Vehicle cloud communication security certificate acquisition method and device, new energy vehicle and readable storage medium

By automatically checking and updating the Vehicle Cloud Communication Certificate when the vehicle is turned on and using temporary certificates and private keys to build a temporary communication channel, the problem of unstable networking function caused by abnormal certificates in vehicle cloud interaction is solved, and the security and stability of Vehicle Cloud Communication is achieved.

CN119995915AActive Publication Date: 2025-05-13CHONGQING SELIS PHOENIX INTELLIGENT INNOVATION TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411401901.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-10-09
Publication Date
2025-05-13
Estimated Expiration
2044-10-09

AI Technical Summary

Technical Problem

The prior art is difficult to ensure the security and stability of information transmission during vehicle-cloud interaction, resulting in some networking functions being unable to be used normally.

Method used

By automatically starting the certificate service every time the vehicle is turned on, checking the certificate status of the vehicle for vehicle cloud communication security. If the status is abnormal and the network connection is valid, a temporary certificate file and temporary private key are used to build a temporary communication channel, send a certificate request to the cloud to obtain available certificate information, and save it to the target path.

Benefits of technology

It realizes that every time the vehicle is turned on, it ensures that there is an available vehicle cloud communication security certificate, avoids affecting the security and stability of vehicle cloud communication due to the unavailability of the certificate, and ensures that the vehicle can apply for a certificate from the cloud through temporary communication channels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995915A_ABST
    Figure CN119995915A_ABST
Patent Text Reader

Abstract

The invention relates to a vehicle cloud communication security certificate acquisition method and device, a new energy vehicle, a computer readable storage medium and a computer program product. The method comprises the following steps: monitoring a startup broadcast message of a vehicle based on a pre-registered broadcast receiver; under the condition that the startup broadcast message is monitored, starting a preset certificate service based on a receiving callback method rewritten in the broadcast receiver; if the certificate service is started, determining the current state of a certificate for vehicle cloud communication security in the vehicle; checking a network connection condition of the vehicle when it is determined that the current state of the certificate is abnormal; if the network connection of the vehicle is valid, constructing a temporary communication channel of vehicle cloud communication according to the temporary certificate file and the temporary private key; based on the temporary communication channel, sending a certificate request to the cloud and receiving certificate information returned by the cloud; and storing the certificate information to the target path for vehicle cloud communication. By adopting the method, the safety and stability of vehicle cloud communication can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of vehicle networking and information security technology, and in particular to a method and device for obtaining a vehicle-cloud communication security certificate, a new energy vehicle, and a computer-readable storage medium. Background Art

[0002] Vehicle-cloud interaction refers to the information interaction between vehicles and the cloud. In the process of vehicle-cloud interaction, sensitive user information such as mobile phone numbers, account passwords, etc. is involved. For this, corresponding information transmission security-related technologies are usually adopted, such as PKI, or Public Key Infrastructure. However, in the actual use of vehicles, vehicle-cloud information transmission security-related technologies are prone to failure, resulting in the inability to use some networking functions normally. Therefore, how to improve the security and stability of vehicle-cloud communication is a technical problem that needs to be solved. Summary of the invention

[0003] Based on this, it is necessary to provide a method, device, new energy vehicle and computer-readable storage medium for obtaining a vehicle-to-cloud communication security certificate to address the above-mentioned technical problems, so as to improve the security and stability of vehicle-to-cloud communication.

[0004] Resolve vehicle-side communication security certificate anomalies and achieve secure vehicle-cloud interaction.

[0005] In a first aspect, the present application provides a method for obtaining a vehicle-to-cloud communication security certificate, comprising:

[0006] Listen to the vehicle's power-on broadcast message based on a pre-registered broadcast receiver;

[0007] When the broadcast receiver monitors the power-on broadcast message, the pre-set certificate service is started based on the receiving callback method overridden in the broadcast receiver;

[0008] When the certificate service is enabled, determine the current status of the certificates in the vehicle used for vehicle-to-cloud communication security;

[0009] If it is determined that there is an abnormality in the current status of the certificate, check the network connection of the vehicle;

[0010] When the vehicle's network connection is valid, a temporary communication channel for vehicle-to-cloud communication is established based on the temporary certificate file and temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and the certificate information returned by the cloud is received; the scope of application of the temporary certificate file and temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate;

[0011] Save the certificate information to the target path for vehicle-cloud communication.

[0012] In one embodiment, determining a current status of a certificate in a vehicle for vehicle-to-cloud communication security includes:

[0013] Check whether the certificate file used for vehicle-cloud communication security exists in the target path;

[0014] If a certificate file exists in the target path, the validity period of the certificate corresponding to the certificate file is determined based on the reading of the certificate file, and whether the certificate is expired is determined based on the validity period of the certificate and the current time;

[0015] When it is detected that the certificate file does not exist in the target path and / or the certificate has expired, it is determined that an abnormality exists in the current state of the certificate.

[0016] In one embodiment, checking the network connection status of the vehicle includes:

[0017] Based on a timing cycle of a preset timer, the vehicle's current active network and current network capability information are obtained at intervals;

[0018] Based on the currently active network and current network capability information, check whether the vehicle's network has Internet connection capability and whether it has been verified; if it is checked that the vehicle's network has Internet connection capability and has been verified, determine that the vehicle's network connection is valid.

[0019] In one embodiment, sending a certificate request to the cloud based on a temporary communication channel includes:

[0020] Construct a certificate request for applying for a vehicle-to-cloud communication security certificate; the variable name in the certificate request corresponds to the key value used to store the vehicle-to-cloud communication security certificate in the cloud;

[0021] Based on the observable data container, a certificate request is sent to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued.

[0022] In one of the embodiments, after sending a certificate request to the cloud through a temporary communication channel based on an observable data container, the method also includes: based on the observation of the data container, monitoring whether the certificate information returned by the cloud is received; if the certificate information is received, verifying the validity of the certificate information; saving the certificate information to the target path, including: if the certificate information is valid, saving the certificate information to the target path.

[0023] In one of the embodiments, the temporary certificate file and the temporary private key are common to vehicles of the same production batch; the method also includes: when the vehicle system is updated, the temporary certificate file and the temporary private key are synchronously updated.

[0024] In one of the embodiments, the method further includes: registering a broadcast receiver in an application configuration file of the vehicle; the broadcast receiver is configured to listen to the vehicle's power-on broadcast message; and rewriting a receiving callback method corresponding to the broadcast receiver to start a certificate service.

[0025] In a second aspect, the present application also provides a vehicle-to-cloud communication security certificate acquisition device, including:

[0026] A monitoring module is used to monitor the vehicle's power-on broadcast message based on a pre-registered broadcast receiver; when the broadcast receiver monitors the power-on broadcast message, a pre-set certificate service is started based on a receiving callback method overwritten in the broadcast receiver;

[0027] A determination module, used to determine the current status of the certificate used for vehicle-to-cloud communication security in the vehicle when the certificate service is started;

[0028] The acquisition module is used to check the vehicle's network connection status when it is determined that the current status of the certificate is abnormal; when the vehicle's network connection is valid, a temporary communication channel for vehicle-to-cloud communication is established based on the temporary certificate file and the temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and the certificate information returned by the cloud is received; the scope of application of the temporary certificate file and the temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate; the certificate information is saved to the target path for use in vehicle-to-cloud communication.

[0029] In a third aspect, the present application also provides a new energy vehicle, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps of the method for obtaining the vehicle-cloud communication security certificate in the first aspect are implemented.

[0030] In a fourth aspect, the present application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method for obtaining a vehicle-cloud communication security certificate in the first aspect.

