132] Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ It is obtained by adopting the vehicle privacy data security encryption method described in Example 1.
[0133] Step 3: After the car owner authorizes, the first cloud sends the Class I encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED Ⅱ The corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the Class I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for viewing by viewers.
[0134] Optionally, when the viewer views private data on the second cloud, the following steps 1' to 3' are included:
[0135] Step 1´, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 ;
[0136] The data packet P stored in the second cloud is obtained using the vehicle privacy data secure uploading method described in Example 2.
[0137] Step 2', the first cloud sends the second key and the desensitization key corresponding to the data packet P to the second cloud;
[0138] Step 3´, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ and check it out.
[0139] Because in the method for securely viewing private vehicle data in this embodiment, the viewer must either view it in the vehicle or in the second cloud. The prerequisite for viewing it in the vehicle is that the vehicle is powered on and the viewer enters the vehicle. Once the vehicle is powered on, it enters the current cycle, and the private data being viewed must belong to a completed historical cycle. The second key for the current cycle generated by the first cloud is recorded as K 2* , the current period desensitization key generated by the first cloud is recorded as K 3* , the first copy of the second key of the current period obtained by the vehicle from the first cloud is recorded as K 2* 1 , the first copy of the current cycle desensitized key obtained by the vehicle from the first cloud is recorded as K 3* 1 .
[0140] If the first copy of the second key of the current period and the first copy of the desensitized key obtained by the vehicle from the first cloud are both tamper-free, then K 2* 1 =K 2* And K 3* 1 =K 3* .
[0141] Also include the following in step 1:
[0142] The car owner registers at the first cloud TSP1 through an offline secure channel, and enters the car owner's account number AC, car owner's account password PW, and car owner's biometric information BI AC and vehicle identification number ID V Upload to the first cloud TSP1, the first cloud TSP1 will save the owner's account number AC, owner's account password PW, owner's biometric information BI AC After binding to the owner's account information, the owner's account information and the vehicle identification code ID VThe corresponding registration information and periodic key information are bound; the viewer VR enters his or her own biometric information on the vehicle V; the viewer VR can be the owner's family, the owner's friend, the owner himself or herself, a vehicle maintenance personnel, etc.
[0143] Biometric information includes fingerprint information, facial image information, etc.
[0144] A car owner's account information can be bound to the registration information and periodic key information of multiple vehicles. In reality, a car owner may own multiple private cars.
[0145] Also include the following in step 2:
[0146] After the vehicle V is powered on, the viewer VR successfully performs biometric authentication on the vehicle V. The viewer VR sends a first viewing request A2 to the vehicle owner account AC through the vehicle V: A2={ID V ||N VR ||TC 1}, where N VR Indicates the viewer VR name.
[0147] As can be seen from steps 1 and 2, only viewers who have entered their own biometric information on the vehicle can send the first viewing request to the vehicle owner's account through the corresponding vehicle; and because the number of viewers changes greatly (for example, for safety reasons, the owner will enter the corresponding vehicle maintenance personnel's biometric information into the vehicle every time the vehicle is sent to the 4S shop for inspection, and delete the maintenance personnel's biometric information from the vehicle after each inspection is completed), in this embodiment, the viewer does not need to register on the first cloud. Instead, the vehicle owner decides who should enter biometric information on the vehicle. This not only gives the right to become a viewer to the vehicle owner, but also is obviously more flexible and convenient than going to the first cloud TSP1 for registration.
[0148] Step 3 also includes the following sub-steps:
[0149] Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3={ID V ||TC 1};
[0150] Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 generates the key distribution information M3 and sends it to the vehicle V: M3=Y[K2], Y=K 2* [K 3* ];
[0151] Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Perform symmetric encryption; Y represents the encryption key of the current cycle; Y[·] represents symmetric encryption using encryption key Y.
[0152] If the period key information of the first cloud platform TSP1 does not contain the first copy of the vehicle V and the time code TC 1 The corresponding second key K2, the first cloud platform TSP1 feeds back a plain text message of "information error" to the car owner account AC.
[0153] Optionally, if the vehicle owner account AC receives "information error" messages from the first cloud platform TSP1 f times in a row, an alert is sent to the vehicle manufacturer. This may be because a hacker intercepted and tampered with the first access request A2 and / or key request message A3 and / or key update message M1. The vehicle manufacturer needs to encrypt or replace the wireless communication channel for the first access request A2 and / or key request message A3 and / or key update message M1.
