Bus data transmission method, device, equipment and medium
By using a public key encryption algorithm to encrypt the target key in the CAN bus network, and combining invalid data insertion rules and symmetric encryption algorithms to group and encrypt the data, the problems of key leakage and low data security in the CAN bus network are solved, achieving higher data transmission security.
Patent Information
- Application Number
- CN202510237505.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-27
AI Technical Summary
In an open network environment, the broadcasting characteristics of the CAN bus enable every node in the network to receive message information on the bus. Attackers can access sensitive data, or even tamper with data, thereby posing a serious threat to the vehicle's control system. In existing encryption technology, keys are transmitted on the bus in plain text, which are easily intercepted by attackers, resulting in key leakage and seriously threatening data security.
The target key of the preset symmetric encryption algorithm is encrypted by using the public key encryption algorithm, and the encrypted key is sent to the data receiving node, and the target key is obtained by decrypting the private key of the data receiving node. At the same time, the data to be transmitted is grouped and invalid data filled based on the preset invalid data insertion rules, and the invalid data insertion rules and each packet data are encrypted using the preset symmetric encryption algorithm, encrypting and transmitting keys and data separately.
Improve the security of key transmission on the bus, reduce the risk of data being deciphered due to key leakage, and enhance the security of the system by separately encrypting and transmitting the key and data, preventing attackers from decrypting complete and valid data by obtaining part of the data.
Smart Images

Figure CN120050107A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data transmission, and particularly relates to a bus data transmission method, device, equipment and medium. Background Art
[0002] The CAN (Controller Area Network) bus has characteristics such as high reliability, convenient connection, and strong real-time performance, and is widely used in automotive electronic control systems. The broadcast characteristic of the CAN bus enables each node in the network to receive the message information on the bus. Although this characteristic can effectively improve communication efficiency in a traditional closed network environment, in an open network environment, this characteristic also provides a convenient attack path for attackers. Attackers can obtain sensitive data and even tamper with data by listening to the message information on the bus, thus posing a serious threat to the vehicle's control system.
[0003] In related CAN bus encryption technologies, a common solution is to use the AES (Advanced Encryption Standard) algorithm to encrypt data. After receiving the encrypted data, the receiving node decrypts and verifies it to ensure the effectiveness and security of data transmission. However, in this solution, although the data is transmitted in ciphertext, the corresponding key is transmitted in plaintext on the bus, which is easily intercepted by attackers, resulting in key leakage. Once the key is leaked, attackers can obtain the original data by decrypting, seriously threatening data security.
[0004] In summary, how to further ensure the security of data transmission on the bus is a problem to be solved at present. Summary of the Invention
[0005] In view of this, the purpose of the present invention is to provide a bus data transmission method, device, equipment and medium, which can further ensure the security of data transmission on the bus. The specific solutions are as follows:
[0006] In the first aspect, the present application discloses a bus data transmission method, which is applied to any bus node in a bus network. When any bus node is used as a data sending node, it includes:
[0007] Encrypt the target key of a preset symmetric encryption algorithm by using the public key corresponding to the data receiving node, and send the encrypted key to the data receiving node, so that the data receiving node decrypts the encrypted key by using the private key corresponding to the public key to obtain the target key;
[0008] Group the data to be transmitted and fill in invalid data based on a preset invalid data insertion rule to obtain several grouped data, and use a preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each grouped data respectively to obtain a ciphertext rule and ciphertext data;
[0009] Send the ciphertext rule and each ciphertext data to the data receiving node in sequence, so that the data receiving node can decrypt the ciphertext rule and each ciphertext data respectively using the target key to obtain the invalid data insertion rule and each grouped data, and extract the data to be transmitted from each grouped data based on the invalid data insertion rule.
[0010] Optionally, the bus data transmission method of the present application further includes:
[0011] Obtain the first key pair corresponding to the local from a preset key management library, and send the public key in the first key pair to the remaining bus nodes in the bus network through the bus; the first key pair includes a public key and a private key;
[0012] Obtain and store the public keys in the second key pairs respectively sent by the remaining bus nodes through the bus after obtaining the corresponding second key pairs from the preset key management library.
[0013] Optionally, the invalid data insertion rule includes a first length value for respectively recording the valid data of each grouped data and a second length value for the invalid data;
[0014] Correspondingly, grouping the data to be transmitted and filling in invalid data based on a preset invalid data insertion rule to obtain several grouped data includes:
[0015] Determine the total length of the data to be transmitted, and compare the total length with a preset length threshold;
[0016] If the total length is less than the preset length threshold, fill the data to be transmitted with first invalid data to construct a single data group; wherein, the first length value is the total length, and the second length value is the difference between the preset length threshold and the total length;
[0017] If the total length is equal to the preset length threshold, construct a single data group based on the data to be transmitted; wherein, the first length value is the total length, and the second length value is zero;
[0018] If the total length is greater than the preset length threshold, group the data to be transmitted with the preset length threshold as the length basis to obtain several data groups, and determine whether the length of the last data group is the preset length threshold, so as to determine the first length value and the second length value corresponding to each data group based on the judgment result.
