Data communication method, terminal, electronic equipment, storage medium, product and vehicle

By double encryption of transmitted data and its identification information, the problem of poor data security in the prior art is solved, and higher data communication security and integrity are achieved.

CN120200852AActive Publication Date: 2025-06-24BYD CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510669964.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-06-24
Estimated Expiration
2045-05-23

AI Technical Summary

Technical Problem

In the prior art, only simple encryption methods are used, making data easily intercepted and tampered, resulting in data leakage and poor security.

Method used

By double encryption of transmitted data and its related identification information, the security of data during transmission is ensured. The specific method includes hashing the identification information and encrypting different types of data using different encryption methods.

Benefits of technology

Enhanced the security of the data communication process, effectively prevent data leakage and security risks, and ensure the integrity of data types and source information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200852A_ABST
    Figure CN120200852A_ABST
Patent Text Reader

Abstract

The invention relates to a data communication method, a terminal, electronic equipment, a storage medium, a product and a vehicle, the method is applied to a first terminal, and the method comprises the following steps: encrypting transmission data and identification information corresponding to the transmission data, and transmitting the encrypted identification information and the encrypted transmission data to a second terminal. According to the method, the transmission data is encrypted, and the identification information (such as the data type, the data source and the like) related to the transmission data is encrypted, so that the security of the data in the communication process can be enhanced, and the data leakage and the security risk are effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of vehicles, and particularly to a data communication method, a terminal, an electronic device, a storage medium, a product, and a vehicle. Background Art

[0002] With the development of communication technology, various data collected (such as image data, location information, speed information, etc.) need to be transmitted between different electronic devices. However, in related technologies, only simple encryption methods are used, making the data easily intercepted and tampered with, resulting in data leakage and poor security. Summary of the Invention

[0003] Embodiments of the present application provide a data communication method, a terminal, an electronic device, a storage medium, a product, and a vehicle to solve the above problems.

[0004] To achieve the above object, according to the first aspect of the present application, there is provided a data communication method applied to a first terminal, and the method includes: Encrypt the transmission data and the identification information corresponding to the transmission data, and transmit the encrypted identification information and the encrypted transmission data to a second terminal.

[0005] Optionally, the identification information includes first identification information indicating the data type of the transmission data and / or second identification information indicating the data source of the transmission data.

[0006] Optionally, the encrypting the identification information corresponding to the transmission data includes: Encrypt the first identification information based on a first encryption method to obtain the encrypted first identification information; Encrypt the second identification information based on a second encryption method to obtain the encrypted second identification information.

[0007] Optionally, the first identification information includes a plurality of data units, and the encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Based on a target data unit in the first identification information and a preset mapping relationship, obtain associated information associated with the target data unit to determine the encrypted first identification information, wherein the preset mapping relationship includes a mapping relationship between a preset data unit and associated information.

[0008] Optionally, the target data unit includes a data unit corresponding to at least one of a service name, a sensor type, and a sensor location.

[0009] Optionally, encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Rearranging a plurality of data units in the first identification information to obtain the encrypted first identification information.

[0010] Optionally, encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Performing an exclusive OR operation on a plurality of data units in the first identification information based on a key of a preset length to obtain the encrypted first identification information.

[0011] Optionally, encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Based on a target data unit in the first identification information and a preset mapping relationship, obtaining associated information associated with the target data unit to obtain first encrypted information; Rearranging a plurality of data units in the first encrypted information to obtain second encrypted information; Performing an exclusive OR operation on a plurality of data units in the second encrypted information based on a key of a preset length to obtain third encrypted information, thereby obtaining the encrypted first identification information.

[0012] Optionally, encrypting the second identification information based on the second encryption method to obtain the encrypted second identification information: Encrypting the second identification information based on a first symmetric key to obtain the encrypted second identification information.

[0013] Optionally, the method further includes: Performing a hashing process on the identification information to obtain a first digest value corresponding to the identification information; Transmitting the first digest value, the encrypted identification information, and the encrypted transmission data to the second terminal.

[0014] Optionally, the method further includes: Performing serialization processing on the transmission data to obtain serialized transmission data, thereby determining the encrypted transmission data.

[0015] Optionally, the transmission data includes multiple types of sub-data, and performing serialization processing on the transmission data to obtain serialized transmission data includes: Performing serialization processing on the sub-data based on a policy corresponding to the type of the sub-data, so as to obtain the serialized transmission data based on the serialized sub-data.

[0016] Optionally, serializing the sub-data based on a policy corresponding to the type of the sub-data includes: Performing a first serialization process on the sub-data of the first type to obtain the serialized sub-data of the first type.

[0017] Optionally, the importance level of the sub-data of the first type exceeds a preset importance level threshold, and / or the data volume of the sub-data of the first type does not exceed a preset data volume threshold, and the first serialization process is used for serializing complex data.

[0018] Optionally, the sub-data of the first type includes the description information of the transmission data.

[0019] Optionally, serializing the sub-data based on a policy corresponding to the type of the sub-data includes: Performing a second serialization process on the sub-data of the second type to obtain the serialized sub-data of the second type.

[0020] Optionally, the importance level of the sub-data of the second type does not exceed a preset importance level threshold, and / or the data volume of the sub-data of the second type exceeds a preset data volume threshold, and the second serialization process is a binary serialization process.

[0021] Optionally, the sub-data of the second type includes multiple point data of the transmission data.

[0022] Optionally, the method further includes: Encrypting the transmission data based on an encryption algorithm corresponding to a first sojourn time of the transmission data to obtain the encrypted transmission data, where the first sojourn time is determined based on a data source of the transmission data.

[0023] Optionally, encrypting the transmission data based on an encryption algorithm corresponding to a first sojourn time of the transmission data to obtain the encrypted transmission data includes: When the first sojourn time is less than or equal to a first preset time threshold, encrypting the transmission data based on a first encryption algorithm to obtain the encrypted transmission data, where a processing time required by the first encryption algorithm is greater than or equal to a second preset time threshold.

[0024] Optionally, encrypting the transmission data based on an encryption algorithm corresponding to a first sojourn time of the transmission data to obtain the encrypted transmission data includes: In the case that the first sojourn time is greater than the first preset time threshold, encrypt the transmission data based on a second encryption algorithm to obtain the encrypted transmission data, where the processing time required by the second encryption algorithm is less than the second preset time threshold.

[0025] Optionally, the method further includes: Obtain the first sojourn time according to the average processing time, a preset coefficient corresponding to the data source, and the length of the queue where the transmission data is located.

[0026] Optionally, the transmission data is data collected by a vehicle.

[0027] According to a second aspect of the present application, an embodiment of the present application further provides a data communication method, which is applied to a second terminal, and the method includes: Decrypt an identification field in the encrypted data transmitted by a first terminal to obtain decrypted identification information, so as to decrypt a data field in the encrypted data to obtain decrypted transmission data.

[0028] Optionally, the identification field includes a first identification field and a second identification field, and the obtaining of the decrypted identification information includes: Based on a first decryption method corresponding to a first encryption method, decrypt the first identification field to obtain decrypted first identification information; Based on a second decryption method corresponding to a second encryption method, decrypt the second identification field to obtain decrypted second identification information.

[0029] Optionally, the decrypting the data field in the encrypted data to obtain decrypted transmission data includes: Perform a hash process on the decrypted identification information to obtain a second digest value corresponding to the decrypted identification information; Determine whether the second digest value is consistent with a digest field in the encrypted data, so as to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0030] Optionally, the decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: When the second digest value is consistent with the digest field in the encrypted data, decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0031] Optionally, the decrypting the data field in the encrypted data to obtain decrypted transmission data includes: Decrypt the data field in the encrypted data based on the decryption algorithm corresponding to the encryption algorithm used by the first terminal, to obtain the decrypted transmission data.

[0032] Optionally, the decrypted transmission data includes multiple types of sub-data, and the method further includes: Perform deserialization processing on the sub-data based on the policy corresponding to the type of the sub-data, so as to obtain the deserialized transmission data based on the deserialized sub-data.

[0033] Optionally, the method further includes: Create a corresponding thread based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold, and based on the thread, perform the step of decrypting the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information, and decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0034] Optionally, creating a corresponding thread based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold includes: When the second sojourn time is greater than or equal to the third preset time threshold, create a first thread and a second thread, wherein, the first thread is used to receive the encrypted data transmitted by the first terminal; The second thread is used to perform the step of decrypting the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information, and decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0035] According to the third aspect of the present application, an embodiment of the present application further provides a terminal for implementing any one of the data communication methods provided by the embodiments of the present application.

[0036] According to the fourth aspect of the present application, an embodiment of the present application further provides an electronic device, including: A memory, on which a computer program is stored; A processor, configured to execute the computer program in the memory to implement the steps of any one of the methods provided by the embodiments of the present application.

[0037] According to the fifth aspect of the present application, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and the computer program, when executed by a processor, implements the steps of any one of the methods provided by the embodiments of the present application.

[0038] According to a sixth aspect of the present application, an embodiment of the present application further provides a computer program product, including a computer program or instructions, and when the computer program or instructions are executed by a processor, the steps of any of the methods provided by the embodiments of the present application are implemented.

[0039] According to a seventh aspect of the present application, an embodiment of the present application further provides a vehicle, including the terminal as described above, or, an electronic device as described above, or, the steps of any of the methods provided by the embodiments of the present application are executed.