[0154] When the hacker intercepts the first viewing request A2 and tampered with it and resends it to the vehicle V, it will cause the vehicle V to obtain the first copy of the second key K2 in the same cycle. 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 This is different from the second key K2, desensitization key K3, and time code TC generated by the first cloud platform TSP1. If a hacker intercepts the key request message A3, modifies it, and resends it to the first cloud platform TSP1, and there is a one in a billion chance that the corresponding second key exists in the periodic key information of the first cloud platform TSP1, then the vehicle will not be able to decrypt the correct vehicle private data using this second key, thus ensuring that the vehicle's private data will not be leaked. If a hacker intercepts the key update message M1, modifies it, and resends it to the vehicle V, then the vehicle will not be able to decrypt the correct vehicle private data using the encryption key of the current period, thus ensuring that the vehicle's private data will not be leaked.
[0155] In this embodiment, f=5.
[0156] Step 33: Vehicle V calculates the first copy of the encryption key Y for the current cycle. 1 =K 2* 1 [K 3* 1 ], then use Y 1After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second copy of the second key K2 2 .
[0157] Step 34: Vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for VR viewing by viewers.
[0158] If the messages in each step of the method for securely encrypting vehicle private data in Example 1 and the messages in each step of the method for securely viewing vehicle private data in this embodiment have not been tampered with by hackers, then K2 2 =K2, vehicle V can also decrypt the correct Class I privacy data PD Ⅰ And / or masked data MD, otherwise the viewer can only see a bunch of garbled data.
[0159] Optional, Class I privacy data PD Ⅰ And / or the time during which the masked data MD is viewed by the viewer VR is a third time threshold Δt3. In this embodiment, Δt3=15 minutes.
[0160] The embodiment of the vehicle private data security viewing method allows the vehicle owner to decide whether the viewer has the right to view the private data on the vehicle, while at the same time allowing the viewer on the vehicle to only see Class I private data PD. Ⅰ and / or desensitized data MD, but cannot see Class II privacy data PD Ⅱ , so that viewers approved by the car owner cannot see the information of non-car owners. This not only ensures that viewers can efficiently view private data, but also ensures that the private data of non-car owners will not be leaked.
[0161] For example, a car owner left their window open after parking the car last night, and the next day, they discovered they couldn't find their wallet. They're unsure whether they left their wallet in the car overnight and someone else took it through the open window. So, they go inside and review the Sentry Mode footage from the day after parking. They see someone taking the wallet through the open window, so they call the police. However, the facial recognition in the Sentry Mode footage is masked, so the owner doesn't know who it is. This prevents the owner from publicly sharing the identity of the person who took the wallet online, potentially infringing on their image rights. Furthermore, if the person simply took the wallet and turned it in, the potential damage from the owner spreading the image online could be exacerbated. If the Sentry Mode footage doesn't show anyone approaching the car, and the owner doesn't find the wallet inside, they might assume it's at home and return home to search.
[0162] The method for securely viewing vehicle private data in this embodiment enables a viewer who is not the vehicle owner to quickly and conveniently view Class I private data and / or desensitized data on the vehicle even when the viewer is not with the vehicle owner.
[0163] For example, vehicle maintenance personnel need to check driving records to quickly determine what problems the vehicle has. At this time, the owner is not in the vehicle. The vehicle maintenance personnel at the 4S shop can also conveniently view the corresponding private data with the owner's consent, which is convenient for the vehicle maintenance personnel to perform corresponding inspections and maintenance on the vehicle.
[0164] In step 31, the owner enters the owner's account number AC, owner's account password PW and owner's biometric information BI AC , log in to the car owner account AC on different mobile devices, including mobile phones, tablets, etc.
[0165] Include the following in Step 2´:
[0166] The first cloud TSP1 extracts the vehicle identification code ID from its own periodic key according to the second check request. V And the first copy of the time code TC 1 After the corresponding second key K2 and desensitized key K3 are obtained, a key transfer message M4 is generated and sent to the second cloud TSP2:
[0167] M4={X3||KD},KD=P X3 [K2||K3],
[0168] Among them, X3 represents the third eigenvalue, KD represents the key body, P X3 represents the third feature segment selected from the first key K1 of the vehicle V using the third feature value X3, P X3[·] indicates the use of P X3 Perform symmetric encryption.
[0169] The method of selecting the third characteristic segment from the first key K1 using the third characteristic value X3 is the same as the method of selecting the first characteristic segment from the first key K1 using the first characteristic value X1 in Example 1, and will not be repeated here.