[0019] Optionally, determining the first length value and the second length value corresponding to each data group based on the judgment result includes:
[0020] If the length of the last data packet is equal to the preset length threshold, the first length value corresponding to each data packet is the preset length threshold, and the second length value is zero;
[0021] If the length of the last data packet is not equal to the preset length threshold, the last data packet is padded based on the second invalid data; wherein, the first length value corresponding to the last data packet is the remainder obtained by dividing the total length by the preset length threshold, the second length value is the difference between the preset length threshold and the remainder, and the first length value corresponding to the remaining data packets is the preset length threshold, and the second length value is zero.
[0022] Optionally, the generation process of the invalid data includes:
[0023] Determine the valid data in the data packet to be filled;
[0024] Calculate the first digest value for the valid data by using a preset hash algorithm, and intercept the data content of the corresponding length from the first digest value in the order from front to back based on the second length value as the invalid data.
[0025] Optionally, extracting the data to be transmitted from each packet of data based on the invalid data insertion rule includes:
[0026] The data receiving node extracts the corresponding valid data from each packet of data based on the first length value, and calculates the second digest value for the valid data by using a preset hash algorithm;
[0027] The data receiving node compares the data content corresponding to the second length value in the second digest value with the invalid data in the packet of data. If the data content and the invalid data are inconsistent, it is determined that a data tampering event has occurred, and all the received data is discarded. If the data content and the invalid data are consistent, the data to be transmitted is obtained based on the valid data in each packet of data.
[0028] Optionally, the data sending node and the data receiving node perform transmission based on a preset bus data frame format. The bus data frame format includes a first bit for identifying the IP address of the data sending node, a second bit for identifying the IP address of the data receiving node, a third bit for identifying whether the currently transmitted data is ciphertext or plaintext, a fourth bit for identifying the type of encryption algorithm currently used, and a fifth bit for identifying the data type of the currently transmitted data.
[0029] In a second aspect, the present application discloses a bus data transmission method, which is applied to any bus node in a bus network. When any bus node serves as a data receiving node, the method includes:
[0030] Obtain the encrypted key sent by the data sending node, and use the local private key to decrypt the encrypted key to obtain the target key; wherein, the encrypted key is obtained by the data sending node encrypting the target key of the preset symmetric encryption algorithm with the public key corresponding to the private key.
[0031] Obtain the ciphertext rule and each ciphertext data sequentially sent by the data sending node; the ciphertext rule and each ciphertext data are obtained by the data sending node encrypting the preset invalid data insertion rule and each grouped data respectively with the preset symmetric encryption algorithm, and the grouped data is obtained by the data sending node grouping and filling invalid data into the data to be transmitted based on the invalid data insertion rule.
[0032] Use the target key to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each grouped data, and extract the data to be transmitted from each grouped data based on the invalid data insertion rule.
[0033] In a third aspect, the present application discloses a bus data transmission device, which is applied to any bus node in a bus network. When any bus node is used as a data sending node, the device includes:
[0034] A key encryption transmission module, configured to encrypt the target key of the preset symmetric encryption algorithm with the public key corresponding to the data receiving node, and send the encrypted key to the data receiving node, so that the data receiving node decrypts the encrypted key with the private key corresponding to the public key to obtain the target key.
[0035] An encryption module, configured to group and fill invalid data into the data to be transmitted based on the preset invalid data insertion rule to obtain a number of grouped data, and encrypt the invalid data insertion rule and each grouped data respectively with the preset symmetric encryption algorithm to obtain the ciphertext rule and ciphertext data.
[0036] A ciphertext sending module, configured to sequentially send the ciphertext rule and each ciphertext data to the data receiving node, so that the data receiving node decrypts the ciphertext rule and each ciphertext data respectively with the target key to obtain the invalid data insertion rule and each grouped data, and extracts the data to be transmitted from each grouped data based on the invalid data insertion rule.
[0037] In a fourth aspect, the present application discloses an electronic device, including:
[0038] A memory, configured to store a computer program;
[0039] A processor, configured to execute the computer program to implement the steps of the foregoing disclosed bus data transmission method.
[0040] Fifth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the aforementioned disclosed bus data transmission method are implemented.
[0041] It can be seen that the present application discloses a bus data transmission method, which is applied to any bus node in a bus network. When any bus node serves as a data sending node, it encrypts the target key of a preset symmetric encryption algorithm by using the public key corresponding to the data receiving node, and sends the encrypted key to the data receiving node, so that the data receiving node can use the private key corresponding to the public key to decrypt the encrypted key to obtain the target key; it groups the data to be transmitted and fills in invalid data based on a preset invalid data insertion rule to obtain a number of grouped data, and encrypts the invalid data insertion rule and each grouped data respectively by using the preset symmetric encryption algorithm to obtain a ciphertext rule and ciphertext data; it sequentially sends the ciphertext rule and each ciphertext data to the data receiving node, so that the data receiving node can use the target key to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each grouped data, and extracts the data to be transmitted from each grouped data based on the invalid data insertion rule.