[0031] The above-mentioned vehicle-cloud communication security certificate acquisition method, device, new energy vehicle, computer-readable storage medium and computer program product, by listening to the vehicle's startup broadcast message according to the pre-registered broadcast receiver, realizes that when the vehicle is started, the certificate service is called to determine the current status of the certificate used for vehicle-cloud communication security in the vehicle. If the current status is abnormal and the network connection is valid, a temporary communication channel for vehicle-cloud communication is constructed through a temporary certificate file and a temporary private key, and a certificate request is sent to the cloud through the temporary communication channel to obtain the certificate information, and the certificate information is saved to the target path for vehicle-cloud communication. This realizes that every time the vehicle is started, the vehicle-cloud communication security certificate in the vehicle can be determined and an available vehicle-cloud communication security certificate can be provided, avoiding the vehicle-cloud communication being affected by factors such as the unavailability of the vehicle-cloud communication security certificate, that is, it is ensured that when vehicle-cloud communication is needed, there is an available vehicle-cloud communication security certificate in the vehicle, thereby ensuring the security and stability of vehicle-cloud communication. At the same time, through the temporary certificate file and the temporary private key, a temporary communication channel is constructed to facilitate the application for an available vehicle-cloud communication security certificate to the cloud, thereby ensuring that the vehicle can apply for a certificate from the cloud through the temporary communication channel before obtaining a formal certificate. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0033] Figure 1 This is an application environment diagram of a method for obtaining a vehicle-to-cloud communication security certificate in an embodiment;

[0034] Figure 2 A schematic diagram of a process for obtaining a vehicle-to-cloud communication security certificate in one embodiment;

[0035] Figure 3 A schematic diagram of a PKI two-way authentication process in one embodiment;

[0036] Figure 4 It is another flowchart of a method for obtaining a vehicle-to-cloud communication security certificate in another embodiment;

[0037] Figure 5 It is a structural block diagram of a device for obtaining a vehicle-to-cloud communication security certificate in an embodiment;

[0038] Figure 6 Schematic diagram of the internal structure of a new energy vehicle in one embodiment. DETAILED DESCRIPTION

[0039] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0040] The method for obtaining the vehicle-to-cloud communication security certificate provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the vehicle 101 and the cloud 102 perform data interaction, that is, vehicle-cloud communication, as long as there is data interaction between the vehicle 101 and the cloud 102. Among them, the vehicle 101 can be but not limited to a sedan, SUV (sport utility vehicle, or suburban utility vehicle), MPV (multi-Purpose Vehicles), sports car, truck, off-road vehicle, dump truck, tractor, agricultural vehicle, special vehicle (such as sanitation vehicle, snowplow, bulldozer, etc.), etc. Exemplarily, the vehicle can be a new energy electric vehicle. The cloud 102 can be broadly understood, and it can provide services for on-demand access to shared computing resources and data. Users can access cloud resources and services at any time, any place, and through any device. For example, the cloud 102 can include a server, which can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services. The cloud 102 can also include a data storage system, and the data storage system can store data that needs to be processed, etc.

[0041] Under current technology, vehicle-to-cloud communication security certificates are usually applied for and uniformly imported into the vehicle during the vehicle's production line stage. This solution enables the operation of applying for the certificate to be completed before the vehicle goes offline, which can ensure the security of communication during the digital certificate application process to a certain extent. However, this application for a certificate is a one-time operation. If there is an abnormality in the certificate later, there is no automatic recovery method. Possible abnormal situations include: certificate expiration, abnormal deletion of certificate files, etc. If the certificate is abnormal, it will affect vehicle-to-cloud communication. Therefore, the technical solution of the present invention provides a method for obtaining a vehicle-to-cloud communication security certificate on the basis of applying for a PKI certificate on the production line. Each time the vehicle is started, a certificate service running in the background is awakened to check the validity of the certificate; if the certificate is abnormal, the certificate application process is automatically triggered based on the network status of the vehicle, and after the certificate application is successful and imported into the vehicle, the service program is automatically stopped without taking up too much memory consumption.

[0042] In an exemplary embodiment, Figure 2 As shown, a method for obtaining a vehicle-cloud communication security certificate is provided, and the method is applied to Figure 1The vehicle 101 in the example is used for explanation. More specifically, it can be applied to a vehicle operating system, a vehicle computer, etc. The vehicle computer is the abbreviation of a vehicle infotainment product or system installed in a car. The vehicle computer can realize information communication between people and cars, and between cars and the outside world. The method specifically includes the following steps S201 to S205:

[0043] Step S201: monitoring the vehicle's power-on broadcast message based on a pre-registered broadcast receiver; when the broadcast receiver monitors the power-on broadcast message, starting a pre-set certificate service based on a callback method overwritten in the broadcast receiver.

[0044] Among them, the broadcast receiver can be a message-type component, whose main function is to monitor and respond to broadcast messages sent by other components in the system or application. These messages can be system events (such as changes in battery power, changes in network status) or custom events (such as completion of in-application data download), etc. Specifically in this embodiment, the message here can be a vehicle startup broadcast message. The vehicle startup broadcast message is a broadcast message indicating that the vehicle has changed from a non-working state to a working state. For the vehicle to change from a non-working state to a working state, for example, it can be but not limited to the vehicle engine ignition start, the vehicle drive motor is powered on, the air conditioner in the car is started, the body anti-theft system is unlocked, the continuous damping control system (CDC, Continuous Damping Control), the vehicle operating system is started, the vehicle cloud communication module is started, etc., and the vehicle computer can also be started.

[0045] Among them, the callback method is a function or method contained in the broadcast receiver. Its principle is that when a certain event occurs, a function or method is called by another function or method. Correspondingly, the receiving callback method is the callback method when the broadcast receiver receives the power-on broadcast message.

[0046] Among them, certificate services, that is, services related to vehicle-cloud communication security certificates, can be understood in a broad sense. Certificate services can include subsequent steps and methods such as determining whether the certificate is valid, polling network connection status, building a temporary communication channel for vehicle-cloud communication, sending certificate requests to the cloud, and receiving certificate information returned by the cloud.

[0047] Among them, the vehicle-cloud communication security certificate is the security certificate used to ensure the security of data transmission during the vehicle-cloud communication process. The security certificate is used to establish an encrypted connection and protect sensitive data from unauthorized access.

[0048] For example, when the vehicle is powered on, the vehicle computer can listen to the vehicle's power-on broadcast message through a pre-registered broadcast receiver. Due to the overridden receiving callback method in the broadcast receiver, when the broadcast receiver listens to the power-on broadcast message, it calls the pre-set certificate service, so that the preset certificate service can be automatically started every time the vehicle is turned on.

[0049] Step S202: When the certificate service is started, determine the current status of the certificate used for vehicle-to-cloud communication security in the vehicle.

[0050] Among them, the current status of the certificate can be understood as whether there is a valid vehicle-to-cloud communication security certificate in the vehicle. For example, the current status can be abnormal or normal. The abnormal current status can be used to indicate that the certificate may not be available, that is, the vehicle may not be able to establish a secure and stable vehicle-to-cloud communication channel through the certificate. On the contrary, if the current status is normal, it means that the certificate is available and a secure and stable vehicle-to-cloud communication channel can be established.

[0051] Exemplarily, when the certificate service is started, the current status of the certificate used for vehicle-to-cloud communication security in the vehicle can be determined, so that the next step can be taken based on whether the current status is abnormal or not.

[0052] Step S203: When it is determined that the current status of the certificate is abnormal, check the network connection status of the vehicle.

[0053] Polling means sending a request periodically to obtain the latest data or status update. Specifically, in this embodiment, it can be to obtain the latest vehicle network connection status. The vehicle network connection status is used to indicate whether the vehicle can access the Internet. The network connection status may include whether the network connection is valid or invalid.

[0054] For example, if it is determined that there is an abnormality in the current status of the certificate, the vehicle's network connection status can be polled, so that the next step can be taken according to the vehicle's network connection status.

[0055] Step S204: When the vehicle's network connection is valid, a temporary communication channel for vehicle-to-cloud communication is established based on the temporary certificate file and the temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and the certificate information returned by the cloud is received; the scope of the temporary certificate file and the temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate.