[0170] Include the following in Step 3´:
[0171] The second cloud TSP2 obtains the first copy X3 of the third eigenvalue from the key transfer message M4 1 and the first copy of the key body KD 1 Then, take out the vehicle identification code ID from your own registration information V The bound first key K1, and then use the first copy of the third characteristic value X3 1 Select the first copy P of the third feature segment from the first key K1 X3 1 Then, use the first copy of the third feature fragment P X3 1 The first copy of the symmetric decryption key KD 1 Get the third copy of the second key K2 3 And the second copy of the desensitized key K2 2 ; The second cloud TSP2 uses the third copy of the second key K2 3 And the second copy of the desensitized key K2 2 Symmetrically decrypt the encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ For viewers to view in VR.
[0172] Because the second cloud TSP2 is supervised by a third party, the viewer VR cannot view the Class I privacy data PD at the second cloud TSP2 at will. Ⅰ and / or Category II privacy data PD Ⅱ Only viewers permitted by the third party can view Class I privacy data PD on the second cloud TSP2 Ⅰ and / or Category II privacy data PD Ⅱ At this time, the viewer VR will not disclose the privacy of others who are not the car owner.
[0173] For example, a car owner came to the car to check the Sentry Mode video after parking last night, and found that someone had indeed taken the wallet in the car directly through the open window in the Sentry Mode video, so the car owner called the police; however, the face image in the Sentry Mode video was desensitized, and the car owner did not know who it was; subsequently, under the supervision of a third party, the car owner viewed the Class II privacy data PD on the second cloud TSP2. Ⅱ , and found that it was the child at home who took out the wallet.
[0174] A method for securely viewing vehicle private data in this embodiment enables the viewer to view the Class II private data PD only at the second cloud TSP2. Ⅱ , viewers who have been allowed by the owner can only view Class I privacy data PD on the vehicle Ⅰ and / or desensitized data MD, which not only meets the viewer's need to quickly and easily access vehicle privacy data, but also ensures that the viewer cannot see / hear Class II privacy data PD containing non-owner privacy in the absence of supervision Ⅱ .
[0175] In this embodiment, a method for securely viewing vehicle private data is provided. The viewer's specific viewing method ensures that the viewer's viewing process will not leak the vehicle private data, and thus will not leak the Class II private data PD containing the privacy of non-vehicle owners. Ⅱ , and will not infringe upon the privacy and legal rights of the vehicle owner and / or others. Further, it also improves the security of vehicle services based on vehicle privacy data.
[0176] The technology, shape, and structure not described in detail in the present invention are all well-known technologies.
[0177] It should also be pointed out that the above are only preferred embodiments of the present invention and are not intended to limit the present invention. The components or steps in the embodiments of the present invention can be decomposed and / or recombined, and these decompositions and / or recombinations should be regarded as equivalent solutions of the present application and should fall within the scope of protection of the present invention.
Claims
1. A method for securely encrypting vehicle privacy data, characterized in that: The following steps are involved: S1: After the vehicle is powered on, it sends an authentication request to the first cloud. After the first cloud successfully authenticates the vehicle, it sends the second key and desensitized key of the current cycle to the vehicle. One cycle is from vehicle power on to vehicle power off; S2: When the vehicle generates Class I private data, it encrypts the Class I private data using the second key of the current cycle. When the vehicle generates Class II private data, it first desensitizes the Class II private data using the desensitizing key of the current cycle, and then encrypts the desensitized Class II private data using the second key of the current cycle. S3: The vehicle is powered off and then powered on again, entering the next cycle and returning to S1; Before S1, it also includes S0: S0, after the vehicle completes registration in the first cloud, the first cloud stores the registration information; the registered vehicle V stores the first key K1 charged by the first cloud TSP1; the registration information of the vehicle V includes the first key K1 and the vehicle identification code ID bound together V ; S1 also includes the following sub-steps: S11, after the vehicle V is powered on, it sends an authentication request A1 to the first cloud TSP1: A1={ID V ||X1||V X1 },V X1 =P X1 [K1]; Among them, || represents a connector; X1 represents