[0042] Beneficial effects: When two bus nodes in a bus network need to communicate, first, the data sending node encrypts the target key of a preset symmetric encryption algorithm by using the public key corresponding to the data receiving node, and sends the encrypted key to the data receiving node, so that the data receiving node can use its own private key to decrypt the encrypted key to obtain the target key for subsequent decryption. In this way, the security of the key transmission on the bus is improved, and the risk of data being deciphered due to key leakage is reduced. Further, the data sending node groups the data to be transmitted and fills in invalid data based on a preset invalid data insertion rule to obtain a number of grouped data, and encrypts the invalid data insertion rule and each grouped data respectively by using the preset symmetric encryption algorithm to obtain the corresponding ciphertext rule and ciphertext data, and sequentially sends the ciphertext rule and each ciphertext data to the data receiving node. That is to say, when encrypting the invalid data insertion rule and each grouped data in the present application, a different encryption algorithm from the encryption of the target key is used. By combining different encryption algorithms, the security of the system can be further improved, and the key and data are encrypted and transmitted separately. Even if an attacker obtains some data by some means, without the key, they cannot decrypt the complete valid data. Finally, the data receiving node uses the target key initially decrypted to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each grouped data, and extracts the data to be transmitted from each grouped data based on the invalid data insertion rule, thus completing a complete communication process. Description of the Drawings
[0043] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0044] Figure 1 It is a flowchart of a bus data transmission method disclosed in the present application;
[0045] Figure 2 It is a flowchart of a method for data grouping and filling disclosed in the present application;
[0046] Figure 3 It is a schematic structural diagram of a CAN data frame disclosed in the present application;
[0047] Figure 4 It is a flowchart of another specific bus data transmission method disclosed in the present application;
[0048] Figure 5 It is a schematic structural diagram of a bus data transmission device disclosed in the present application;
[0049] Figure 6 It is a structural diagram of an electronic device disclosed in the present application. Detailed implementation manners
[0050] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0051] In related CAN bus encryption technologies, a common solution is to use the AES algorithm to encrypt data. After receiving the encrypted data, the receiving node decrypts and verifies it to ensure the effectiveness and security of data transmission. However, in this solution, although the data is transmitted in ciphertext, the corresponding key is transmitted in plaintext on the bus, which is easily intercepted by attackers, resulting in key leakage. Once the key is leaked, the attacker can obtain the original data through decryption, seriously threatening data security. Therefore, the embodiments of the present application disclose a bus data transmission method, device, equipment and medium, which can further ensure the security of data transmission on the bus.
[0052] See Figure 1As shown in the figure, an embodiment of the present application discloses a bus data transmission method, which is applied to any bus node in a bus network. When any bus node serves as a data sending node, the method includes:
[0053] Step S11: Encrypt the target key of a preset symmetric encryption algorithm using the public key corresponding to the data receiving node, and send the encrypted key to the data receiving node, so that the data receiving node can decrypt the encrypted key using the private key corresponding to the public key to obtain the target key.
[0054] In this embodiment, any bus node in the bus network can serve as both a data sending node and a data receiving node. When communication is required between the two nodes, the data sending node will encrypt the target key of the preset symmetric encryption algorithm using the public key corresponding to the data receiving node (i.e., the RSA algorithm), and send the encrypted key to the data receiving node. In this way, the data receiving node can use its own private key to decrypt the encrypted key to obtain the target key for subsequent decryption. Since the RSA algorithm is an asymmetric encryption algorithm, even if the public key is transmitted on the bus in plain text and only the node itself knows the private key, the target key transmitted through RSA encryption is only known to the respective nodes. Even if monitored by an attacker, the target key cannot be parsed. It should be noted that considering that the RSA algorithm is computationally slow, it is only used for the encryption and decryption transmission of the target key. The subsequent invalid data filling rules and the transmission of subsequent data are both encrypted and decrypted using the preset symmetric encryption algorithm. By combining different encryption algorithms, the security of the system can be further improved. In this way, the security of the key transmission on the bus is improved, and the risk of data being deciphered due to key leakage is reduced.
[0055] The above method further includes: obtaining a first key pair corresponding to the local from a preset key management library, and sending the public key in the first key pair to the remaining bus nodes in the bus network through the bus; the first key pair includes a public key and a private key; obtaining and storing the public keys in the second key pairs respectively sent by the remaining bus nodes through the bus after obtaining the corresponding second key pairs from the preset key management library. It can be understood that before each bus node conducts communication, it is necessary to first determine its own public key and private key. In the specific implementation manner, each bus node can obtain a first key pair corresponding to the local from the preset key management library. Specifically, the preset key management library will generate a unique public key and private key pair for each bus node, and distribute the generated key pair to each bus node through a secure channel, such as a secure wired connection or an encrypted wireless transmission method. After the bus node obtains the first key pair corresponding to the local, it then sends the public key in the first key pair to the remaining bus nodes in the bus network through the bus. Here, the public key is transmitted in plain text on the bus. At the same time, each bus node will also obtain and store the public keys in the second key pairs respectively sent by the remaining bus nodes through the bus after obtaining the corresponding second key pairs from the preset key management library. In this way, each bus node can know the public key information of other bus nodes in the network.
[0056] In addition, to further improve security, the public keys and private keys used by each bus node can be updated regularly. Specifically, it includes: monitoring the total usage time of the first key pair. If the total usage time exceeds a preset time threshold, re-obtain the key pair corresponding to the local from the preset key management library and use it as the new first key pair, and then send the public key in the new first key pair to the remaining bus nodes in the bus network through the bus. That is, the present application can set a fixed time interval for updating the local key pair, such as updating once per hour. After the update is completed, it is sent to the remaining bus nodes again to achieve real-time synchronization of information. This is to prevent the risk of being cracked by using the same key for a long time. Periodically replacing the key can effectively reduce security risks. In addition, in addition to obtaining the public key and private key from the preset key management library, a pair of key pairs can also be generated using an asymmetric encryption algorithm. The embodiments of the present application do not limit the manner of obtaining the key pair.