[0056] Among them, a temporary certificate file is a file containing public key information and public key owner information, which is used to verify the identity of a user or service within a specific time period. The temporary private key corresponds to the temporary certificate file, which is a private key used to encrypt and decrypt data and is used together with the temporary certificate file. The temporary certificate file and the temporary private key are used to obtain temporary authorization to access protected resources, such as cloud storage services. Specifically, in this embodiment, it can be resources related to the vehicle-cloud communication security certificate. The validity period of the temporary certificate file and the temporary private key is limited, for example, it can be between 30 minutes and 36 hours, which reduces the risk of information leakage, because even if the temporary key is leaked, the attacker can only use it within a limited time. The certificate information returned by the cloud is the relevant information returned by the cloud to the vehicle in response to the certificate request it received from the vehicle.

[0057] For example, if it is determined that there is an abnormality in the certificate and the vehicle's network connection is valid, a temporary communication channel for vehicle-to-cloud communication can be constructed based on the pre-saved temporary certificate file and temporary private key. Through the temporary communication channel, a certificate request can be sent to the cloud, that is, to apply for an available vehicle-to-cloud communication security certificate, and the certificate information returned by the cloud can be received. The scope of application of the temporary certificate file and temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate.

[0058] Step S205: Save the certificate information to the target path for use in vehicle-cloud communication.

[0059] Among them, the target path is the storage path used to store the vehicle-to-cloud communication security certificate file. Through the target path, the information related to the vehicle-to-cloud communication security certificate can be accessed, modified, deleted, replaced, saved, and other operations can be performed.

[0060] Exemplarily, after the aforementioned steps and receiving the certificate information, the certificate information can be automatically saved to the target path. When vehicle-cloud communication is required, the certificate information can be called according to the target path to achieve secure and stable communication between the vehicle and the cloud.

[0061] In this embodiment, by monitoring the vehicle's startup broadcast message according to the pre-registered broadcast receiver, it is realized that when the vehicle is started, the certificate service is called to determine the current status of the certificate used for vehicle-to-cloud communication security in the vehicle. If the current status is abnormal and the network connection is valid, a temporary communication channel for vehicle-to-cloud communication is constructed through a temporary certificate file and a temporary private key, and a certificate request is sent to the cloud through the temporary communication channel to obtain certificate information, and the certificate information is saved to the target path for vehicle-to-cloud communication. This realizes that every time the vehicle is started, the vehicle-to-cloud communication security certificate in the vehicle can be determined and an available vehicle-to-cloud communication security certificate can be provided, avoiding the vehicle-to-cloud communication being affected by factors such as the unavailability of the vehicle-to-cloud communication security certificate, that is, it is ensured that when vehicle-to-cloud communication is needed, there is an available vehicle-to-cloud communication security certificate in the vehicle, thereby ensuring the security and stability of vehicle-to-cloud communication. At the same time, through a temporary certificate file and a temporary private key, a temporary communication channel is constructed to facilitate the application for an available vehicle-to-cloud communication security certificate to the cloud, thereby ensuring that before obtaining a formal certificate, the vehicle can apply for a certificate from the cloud through a temporary communication channel.

[0062] In one of the embodiments, "determining the current status of the certificate used for vehicle-to-cloud communication security in the vehicle" in the aforementioned embodiment may include: checking whether there is a certificate file used for vehicle-to-cloud communication security in the target path; if there is a certificate file in the target path, determining the certificate validity period corresponding to the certificate file based on reading the certificate file, and determining whether the certificate is expired based on the certificate validity period and the current time; if it is checked that there is no certificate file in the target path and / or the certificate has expired, determining that there is an abnormality in the current status of the certificate.

[0063] Among them, the certificate file is the specific data file corresponding to the certificate used for vehicle-cloud communication security; the certificate validity period is the period during which the certificate used for vehicle-cloud communication security is available, which may include the number of days the certificate is available, such as 30 days, 100 days, 150 days, etc., and may also include the last available time of the certificate, etc.

[0064] Exemplarily, to determine the current status of the certificate used for vehicle-to-cloud communication security in the vehicle, it is possible to first check whether there is a certificate file used for vehicle-to-cloud communication security in the target path. If so, the certificate file can be read to determine the validity period of the certificate corresponding to the certificate file. Then, determine whether the certificate is expired based on the certificate validity period and the current time. For example, if the current time is after the certificate validity period, it means that the certificate has expired. If the current time is within the certificate validity period, it means that the certificate has not expired. Furthermore, if at least one of the following conditions is met, the current status of the certificate can be determined as abnormal: Case 1, it is checked that there is no certificate in the target path; Case 2, the certificate has expired.

[0065] In this embodiment, the current status of the certificate used for vehicle-to-cloud communication security in the vehicle is comprehensively determined by checking whether there is a certificate file used for vehicle-to-cloud communication security in the target path and determining whether the certificate is expired. This helps to obtain a more accurate current status of the certificate, which in turn helps to ensure the provision of an available vehicle-to-cloud communication security certificate and avoid anomalies in the vehicle-to-cloud communication security certificate that affect the security and stability of the vehicle-to-cloud communication.

[0066] In one of the embodiments, "checking the vehicle's network connection status" in the aforementioned embodiment may include: based on a timing cycle of a preset timer, obtaining the vehicle's current active network and current network capability information at intervals; based on the current active network and current network capability information, checking whether the vehicle's network has Internet connection capabilities and whether it has been verified; and determining that the vehicle's network connection is valid if it is checked that the vehicle's network has Internet connection capabilities and has been verified.

[0067] Among them, the preset timer, i.e., a pre-set component, unit, or module for timing, etc., can be a countdown or countup, etc., and the timer can be provided with a timing cycle, and the timing cycle can have a large cycle and a small cycle, for example, every 10 seconds can be a small cycle, and every 10 small cycles can be a large cycle, i.e., 100 seconds. The current active network, i.e., the network to which the vehicle is currently connected. For example, the vehicle is currently connected to a WIFI named ABC; the current network capability information, i.e., the capability information of the network to which the vehicle is currently connected, for example, whether it can access the Internet, the maximum download speed and upload speed allowed, etc. It has Internet connection capability (NET_CAPABILITY_INTERNET), i.e., it can theoretically provide access to the public Internet; it has been verified (NET_CAPABILITY_VALIDATED), indicating that the network not only claims to support Internet connection, but has also been tested by the system and confirmed that it can indeed access the Internet.

[0068] Exemplarily, the following method can be used to poll the vehicle's network connection status: obtain the vehicle's current active network and current network capability information at intervals through a preset timer timing cycle, for example, obtain the vehicle's current active network and current network capability information every 2 seconds, and obtain five times in one cycle. Further, if the vehicle's current active network and current network capability information are obtained within one cycle, indicating that the vehicle's network connection is valid, then stop obtaining, that is, stop polling; otherwise, the next cycle can be started. After obtaining the vehicle's current active network and current network capability information, it can be checked whether the vehicle's network has Internet connection capabilities and whether it has been verified based on the current active network and current network capability information; if it is checked that the vehicle's network has Internet connection capabilities and has been verified, it can be determined that the vehicle's network connection is valid.

[0069] In this embodiment, the current active network and current network capability information of the vehicle are obtained through the timing cycle, and based on the obtained current active network and current network capability information, the vehicle's network is checked to see whether it has Internet connection capability and whether it has been verified, so as to determine whether the vehicle's network connection is valid. This helps to obtain the vehicle's network connection status more accurately and efficiently, thereby serving the subsequent steps of sending a certificate request to the cloud and receiving the certificate information returned by the cloud, which helps to provide an available vehicle-to-cloud communication certificate as soon as the vehicle is started, so as to ensure the security and stability of vehicle-to-cloud communication.