[0040] Some embodiments of this specification at least include the following beneficial effects: By using the encrypted identification information and the encrypted transmission data as encrypted data and transmitting them to the second terminal, not only the transmission data itself is encrypted, but also the identification information related to the transmission data (such as data type, data source, etc.) is encrypted, which can enhance the security during the data communication process, thereby effectively preventing data leakage and security risks.

[0041] Other features and advantages of the present application will be described in detail in the subsequent specific implementation part. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present application. For those skilled in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0043] In order to more completely understand the present application and its beneficial effects, the following will be described in conjunction with the drawings, where the same reference numerals represent the same parts in the following description.

[0044] Figure 1 is an application scenario diagram of the data communication method shown in some embodiments of this specification; Figure 2 is an exemplary flowchart of the data communication method shown in some embodiments of this specification; Figure 3 is an exemplary flowchart of obtaining the encrypted first identification information shown in some embodiments of this specification; Figure 4 is an exemplary flowchart of another data communication method shown in some embodiments of this specification; Figure 5 is a schematic structural diagram of the data communication system shown in some embodiments of this specification; Figure 6 is a schematic structural diagram of an electronic device shown in some embodiments of this specification; Figure 7 It is an exemplary schematic diagram of a vehicle shown according to some embodiments of this specification. Detailed implementation manners

[0045] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the protection scope of the present application.

[0046] To facilitate the understanding of the implementation solutions provided in the embodiments of the present application, the relevant application backgrounds of the data communication method provided in the embodiments of the present application will be described first.

[0047] Currently, with the rapid development of intelligent connected vehicles and autonomous driving technologies, the demand for data exchange inside and between vehicles is increasing day by day. Related technologies adopt Data Distribution Service (DDS) communication, define data topics (Topics), and DDS communication allows different devices (such as sensors, ECUs, etc.) to participate in data exchange as publishers or subscribers. The publisher publishes data to a specific topic, and the subscriber can subscribe to the topics of interest according to its own needs, so as to achieve efficient distribution and reception of data, ensuring that various sensor data, control instructions, and status information can be transmitted in real time between different electronic control units (Electronic Control Unit, ECU) or between the vehicle and external systems. However, in related DDS communication, only the collected data is encrypted, or the encryption algorithm (such as the symmetric encryption algorithm aes) is relatively single, or a certain serialization and deserialization (such as boost or cdr, etc.) is fixed, resulting in low security.

[0048] In view of this, some embodiments of this specification provide a data communication method, which encrypts the identification information corresponding to the transmitted data to enhance security. And different data sources are distinguished, and different encryption methods are adopted to improve communication efficiency. And through the multi-threaded operation method, the main thread is used to subscribe to data and obtain data, and the sub-thread is used to decrypt data and write data to disk. In this way, the resource preemption of subscribing data - obtaining data during the process of decrypting data - writing data to disk is reduced, and the occurrence of frame loss is reduced.

[0049] Figure 1 It is an application scenario diagram of the data communication method shown according to some embodiments of this specification.

[0050] The data communication method provided by the embodiments of the present application can be applied to various application scenarios. For example, autonomous driving, intelligent transportation, industrial automation, etc.

[0051] The execution subject of the technical solution of the embodiments of the present application can be an electronic device, which can be deployed on a movable device or connected to a movable device in a wired or wireless manner. Of course, the electronic device can also be the movable device itself. The movable device can have any appearance, such as an intelligent vehicle, etc.

[0052] In some embodiments, the electronic device can be an in-vehicle terminal integrated in a vehicle, such as an electronic control unit (ECU), a vehicle control unit (VCU), a micro control unit (MCU), etc., or a device that interacts with the vehicle for data. The embodiments of the present application do not impose any restrictions on the specific type of the electronic device.

[0053] When the electronic device is connected to a movable device, the electronic device can be a terminal device, such as a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., but is not limited thereto.

[0054] In some embodiments, the application scenario can also include, for example, a network, a storage device, etc. The network can include any suitable wired or wireless network that can facilitate information and / or data exchange. The storage device is used to store data, instructions, and / or any other information. It should be noted that the information (including but not limited to device information, user information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.), and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations and standards. For example, the transmission data involved in the embodiments of the present application are all obtained under full authorization.

[0055] Hereinafter, an example will be given with the movable device being an intelligent vehicle (referred to as a vehicle) for illustration. It should be noted that the application scenario of the data communication method is only provided for the purpose of illustration and is not intended to limit the scope of this specification. For those of ordinary skill in the art, various changes and modifications can be made according to the description of this specification. For example, the application scenario can also include a database, an information source, etc. Another example is that the application scenario can be implemented on other devices to achieve similar or different functions. However, these changes and modifications will not deviate from the scope of this specification.

[0056] Figure 2is an exemplary flowchart of a data communication method according to some embodiments of this specification. In some embodiments, this process may be executed based on a first terminal. As Figure 2 shown, this process includes the following steps.

[0057] Step 210: Encrypt the transmission data and the identification information corresponding to the transmission data.

[0058] In some embodiments, the first terminal is a publisher, and the second terminal is a subscriber, that is, data communication is performed between the first terminal and the second terminal based on DDS. In some embodiments, the publisher and the subscriber may be on the same terminal, that is, the first terminal and the second terminal may be the same terminal; in more cases, the publisher and the subscriber are not on the same terminal, that is, the first terminal and the second terminal may be different terminals; in the embodiments of this application, the case where the first terminal and the second terminal are different terminals is taken as an example for description. Moreover, the first terminal may be an Internet of Things device, a vehicle terminal (such as a domain controller), a mobile phone, or a tablet computer, etc.; the second terminal may also be an Internet of Things device, a vehicle terminal (such as a host computer), a mobile phone, or a tablet computer, etc.

[0059] In some embodiments, the first terminal includes a first application and a first middleware, and the second terminal includes a second application and a second middleware. The first application is a publisher, that is, the first application publishes the transmission data that needs to be transmitted. For example, a sensor node may generate temperature data, or a control system may generate a control instruction. The first middleware is used to encapsulate the transmission data generated by the first application into a data sample in DDS communication and publish it to the network. The first middleware is also used to manage the transmission of data, including serialization, encryption, deserialization, decryption, etc. The second middleware is used to receive the data sample from the network and pass it to the second application. The second middleware is used to manage the reception of data, including deserialization, data caching, data distribution, etc. The second application is a subscriber, that is, the second application subscribes to the transmission data; data communication is performed between the first DDS middleware and the second DDS middleware so that the first application and the second application can share the transmission data.

[0060] The transmission data is the specific data that needs to be transmitted to the second terminal. For example, the transmission data may be sensor data, control instructions, etc.

[0061] In some embodiments, the transmission data is data collected by a vehicle.

[0062] In some embodiments, each domain controller in a vehicle can be the first terminal, and a vehicle control unit or a host computer can be the second terminal. The transmitted data includes sensor data, status information, and control instructions that each domain controller in the vehicle (such as the body domain, cockpit domain, driving domain, etc.) sends to the vehicle control unit (VCU) of the vehicle. For another example, the vehicle control unit receives the transmitted data from each domain controller and makes centralized decisions and controls based on this transmitted data. The VCU not only processes the data from each domain controller but also sends control instructions, status updates, and other relevant information back to each domain controller and other devices.

[0063] Exemplarily, the transmitted data can include, but is not limited to, the door status of the body domain, the status of the air conditioning system, sensor data inside and outside the vehicle, etc.; the transmitted data can also include, but is not limited to, driver information in the cockpit domain, navigation system data, voice assistant commands, etc.; the transmitted data can also include, but is not limited to, vehicle dynamic data in the driving domain, engine status, brake system status data, camera data, etc.

[0064] Exemplarily, the transmitted data can also include, but is not limited to, door control instructions, window control instructions, etc. sent to the body domain; the transmitted data can also include, but is not limited to, navigation system instructions, entertainment system control instructions, etc. sent to the cockpit domain; the transmitted data can also include, but is not limited to, engine control instructions, brake system control instructions, etc. sent to the driving domain.

[0065] Exemplarily, the transmitted data can also include data collected by sensors. The sensors send CAN data to the domain controller through a CAN (Controller Area Network, a serial communication protocol) bus, and the domain controller encapsulates the CAN data into DDS communication data according to certain mapping rules.

[0066] The identification information is the key information used to identify and describe the transmitted data. For example, the identification information is additional information associated with the transmitted data, used to identify or distinguish the data source of the transmitted data (such as sensor ID, device name, etc.), data type (such as image data, text data, etc.), usage (such as control, logging, perception, etc.), or other attributes, etc.

[0067] Step 220, transmit the encrypted identification information and the encrypted transmitted data to the second terminal.

[0068] In some embodiments, the encrypted identification information and the encrypted transmitted data can be concatenated and packed and then transmitted to the second terminal.

[0069] In some embodiments, the identification information includes first identification information indicating the data type of the transmitted data and / or second identification information indicating the data source of the transmitted data.

[0070] The data source may be device information related to the generation end of the transmitted data or the sending end of the transmitted data.

[0071] In some embodiments, the first identification information may be a string or an enumerated value. Alternatively, the first identification information may also be a topic. A topic is a logical channel for data transmission. The publisher publishes data to the corresponding topic, and the subscriber subscribes to data from the required topics. Different topics correspond to different data types and data structures.

[0072] In some embodiments, the second identification information may include the device ID or location information of the first terminal, etc. Alternatively, the second identification information may also be a globally unique identifier (GUID, Global Unique Identifier), which is an identifier used to uniquely identify the data source or an entity in DDS communication.