[0057] Step S12: Group the data to be transmitted and fill in invalid data based on a preset invalid data insertion rule to obtain a number of grouped data, and use a preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each grouped data respectively to obtain a ciphertext rule and ciphertext data.
[0058] In this embodiment, the data sending node groups the data to be transmitted and fills in invalid data based on a preset invalid data insertion rule to obtain several grouped data, and uses a preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each grouped data respectively to obtain the corresponding ciphertext rule and ciphertext data. It should be noted that when encrypting the invalid data insertion rule and each grouped data in this application, a different encryption algorithm from the encryption target key is used. By combining different encryption algorithms, the security of the system can be further improved. The preset symmetric encryption algorithm here can specifically be the AES (Advanced Encryption Standard) algorithm.
[0059] In the specific implementation, the invalid data insertion rule includes a first length value for respectively recording the valid data of each grouped data and a second length value for the invalid data. It should be noted that the invalid data insertion rule is actually a 32-bit data frame sent down. Among them, data[15:0] is the length length1 of the valid data of the transmitted data packet, with the unit of bit; data[31:16] is the length length2 of the filled invalid data, with the unit of bit.
[0060] Therefore, the above-mentioned grouping of the data to be transmitted and filling in invalid data based on a preset invalid data insertion rule to obtain several grouped data specifically includes the following steps, as Figure 2 shown:
[0061] Step S121: Determine the total length of the data to be transmitted, and compare the total length with a preset length threshold.
[0062] In this embodiment, since the CAN bus protocol can transfer a maximum of 64-bit data, taking the AES algorithm as an example, its encryption and decryption unit is 128 bits. Therefore, the source node needs to group the data to be transmitted. For groups less than 128 bits, invalid data filling processing is required.
[0063] Therefore, this application needs to determine the total length of the data to be transmitted and compare the total length with a preset length threshold. The preset length threshold here is 128 bits. It should be noted that when using other symmetric encryption algorithms, the preset length threshold will also change accordingly.
[0064] Step S122: If the total length is less than the preset length threshold, fill the data to be transmitted with first invalid data to construct a single data group; where the first length value is the total length, and the second length value is the difference between the preset length threshold and the total length.
[0065] In this embodiment, if the total length is less than the preset length threshold, it indicates that the data to be transmitted fails to reach the encryption / decryption unit of the symmetric encryption algorithm. Therefore, the data to be transmitted is directly used as a data packet, and it is necessary to fill it with the first invalid data so that the total length of the filled data is 128 bits. In this case, the first length value in the invalid data insertion rule is the original total length of the data to be transmitted, and the second length value is the difference between the preset length threshold and the total length. For example, if the total length of the data to be transmitted is 100 bits, it means that the first length value corresponding to the valid data is 100 bits, and the second length value corresponding to the invalid data to be filled is 28 bits.
[0066] Step S123: If the total length is equal to the preset length threshold, a single data packet is constructed based on the data to be transmitted; where the first length value is the total length and the second length value is zero.
[0067] In this embodiment, if the total length is equal to the preset length threshold of 128 bits, a single data packet is directly constructed based on the data to be transmitted. That is, if the length of this group of data is exactly 128 bits, no filling is required. Therefore, the first length value corresponding to the valid data is 128 bits, and the second length value corresponding to the invalid data to be filled is 0.
[0068] Step S124: If the total length is greater than the preset length threshold, the data to be transmitted is grouped with the preset length threshold as the length basis to obtain a certain number of data packets, and it is determined whether the length of the last data packet is the preset length threshold, so as to determine the first length value and the second length value corresponding to each data packet based on the judgment result.
[0069] In this embodiment, if the total length is greater than the preset length threshold of 128 bits, the data to be transmitted is grouped with the preset length threshold as the length basis to obtain a certain number of data packets. After the grouping is completed, it is then determined whether the length of the last data packet is the preset length threshold, so as to determine the first length value and the second length value corresponding to each data packet based on the judgment result.
[0070] In the specific implementation manner, determining the first length value and the second length value corresponding to each data packet based on the judgment result includes: if the length of the last data packet is the preset length threshold, the first length value corresponding to each data packet is the preset length threshold, and the second length value is zero; if the length of the last data packet is not the preset length threshold, the last data packet is filled with the second invalid data; where the first length value corresponding to the last data packet is the remainder obtained by dividing the total length by the preset length threshold, and the second length value is the difference between the preset length threshold and the remainder, and the first length value corresponding to the remaining data packets is the preset length threshold, and the second length value is zero.
[0071] In a specific embodiment, if the length of the last data packet is also the preset length threshold, it indicates that the original total length of the data to be transmitted is an integer multiple of 128 bits. After packetization, the length of each data packet is 128 bits. Therefore, in this case, the first length value of the valid data corresponding to each packet is 128 bits, and the second length value of the corresponding invalid data is zero.
[0072] In another specific embodiment, if the length of the last data packet is not the preset length threshold, it indicates that the original total length of the data to be transmitted is not an integer multiple of 128 bits. For example, if the total length is 300 bits in total, after dividing with 128 bits as the length benchmark, three data packets will be obtained. The lengths of the first two data packets are both 128 bits, and the length of the third data packet is 44 bits. Therefore, in this case, since the length of the third data packet does not reach 128 bits, it is necessary to fill the last data packet based on the second invalid data, and the length value of the filled invalid data is 128 bits - 44 bits = 84 bits. Therefore, the first length value corresponding to the last data packet is the remainder 44 bits obtained by dividing the total length by the preset length threshold, the second length value is the difference 84 bits between the preset length threshold and the remainder, and the first length values corresponding to the other data packets are the preset length threshold 128 bits, and the second length value is 0.