[0070] In one of the embodiments, the "sending a certificate request to the cloud based on a temporary communication channel" in the aforementioned embodiment may include: constructing a certificate request for applying for a vehicle-cloud communication security certificate; the variable name in the certificate request corresponds to the key value used to store the vehicle-cloud communication security certificate in the cloud; based on an observable data container, sending a certificate request to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued.

[0071] Among them, the certificate request, that is, the request for applying for a vehicle-cloud communication security certificate, may include two parts: the request object and the parameters corresponding to the request object. The request object may include, but is not limited to, geographic categories, such as country, region, province, city, etc., subject categories, such as the organization to which the applicant belongs, the applicant's contact email, etc., public key, and other optional attributes; accordingly, the parameters corresponding to the request object may be specific information, for example, the code and name corresponding to a specific country, region, province, city, etc., and the organization name specifically described by the applicant is A unit, etc. Variable name, that is, the name used to represent the variable. Key value, that is, key value, Key-Value. An observable data container is a special class that can package data so that when the data changes, it can automatically notify all observers. This container usually has lifecycle awareness, which means that it can decide when to update the observer based on the lifecycle status of other application components. Network request result monitoring, that is, after sending a certificate request to the cloud, monitor the result returned by the cloud for the certificate request.

[0072] Exemplarily, a certificate request for applying for a vehicle-cloud communication security certificate can be constructed, specifically by setting a request object and setting corresponding parameters, and the variable name in the constructed certificate request corresponds to the key value used to store the vehicle-cloud communication security certificate in the cloud. The variable name in the certificate request corresponds to the key value used to store the vehicle-cloud communication security certificate in the cloud. This is because the certificate request is a request class for json data, and the information related to the vehicle-cloud communication security certificate stored in the cloud is json data. json, namely JSON, JavaScript Object Notation, JS object tag, is a lightweight data exchange format. json data is a collection of key-value pairs. Then, you can use the observable data container to send a certificate request to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued.

[0073] It should be pointed out that the certificate request is sent to the cloud through the temporary communication channel. The cloud here can be a cloud specifically responsible for the vehicle-cloud communication security certificate, or it can be a cloud with other functions. The cloud here can be the same as or different from the cloud for vehicle-cloud communication.

[0074] In this embodiment, a certificate request for applying for a vehicle-to-cloud communication security certificate is constructed; based on an observable data container, a certificate request is sent to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued. That is, a specific implementation method for sending a certificate request to the cloud based on a temporary communication channel is provided. At the same time, since the variable name in the certificate request corresponds to the key value used to store the vehicle-to-cloud communication security certificate in the cloud, it is possible to accurately obtain the required data, that is, the certificate information, and avoid affecting the acquisition of certificate information due to inconsistent formats and names. By using an observable data container to implement network request result monitoring, it serves the subsequent development of related steps such as receiving the certificate information returned by the cloud, and then serves to provide an available vehicle-to-cloud communication security certificate as soon as the vehicle is started to ensure the security and stability of the vehicle-to-cloud communication.

[0075] In one of the embodiments, after sending a certificate request to the cloud through a temporary communication channel based on an observable data container to automatically trigger network request result monitoring after the certificate request is issued, the method for obtaining the vehicle-cloud communication security certificate in the aforementioned embodiment also includes: based on the observation of the data container, monitoring whether the certificate information returned by the cloud is received; if the certificate information is received, verifying the validity of the certificate information; the "saving the certificate information to the target path" in the aforementioned embodiment may include: if the certificate information is valid, saving the certificate information to the target path.

[0076] The certificate information refers to the information related to the vehicle-to-cloud communication security certificate returned by the cloud in response to the certificate request. The certificate information returned by the cloud may include a real and valid vehicle-to-cloud communication security certificate, or may be a null value, or may be an invalid vehicle-to-cloud communication security certificate, or other information.

[0077] Exemplarily, through the observable data container in the aforementioned step, it is possible to monitor whether the certificate information returned by the cloud is received. In the case where the certificate information is confirmed to be received through monitoring, since the certificate information may be invalid as mentioned above, it is necessary to verify the validity of the certificate information. If the verification is passed, that is, the certificate information is valid, the certificate information can be saved to the target path.

[0078] In this embodiment, by monitoring whether the certificate information returned by the cloud is received, when the certificate information is received, the certificate information is verified to ensure that the certificate information is authentic and valid, and the valid certificate information is saved to the target path. This makes the vehicle-to-cloud communication security certificate used by the vehicle available, that is, it avoids the situation where the certificate information returned by the cloud has null values, invalid certificates, etc., which affects the vehicle-to-cloud communication based on the certificate information, that is, it helps to ensure that the provided vehicle-to-cloud communication security certificate is available and does not affect the security and stability of vehicle-to-cloud communication.

[0079] In one of the embodiments, the temporary certificate file and the temporary private key are used by vehicles in the same production batch; the method for obtaining the vehicle-cloud communication security certificate in the aforementioned embodiment also includes: when the vehicle system is updated, the temporary certificate file and the temporary private key are synchronously updated.

[0080] Among them, the system update can be an update of the entire system, or an update of a part of the system or subsystem; updating the temporary certificate file and the temporary private key can be updating the temporary certificate file and the temporary private key at the same time, or updating the temporary certificate file and the temporary private key separately in a certain order, such as chronological order.

[0081] For example, the temporary certificate file and temporary private key can be universal for the production batch corresponding to the vehicle. The temporary certificate file and temporary private key can be a temporary security channel dedicated to building vehicle-to-cloud communication to serve the vehicle to apply for and obtain the vehicle-to-cloud communication security certificate from the cloud. After the vehicle obtains the certificate, the temporary certificate file and temporary private key can no longer be used. Therefore, vehicles in the same production batch can share the same temporary certificate file and temporary private key. At the same time, the temporary certificate file and temporary private key can be updated as the vehicle system is updated.

[0082] In this embodiment, since the temporary certificate file and the temporary private key can be common to the production batch corresponding to the vehicle, the number of temporary certificate files and temporary private keys required can be reduced, and the related management costs can be reduced. At the same time, the temporary certificate file and the temporary private key can be updated as the vehicle system is updated, so that the temporary certificate file and the temporary private key in the vehicle are in the latest state, and there is no need to specifically update the temporary certificate file and the temporary private key.

[0083] In one of the embodiments, the method for obtaining the vehicle-cloud communication security certificate in the aforementioned embodiment also includes: registering a broadcast receiver in an application configuration file in the vehicle; the broadcast receiver is set to listen to the vehicle's startup broadcast message; and rewriting the receiving callback method corresponding to the broadcast receiver to start the certificate service.

[0084] Among them, the application configuration file can be an AndroidManifest.xml file. Each application project corresponds to an AndroidManifest.xml file. As the root configuration file of the project source code set, it describes the necessary information about the application project. The application here can be the application corresponding to the broadcast receiver. The broadcast receiver, certificate service, and the method for obtaining the entire vehicle-to-cloud communication security certificate can correspond to the same application. The receiving callback method is the method that will be called when the broadcast receiver receives the power-on broadcast, for example, the onReceive method.

[0085] For example, to receive the vehicle system's power-on broadcast through a broadcast receiver, a broadcast receiver can be registered in the application configuration file in advance, and the broadcast receiver is set to listen to the vehicle's power-on broadcast message. Since the receiving callback method is rewritten to start the certificate service, if the broadcast receiver receives the power-on broadcast, the certificate service will be started.

[0086] In this embodiment, a broadcast receiver is registered in the application configuration file and the event of interest to the broadcast receiver, the vehicle's power-on broadcast message, is set. At the same time, the corresponding receiving callback method of the broadcast receiver is rewritten to start the certificate service. This enables the certificate service to be automatically started once the vehicle is turned on, thereby facilitating subsequent steps such as determining whether the certificate is valid, thereby helping to ensure that there is an available vehicle-to-cloud communication security certificate in the vehicle at the first possible time and avoid affecting vehicle-to-cloud security communications.