[0073] In some embodiments of this specification, by encrypting the identification information and the transmitted data, not only can the security of the transmitted data be improved, but also the security of the identification information during the transmission process can be ensured, while retaining the integrity of the data type and source information. By encrypting the identification information, even if the transmitted data is intercepted during the transmission process, the attacker cannot directly obtain information such as the data type and data source, which helps prevent the leakage of sensitive information.

[0074] In some embodiments, encrypting the identification information corresponding to the transmitted data includes: Based on the first encryption method, encrypt the first identification information to obtain the encrypted first identification information; Based on the second encryption method, encrypt the second identification information to obtain the encrypted second identification information.

[0075] The first encryption method refers to the encryption algorithm used to encrypt the first identification information. For example, the first encryption method may be symmetric encryption (such as AES (Advanced Encryption Standard)) or asymmetric encryption (such as RSA (Rivest Shamir Adleman)), etc.

[0076] The second encryption method refers to the encryption algorithm used to encrypt the second identification information. For example, the second encryption method may be the same as or different from the first encryption method, depending on the security requirements and actual applications.

[0077] In some embodiments of the present specification, by encrypting the first identification information and the second identification information respectively, appropriate encryption algorithms and key management strategies can be selected according to different security requirements. For example, the first identification information may require a higher encryption strength, while the second identification information may require a faster encryption speed to adapt to different application scenarios and security requirements. For example, in some scenarios, the data type may need to be strictly confidential, while in other scenarios, the data source may require higher security.

[0078] The first encryption method can be implemented in various ways. For example, the first encryption method can include any one or a combination of obfuscation processing, rearrangement, and exclusive-or processing.

[0079] Obfuscation processing is an encryption method that changes the representation form of data. For example, obfuscation processing can be achieved through character replacement, encoding conversion, and preset mapping relationships, etc. Character replacement can be replacing some characters in the data with other characters; encoding conversion can be converting the data from one encoding to another encoding, such as from ASCII to Base64; the preset mapping relationship can be mapping the information of the target data unit to other forms of associated information using a preset mapping table.

[0080] Rearrangement can be a method of changing the order of data units, and exclusive-or processing can be logical operations such as exclusive-or.

[0081] In some embodiments, the first identification information includes multiple data units. Based on the first encryption method, the first identification information is encrypted to obtain the encrypted first identification information, including: Based on the target data unit in the first identification information and the preset mapping relationship, the associated information associated with the target data unit is obtained to determine the encrypted first identification information. Wherein, the preset mapping relationship includes the mapping relationship between the preset data unit and the associated information.

[0082] A data unit refers to a component of the first identification information. For example, a data unit can be each specific element in the first identification information. Exemplarily, each data unit can be a bit, a character, a byte, an integer, a floating-point number, or any other basic data type.

[0083] In some embodiments, the first identification information may include multiple fields, where a field consists of at least one character (e.g., a field can be a complete string, etc.), and a complete field can be regarded as a data unit. For example, a field is a data unit, or a character in the field or the corresponding byte of the character is regarded as a data unit. For example, the data unit is "t", "m", etc. The field may include but is not limited to data type data_type (such as numeric type, character type, boolean type, etc.), data format format (such as text format, binary format, etc.), data unit unit (such as temperature unit, length unit, time unit, etc.).

[0084] The target data unit is a specific data unit selected from the first identification information. The target data unit can be a set of one or more data units, depending on the application scenario.

[0085] The preset mapping relationship is a predefined mapping table used to indicate the correspondence between preset data units (such as data_type, format, etc.) and associated information. For example, the preset mapping relationship can be a dictionary or a table.

[0086] The associated information is a field or string derived from the information of the target data unit according to the preset mapping relationship. The associated field can be an encrypted value, a replacement value, or other relevant information. In some embodiments, the information of the target data unit can be replaced with the corresponding associated information.

[0087] The encrypted first identification information contains the associated information and does not contain the information of the original target data unit to ensure the security of the first identification information during transmission.

[0088] In some embodiments, the target data unit includes at least one of the data units corresponding to the business name, sensor type, and sensor location.

[0089] The business name is a name or identifier related to the business or application that transmits data.

[0090] The sensor type is used to identify the type of the sensor that collects and transmits data. For example, a temperature sensor, a pressure sensor, etc.

[0091] The sensor location is used to identify the physical location or installation location of the sensor that collects and transmits data.

[0092] Exemplarily, the first identification information is a theme, which consists of multiple fields, each field is separated by a delimiter " / ", and the format of the theme is / idc / lidar / left / detection. Among them, the fields after the first delimiter " / " are used to indicate the business name of the relevant department, the fields after the second delimiter " / " are used to indicate the sensor type, the fields after the third delimiter are used to indicate the sensor location, and the fields after the fourth delimiter are used to indicate the application scenario. For example, detection means perception.

[0093] Based on the preset mapping relationship, the fields after the first three delimiters are used as target data units for obfuscation processing, and obfuscated values unrelated to the theme are obtained. Exemplarily, idc is obfuscated to opc, lidar is obfuscated to camera, and left is obfuscated to right.

[0094] In some embodiments, the obfuscated values (associated information) related to each field can be formed into an obfuscation matrix as the preset mapping relationship. Each row in the obfuscation matrix corresponds to a target data unit, and each column corresponds to a possible obfuscated value. The same obfuscation matrix is stored in the local caches of both the subscriber and the publisher as the preset mapping relationship to ensure that both parties can perform obfuscation and de-obfuscation processing consistently.

[0095] In some embodiments of this specification, by means of obfuscation processing, the key fields in the first identification information can be hidden or protected during transmission, while retaining the necessary information for data parsing and processing.

[0096] In some embodiments, based on the first encryption method, the first identification information is encrypted to obtain the encrypted first identification information, including: Rearranging the multiple data units in the first identification information to obtain the encrypted first identification information.

[0097] In some embodiments, a field can be used as a data unit, and a random sequence can be generated. The sequence represents the arrangement of each data unit in the first identification information. The length of the sequence is the same as the number of data units. The value of each element in the sequence represents the position index value of the corresponding data unit in the first identification information, and each position index value is unique. According to this sequence, each data unit is moved to a new position to generate the encrypted first identification information. For example, for 4 data units, the sequence can be [2, 0, 3, 1]; according to the sequence, multiple data units are rearranged. For example, according to the sequence [2, 0, 3, 1], ["idc", "lidar", "left", "detection"] can be rearranged to ["left", "idc", "detection", "lidar"]; the rearranged data units are combined into the encrypted first identification information. For example, ["left", "idc", "detection", "lidar"] is combined into / left / idc / detection / lidar.

[0098] In some embodiments, the first identification information can be converted into a byte sequence. For example, each character in the first identification information is converted into the corresponding binary representation (such as the ASCII code value) to obtain the byte sequence of the first identification information. Each byte in the byte sequence represents an independent data unit, and each byte can be rearranged according to the generated sequence to generate the encrypted first identification information.

[0099] It can be understood that the multiple rearranged data units and the multiple obfuscated data units can be in the same form or different forms. For example, the target data unit in the obfuscated first identification information can refer to the field after the delimiter, and the multiple data units in the rearranged first identification information can be in the form of bytes. This specification does not limit this.

[0100] In this specification, for the sake of illustration, examples of rearrangement are given, but the present invention is not limited thereto. Other methods can also be used. For example, only a part of the first identification information can be rearranged.

[0101] In some embodiments of this specification, by rearranging the data units in the first identification information, encryption or obfuscation of the first identification information can be achieved, and at the same time, the parsing difficulty is not increased, which can be applied to application scenarios requiring lightweight security encryption.

[0102] In some embodiments, based on the first encryption method, the first identification information is encrypted to obtain the encrypted first identification information, including: Perform an exclusive OR operation on multiple data units in the first identification information based on a preset-length key to obtain the encrypted first identification information.

[0103] The preset-length key is a predefined fixed-length preset key, which can be composed of randomly generated characters, numbers, or bytes. The preset length can be the same as the length of the first identification information or a certain data unit, or it can be other lengths. Exemplarily, when the length of the preset key is shorter than the first identification information, the preset key can be cyclically used to cover the entire first identification information.

[0104] In some embodiments, a field of a preset number of bits or a field after a delimiter / is used as a data unit. A corresponding key can be configured for each data unit, or a total key can be configured for the first identification information. Based on multiple keys or the total key, an exclusive OR operation is performed on multiple data units of the first identification information or the first identification information.

[0105] In some embodiments, the preset length is the same as the length of the byte sequence corresponding to the first identification information. The byte sequence corresponding to the first identification information can be exclusive-ORed bit by bit with the binary representation of the preset-length key; the binary result after the exclusive OR operation is converted back to a character form to form the encrypted first identification information. Exemplarily, based on the byte sequence of the first identification information, an exclusive OR operation is performed using the selected key; the result after the exclusive OR is converted back to a character form to form the encrypted first identification information.

[0106] It can be understood that the multiple data units for the exclusive OR operation and the multiple data units for the above-mentioned confusion processing and rearrangement can be in the same form or different forms. For example, the target data unit in the first identification information for the confusion processing can refer to the field after the delimiter, and the multiple data units in the first identification information for the exclusive OR operation can be in the form of bytes. This specification does not limit this.

[0107] In some embodiments of this specification, the exclusive OR operation is easy to implement, does not require complex algorithms and a large amount of computing resources, effectively hides the content of the first identification information, and ensures the protection of the first identification information during transmission.