[0073] It should be noted that the generation process of the invalid data includes: determining the valid data in the data packet to be filled; calculating the first digest value for the valid data using a preset hash algorithm, and based on the second length value, intercepting the corresponding length of data content from the first digest value in the order from front to back as the invalid data. That is, when data needs to be filled, the valid data in the data packet to be filled is determined, and then the first digest value is calculated for the valid data using a preset hash algorithm. Since the length of the calculated digest value is 128 bits, and the length of the actually filled invalid data is the second length value, the corresponding length of data content is intercepted from the first digest value in the order from front to back as the invalid data. The specific intercepted content is hash[N:0], where N = length2 - 1. And it should be noted that the filled invalid data needs to be inserted into the end part of the data packet to be filled in order.
[0074] Step S13: Send the ciphertext rule and each ciphertext data to the data receiving node in sequence, so that the data receiving node uses the target key to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each packet of data, and extracts the data to be transmitted from each packet of data based on the invalid data insertion rule.
[0075] In this embodiment, the ciphertext rules and each ciphertext data are sequentially sent to the data receiving node. By encrypting and transmitting the key and the data separately, even if an attacker obtains some data in some way, without the key, the attacker cannot decrypt the complete valid data. Finally, the data receiving node uses the target key initially decrypted to decrypt the ciphertext rules and each ciphertext data respectively to obtain the invalid data insertion rules and each grouped data, and extracts the data to be transmitted from each grouped data based on the invalid data insertion rules, thus completing a complete communication process.
[0076] In the specific implementation manner, extracting the data to be transmitted from each grouped data based on the invalid data insertion rules includes: the data receiving node extracts the corresponding valid data from each grouped data based on the first length value, and calculates the second digest value for the valid data by using a preset hash algorithm; the data receiving node compares the data content corresponding to the second length value in the second digest value with the invalid data in the grouped data. If the data content is inconsistent with the invalid data, it is determined that a data tampering event has occurred, and all the received data is discarded. If the data content is consistent with the invalid data, the data to be transmitted is obtained based on the valid data in each grouped data.
[0077] That is, after decrypting to obtain the invalid data insertion rules and each grouped data, the data receiving node needs to restore the original data to be transmitted. Specifically, the data receiving node needs to extract the corresponding valid data from each grouped data in the order from front to back based on the first length value. It should be noted that when the first length value of each data packet is the preset length threshold, the data to be transmitted is directly spliced. When the first length value is less than the preset length threshold, the invalid data carried therein can also be used as the basis for data authentication. That is, the data receiving node can further calculate the second digest value for the valid data by using a preset hash algorithm, and then compare the data content corresponding to the second length value in the second digest value with the invalid data in the grouped data to determine whether the transmitted data has errors or is tampered with. Specifically, if the data content is inconsistent with the invalid data, it is determined that a data tampering event has occurred, and all the received data is discarded. If the data content is consistent with the invalid data, the data to be transmitted is spliced based on the valid data in each grouped data.
[0078] In addition, it should be noted that the data transmission between the data sending node and the data receiving node is based on a preset bus data frame format. The bus data frame format includes a first bit for identifying the IP address of the data sending node, a second bit for identifying the IP address of the data receiving node, a third bit for identifying whether the currently transmitted data is ciphertext or plaintext, a fourth bit for identifying the type of encryption algorithm currently adopted, and a fifth bit for identifying the data type of the currently transmitted data. That is, in this application, the data is transmitted between the data sending node and the data receiving node in the form of a CAN data frame, specifically as Figure 3 shown. The CAN data frame specifically includes a frame start, an arbitration segment, a control segment, a data segment, a CRC (check) segment, an ACK (acknowledgment) segment, and an end segment.
[0079] This embodiment mainly introduces the bus data frame format used in the arbitration segment. The frame format adopted in this embodiment is in the form of a 29-bit ID and is located in the arbitration segment. Among them, ID[12:0] represents the destination ID, and ID[25:13] is the source ID. Through the ID, it can be known which node the message is sent to and where the source of the sent message is located. In the subsequent public key transmission of each node, the receiving node can use this information to save the public key information of each node. When sending information to a certain node, the target key key is encrypted using the public key of the peer node through the RSA asymmetric encryption algorithm, so that the peer can parse out the target key using the private key as the basis for subsequent communication. In the embodiment of this application, the data is sent in plaintext and ciphertext, and the sent data is encrypted using RSA and AES. Therefore, identification is required. ID
[26] is used to distinguish whether the transmitted frame data is plaintext or ciphertext. ID
[26] =1 indicates ciphertext, and ID
[26] =0 indicates plaintext; ID
[27] is used to identify the encryption and decryption algorithm adopted. ID
[27] =1 indicates the use of AES encryption and decryption, and ID
[27] =0 indicates the use of RSA encryption and decryption; ID
[28] is used to identify whether the transmitted data is an invalid data insertion rule or data to be transmitted. ID
[28] =1 indicates data to be transmitted, and ID
[28] =0 indicates the transmitted invalid data insertion rule.