[0087] In an exemplary embodiment, a method for obtaining a vehicle-to-cloud communication security certificate is provided. The method is for a PKI certificate. For ease of understanding, the PKI is first described below:

[0088] PKI, also known as Public Key Infrastructure, is a basic framework for implementing authentication and encryption in a modern digital environment, and is used to protect the security of network communications. PKI uses an asymmetric encryption method, that is, a key pair is used to encrypt and decrypt data. The key pair contains a public key and a private key. The public key is public and can be distributed freely, while the private key is kept confidential. Anyone can use the public key to encrypt information, but only the holder of the private key can decrypt the information. So far, encryption has only solved half of the problem of secure communication. The other half of the problem is how to determine the true owner of the information. This is where another core component of PKI, the digital certificate, comes into play. The digital certificate itself is similar to an ID card. Its essence is an electronic document. This file usually contains the information of the authenticator, the information of the person being authenticated and the limited period, the verification method of all the above, etc., to ensure that the identity of the certificate holder is authentic and reliable. The process of using digital certificates to communicate is called authentication, which is usually divided into one-way authentication and two-way authentication. One-way authentication is for one party to confirm the identity, and two-way authentication is for both parties to confirm the identity of each other, such as Figure 3 As shown, a possible two-way authentication process is provided, which includes nine steps: the client sends an HTTPS connection establishment request, the server returns a certificate containing the server public key, the client obtains the server public key from the server certificate, and the client sends the certificate containing the client public key to the server.

[0089] At present, in cases where vehicles need to communicate with the cloud, PKI-related technologies can usually be used to ensure the security of vehicle-to-cloud communications. Under current technology, digital certificates are usually applied for during the vehicle's production line stage and uniformly imported into the vehicle's memory. This solution enables the operation of applying for a certificate to be completed before the vehicle goes offline, which to a certain extent guarantees the security of communication during the digital certificate application process. However, the application for a certificate in this solution is a one-time operation. If there is an abnormality with the certificate later, there is no automatic recovery method. Possible abnormalities include: certificate expiration, abnormal deletion of certificate files, etc. If the certificate is abnormal, some networking functions cannot be used normally, such as failure to log in to the owner's account or no response, which affects the stability of vehicle-to-cloud communications.

[0090] This embodiment proposes the above method based on applying for a PKI certificate for the production line. The method is described in detail below:

[0091] like Figure 4 As shown in the figure, the overall idea and steps of the method are provided: each time the vehicle computer is started, a PKI service program (i.e., PKIService) running in the background is awakened to check the validity of the certificate; if the certificate is abnormal, the network connection status is polled to detect, and when the network is connected, the certificate application process is automatically triggered; after the certificate application is successful and imported, the service program is automatically stopped to avoid excessive memory consumption.

[0092] Taking the Android system as an example, the specific instructions for the steps in the figure are as follows:

[0093] First, regarding the steps to implement the automatic startup of PKIService, the corresponding steps are "listening to the vehicle startup broadcast message based on the pre-registered broadcast receiver; when the broadcast receiver listens to the startup broadcast message, starting the pre-set certificate service based on the receiving callback method overwritten in the broadcast receiver" and other related contents. The details are as follows:

[0094] CDC is turned on, and then the vehicle system sends a boot broadcast, and the PKIService is started through the boot broadcast. The overall idea is: define a broadcast receiver (BootReceiver), which needs to be registered in AndroidManifest.xml to listen to the boot broadcast, and start PKIService in the onReceive callback method of this listener, so as to realize the boot-up self-start.

[0095] Among them, CDC is the car CDC (Continuous Damping Control) system, which is a continuous damping control system that can automatically adjust the damping of the shock absorber according to the road conditions and the vehicle's driving status to provide better ride comfort and handling stability. CDC startup, that is, the start of the CDC system, refers to the process in which its electronic control unit begins to monitor the vehicle status and control the shock absorber damping. This process is carried out automatically when the vehicle is ignited, without the need for manual operation by the user. AndroidManifest.xml is a key file in Android applications. It provides basic information about the application and defines the components, permissions, and other important settings of the application. The onReceive method is a core callback method of the broadcast receiver in Android. When the registered broadcast receiver matches the corresponding broadcast intent (Intent), the system automatically calls this method.

[0096] The following is a possible specific implementation method, including specific code and corresponding code comments. The code comments are after double slashes " / / ", and the same applies to the following:

[0097] The main code implementation of the BootReceiver class is as follows:

[0098] / / Set BootReceiver in the PKIService program to listen to the boot broadcast.

[0099] class BootReceiver:BroadcastReceiver(){

[0100] / / Handle received broadcast messages by overriding the onReceive method.

[0101] / / When the system sends out the boot completed broadcast (BOOT_COMPLETED), onReceive will be automatically called.

[0102] override fun onReceive(context: Context?, intent: Intent?) {

[0103] / / Create an Intent object startIntent to start the PKIService service.

[0104] val startIntent = Intent(context, PKIService::class.java)

[0105] / / Used to actually start the service, so that PKIService starts automatically after the device boots.

[0106] context?.startService(startIntent)

[0107] }

[0108] }

[0109] To enable BootReceiver to receive the boot broadcast, it is also necessary to register this broadcast receiver in the AndroidManifest.xml file. The relevant code is as follows:

[0110] <!-- Declare a broadcast receiver, specify the class name of the receiver, and set to listen for system broadcasts -->

[0111] <receiver android:name=".receiver.BootReceiver"

[0112] android:exported="true">

[0113] <!— Set to listen for the android.intent.action.BOOT_COMPLETED, i.e., the boot completed broadcast -->

[0114] <intent-filter>

[0115] <action android:name="android.intent.action.BOOT_COMPLETED" / >

[0116] / / BOOT_COMPLETED,

[0117]

[0118]

[0119] It is understandable that based on the implementation logic of the above specific implementation method, other languages ​​or codes can also be used to implement the same logic, and this application does not limit the implementation code and language.

[0120] Second, regarding the steps to implement certificate validity detection, this corresponds to "determining the current status of the certificate used for vehicle-to-cloud communication security in the vehicle when the certificate service is started" and other related content, as follows:

[0121] The general idea is to set the certificate validity judgment conditions and make judgments when PKIService starts. If all the judgment conditions are met, the certificate is considered valid; if any of the conditions are not met, the certificate is considered invalid. The judgment conditions are set specifically as to whether the certificate exists and whether the certificate has expired. The following provides a possible specific implementation method, including specific code and corresponding code comments:

[0122] / / First, define the total judgment function for direct calling. The validity of the certificate is judged by the function return value of true or false.

[0123] fun certValidCheck():Boolean{

[0124] / / If the following two test conditions are met at the same time, the certificate is considered valid.

[0125] / / All conditional results are ANDed so that the judgment conditions can be modified according to specific business.

[0126] return checkExitst() && checkExpried()

[0127] }

[0128] / / Check if the certificate file exists.

[0129] fun checkExists():Boolean{

[0130] / / certPath is the full path of the certificate file, which is customized according to project requirements and remains unchanged globally. The full path of a file refers to the complete path from the root directory of the file system to the location of the file. It includes all directory levels starting from the root directory and the final file name. The full path of the file ensures the uniqueness of the file in the file system, so that the file can be directly accessed through this path.

[0131] / / You can use the Java public File class exists method to determine whether the file exists.

[0132] return File(certPath).exists

[0133] }

[0134] / / Check if the certificate is expired

[0135] fun checkExpired():Boolean{

[0136] / / Get the certificate factory and define the certificate format to be read as X.509

[0137] val cf = CertificateFactory.getInstance("X.509")

[0138] / / Create a file reading stream and read from the full path of the certPath certificate

[0139] val in1 = FileInputStream(certPath)

[0140] / / Get the certificate from the file read stream and convert it into X.509 format for easy reading of information

[0141] val cert = cf.generateCertificate(in1) as X509Certificate

[0142] / / Get the certificate validity period

[0143] val notAfter = cert.notAfter / / Validity end time

[0144] val now = Date() / / Get the current date and time

[0145] / / Check if the certificate is expired

[0146] if(now.compareTo(notAfter)>0){

[0147] / / now is after notAfter, which means the certificate has expired

[0148] return false

[0149] }else{

[0150] return true

[0151] }

[0152] }

[0153] It is understandable that based on the implementation logic of the above specific implementation method, other languages ​​or codes can also be used to implement the same logic, and this application does not limit the implementation code and language.