[0108] Figure 3 is an exemplary flowchart of obtaining the encrypted first identification information shown in some embodiments of this specification. In some embodiments, this process can be executed based on a first terminal. As Figure 3 shown, this process includes the following steps.

[0109] In some embodiments, encrypting the first identification information based on a first encryption method to obtain the encrypted first identification information includes: Step 310: Based on the target data unit in the first identification information and the preset mapping relationship, obtain the associated information associated with the target data unit to obtain the first encrypted information; Step 320: Rearrange multiple data units in the first encrypted information to obtain the second encrypted information; Step 330: Perform an exclusive OR operation on multiple data units in the second encrypted information based on a key of a preset length to obtain the third encrypted information, so as to obtain the encrypted first identification information.

[0110] The first encrypted information is the first identification information after being scrambled. The second encrypted information is the first identification information after being rearranged. The third encrypted information is the first identification information after being exclusive ORed.

[0111] In some embodiments, the first encryption method may use any one of the above encryption methods alone, or may combine multiple encryption methods to enhance the encryption effect. Exemplarily, the first encryption method includes scrambling and rearrangement; for example, by using the preset mapping relationship, the subject / idc / lidar / left / detection is obtained as the first encrypted information of the first identification information, and the first encrypted information of the first identification information, that is, / opc / camera / right / detection, is rearranged to obtain / right / detection / opc / camera as the second encrypted information. Another example, the first encryption method includes rearrangement and exclusive OR processing. The subject / idc / lidar / left / detection is rearranged to obtain / left / detection / idc / lidar as the second encrypted information, and an exclusive OR operation is performed on / left / detection / idc / lidar and a key of a preset length to obtain the third encrypted information as the encrypted first identification information.

[0112] In some embodiments, the first encryption method includes scrambling, rearrangement, and exclusive OR processing. Exemplarily, use the preset mapping relationship to replace the information of the target data unit in the first identification information (such as the fields indicating the service name, sensor type, and sensor location) with the corresponding associated information to obtain the first encrypted information; for the first encrypted information, rearrange multiple data units in the first encrypted information through a randomly generated sequence to obtain the second encrypted information; for each byte in the byte sequence corresponding to the second encrypted information, perform a bitwise exclusive OR operation with a key of a preset length to obtain the third encrypted information as the encrypted first identification information.

[0113] In some embodiments of this specification, by combining obfuscation processing, rearrangement, and XOR processing, the security of data can be enhanced at different levels, and the security of the first identification information can be further improved.

[0114] It can be understood that the second encryption method can be the same as the first encryption method, that is, the second identification information can also be encrypted based on the first encryption method to obtain the encrypted second identification information.

[0115] In some embodiments, based on the second encryption method, the second identification information is encrypted to obtain the encrypted second identification information: Based on the first symmetric key, the second identification information is encrypted to obtain the encrypted second identification information.

[0116] In some embodiments, the second encryption method can be different from the first encryption method. For example, the second encryption method is a symmetric encryption algorithm.

[0117] The first symmetric key can be the key of the symmetric encryption algorithm. The key length of the first symmetric key can be 128 bits, 192 bits, or 256 bits, which can be determined according to the actual situation, or padded or truncated, etc.

[0118] In some embodiments, a random symmetric key can be generated using a random number generator as the first symmetric key, and based on the first symmetric key, the second identification information is encrypted through a symmetric encryption algorithm to obtain the encrypted second identification information. Symmetric encryption algorithms include but are not limited to AES (Advanced Encryption Standard), DES (Data Encryption Standard), 3DES (Triple DES), RC4, etc.

[0119] It should be noted that by encrypting different identification information using different encryption methods, even if an attacker decrypts one identification information, the other identification information cannot be obtained by the attacker using the same decryption method, improving the security of communication.

[0120] In some embodiments of this specification, through different encryption methods, encryption based on the first symmetric key can hide or protect the content of the second identification information during transmission, further improving the security of the identification information.

[0121] In some embodiments, the method further includes: Performing a hash process on the identification information to obtain a first digest value corresponding to the identification information; Transmitting the first digest value, the encrypted identification information, and the encrypted transmission data to the second terminal.

[0122] The first digest value is a string obtained by hashing the identification information.

[0123] Hashing is an operation process that converts data of any length into a value of a fixed length.

[0124] In some embodiments, hashing can be implemented based on a hashing algorithm, such as SHA-256, MD5, etc.

[0125] In some embodiments, the first digest value corresponding to the identification information, the encrypted identification information, and the encrypted transmission data can be concatenated to obtain the concatenated encrypted data and sent to the second terminal.

[0126] In some embodiments, when sending transmission data, the first terminal can use a hashing algorithm to generate a data digest from the transmission data, then encrypt the data digest with the private key of the first terminal, and send the encrypted data digest together with the encrypted transmission data, the first digest value corresponding to the identification information, and the encrypted identification information to the second terminal. The second terminal can first decrypt the encrypted transmission data, calculate a data digest from the decrypted transmission data using the hashing algorithm corresponding to the first terminal, and use the public key to decrypt the attached digital signature to obtain the decrypted data digest. If the two digests, the decrypted data digest and the calculated data digest, are the same, it is determined that the transmission is successful, and the transmission data of the first terminal is obtained.

[0127] In some embodiments of this specification, the digest value generated by hashing can be used to verify whether the identification information has been tampered with during transmission. The second terminal needs to recalculate the digest value and compare it with the digest value provided by the sender. If they are inconsistent, it means the data has been tampered with, which helps to verify the source and integrity of the data.

[0128] In some embodiments, the method further includes: Performing serialization processing on the transmission data to obtain the serialized transmission data to determine the encrypted transmission data.

[0129] The serialization process converts a data sample into a serialized format (such as a byte stream, etc.) for the purpose of facilitating transmission and storage. For example, the serialized format can include one or a combination of the following: the original binary format, the cross-platform binary format (External Data Representation, XDR), the JSON text format, the XML markup language, etc.

[0130] In some embodiments, the serialized data includes various data in the DDS. For example, the transmission data can be serialized to obtain the serialized transmission data, and the identification information can be serialized to obtain the serialized identification information. The serialized transmission data and the serialized identification information can be used for encryption to obtain the encrypted identification information and the encrypted transmission data.

[0131] In some embodiments of this specification, by serializing various data in the DDS, the data can be efficiently converted into a byte stream for easy transmission and storage in the network.

[0132] In some embodiments, the transmission data includes various types of sub-data. Serializing the transmission data to obtain the serialized transmission data includes: Based on the policy corresponding to the type of sub-data, the sub-data is serialized to obtain the serialized transmission data based on the serialized sub-data.

[0133] The corresponding policy is a pre-set method and rule for serialization processing.

[0134] The sub-data is a part of the transmission data, and each type of sub-data corresponds to a specific data type. The data type can include descriptive information, point data, etc.

[0135] In some embodiments, different types of sub-data correspond to different serialization processes. The serialization process can include Boost serialization, cdr serialization, etc. Among them, Boost serialization is used for serializing complex data and custom type data and supports serialization in text format, binary format, and XML format.

[0136] Boost serialization supports multiple formats of data, which is time-consuming and may be slow when serializing complex data. It is suitable for scenarios where complex C++ objects need to be serialized, and scenarios where performance or storage occupancy requirements are not high, or scenarios where compatibility with different versions of application programs needs to be considered.

[0137] Cdr serialization adopts a static structure design, eliminating the process of data copying and buffer reallocation, and is suitable for scenarios with high performance requirements, such as real-time communication systems and application programs that need to process a large amount of data, and scenarios with high requirements for transmission speed.

[0138] In some embodiments, the serialization method can also be selected according to the actual situation. For example, when considering high performance and low latency and the data structure is relatively fixed, cdr serialization can be selected. When considering ease of use, Boost serialization can be selected.

[0139] In some embodiments, based on a policy corresponding to the type of sub-data, serializing the sub-data includes: Performing a first serialization process on the sub-data of the first type to obtain the serialized sub-data of the first type.

[0140] In some embodiments, the importance level of the sub-data of the first type exceeds a preset importance level threshold, and / or the data volume of the sub-data of the first type does not exceed a preset data volume threshold. The first serialization process is used for serializing complex data.

[0141] The importance level is used to characterize the importance of the sub-data. In some embodiments, the importance level can be expressed as a numerical value (e.g., importance degree, importance value, etc.) or a level (e.g., importance level).

[0142] The preset importance level threshold is a threshold condition for judging the importance of the sub-data. The preset data volume threshold can be a system default value, an empirical value, a value preset by a person, etc. or any combination thereof, and can be set according to actual needs. This specification does not limit this.

[0143] The data volume is used to characterize the size or quantity of the sub-data. The data volume can be expressed in units such as bytes (Bytes), kilobytes (KB), megabytes (MB), gigabytes (GB), etc.

[0144] The preset data volume threshold is a threshold condition for judging the size of the data volume of the sub-data. The preset data volume threshold can be a system default value, an empirical value, a value preset by a person, etc. or any combination thereof, and can be set according to actual needs. This specification does not limit this.

[0145] In some embodiments, the first serialization process is Boost serialization.

[0146] In some embodiments, the sub-data of the first type includes description information of the transmitted data.

[0147] The description information is used to provide an explanation or annotation about the transmitted data. For example, the description information can include the source of the data (e.g., sensor ID), the generation time of the data (e.g., timestamp), the use of the data (e.g., description field), etc.