[0080] Correspondingly, the data parsing process of each bus node is as follows:
[0081] (1) Determine whether the message is transmitted to this node through ID[12:0]. If so, proceed to step (2); if not, discard it.
[0082] (2) According to the ID
[26] in the frame, if it is 0, it represents plaintext. In this application, only the public keys of each node are transmitted in plaintext. The source of the message can be understood through ID [25:13]. Record the public key information of each node. If ID
[26] is 1, it represents ciphertext. At this time, ID
[27] needs to be identified. When ID
[27] is 0, it represents RSA encryption and decryption, indicating that the data transmitted at this time is the encrypted target key key, and the target key key is resolved through the local private key. When ID
[27] is 1, operate according to step (3).
[0083] (3) Judge ID
[28] . If ID
[28] is 0, it means that the currently transmitted is an invalid data insertion rule. At this time, resolve the valid data length length1 and the filled invalid data length length2 of the subsequent transmitted data according to the invalid data insertion rule. If ID
[28] is 1, operate according to step (4).
[0084] (4) Receive data according to length1 and length2. Decrypt the received data using the target key key parsed in step (2). Extract the valid data length according to length1. When length2 is 0, the received data is the complete data. When length2 is not 0, operate according to step (5).
[0085] (5) It means that there is padding and the filled invalid data is part of the calculated digest value, which can be used as the basis for data authentication. At this time, receive the valid data according to the length of length1, calculate the digest value of the valid data, and by comparing with the received digest value, it can be known whether the transmitted data has errors or has been tampered with. If they are consistent, receive it normally. If they are inconsistent, discard it.
[0086] It can be seen that when both bus nodes in a bus network need to communicate, first, the data sending node encrypts the target key of a preset symmetric encryption algorithm using the public key corresponding to the data receiving node, and sends the encrypted key to the data receiving node. In this way, the data receiving node can decrypt the encrypted key using its own private key to obtain the target key for subsequent decryption. In this way, the security of the key transmission on the bus is improved, and the risk of data being deciphered due to key leakage is reduced. Further, the data sending node groups the data to be transmitted and fills in invalid data based on a preset invalid data insertion rule to obtain several grouped data, and uses the preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each grouped data respectively to obtain the corresponding ciphertext rule and ciphertext data, and sequentially sends the ciphertext rule and each ciphertext data to the data receiving node. That is, when encrypting the invalid data insertion rule and each grouped data in this application, a different encryption algorithm from the one used to encrypt the target key is used. By combining different encryption algorithms, the security of the system can be further improved. Moreover, the key and the data are encrypted and transmitted separately. Even if an attacker obtains some data by some means, without the key, they cannot decrypt the complete valid data. Finally, the data receiving node uses the target key initially decrypted to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each grouped data, and extracts the data to be transmitted from each grouped data based on the invalid data insertion rule, thus completing a complete communication process.
[0087] See Figure 4 As shown, another specific bus data transmission method is disclosed in an embodiment of this application, which is applied to any bus node in a bus network. When any bus node serves as a data receiving node, the method includes:
[0088] Step S21: Obtain the encrypted key sent by the data sending node, and decrypt the encrypted key using the local private key to obtain the target key; wherein, the encrypted key is obtained by the data sending node encrypting the target key of a preset symmetric encryption algorithm using the public key corresponding to the private key.
[0089] Step S22: Obtain the ciphertext rule and each ciphertext data sequentially sent by the data sending node; the ciphertext rule and each ciphertext data are obtained by the data sending node encrypting the preset invalid data insertion rule and each grouped data respectively using the preset symmetric encryption algorithm, and the grouped data is obtained by the data sending node grouping the data to be transmitted and filling in invalid data based on the invalid data insertion rule.
[0090] Step S23: Use the target key to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each group of data, and extract the data to be transmitted from each group of data based on the invalid data insertion rule.
[0091] It can be seen that after the data receiving node obtains the encrypted key sent by the data sending node, it uses the local private key to decrypt the encrypted key to obtain the target key. It can be understood that the encrypted key is obtained by the data sending node encrypting the target key of the preset symmetric encryption algorithm with the public key corresponding to the private key. In this way, the security of the key transmission on the bus is improved, and the risk of data being deciphered due to key leakage is reduced. The data receiving node further obtains the ciphertext rule and each ciphertext data sent by the data sending node in sequence, and the ciphertext rule and each ciphertext data are obtained by the data sending node encrypting the preset invalid data insertion rule and each group of data respectively using the preset symmetric encryption algorithm. That is, when encrypting the invalid data insertion rule and each group of data in this application, a different encryption algorithm from the encryption target key is used. By combining different encryption algorithms, the security of the system can be further improved. Moreover, the key and data are encrypted and transmitted separately. Even if an attacker obtains some data through some means, without the key, they cannot decrypt the complete valid data. Finally, the data receiving node uses the initially decrypted target key to decrypt the ciphertext rule and each ciphertext data respectively to obtain the invalid data insertion rule and each group of data, and extracts the data to be transmitted from each group of data based on the invalid data insertion rule, thus completing a complete communication process.