[0154] Third, regarding the steps to implement network connection polling detection, the corresponding content here is "check the vehicle's network connection status when it is determined that the current status of the certificate is abnormal", as follows:

[0155] The general idea is: set a timer, and start timing when the certificate is invalid after the PKIService is started, set 1s as the interval, and perform network connection detection once a second. If the network is detected to be connected, stop polling and execute the certificate request; if the network is detected to be disconnected, continue polling. The following provides a possible specific implementation method, including specific code and corresponding code comments:

[0156] / / Use CountDownTimer to define a countdown timer.

[0157] / / Set the total time to 10*1000ms (i.e. 10s), with each interval being 1000ms (i.e. 1s).

[0158] val networkAvailableTimer = object :CountDownTimer(10*1000,1000){

[0159] / / The onTick method will be automatically executed every 1s, and the polling operation can be implemented by overriding the onTick method.

[0160] / / The onTick method is a callback method of the CountDownTimer class. When using CountDownTimer to implement the countdown function, the onTick method will be called every time the countdown is updated.

[0161] override fun onTick(p0: Long) {

[0162] / / Use the isConnectedAvailableNetwork method to determine the network connection. Both tbox and wifi networks can be determined by this method.

[0163] if (isConnectedAvailableNetwork(this@PKIService)){

[0164] / / If the network is connected, cancel the timing.

[0165] cancel()

[0166] / / Trigger automatic certificate application.

[0167] requestCert()

[0168] }

[0169] }

[0170] / / After the timer countdown ends, the onFinish method will be automatically executed and can be rewritten to restart the countdown.

[0171] override fun onFinish() { / / Execute when the timing ends.

[0172] / / Judge the network connection.

[0173] if (!isConnectedAvailableNetwork(this@PKIService)){

[0174] / / If the network is not connected, restart the timing.

[0175] start()

[0176] }

[0177] }

[0178] }

[0179] / / The following section expands on the implementation of the isConnectedAvailableNetwork method to determine network connectivity.

[0180] fun isConnectedAvailableNetwork(context: Context): Boolean {

[0181] / / Get network connection information through the ConnectivityManager service provided by Android.

[0182] val cm:ConnectivityManager =

[0183] context.getSystemService(Context.CONNECTIVITY_SERVICE) asConnectivityManager

[0184] / / Get the current active network, return true if there is one, otherwise return false.

[0185] val network: Network = cm.activeNetwork ?: return false

[0186] / / Get the current network capability information, if not, return false.

[0187] val capabilities: NetworkCapabilities =

[0188] cm.getNetworkCapabilities(network) ?: return false

[0189] / / Use the hasCapability method to check whether the network has Internet connection capability and whether it has been verified.

[0190] / / If both conditions are met, return true, indicating that the current network connection is available and can access the Internet.

[0191] / / Otherwise returns false, indicating that the current network is unavailable or the Internet cannot be accessed.

[0192] return (capabilities.hasCapability(NetworkCapabilities.NET_CAPABILITY_INTERNET)

[0193] && capabilities.hasCapability(NetworkCapabilities.NET_CAPABILITY_VALIDATED))

[0194] }

[0195] It is understandable that based on the implementation logic of the above specific implementation method, other languages ​​or codes can also be used to implement the same logic, and this application does not limit the implementation code and language.

[0196] The following content corresponds to "When the vehicle's network connection is valid, a temporary communication channel for vehicle-cloud communication is established based on the temporary certificate file and temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and the certificate information returned by the cloud is received; the scope of the temporary certificate file and temporary private key is the situation of applying for a vehicle-cloud communication security certificate; the certificate information is saved to the target path for use in vehicle-cloud communication" and other related content.

[0197] Fourth, the steps to implement the certificate application request:

[0198] The following is a possible specific implementation method, including specific code and corresponding code comments:

[0199] / / CertRequest is the request class corresponding to the cloud request json data, and the variable name in its object corresponds to the jsonkey value. This means that when parsing JSON data into Java objects, the key in JSON matches the field (variable) name in the Java object. This correspondence makes the parsing process more intuitive and efficient.

[0200] / / Used to store and manage certificate request (CertRequest) objects. By publishing the request object to LiveData, responsive processing of network requests can be achieved. LiveData is an observable data holder class that can notify observers when data changes. It has the following features: Lifecycle-aware LiveData automatically manages the lifecycle of the observer, ensuring that updates are sent only when the observer is active (such as STARTED or RESUMED); Safe data updates: LiveData ensures that data updates are always performed on the main thread, avoiding concurrency issues in a multi-threaded environment; Prevent memory leaks: Because LiveData is bound to the lifecycle, when the observer is no longer active, LiveData automatically removes the observer, thereby preventing memory leaks; Convertible data: LiveData supports data conversion using the Transformations class, such as the map() and switchMap() methods, which can provide new data views without changing the original LiveData.

[0201] val requestLiveData = MutableLiveData <certrequest>()

[0202] fun requestCert(){

[0203] / / Build a certificate application request and use LiveData to respond to the request.

[0204] requestLiveData.postValue(CertRequest())

[0205] }

[0206] val requestData = Transformations.switchMap(requestLiveData){certRequest->

[0207] / / Set the certRequest request parameters and execute the network request to apply for a certificate.

[0208] / / Before building a PKI certificate application request and sending it to the certificate authority, you need to set the parameters in the application request. These parameters are used to describe the identity information of the certificate holder and the usage scenario of the certificate, so that the CA can correctly issue the certificate and ensure that the applied certificate meets expectations and meets security requirements.

[0209] / / Repo is a network encapsulation class. The requestCert function sends a request and returns a server response.

[0210] Repo.requestCert(requestBody)

[0211] }

[0212] / / When the service is created, initialize the certificate request and return the listener.

[0213] / / If the request returns, it will automatically respond to subsequent operations such as certificate import.

[0214] fun initRequestCertObserve(){ / / Monitor by observing the changes of livedata.

[0215] requestData.observe(this@PKIService){result->

[0216] / / Get the reply response.

[0217] / / The observe method is a key method of LiveData, which is used to register observers to monitor data changes of LiveData objects. When the value of the LiveData object changes, the registered observer will receive a notification and perform corresponding operations in its callback method.

[0218] val response = result.getOrNull()

[0219] / / getOrNull() is used to safely get a value. If the specified key does not exist in the map, it returns null instead of throwing an exception.

[0220] if(response!=null && response.status ==true){

[0221] / / Certificate application is successful, import the certificate.

[0222] }

[0223] }

[0224] }

[0225] In addition to the above descriptions of the steps in the figure, PKIService also needs to have a built-in temporary certificate file and a temporary private key, which are updated in real time with system updates to ensure their validity. The temporary certificate is only used to establish a secure communication channel with the cloud when applying for a certificate, thereby ensuring the security of automatic certificate application. The temporary certificate and temporary private key are universal certificates for the same batch of car computers, which can establish a secure communication channel with the cloud, but are only used for certificate application. Non-temporary certificates (collectively referred to as formal certificates) are obtained in the certificate application step, which contains car computer equipment information, so they are only used to establish a secure communication channel between the current car computer and the cloud, that is, for other app networking functions. The method for establishing a secure communication channel between the temporary certificate and the formal certificate and the cloud can be basically the same. The following is a possible implementation method:

[0226] Use OkHttp to establish a connection with the cloud. When establishing the OkHttp builder, you can set the certificate chain information through the builder.sslSocketFactory method. The certificate chain information here can be imported through KeyManagerFactory and TrustManagerFactory to generate objects with certificate and private key files, and then use them as parameters to establish the OkHttpp builder, and then create an OkHttp Client. Through this Client, communication with the cloud is completed to achieve secure communication using certificates.