[0148] In some embodiments of this specification, the description information generally does not occupy too much space and can adopt a more complex serialization method without affecting performance to ensure the security and efficient transmission of the data.

[0149] In some embodiments, based on a policy corresponding to the type of sub-data, serializing the sub-data includes: Performing a second serialization process on the sub-data of the second type to obtain the serialized sub-data of the second type.

[0150] In some embodiments, the importance level of the second type of sub-data does not exceed a preset importance level threshold, and / or the data volume of the second type of sub-data exceeds a preset data volume threshold, and the second serialization process is a binary serialization process.

[0151] In some embodiments, the first serialization process is a cdr serialization.

[0152] In some embodiments, the second type of sub-data includes multiple point data of transmitted data.

[0153] Point data refers to numerical or status information related to a measurement point or a data point. Multiple point data can exist in the form of an array or a list, and each element in the array or list represents a point data. Each point data can be a structured object containing multiple fields (such as a location ID and a value, etc.).

[0154] In some embodiments of this specification, the data volume of the point data is large, and efficient serialization processing is required to ensure data compactness and transmission efficiency.

[0155] In some embodiments, serialized transmitted data can be obtained based on the serialized first type of sub-data and the serialized second type of sub-data.

[0156] Exemplarily, in the scenario of DDS communication in a vehicle where the host computer is a subscriber and the lower computer (such as a domain controller) acts as a publisher for data acquisition and disk writing, each frame of transmitted data contains description information such as a timestamp, speed, and angular velocity of the transmitted data for describing each frame of transmitted data. Each frame of transmitted data can correspond to one piece of description information, and the importance level of the description information is relatively high. Boost serialization can be used to perform serialization processing on the description information.

[0157] For the point data of each frame of transmitted data in radar point clouds and image data, its data volume is large, and writing a large amount of point data to disk puts certain pressure on the software and hardware. CDR serialization can be used to perform serialization processing on multiple point data.

[0158] Adopting two or more serialization processing methods can reduce the risk of a single attack path. An attacker needs to understand and crack multiple serialization formats and their combination methods, increasing the difficulty of the attack. For sub-data such as radar point cloud data and image point data, a serialization processing method different from that of the description information is adopted. Combining the use of CDR and Boost serialization processing can ensure that the transmitted data is not tampered with during the serialization and deserialization processes. Even if the description information of a frame of transmitted data is decrypted and deserialized by an attacker, the radar point cloud data and image point data cannot be deserialized by the attacker in the same serialization method, improving the security of communication.

[0159] In some embodiments, the method further includes: Encrypting the transmission data based on the encryption algorithm corresponding to the first sojourn time of the transmission data to obtain the encrypted transmission data.

[0160] The first sojourn time refers to the time that the transmission data stays in a certain stage. For example, the first sojourn time is the time that the transmission data queues in the transmission queue, or the first sojourn time is the processing time of the transmission queue corresponding to the transmission data.

[0161] For different first sojourn times, different encryption algorithms are selected to encrypt the transmission data. For example, if the transmission data stays in the transmission queue for a long time, a fast encryption algorithm can be selected; if the transmission data stays in the transmission queue for a short time, a more secure but slower encryption algorithm can be selected.

[0162] In some embodiments, the first sojourn time can be determined in various ways. For example, the first sojourn time can be determined based on prior knowledge or historical data.

[0163] In some embodiments, encrypting the transmission data based on the encryption algorithm corresponding to the first sojourn time of the transmission data to obtain the encrypted transmission data includes: When the first sojourn time is less than or equal to the first preset time threshold, encrypting the transmission data based on the first encryption algorithm to obtain the encrypted transmission data, and the processing time required by the first encryption algorithm is greater than or equal to the second preset time threshold.

[0164] In some embodiments, encrypting the transmission data based on the encryption algorithm corresponding to the first sojourn time of the transmission data to obtain the encrypted transmission data includes: When the first sojourn time is greater than the first preset time threshold, encrypting the transmission data based on the second encryption algorithm to obtain the encrypted transmission data, and the processing time required by the second encryption algorithm is less than the second preset time threshold.

[0165] The first preset time threshold is a predefined threshold condition for judging the magnitude of the first sojourn time. The first preset time threshold can be the system default value, empirical value, artificially preset value, etc. or any combination thereof, and can be set according to actual needs, and this specification does not limit this.

[0166] In some embodiments, the first preset time threshold can be determined according to the processing capacity of the second terminal. Exemplarily, the first preset time threshold can be the receiving processing time of the second terminal, where the receiving processing time = the average processing time of the second terminal multiplied by the receiving frame rate.

[0167] Among them, the average processing time of the second terminal refers to the time required for the second terminal to process each frame of transmitted data. The average processing time of the second terminal reflects the processing capacity of the second terminal, which can be in milliseconds (ms) or seconds (s).

[0168] The reception frame rate refers to the number of frames of transmitted data received by the second terminal per unit time, which can be in frames per second (fps).

[0169] The second preset time threshold is a threshold condition for evaluating the magnitude of the processing time required by the encryption algorithm. The second preset time threshold can be a system default value, an empirical value, a manually preset value, etc. or any combination thereof, and can be set according to actual needs. This specification does not limit this.

[0170] The first encryption algorithm can provide higher security, but may require more processing time and computing resources. The second encryption algorithm can provide a faster processing speed, but the security may be lower than that of the first encryption algorithm.

[0171] In some embodiments, the first sojourn time is determined based on the data source of the transmitted data.

[0172] For different data sources, there are corresponding different first sojourn times, and their corresponding relationships can be determined based on experiments or experience.

[0173] In some embodiments, the method further includes: Obtaining the first sojourn time according to the average processing time, the preset coefficient corresponding to the data source, and the length of the queue where the transmitted data is located.

[0174] It should be noted that the average processing time for calculating the first sojourn time is the average processing time of the first terminal.

[0175] The average processing time refers to the time required for the first terminal to process and encrypt each frame of transmitted data on average. In some embodiments, the average processing time can be obtained through historical data statistics or dynamically adjusted through real-time monitoring.

[0176] The preset coefficient is a preset value used to adjust the calculation result of the first sojourn time. The preset coefficient can be determined based on factors such as the data source of the transmitted data, or set according to actual needs and experience.

[0177] In some embodiments, for different data sources (such as radar sensors, image acquisition devices, etc.), their corresponding preset coefficients are different, and their corresponding relationships can be determined based on experiments or experience. The preset coefficient reflects the complexity of encrypting the transmitted data of different data sources.

[0178] The length of the queue where the transmitted data is located represents the number of transmitted data queuing for transmission in the current transmission queue.

[0179] Exemplarily, based on the first sojourn time and the receiving and processing time of the transmitted data from different data sources, the radar data and the image data are judged: For the radar data, when the first sojourn time of the radar data is less than or equal to the receiving and processing time, it indicates that the DDS communication can process the encryption task of the radar data, the system load is low and the possibility of blocking is low, so a more complex encryption algorithm (e.g., Serpent) is selected; when the first sojourn time of the radar data is greater than the receiving and processing time, it indicates that the system load is high or the transmission queue is too long, so a lighter encryption algorithm (e.g., XTEA) is selected.

[0180] For the image data, when the first sojourn time of the image data is less than or equal to the receiving and processing time, it indicates that the DDS communication can process the encryption task of the image data, the system load is low and the possibility of blocking is low, so a more complex encryption algorithm (e.g., Serpent) is selected; when the first sojourn time of the image data is greater than the receiving and processing time, it indicates that the system load is high or the transmission queue is too long, so a lighter encryption algorithm (e.g., XTEA) is selected.

[0181] In some embodiments of this specification, by determining and distinguishing the queue lengths of different data sources and the average processing time of the first terminal, and multiplying by different preset coefficients, the first sojourn time of the transmitted data from different data sources is calculated, and the queuing time of the transmitted data from different sources can be accurately estimated. According to the sojourn time and the receiving and processing time, a suitable encryption algorithm is dynamically selected to ensure that there is no blocking or frame loss, and the smooth processing of real-time data can be guaranteed.

[0182] Figure 4 It is an exemplary flowchart of another data communication method shown in some embodiments of this specification. In some embodiments, this process can be executed based on a second terminal. As Figure 4 shown, this process includes the following steps.

[0183] Step 410, decrypt the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information.

[0184] Step 420, decrypt the data field in the encrypted data to obtain the decrypted transmitted data.

[0185] The encrypted data refers to the encrypted transmitted data sent by the first terminal. The identification field indicates the encrypted identification information in the encrypted data. The data field indicates the encrypted transmitted data in the encrypted data.

[0186] In some embodiments, the second terminal may extract the identification field and the data field of the encrypted data according to the flag bit in the encrypted data or according to a preset byte length. For example, the first 32 bytes may be used as the identification field, and the content of all subsequent bytes may be used as the data field.

[0187] In some embodiments, the second terminal may use the corresponding decryption algorithm to decrypt the identification field and the data field to obtain the decrypted identification information and the decrypted transmission data.

[0188] In some embodiments of this specification, by decrypting the identification field and the data field separately, the security of the data in the DDS communication is increased. Even if an attacker can decrypt the identification field, they still cannot access the actual data content; the identification field contains meta-information about the transmitted data, such as the data type, data source, etc. By encrypting the identification field, the meta-information can be hidden, reducing the chance for an attacker to obtain useful information.