the first eigenvalue; V X1 Represents the first authentication entity; P X1 represents the first feature segment selected from the first key K1 using the first feature value X1; X1 [·] indicates the use of the first feature segment P X1 Symmetric encryption; S12, the first cloud TSP1 obtains the first copy ID of the vehicle identification code from the authentication request A1 V 1 , the first eigenvalue first copy X1 1 and the first copy of the first authentication entity V X1 1 Then, extract the first copy ID of the vehicle identification code from the registration information V 1 The first copy of the bound first key K1 1 ; Then use the first copy of the first eigenvalue X1 1 From the first copy of the first key K1 1 Select the first copy of the first feature segment P X1 1 , calculate the second copy V of the first authentication body X1 2 =P X1 1 [K1 1 ]; Among them, P X1 1 [·] indicates the use of the first copy of the first feature segment P X1 1 Symmetric encryption; If V X1 2 =V X1 1 , then the first cloud TSP1 successfully authenticates the vehicle V, that is, X1 1 =X1 and K1 1 =K1 and ID V 1 =ID V And P X1 1 =P X1 ; If the first copy of the vehicle identification code does not exist in the registration information V 1 , or V X1 2 ≠V X1 1 , then the first cloud TSP1 fails to authenticate the vehicle V, and the first cloud TSP1 discards the authentication request A1; S13, after the first cloud TSP1 successfully authenticates the vehicle V, it generates the second key K2, desensitization key K3 and time code TC of the current cycle, and then binds the second key K2, desensitization key K3 and time code TC of the current cycle one by one with the vehicle identification code ID V Bind to the periodic key information of vehicle V; at the same time, the first cloud TSP1 sends key update information M1 to vehicle V: M1 = K1[K2||K3||TC]; where K1[·] represents symmetric encryption using the first key K1; S14, vehicle V uses the first key K1 to symmetrically decrypt the key update information M1 to obtain the first copy K2 of the second key of the current cycle 1 , the first copy of the desensitized key K3 1 and the first copy of the time code TC 1 and store it; In S3: When the vehicle V is powered off, the first copy of the current second key K2 is automatically cleared 1 and the first copy of the desensitized key K3 1 .
2. A vehicle privacy data security encryption method according to claim 1, characterized in that: The first characteristic value X1 is used to select the first characteristic segment from the first key K1, specifically including the following contents: Let the length of the first key K1 be L, set the segment length to d, 0<d<L, when (X1+d)≤L, take the first key K1 from the left X1 to the (X1+d) as the first feature segment P X1 When (X1+d)>L, the first key K1 from the left X1 to the L position is used as the first feature segment P X1 .
3. The method for securely encrypting vehicle privacy data according to claim 1, characterized in that: S2 also includes the following: When vehicle V generates Class I privacy data PD Ⅰ When vehicle V uses the first copy of the second key K2 1 For Class I privacy data PD Ⅰ After symmetric encryption, type I encrypted data ED is formed Ⅰ , and then type I encrypted data ED Ⅰ With the first copy of time code TC 1 After binding, a Class I data packet P is formed Ⅰ Storage; Class I privacy data PD Ⅰ Including GPS location information, vehicle cabin audio, and vehicle cabin video; When vehicle V generates Class II privacy data PD Ⅱ When vehicle V uses the first copy of the desensitized key K3 1 For Class II privacy data PD Ⅱ The face image of the non-owner, the license plate image of the non-vehicle V, and the audio of the non-owner are symmetrically encrypted and desensitized to form desensitized data MD, and then the first copy of the second key K2 is used 1 After symmetric encryption of the desensitized data MD, type II encrypted data ED is generated Ⅱ , and then type II encrypted data ED Ⅱ With the first copy of time code TC 1 After binding, a type II data packet P is formed Ⅱ Storage; Class II privacy data PD Ⅱ Including driving records and sentry mode recordings.
4. A vehicle privacy data security encryption method according to claim 3, characterized in that: Vehicle V to Class II Privacy Data PD Ⅱ After desensitization, desensitized data MD is generated, which specifically includes the following sub-steps: S201, vehicle V identifies Class II privacy data PD Ⅱ The non-owner's face image and the non-vehicle V's license plate image in each frame are recorded as sensitive images; Vehicle V identifies Class II privacy data PD Ⅱ The audio frames containing human voices other than the car owner are recorded as sensitive audio; S202, vehicle V uses the first copy of the desensitized key K3 1 After symmetric encryption and desensitization of pixels in sensitive images and sensitive audio, the Class II privacy data PD Ⅱ Converted into desensitized data MD.