[0227] Among them, OkHttp is a network request framework used in Android development. SSLSocketFactory is a factory class in Java for creating SSL / TLS secure sockets. It allows applications to communicate securely through SSL or TLS protocols, and is usually used for HTTPS connections. KeyManagerFactory and TrustManagerFactory are two important factory classes in Java for handling SSL / TLS certificate and key management. They are responsible for managing and verifying the identity authentication of the client and server, respectively. Specifically, KeyManagerFactory is used to create KeyManager objects, which manage the client's identity authentication information, that is, how the client proves its identity to the server; TrustManagerFactory is used to create TrustManager objects, which manage the list of trusted certificates to verify whether the certificate provided by the server is credible. TrustManager decides whether to accept the certificate from the server and ensures that the certificate is issued by a trusted CA (certificate authority).

[0228] It is understandable that based on the implementation logic of the above specific implementation method, other languages ​​or codes can also be used to implement the same logic, and this application does not limit the implementation code and language.

[0229] In general, the above method provided in this embodiment can be used in a variety of scenarios. It does not have to be used alone in the scenario of abnormal certificate recovery. It can also be used in other scenarios. For example, if the vehicle system needs to be upgraded from a version without PKI to a version with PKI, it is necessary to obtain a PKI certificate outside the production line. In this case, the PKIService service can be used directly to automatically apply for the certificate after the system is upgraded.

[0230] In this embodiment, the PKI certificate application has a higher fault tolerance rate. Each time the vehicle computer starts to connect to the Internet, it can automatically detect the certificate status, automatically apply for the certificate, and automatically resolve certificate anomalies. This increases the fault tolerance rate of the PKI certificate application service, ensures the normal use of the vehicle computer networking function, maintains the security of the vehicle-cloud communication, and also ensures the normal use of the vehicle networking function.

[0231] By registering a broadcast receiver in the application configuration file and setting the event of interest to the broadcast receiver - the vehicle's startup broadcast message, and rewriting the corresponding receiving callback method of the broadcast receiver to start the certificate service, the certificate service can be automatically started once the vehicle is turned on to determine the current status of the certificate used for vehicle-to-cloud communication security in the vehicle. The current status of the certificate used for vehicle-to-cloud communication security in the vehicle is comprehensively determined by checking whether there is a certificate file used for vehicle-to-cloud communication security in the target path and determining whether the certificate is expired. This helps to obtain a more accurate current status of the certificate. If the current status is abnormal, the vehicle's network connection is polled. The current active network and current network capability information of the vehicle are obtained through the timing cycle of the timer, and based on the obtained current active network and current network capability information, the vehicle's network is checked to see whether it has Internet connection capabilities and whether it has been verified to determine whether the vehicle's network connection is valid. This helps to obtain the vehicle's network connection status more accurately and efficiently. If the network connection is valid, a temporary communication channel for vehicle-to-cloud communication is constructed through a temporary certificate file and a temporary private key. Since the temporary certificate file and the temporary private key can be universal for the production batch corresponding to the vehicle, the number of temporary certificate files and temporary private keys required can be reduced, and the related management costs can be reduced. At the same time, the temporary certificate file and the temporary private key can be updated as the vehicle system is updated, which makes the temporary certificate file and the temporary private key in the vehicle in the latest state and does not need to be updated specifically. Send a certificate request to the cloud through a temporary communication channel to obtain certificate information. Among them, by constructing a certificate request for a vehicle-cloud communication security certificate application, and based on an observable data container, a certificate request is sent to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued. Since the variable name in the certificate request corresponds to the key value used to store the vehicle-cloud communication security certificate in the cloud, it is possible to accurately obtain the required data, that is, the certificate information, and avoid affecting the acquisition of certificate information due to inconsistent formats and names. By using an observable data container to implement network request result monitoring, monitor whether the certificate information returned by the cloud is received, and when the certificate information is received, verify the certificate information to ensure that the certificate information is true and valid, and save the valid certificate information to the target path. This makes the vehicle-to-cloud communication security certificate used by the vehicle available, avoiding situations where the certificate information returned by the cloud contains empty values, invalid certificates, etc., which may affect the vehicle's vehicle-to-cloud communication based on the certificate information. This helps ensure that the provided vehicle-to-cloud communication security certificate is available and does not affect the security and stability of the vehicle-to-cloud communication.This ensures that each time the vehicle is started, the status of the vehicle-to-cloud communication security certificate in the vehicle can be determined and an available vehicle-to-cloud communication security certificate can be provided, avoiding the impact on vehicle-to-cloud communication due to factors such as the unavailability of the vehicle-to-cloud communication security certificate. This ensures that when vehicle-to-cloud communication is needed, there is an available vehicle-to-cloud communication security certificate in the vehicle, thereby ensuring the security and stability of vehicle-to-cloud communication.

[0232] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.

[0233] Based on the same inventive concept, the embodiment of the present application also provides a vehicle-to-cloud communication security certificate acquisition device for implementing the vehicle-to-cloud communication security certificate acquisition method involved above. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above method, so the specific limitations in one or more vehicle-to-cloud communication security certificate acquisition device embodiments provided below can refer to the limitations of the vehicle-to-cloud communication security certificate acquisition method above, and will not be repeated here.

[0234] In an exemplary embodiment, Figure 5 As shown, a vehicle-to-cloud communication security certificate acquisition device 500 is provided, comprising:

[0235] The monitoring module 501 is used to monitor the vehicle startup broadcast message based on the pre-registered broadcast receiver; when the broadcast receiver monitors the startup broadcast message, the pre-set certificate service is started based on the receiving callback method overwritten in the broadcast receiver;

[0236] A determination module 502, configured to determine the current status of a certificate used for vehicle-to-cloud communication security in the vehicle when the certificate service is started;

[0237] Acquisition module 503 is used to check the vehicle's network connection status when it is determined that there is an abnormality in the current status of the certificate; when the vehicle's network connection is valid, build a temporary communication channel for vehicle-cloud communication based on the temporary certificate file and the temporary private key; based on the temporary communication channel, send a certificate request to the cloud and receive the certificate information returned by the cloud; the scope of application of the temporary certificate file and the temporary private key is the situation of applying for a vehicle-cloud communication security certificate; save the certificate information to the target path for use in vehicle-cloud communication.

[0238] Based on the vehicle-to-cloud communication security certificate acquisition device 500 of the above embodiment, the monitoring module 501 monitors the vehicle's startup broadcast message according to the pre-registered broadcast receiver, so that the certificate service is called when the vehicle is started. When the monitoring module 501 starts the certificate service, the determination module 502 determines the current status of the certificate used for vehicle-to-cloud communication security in the vehicle. If the determination module 502 determines that the current status of the certificate is abnormal, the acquisition module 503 detects whether the network connection is valid. If it is valid, the acquisition module 503 constructs a temporary communication channel for vehicle-to-cloud communication through a temporary certificate file and a temporary private key, sends a certificate request to the cloud through the temporary communication channel to obtain certificate information, and saves the certificate information to the target path for vehicle-to-cloud communication. This realizes that every time the vehicle is started, the vehicle-to-cloud communication security certificate in the vehicle can be determined and an available vehicle-to-cloud communication security certificate can be provided, avoiding the vehicle-to-cloud communication being affected by factors such as the unavailability of the vehicle-to-cloud communication security certificate, that is, it is ensured that when vehicle-to-cloud communication is needed, there is an available vehicle-to-cloud communication security certificate in the vehicle, thereby ensuring the security and stability of vehicle-to-cloud communication. At the same time, a temporary communication channel is constructed through temporary certificate files and temporary private keys to facilitate the application for an available vehicle-cloud communication security certificate from the cloud, thereby ensuring that the vehicle can apply for a certificate from the cloud through a temporary communication channel before obtaining a formal certificate.