[0189] In some embodiments, the identification field includes a first identification field and a second identification field, and the obtained decrypted identification information includes: Based on the first decryption method corresponding to the first encryption method, decrypt the first identification field to obtain the decrypted first identification information; Based on the second decryption method corresponding to the second encryption method, decrypt the second identification field to obtain the decrypted second identification information.

[0190] The first identification field is a part of the identification field and is used to indicate the data type of the encrypted data.

[0191] The second identification field is a part of the identification field and is used to indicate the data source of the encrypted data.

[0192] In some embodiments, the first decryption method can be implemented in various ways. For example, the first decryption method may include any one or a combination of deobfuscation processing, rearrangement, and XOR processing, depending on the first encryption method.

[0193] In some embodiments, the first encryption method includes obfuscation processing, rearrangement, and XOR processing. Based on the first decryption method corresponding to the first encryption method, decrypt the first identification field to obtain the decrypted first identification information, including: Perform XOR processing on multiple data units in the first identification field based on a key of a preset length to obtain the first decryption information; Rearrange the multiple data units in the first decryption information to obtain the second decryption information; Based on the associated information in the second decryption information and the preset mapping relationship, obtain the target data unit associated with the associated information to obtain the third decryption information as the decrypted first identification information.

[0194] The first decryption information is the first identification field after re - XOR. The second decryption information is the first identification field after rearrangement. The third decryption information is the first identification field after de - obfuscation.

[0195] For example, during encryption, assume the obfuscated first identification information is [D_0, D_1,..., D_{n - 1}], where D_0, D_1,..., D_{n - 1} are data units respectively. Rearrange the order of each data unit of the obfuscated first identification information according to the sequence sequence to obtain the rearranged first identification information [P_0, P_1,..., P_{n - 1}]; create a key with the same data length as the rearranged first identification information, which can be a randomly generated byte array, and perform an XOR operation on each data unit in the sorted first identification information and the corresponding key part one by one to achieve encryption. Specifically, for the rearranged first identification information [P_0, P_1,..., P_{n - 1}] and the key [K_0, K_1,..., K_{n - 1}], perform a byte - by - byte XOR operation to generate the XOR - after first identification information [P_0^K_0, P_1^K_1,..., P_{n - 1}^K_{n - 1}].

[0196] Use index permutation and XOR operation to disrupt the order of the original data units, and then encrypt each data unit based on the key, which further ensures the security of the identification information, and at the same time does not increase the computational amount during decryption, improving the decryption efficiency.

[0197] During encryption, each data unit is XOR - operated with the corresponding value in the key. During decryption, the same XOR operation needs to be performed again to obtain the original identification information.

[0198] For the first identification field [E_0, E_1,..., E_{n - 1}] and the key [K_0, K_1,..., K_{n - 1}], perform a byte - by - byte XOR operation to obtain the first identification field after re - XOR [E_0^K_0, E_1^K_1,..., E_{n - 1}^K_{n - 1}]. Due to the property of the XOR operation, E_i^K_i^K_i = E_i, and the first identification field after re - XOR can theoretically be the same as the rearranged first identification information.

[0199] Using the same sequential sequence, the first identification field after re - XOR is restored to the sequence corresponding to the original first identification information, that is, the first identification information after confusion. For example, if the first identification field after re - XOR can be [P_0, P_1,..., P_{n - 1}], then during decryption, it is restored to the original sequence according to the corresponding sequential sequence, and the rearranged first identification field obtained can be [D_0, D_1,..., D_{n - 1}].

[0200] The second terminal can also perform decryption based on the rearranged first identification field [D_0, D_1,..., D_{n - 1}] and the confusion matrix saved locally to obtain the first identification field after de - confusion, which is used as the decrypted first identification information.

[0201] It can be understood that the preset - length key used by the second terminal corresponds to the preset - length key used by the first terminal.

[0202] In some embodiments, decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: Performing a hash process on the decrypted identification information to obtain a second digest value corresponding to the decrypted identification information; Determining whether the second digest value is consistent with the digest field in the encrypted data to decrypt the data field in the encrypted data and obtain the decrypted transmission data.

[0203] The second digest value is used to represent the string obtained after performing a hash process on the decrypted identification information.

[0204] The digest field is used to represent the string obtained after the first terminal performs a hash process on the identification information.

[0205] In some embodiments, the hash process can be implemented based on a hash algorithm, such as SHA - 256, MD5, etc.

[0206] For example, to ensure that the identification information has not been tampered with, an integrity check mechanism can be used during the encryption process, such as performing a hash operation on the original identification information and performing a hash operation again for comparison during decryption: if the integrity check passes, it indicates that the identification information is successfully decrypted; otherwise, it indicates that an error has occurred during the transmission or storage of the identification information.

[0207] Exemplarily, the identification field is / xxx / xxx / xxx / xxx-000000, where 000000 may represent the digest field corresponding to the identification information. The subscriber may first decrypt the identification field to obtain the decrypted identification information, perform a hashing process on the decrypted identification information to obtain a second digest value, and determine whether the second digest value is consistent with the digest field in the encrypted data. The above description of the identification field is for illustrative purposes only and is only an example, not a limitation on the identification field.

[0208] In some embodiments, the second terminal may establish a secure communication link with the first terminal, obtain a first symmetric key, and based on the first symmetric key, decrypt the second identification field through a symmetric decryption algorithm to obtain the decrypted second identification information. The symmetric decryption algorithm corresponds to the symmetric encryption algorithm used by the first terminal to encrypt the second identification information.

[0209] In some embodiments of the present specification, by comparing the digest field and the second digest value, it helps to verify the integrity of the encrypted transmission data.

[0210] In some embodiments, decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: When the second digest value is consistent with the digest field in the encrypted data, decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0211] In some embodiments, when the second digest value is consistent with the digest field in the encrypted data, it is determined that the encrypted data is the data of the topic required by the second terminal, and the data field in the encrypted data is decrypted to obtain the decrypted transmission data.

[0212] In some embodiments of the present specification, by analyzing the second digest value and the digest field in the encrypted data, it helps to determine whether the encrypted data is the data of the topic required by the second terminal.

[0213] In some embodiments, decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: Based on the decryption algorithm corresponding to the encryption algorithm used by the first terminal, decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0214] In some embodiments, the first terminal (publisher) may record information related to the encryption algorithm used in the encrypted data and pass the information of the encryption algorithm to the second terminal (subscriber). The second terminal (subscriber) may determine the encryption algorithm used by the first terminal by parsing the encrypted data. For example, the first terminal may configure the information of the encryption algorithm in the identification field of the encrypted data. The first terminal may determine the encryption algorithm corresponding to the transmission data based on the first sojourn time. For more content on determining the corresponding encryption algorithm based on the first sojourn time, reference may be made to the relevant descriptions above.

[0215] In the DDS communication process, the method adopted by the related technology is to uniformly encrypt the serialized transmission data using a common encryption algorithm (such as the symmetric encryption algorithm aes), without distinguishing different data sources. However, when a certain encryption algorithm is fixed in the application, when the data volume of the transmission data at a certain moment is too large, problems such as reduced transmission rate, transmission blockage, long time-consuming for the host computer to receive, decrypt, and deserialize the data, resulting in frame loss may occur. Or, when the data volume of the transmission data is not very large, if the current hardware configuration is very good, that is, the bandwidth, domain controller, and host computer performance are all good, there is a problem that the hardware resources are not fully utilized. The embodiments of the present application use the sojourn time in the queue problem to estimate the possible time-consuming and the probability of possible frame loss in encryption or decryption, and dynamically adjust the relevant encryption algorithms to balance between encryption and ensuring no frame loss.

[0216] In some embodiments, the decrypted transmission data includes multiple types of sub-data, and the method further includes: Based on the policy corresponding to the type of the sub-data, perform deserialization processing on the sub-data to obtain the deserialized transmission data based on the deserialized sub-data.

[0217] For example, perform a first deserialization process on the first type of sub-data in the decrypted transmission data. The first deserialization process corresponds to the first serialization process to obtain the deserialized first type of sub-data; perform a second deserialization process on the second type of sub-data. The second deserialization process corresponds to the second serialization process to obtain the deserialized second type of sub-data.

[0218] Exemplarily, use boost deserialization to operate on the description information to obtain the deserialized first type of sub-data, use cdr deserialization to operate on multiple point data to obtain the deserialized second type of sub-data; based on the deserialized first type of sub-data and the deserialized second type of sub-data, obtain the deserialized transmission data.

[0219] In some embodiments, the original transmission data sent by the first terminal can be obtained based on the deserialized transmission data. For example, the deserialized transmission data can be used as the original transmission data sent by the first terminal. Different sub-data can use the serialization / deserialization method most suitable for its content to improve communication efficiency.

[0220] In some embodiments of this specification, the subscriber deserializes the sub-data using the corresponding policy according to the type of the sub-data, thereby restoring the original transmission data; deserializing based on the type of the sub-data enables the subscriber to process the received encrypted data more efficiently, flexibly, and reliably, ensuring the security and integrity of the data, while improving the overall performance and maintainability of the system.

[0221] In some embodiments, the method further includes: Based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold, a corresponding thread is created to decrypt the identification field in the encrypted data transmitted by the first terminal based on the thread to obtain the decrypted identification information, and to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0222] The second sojourn time refers to the time that the encrypted data stays in a certain stage (such as in a queue or a processing buffer).

[0223] The third preset time threshold is a preset time value used to determine whether a new thread needs to be created to process the encrypted data. The third preset time threshold can be preset according to parameters such as the average processing capacity, frame rate, and quality of service (QoS) requirements of the second terminal. The third preset time threshold can also be dynamically adjusted, for example, adjusted according to historical data or real-time monitoring results.