5. A method for securely uploading vehicle privacy data, characterized in that: The following steps are involved: S1′, the first cloud TSP synchronizes the registration information to the second cloud TSP2 in real time through quantum communication; S2′, vehicle V selects the Class I data packet P to be uploaded Ⅰ and / or Class II data packets P Ⅱ , send data upload message M2 to the second cloud TSP2: M2 = {ID V ||X2||G X2 }, G X2 =P X2 [K1||P]; Among them, X2 represents the second eigenvalue; G X2 Represents the second data body; P X2 represents the second feature segment selected from the first key K1 using the second feature value X2; X2 [·] indicates the use of the second feature segment P X2 Symmetric encryption; P represents a data packet, including type I data packet P Ⅰ and / or Class II data packets P Ⅱ ; Class I data packet P Ⅰ and / or Class II data packets P Ⅱ It is obtained by adopting a vehicle privacy data security encryption method as claimed in claim 3 or 4; S3′, the second cloud TSP2 obtains the second copy ID of the vehicle identification code from the data upload message M2 V 2 , the first copy of the second eigenvalue X2 1 And the first copy of the second data body G X2 1 After that, take out the second copy of the vehicle identification code ID in the registration information V 2 The second copy of the bound first key K1 2 ; Then use the first copy of the second eigenvalue X2 1 From the second copy of the first key K1 2 Select the first copy P of the second feature segment X2 1 Then, use the first copy of the second feature fragment P X2 1 Symmetrically decrypt the first copy of the second data body G X2 1 Get the third copy of the first key K1 3 and the first copy of the data packet P 1 If K1 3 =K1 2 , then the second cloud TSP2 successfully authenticates the vehicle V, that is, P 1 =P, the second cloud TSP2 saves the data packet P and sends a plaintext message "upload successful" to the vehicle V. At this time, the vehicle V successfully uploads the private data; If K1 3 ≠K1 2 , the second cloud TSP2 fails to authenticate the vehicle V, the second cloud TSP2 discards the data upload message M2, the vehicle V fails to upload the private data, and the second cloud TSP2 sends a plaintext message of "upload failed" to the vehicle V.
6. A method for securely viewing vehicle privacy data, characterized in that: The viewer views private data on a vehicle, including the following steps: Step 1: After the car owner completes registration on the first cloud, the first cloud stores the car owner's account information; the viewer enters his or her own biometric information on the vehicle; Step 2: After the vehicle is powered on, the viewer passes the vehicle's biometric verification and sends a first viewing request to the vehicle owner's account through the vehicle. The first viewing request includes the Class I encrypted data ED that is expected to be viewed. Ⅰ and / or Class II encrypted data ED Ⅱ The first copy of the time code TC 1 ; Type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ Obtained by using a vehicle privacy data security encryption method as claimed in claim 3 or 4; Step 3: After the car owner authorizes, the first cloud sends the Class I encrypted data ED to the vehicle. Ⅰ and / or Class II encrypted data ED Ⅱ The corresponding second key; the vehicle uses the corresponding second key to symmetrically decrypt the Class I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for viewing by viewers.
7. A method for securely viewing vehicle private data according to claim 6, characterized in that: Step 3 includes the following sub-steps: Step 31: After the car owner authorizes, the car owner account AC sends a key request message A3 to the first cloud platform TSP1: A3 = {ID V ||TC 1 }; Step 32: The first cloud platform TSP1 extracts the key information related to the vehicle V and the first copy of the time code TC from the periodic key information according to the key request information A3. 1 The corresponding second key K2 generates the key distribution information M3 and sends it to the vehicle V: M3 = Y[K2], Y = K 2* [K 3* ]; Among them, K 3* Indicates the desensitization key used by vehicle V in the current cycle; K 2* K represents the second key used by vehicle V in the current cycle; 2* [·] indicates the use of K 2* Perform symmetric encryption; Y represents the encryption key of the current cycle; Y[·] represents symmetric encryption using encryption key Y; Step 33: Vehicle V calculates the first copy of the encryption key Y for the current cycle. 1 =K 2* 1 [K 3* 1 ], then use Y 1 After symmetric decryption key distribution information M3, the first copy of the time code TC is obtained. 1 The corresponding second copy of the second key K2 2 ; Step 34: Vehicle V uses the second copy of the second key K2 2 Symmetric decryption corresponding to the type I encrypted data ED Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or the masked data MD is provided for VR viewing by viewers.
8. A method for securely viewing vehicle privacy data, characterized in that: The viewer views private data in the second cloud, including the following steps: Step 1′, the viewer sends a second viewing request to the first cloud via the second cloud, and the second viewing request includes the vehicle identification code ID V and the first copy of the time code TC in the packet P that is expected to be viewed 1 The data packet P stored in the second cloud is obtained by using a method for securely uploading vehicle privacy data as described in claim 5; Step 2′: the first cloud sends the second key and the desensitization key corresponding to the data packet P to the second cloud; Step 3′, the viewer uses the corresponding second key and the desensitization key to symmetrically decrypt the type I encrypted data ED in the data packet P Ⅰ and / or Class II encrypted data ED Ⅱ After that, we get Class I privacy data PD Ⅰ and / or Category II privacy data PD Ⅱ and check it out.
Citation Information
Patent Citations
Data encryption system for mobile phone terminal
CN117768093A
Vehicle sentry mode data supervision method and supervision system
CN117812582A