[0239] In one of the embodiments, the determination module 502 is also used to check whether there is a certificate file for vehicle-cloud communication security in the target path; if there is a certificate file in the target path, based on reading the certificate file, the certificate validity period corresponding to the certificate file is determined, and based on the certificate validity period and the current time, whether the certificate is expired is determined; if it is checked that there is no certificate in the target path and / or the certificate has expired, it is determined that there is an abnormality in the current status of the certificate.

[0240] In one of the embodiments, the acquisition module 503 is also used to obtain the vehicle's current active network and current network capability information at intervals based on a timing cycle of a preset timer; based on the current active network and current network capability information, check whether the vehicle's network has Internet connection capabilities and whether it has been verified; if it is checked that the vehicle's network has Internet connection capabilities and has been verified, determine that the vehicle's network connection is valid.

[0241] In one of the embodiments, the acquisition module 503 is also used to construct a certificate request for applying for a vehicle-cloud communication security certificate; the variable name in the certificate request corresponds to the key value used to store the vehicle-cloud communication security certificate in the cloud; based on an observable data container, the certificate request is sent to the cloud through a temporary communication channel to automatically trigger network request result monitoring after the certificate request is issued.

[0242] In one of the embodiments, the acquisition module 503 is also used to send a certificate request to the cloud through a temporary communication channel based on an observable data container, so as to automatically trigger network request result monitoring after the certificate request is issued, and then monitor whether the certificate information returned by the cloud is received based on the observation of the data container; if the certificate information is received, verify the validity of the certificate information; if the certificate information is valid, save the certificate information to the target path.

[0243] In one of the embodiments, the temporary certificate file and the temporary private key are common to the production batch corresponding to the vehicle; the acquisition module 503 is also used to update the temporary certificate file and the temporary private key when the vehicle is undergoing a system update.

[0244] In one of the embodiments, the monitoring module 501 is also used to register a broadcast receiver in an application configuration file; the broadcast receiver is configured to monitor the vehicle's startup broadcast message; and the receiving callback method corresponding to the broadcast receiver is rewritten to start the certificate service.

[0245] Each module in the above-mentioned vehicle-to-cloud communication security certificate acquisition device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above-mentioned modules can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.

[0246] In an exemplary embodiment, a new energy vehicle is provided. The new energy vehicle may be a terminal, and its internal structure diagram may be as follows: Figure 6 As shown. The new energy vehicle includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the new energy vehicle is used to provide computing and control capabilities. The memory of the new energy vehicle includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the new energy vehicle is used to exchange information between the processor and the external device. The communication interface of the new energy vehicle is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (Near Field Communication, NFC) or other technologies. When the computer program is executed by the processor, a method for obtaining a vehicle-cloud communication security certificate is implemented. The display unit of the new energy vehicle is used to form a visually visible picture, which can be a display screen, a projection device or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the new energy vehicle can be a touch layer covering the display screen, or a button, trackball or touchpad set on the new energy vehicle, or an external keyboard, touchpad or mouse.

[0247] Those skilled in the art will understand that Figure 6 The structure shown in the figure is only a block diagram of a part of the structure related to the scheme of the present application, and does not constitute a limitation on the new energy vehicle to which the scheme of the present application is applied. A specific new energy vehicle may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0248] In one embodiment, a new energy vehicle is also provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.

[0249] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0250] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0251] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.

[0252] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.

[0253] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.< / certrequest>

Claims

1. A method for obtaining a vehicle-cloud communication security certificate, characterized in that: The method comprises: Listen to the vehicle's power-on broadcast message based on a pre-registered broadcast receiver; When the broadcast receiver monitors the power-on broadcast message, starting a pre-set certificate service based on the receiving callback method overwritten in the broadcast receiver; In the case where the certificate service is started, determining a current status of a certificate in the vehicle for vehicle-to-cloud communication security; In the case where it is determined that there is an abnormality in the current status of the certificate, checking the network connection status of the vehicle; When the network connection of the vehicle is valid, a temporary communication channel for vehicle-to-cloud communication is established based on the temporary certificate file and the temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and certificate information returned by the cloud is received; the scope of application of the temporary certificate file and the temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate; The certificate information is saved to the target path for use in vehicle-cloud communication.

2. The method according to claim 1, characterized in that The determining a current status of a certificate in the vehicle for vehicle-to-cloud communication security includes: Check whether there is a certificate file for vehicle-to-cloud communication security in the target path; In the case where the certificate file exists in the target path, determining the validity period of the certificate corresponding to the certificate file based on reading the certificate file, and determining whether the certificate is expired based on the validity period of the certificate and the current time; When it is detected that the certificate file does not exist in the target path and / or the certificate has expired, it is determined that there is an abnormality in the current state of the certificate.

3. The method according to claim 1, characterized in that The checking of the network connection status of the vehicle includes: Based on a timing cycle of a preset timer, obtaining the current active network and current network capability information of the vehicle at intervals; Checking, based on the current active network and the current network capability information, whether the network of the vehicle has Internet connection capability and whether it has been verified; When it is checked that the network of the vehicle has Internet connection capability and is verified, it is determined that the network connection of the vehicle is valid.

4. The method according to claim 1, characterized in that The sending a certificate request to the cloud based on the temporary communication channel includes: Constructing a certificate request for applying for a vehicle-to-cloud communication security certificate; the variable name in the certificate request corresponds to the key value used to store the vehicle-to-cloud communication security certificate in the cloud; Based on the observable data container, the certificate request is sent to the cloud through the temporary communication channel to automatically trigger network request result monitoring after the certificate request is sent.

5. The method according to claim 4, characterized in that After sending the certificate request to the cloud through the temporary communication channel based on the observable data container, the method further includes: Based on the observation of the data container, monitoring whether the certificate information returned by the cloud is received; Upon receiving the certificate information, verifying the validity of the certificate information; The step of saving the certificate information to a target path includes: When the certificate information is valid, the certificate information is saved to the target path.

6. The method according to any one of claims 1 to 5, characterized in that The temporary certificate file and the temporary private key are common to vehicles of the same production batch; The method further comprises: When the vehicle system is updated, the temporary certificate file and the temporary private key are updated synchronously.

7. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Registering the broadcast receiver in an application configuration file of the vehicle; the broadcast receiver is configured to monitor a startup broadcast message of the vehicle; The receiving callback method corresponding to the broadcast receiver is rewritten to start the certificate service.

8. A vehicle-to-cloud communication security certificate acquisition device, characterized in that: The device comprises: A monitoring module, used for monitoring a vehicle startup broadcast message based on a pre-registered broadcast receiver; when the broadcast receiver monitors the startup broadcast message, starting a pre-set certificate service based on a receiving callback method overwritten in the broadcast receiver; a determination module, configured to determine a current status of a certificate used for vehicle-to-cloud communication security in the vehicle when the certificate service is started; An acquisition module is used to poll the network connection status of the vehicle when it is determined that there is an abnormality in the current status of the certificate; when the network connection of the vehicle is valid, a temporary communication channel for vehicle-to-cloud communication is established based on a temporary certificate file and a temporary private key; based on the temporary communication channel, a certificate request is sent to the cloud, and certificate information returned by the cloud is received; the scope of application of the temporary certificate file and the temporary private key is the situation of applying for a vehicle-to-cloud communication security certificate; and the certificate information is saved to a target path for use in vehicle-to-cloud communication.

9. A new energy vehicle, comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Communication authentication method and device, electronic equipment and storage medium

    CN114666112A

  • Certificate issuing method and device

    CN115514497A

  • Vehicle ECU digital certificate application method and system

    CN116094730A

  • Vehicle Certificate Application Method, Vehicle-Mounted Device, and Roadside Unit

    US20230155813A1