[0224] In some embodiments, the second terminal can calculate the second sojourn time based on a manner similar to that for determining the first sojourn time. For more content about the first sojourn time, reference can be made to the relevant description above.

[0225] In some embodiments, creating a corresponding thread based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold includes: When the second sojourn time is greater than or equal to the third preset time threshold, a first thread and a second thread are created. Wherein, the first thread is used to receive the encrypted data transmitted by the first terminal. The second thread is used to decrypt the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information, and to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

[0226] In the process of DDS communication, the time-consuming for decrypting data and storing the decrypted data to disk is relatively long. When the processor is occupied, it may not be able to subscribe to and publish new data in a timely manner. Especially when using a relatively complex encryption algorithm (or decryption algorithm) to process a large amount of data, frame loss may occur. In the embodiments of the present application, by setting a reasonable third preset time threshold based on the sojourn time in the queue problem, when the second sojourn time of a certain frame of data is too high, the four steps of the host computer subscribing to data, obtaining data, decrypting data, and storing the decrypted data to disk are divided into two multi-threaded operation modes. The main thread subscribes to data and obtains data, and the sub-thread decrypts data and stores the decrypted data to disk. In this way, the resource preemption of subscribing to data and obtaining data during the process of decrypting data and storing the decrypted data to disk is reduced, and the occurrence of frame loss is reduced.

[0227] In some embodiments, before performing DDS communication, the DDS communication environment in the second terminal can be initialized. For example, basic environments such as participants, topics, and data readers of DDS communication can be configured.

[0228] The first thread can be used as the main thread for subscribing to the transmission data of a specific topic. After receiving the encrypted data of the specific topic, the subscriber puts the encrypted data into the queue of the second thread for the second thread to process.

[0229] After the second terminal obtains the encrypted transmission data (i.e., encrypted data), it formats or packages it into a suitable intermediate format and stores it in the queue. Whenever new encrypted data is written into the queue, the queue notifies the sub-thread that there is new encrypted data to be processed, ensuring the efficiency and continuity of encrypted data acquisition.

[0230] The second thread can be used as the sub-thread for decrypting and storing the encrypted data to disk. For example, the sub-thread takes out the data from the queue and performs decryption operations. To ensure a short decryption processing time, an efficient decryption algorithm is used, and the integrity of the data is verified after decryption. The second thread can also convert the decrypted transmission data into a format suitable for writing to the database and write the decrypted transmission data into the database file. Exemplarily, batch writing or transaction writing methods can be used to reduce the impact of I / O operations on performance.

[0231] In some embodiments, when storing data to disk, an asynchronous I / O method can be used to better utilize system resources. If the amount of data is large, multiple data can be considered for batch processing to reduce the number of operations. After the operation is completed, the sub-thread notifies the main thread to prevent task accumulation and implement an error handling mechanism. For example, when decryption or storing to disk fails, a log is recorded and a retry is performed.

[0232] In some embodiments, a QoS (Quality of Service) policy can be configured to customize behaviors in DDS communication according to application requirements, such as attributes like reliability, persistence, history, etc. Different application scenarios may require setting different QoS policies to optimize performance or meet specific functional requirements.

[0233] In some embodiments, the event handling mechanism of DDS can be used. For example, more efficient data arrival processing can be achieved through callback functions. Blocking queues or other thread data structures can also be used to manage cross-thread data transfer.

[0234] In some embodiments, the system load can be evaluated and the number of threads in the publisher-subscriber mode can be dynamically adjusted to ensure the optimal utilization of system resources.

[0235] It should be noted that the above description of the process is only for illustration and example, and does not limit the scope of application of this specification. For those skilled in the art, various modifications and changes can be made to the process under the guidance of this specification. However, these modifications and changes are still within the scope of this specification.

[0236] Figure 5 is a schematic structural diagram of a data communication system shown in some embodiments of this specification.

[0237] Such as Figure 5 shown, in one or more embodiments of this specification, a schematic structural diagram of a data communication system is also provided. The data communication system can include a first terminal and a second terminal. The first terminal and the second terminal can communicate through DDS.

[0238] DDS communication is data-centric, and a topic is an identifier that uniquely identifies a certain type of data. Messages of a specific topic have a determined data type, and the data type is defined through basic types such as char, byte, int, etc. Exemplarily, the topic can be "TEXT", and the data type of the messages of this topic is char. DDS provides message interfaces for defining the message formats and data types of the messages to be sent and received. The message interfaces provided by DDS include write interfaces and read interfaces, etc.

[0239] The communication mode of DDS is a publisher-subscriber model. This publisher-subscriber model divides the system into several logically independent domains, and each domain contains several entities that complete tasks such as data publication, subscription, and other interactions. Entities include: domain participants, publishers, subscribers, topics, data writers, and data readers.

[0240] A domain is a scope concept, uniquely identified by a domain ID. Generally, entities within the same domain can communicate, and there is generally no logical relationship between entities in different domains. As the entry point of DDS, the domain participant is used to create topics, register data types, and manage entities such as publishers and subscribers.

[0241] The publisher is responsible for managing (such as creating and deleting) data writers. When registering as a data publisher in DDS, the publisher can declare the data type, topic, and describe the registered declaration information such as the provided QoS. The subscriber is responsible for managing (such as creating and deleting) data readers. When registering as a data subscriber in DDS, the subscriber can declare the data type, topic, and QoS it needs, as well as other registered declaration information.

[0242] A topic is an agreement between the first terminal (publisher) and the second terminal (subscriber) during communication. Each publisher and subscriber can be bound to a topic. The topics between communicating publishers and subscribers are the same. When the message communication mode is the topic mode, the topic includes a topic identifier. When the message communication mode is the method mode, the topic includes a method identifier. When the message communication mode is the parameter mode, the topic includes a parameter identifier.

[0243] Among them, the first terminal and the second terminal can be respectively used to execute the steps in the corresponding embodiments of the above data communication method. For the specific implementation manners of these terminals and more detailed content, reference can be made to the corresponding method part, and details will not be elaborated here one by one.

[0244] For the specific implementation of each of the above operations, reference can be made to the previous embodiments, and details will not be elaborated here.

[0245] Figure 6 It is a schematic structural diagram of an electronic device shown in some embodiments of this specification. As Figure 6As shown, the electronic device 600 may include: a processor 601 and a memory 602. The electronic device 600 may also include one or more of a multimedia component 603, an input / output (I / O) component 604, and a communication component 605. In this embodiment, the electronic device 600 may be a device for implementing the data communication method provided in this embodiment.

[0246] Among them, the processor 601 is used to control the overall operation of the electronic device 600 to complete all or part of the steps in the above data communication method. The memory 602 is used to store various types of data to support the operation of the electronic device 600. These data may include, for example, instructions for any application or method operating on the electronic device 600, as well as application-related data, such as contact data, sent and received messages, pictures, audio, video, and so on. The memory 602 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc. The multimedia component 603 may include a screen and an audio component. The screen can be, for example, a touch screen, and the audio component is used to output and / or input audio signals. For example, the audio component may include a microphone for receiving external audio signals. The received audio signal can be further stored in the memory 602 or sent through the communication component 605. The audio component also includes at least one speaker for outputting audio signals. The I / O component 604 provides an interface between the processor 601 and other interface modules, and the above other interface modules can be a keyboard, a mouse, buttons, etc. These buttons can be virtual buttons or physical buttons. The communication component 605 is used for wired or wireless communication between the electronic device 600 and other devices. Wireless communication, such as Wi-Fi, Bluetooth, Near Field Communication (NFC), 2G, 3G, 4G, Narrow Band Internet of Things (NB-IoT), Enhanced Machine Type Communication (eMTC), or other 5G, etc., or a combination of one or more of them, is not limited herein. Accordingly, the communication component 605 may include: a Wi-Fi module, a Bluetooth module, an NFC module, and so on.

[0247] In an exemplary embodiment, the electronic device 600 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors or other electronic components, and is used to execute the above data communication method.

[0248] In another exemplary embodiment, a computer-readable storage medium is further provided, on which a computer program is stored. When the program instructions are executed by a processor, the steps of the above data communication method are implemented. For example, the computer-readable storage medium may be the above-mentioned memory 602 including program instructions, and the above program instructions may be executed by the processor 601 of the electronic device 600 to implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application; Or, when the instructions are executed by a computer, the various methods, steps and logic block diagrams disclosed in the embodiments of the present application are implemented or executed.

[0249] In another exemplary embodiment, a computer program product is further provided, including a computer program or instructions. When the computer program or instructions are executed by a processor, the steps of the above data communication method are implemented. For example, the computer program product may be the above-mentioned memory 602 including a computer program, and the above computer program may be executed by the processor 601 of the electronic device 600 to implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application; Or, when the instructions are executed by a computer, the various methods, steps and logic block diagrams disclosed in the embodiments of the present application are implemented or executed.

[0250] Figure 7 It is an exemplary schematic diagram of a vehicle shown according to some embodiments of the present specification.

[0251] As Figure 7 shown, the present application further provides a vehicle, on which the electronic device, or the data communication system, or the terminal provided in any of the above embodiments is provided, and the electronic device is used to execute the steps of the data communication method provided in any of the above embodiments. Among them, the vehicle may be a fuel vehicle, a plug-in hybrid vehicle or a new energy vehicle, etc., and the present specification does not make specific limitations thereon.