[0092] See Figure 5 As shown, an embodiment of the present application discloses a bus data transmission device, which is applied to any bus node in a bus network. When any bus node is used as a data sending node, the device includes:
[0093] A key encryption and transmission module 11, configured to encrypt the target key of the preset symmetric encryption algorithm using the public key corresponding to the data receiving node, and send the encrypted key to the data receiving node, so that the data receiving node can use the private key corresponding to the public key to decrypt the encrypted key to obtain the target key;
[0094] An encryption module 12, configured to group the data to be transmitted and fill in invalid data based on the preset invalid data insertion rule to obtain several groups of data, and use the preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each group of data respectively to obtain the ciphertext rule and ciphertext data;
[0095] The ciphertext sending module 13 is used to sequentially send the ciphertext rule and each piece of ciphertext data to the data receiving node, so that the data receiving node can use the target key to decrypt the ciphertext rule and each piece of ciphertext data respectively to obtain the invalid data insertion rule and each piece of grouped data, and extract the data to be transmitted from each piece of grouped data based on the invalid data insertion rule.
[0096] It can be seen that when both bus nodes in the bus network need to communicate, first, the data sending node encrypts the target key of the preset symmetric encryption algorithm using the public key corresponding to the data receiving node, and sends the encrypted key to the data receiving node. In this way, the data receiving node can use its own private key to decrypt the encrypted key to obtain the target key for subsequent decryption. In this way, the security of the key transmission on the bus is improved, and the risk of data being deciphered due to key leakage is reduced. Further, the data sending node groups the data to be transmitted and fills in invalid data based on the preset invalid data insertion rule to obtain several pieces of grouped data, and uses the preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each piece of grouped data respectively to obtain the corresponding ciphertext rule and ciphertext data, and sequentially sends the ciphertext rule and each piece of ciphertext data to the data receiving node. That is, when encrypting the invalid data insertion rule and each piece of grouped data in this application, a different encryption algorithm from the encryption target key is used. By combining different encryption algorithms, the security of the system can be further improved. Moreover, the key and the data are encrypted and transmitted separately. Even if an attacker obtains some data by some means, without the key, they cannot decrypt the complete valid data. Finally, the data receiving node uses the target key initially decrypted to decrypt the ciphertext rule and each piece of ciphertext data respectively to obtain the invalid data insertion rule and each piece of grouped data, and extracts the data to be transmitted from each piece of grouped data based on the invalid data insertion rule, thus completing a complete communication process.
[0097] Since the embodiments of the device part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the device part, which will not be elaborated here. And it has the same beneficial effects as the above-mentioned bus data transmission method.
[0098] Figure 6 It is a schematic structural diagram of an electronic device provided by an embodiment of this application. Specifically, it may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the bus data transmission method executed by the electronic device disclosed in any of the foregoing embodiments.
[0099] In this embodiment, the power supply 23 is used to provide operating voltages for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and no specific limitation is imposed thereon herein; the input / output interface 25 is used to obtain external input data or output data to the outside, and the specific interface type thereof can be selected according to specific application requirements, and no specific limitation is imposed thereon herein.
[0100] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), or PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor used to process data in the wake state, also known as the CPU (Central Processing Unit); the coprocessor is a low-power processor used to process data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may further include an AI (Artificial Intelligence) processor, and the AI processor is used to process computational operations related to machine learning.
[0101] In addition, the memory 22, as a carrier for resource storage, may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon include an operating system 221, a computer program 222, data 223, etc., and the storage method may be transient storage or permanent storage.
[0102] Among them, the operating system 221 is used to manage and control each hardware device on the electronic device 20 and the computer program 222, so as to enable the processor 21 to perform operations and processing on the massive data 223 in the memory 22. It can be Windows, Unix, Linux, etc. In addition to the computer program that can be used to complete the bus data transmission method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 may further include computer programs that can be used to complete other specific tasks. The data 223 may include not only the data transmitted by external devices received by the electronic device, but also the data collected by its own input / output interface 25, etc.
[0103] Furthermore, an embodiment of the present application also discloses a computer-readable storage medium, in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the bus data transmission method disclosed in any of the foregoing embodiments are implemented.
[0104] Furthermore, an embodiment of the present application also discloses a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the bus data transmission method disclosed in any of the foregoing embodiments are implemented.
[0105] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. For the same or similar parts among the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple. For the relevant parts, reference can be made to the description in the method part.
[0106] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0107] The steps of the methods or algorithms described in combination with the embodiments disclosed in this article can be implemented directly by hardware, software modules executed by a processor, or a combination of both. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, compact disc read-only memory (CD-ROM), or any other form of storage medium known in the technical field.
[0108] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0109] The above has introduced in detail a bus data transmission method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A bus data transmission method, characterized in that: Applied to any bus node in a bus network, when any bus node is used as a data sending node, the method comprises: Encrypting a target key of a preset symmetric encryption algorithm using a public key corresponding to a data receiving node, and sending the encrypted key to the data receiving node, so that the data receiving node decrypts the encrypted key using a private key corresponding to the public key to obtain the target key; Based on a preset invalid data insertion rule, the data to be transmitted is grouped and filled with invalid data to obtain a plurality of grouped data, and the invalid data insertion rule and each of the grouped data are encrypted by using the preset symmetric encryption algorithm to obtain a ciphertext rule and ciphertext data; The ciphertext rules and each ciphertext data are sent to the data receiving node in sequence, so that the data receiving node uses the target key to decrypt the ciphertext rules and each ciphertext data respectively to obtain the invalid data insertion rule and each group data, and extracts the data to be transmitted from each group data based on the invalid data insertion rule.