[0252] In one embodiment, a vehicle may be configured to operate in a fully or partially autonomous driving mode. For example, while in the autonomous driving mode, the vehicle can control itself and can determine the current state of the vehicle and its surrounding environment through manual operation, determine the possible behavior of at least one other vehicle in the surrounding environment, and determine the confidence level corresponding to the likelihood of the other vehicle performing the possible behavior, and control the vehicle based on the determined information. When the vehicle is in the autonomous driving mode, the vehicle can be set to operate without interacting with a human.

[0253] In the description of the present application, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more features. In the description of the present application, "a plurality of" means two or more unless otherwise specifically defined.

[0254] In the embodiments, implementation manners and related technical features of the present application, they can be combined and replaced with each other without conflict.

[0255] The above are only the preferred embodiments of the present application and do not impose any form of limitation on the present application. Although in the embodiments of the present application, the descriptions of the various embodiments have their own emphases, for the parts not detailed in a certain embodiment, reference can be made to the relevant embodiments of other embodiments. However, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present application without departing from the content of the technical solution of the present application still fall within the scope of the technical solution of the present application.

Claims

1. A data communication method, characterized in that, Applied to a first terminal, the method includes: Encrypt the transmission data and the identification information corresponding to the transmission data, and transmit the encrypted identification information and the encrypted transmission data to a second terminal.

2. The method according to claim 1, wherein The identification information includes first identification information indicating the data type of the transmission data and / or second identification information indicating the data source of the transmission data.

3. The method according to claim 2, wherein The encrypting the identification information corresponding to the transmission data includes: Based on a first encryption method, encrypt the first identification information to obtain the encrypted first identification information; Based on a second encryption method, encrypt the second identification information to obtain the encrypted second identification information.

4. The method according to claim 3, wherein The first identification information includes a plurality of data units. The encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Based on a target data unit in the first identification information and a preset mapping relationship, obtain associated information associated with the target data unit to determine the encrypted first identification information, wherein the preset mapping relationship includes a mapping relationship between a preset data unit and associated information.

5. The method according to claim 4, wherein The target data unit includes a data unit corresponding to at least one of a service name, a sensor type, and a sensor location.

6. The method according to claim 3, characterized in that, The encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Rearranging a plurality of data units in the first identification information to obtain the encrypted first identification information.

7. The method according to claim 3, wherein The encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Based on a key of a preset length, perform an exclusive OR operation on a plurality of data units in the first identification information to obtain the encrypted first identification information.

8. The method according to claim 3, wherein The encrypting the first identification information based on the first encryption method to obtain the encrypted first identification information includes: Based on a target data unit in the first identification information and a preset mapping relationship, obtain associated information associated with the target data unit to obtain a first encrypted message; Rearranging a plurality of data units in the first encrypted message to obtain a second encrypted message; Based on a key of a preset length, perform an exclusive OR operation on a plurality of data units in the second encrypted message to obtain a third encrypted message to obtain the encrypted first identification information.

9. The method according to claim 3, wherein The encrypting the second identification information based on the second encryption method to obtain the encrypted second identification information: Based on a first symmetric key, encrypt the second identification information to obtain the encrypted second identification information.

10. The method according to claim 1, characterized in that, The method further includes: Perform a hashing process on the identification information to obtain a first digest value corresponding to the identification information; Transmit the first digest value, the encrypted identification information, and the encrypted transmission data to the second terminal.

11. The method according to claim 1, wherein The method further includes: Perform a serialization process on the transmission data to obtain a serialized transmission data to determine the encrypted transmission data.

12. The method according to claim 11, wherein The transmitted data includes multiple types of sub-data, and the serialization processing of the transmitted data to obtain the serialized transmitted data includes: Based on a policy corresponding to the type of the sub-data, performing serialization processing on the sub-data to obtain the serialized transmitted data based on the serialized sub-data.

13. The method according to claim 12, characterized in that, The performing serialization processing on the sub-data based on a policy corresponding to the type of the sub-data includes: Performing first serialization processing on the sub-data of the first type to obtain the serialized sub-data of the first type.

14. The method according to claim 13, wherein The importance level of the sub-data of the first type exceeds a preset importance level threshold, and / or the data volume of the sub-data of the first type does not exceed a preset data volume threshold, and the first serialization processing is used for serialization processing of complex data.

15. The method according to claim 13, wherein The sub-data of the first type includes the description information of the transmitted data.

16. The method according to claim 12, wherein The performing serialization processing on the sub-data based on a policy corresponding to the type of the sub-data includes: Performing second serialization processing on the sub-data of the second type to obtain the serialized sub-data of the second type.

17. The method according to claim 16, wherein The importance level of the sub-data of the second type does not exceed a preset importance level threshold, and / or the data volume of the sub-data of the second type exceeds a preset data volume threshold, and the second serialization processing is binary serialization processing.

18. The method according to claim 16, wherein The sub-data of the second type includes multiple point data of the transmitted data.

19. The method according to claim 1, characterized in that The method further includes: Encrypting the transmitted data based on an encryption algorithm corresponding to the first sojourn time of the transmitted data to obtain the encrypted transmitted data, where the first sojourn time is determined based on the data source of the transmitted data.

20. The method according to claim 19, wherein The encrypting the transmitted data based on an encryption algorithm corresponding to the first sojourn time of the transmitted data to obtain the encrypted transmitted data includes: In the case where the first sojourn time is less than or equal to a first preset time threshold, encrypting the transmitted data based on a first encryption algorithm to obtain the encrypted transmitted data, where the processing time required by the first encryption algorithm is greater than or equal to a second preset time threshold.

21. The method according to claim 19, wherein The encrypting the transmitted data based on an encryption algorithm corresponding to the first sojourn time of the transmitted data to obtain the encrypted transmitted data includes: In the case where the first sojourn time is greater than the first preset time threshold, encrypting the transmitted data based on a second encryption algorithm to obtain the encrypted transmitted data, where the processing time required by the second encryption algorithm is less than the second preset time threshold.

22. The method according to claim 19, wherein The method further includes: Obtaining the first sojourn time according to the average processing time, a preset coefficient corresponding to the data source, and the length of the queue where the transmitted data is located.

23. The method according to any one of claims 1 to 22, characterized in that The transmitted data is data collected by a vehicle.

24. A data communication method, characterized in that, Applied to a second terminal, the method includes: Decrypting an identification field in the encrypted data transmitted by a first terminal to obtain the decrypted identification information, so as to decrypt a data field in the encrypted data to obtain the decrypted transmitted data.

25. The method according to claim 24, wherein The identification field includes a first identification field and a second identification field, and the obtaining the decrypted identification information includes: Decrypt the first identification field based on the first decryption method corresponding to the first encryption method to obtain the decrypted first identification information; Decrypt the second identification field based on the second decryption method corresponding to the second encryption method to obtain the decrypted second identification information.

26. The method according to claim 24, wherein The decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: Performing a hashing process on the decrypted identification information to obtain a second digest value corresponding to the decrypted identification information; Determining whether the second digest value is consistent with the digest field in the encrypted data, so as to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

27. The method according to claim 26, wherein The decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: When the second digest value is consistent with the digest field in the encrypted data, decrypt the data field in the encrypted data to obtain the decrypted transmission data.

28. The method according to claim 24, wherein The decrypting the data field in the encrypted data to obtain the decrypted transmission data includes: Based on the decryption algorithm corresponding to the encryption algorithm used by the first terminal, decrypt the data field in the encrypted data to obtain the decrypted transmission data.

29. The method according to claim 24, wherein The decrypted transmission data includes multiple types of sub-data, and the method further includes: Based on the policy corresponding to the type of the sub-data, perform deserialization processing on the sub-data, so as to obtain the deserialized transmission data based on the deserialized sub-data.

30. The method according to claim 24, wherein The method further includes: Based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold, create a corresponding thread, so as to execute, based on the thread, the step of decrypting the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information, so as to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

31. The method according to claim 30, characterized in that, The creating a corresponding thread based on the relationship between the second sojourn time of the encrypted data and the third preset time threshold includes: When the second sojourn time is greater than or equal to the third preset time threshold, create a first thread and a second thread, wherein, the first thread is used to receive the encrypted data transmitted by the first terminal; The second thread is used to execute the step of decrypting the identification field in the encrypted data transmitted by the first terminal to obtain the decrypted identification information, so as to decrypt the data field in the encrypted data to obtain the decrypted transmission data.

32. A terminal, characterized in that, For implementing the data communication method according to any one of claims 1 to 31.

33. An electronic device, characterized in that, Including: A memory, on which a computer program is stored; A processor, configured to execute the computer program in the memory to implement the steps of the method according to any one of claims 1 to 31.

34. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 31 are implemented.

35. A computer program product, characterized in that, Including a computer program or instruction, when the computer program or instruction is executed by the processor, the steps of the method according to any one of claims 1 to 31 are implemented.

36. A vehicle, characterized in that, Comprising a terminal as described in claim 32, or an electronic device as described in claim 33, or performing the steps of the method according to any one of claims 1 to 31.

Citation Information

Patent Citations

  • Encryption method and encryption device

    CN104410501A

  • Data encryption method and device, computer device and storage medium

    CN109246130A

  • Data transmission method, device and system, electronic equipment and storage medium

    CN115408707A

  • Vehicle data transmission method and device, electronic equipment and storage medium

    CN119628915A

  • Charging facility data security protection method and system, electronic equipment and storage medium

    CN119854041A