2. The bus data transmission method according to claim 1, characterized in that: Also includes: Obtaining a first key pair corresponding to the local from a preset key management library, and sending a public key in the first key pair to other bus nodes in the bus network through a bus; The first key pair includes a public key and a private key; Acquire and store the public keys in the second key pair respectively sent by the remaining bus nodes through the bus after acquiring the corresponding second key pair from the preset key management library.
3. The bus data transmission method according to claim 1, characterized in that: The invalid data insertion rule includes a first length value for recording the valid data and a second length value for the invalid data of each packet data respectively; Accordingly, the data to be transmitted is grouped and filled with invalid data based on the preset invalid data insertion rule to obtain a plurality of grouped data, including: Determine the total length of the data to be transmitted, and compare the total length with a preset length threshold; If the total length is less than the preset length threshold, padding the data to be transmitted based on the first invalid data to construct a single data packet; wherein the first length value is the total length, and the second length value is the difference between the preset length threshold and the total length; If the total length is equal to the preset length threshold, a single data packet is constructed based on the data to be transmitted; wherein the first length value is the total length and the second length value is zero; If the total length is greater than the preset length threshold, the data to be transmitted is grouped based on the preset length threshold to obtain a number of data groups, and it is determined whether the length of the last data group is the preset length threshold, so as to determine the first length value and the second length value corresponding to each data group based on the judgment result.
4. The bus data transmission method according to claim 3, characterized in that: The determining the first length value and the second length value corresponding to each data packet based on the judgment result includes: If the length of the last data packet is the preset length threshold, the first length value corresponding to each data packet is the preset length threshold, and the second length value is zero; If the length of the last data packet is not the preset length threshold, the last data packet is padded based on the second invalid data; wherein the first length value corresponding to the last data packet is the remainder obtained by dividing the total length by the preset length threshold, and the second length value is the difference between the preset length threshold and the remainder, and the first length value corresponding to the remaining data packets is the preset length threshold, and the second length value is zero.
5. The bus data transmission method according to claim 3, characterized in that: The process of generating invalid data includes: Determine valid data in the data group to be filled; A preset hash algorithm is used to calculate the valid data to obtain a first digest value, and based on the second length value, data content of a corresponding length is cut out from the first digest value in a sequence from front to back as invalid data.
6. The bus data transmission method according to claim 5, characterized in that: The extracting the data to be transmitted from each of the packet data based on the invalid data insertion rule comprises: Extracting corresponding valid data from each of the packet data based on the first length value by the data receiving node, and calculating the valid data using the preset hash algorithm to obtain a second digest value; The data receiving node compares the data content corresponding to the second length value in the second summary value with the invalid data in the packet data. If the data content is inconsistent with the invalid data, it is determined that a data tampering event has occurred and all received data is discarded. If the data content is consistent with the invalid data, the data to be transmitted is obtained based on the valid data in each packet data.
7. The bus data transmission method according to any one of claims 1 to 6, characterized in that: The data sending node and the data receiving node transmit data based on a preset bus data frame format, and the bus data frame format includes a first bit for identifying the IP address of the data sending node, a second bit for identifying the IP address of the data receiving node, a third bit for identifying whether the currently transmitted data is ciphertext or plaintext, a fourth bit for identifying the type of encryption algorithm currently used, and a fifth bit for identifying the data type of the currently transmitted data.
8. A bus data transmission method, characterized in that: Applied to any bus node in a bus network, when any bus node serves as a data receiving node, the method comprises: Obtaining the encrypted key sent by the data sending node, and decrypting the encrypted key using the local private key to obtain the target key; wherein the encrypted key is obtained by the data sending node encrypting the target key of the preset symmetric encryption algorithm using the public key corresponding to the private key; Acquire the ciphertext rules and ciphertext data sequentially sent by the data sending node; the ciphertext rules and the ciphertext data are obtained after the data sending node uses the preset symmetric encryption algorithm to encrypt the preset invalid data insertion rules and the grouped data respectively, and the grouped data is obtained after the data sending node groups the data to be transmitted and fills the invalid data based on the invalid data insertion rules; The target key is used to decrypt the ciphertext rule and each ciphertext data to obtain the invalid data insertion rule and each packet data, and the data to be transmitted is extracted from each packet data based on the invalid data insertion rule.
9. A bus data transmission device, characterized in that: Applicable to any bus node in a bus network, when any bus node is used as a data sending node, the device comprises: A key encryption transmission module is used to encrypt a target key of a preset symmetric encryption algorithm using a public key corresponding to a data receiving node, and send the encrypted key to the data receiving node, so that the data receiving node decrypts the encrypted key using a private key corresponding to the public key to obtain the target key; An encryption module, used for grouping the data to be transmitted and filling the data with invalid data based on a preset invalid data insertion rule to obtain a plurality of grouped data, and using the preset symmetric encryption algorithm to encrypt the invalid data insertion rule and each of the grouped data to obtain a ciphertext rule and ciphertext data; The ciphertext sending module is used to send the ciphertext rules and each ciphertext data to the data receiving node in sequence, so that the data receiving node uses the target key to decrypt the ciphertext rules and each ciphertext data respectively to obtain the invalid data insertion rule and each grouped data, and extract the data to be transmitted from each grouped data based on the invalid data insertion rule.
10. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the steps of the bus data transmission method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that: Used to store computer programs; wherein, when the computer program is executed by a processor, the steps of the bus data transmission method according to any one of claims 1 to 8 are implemented.